View Single Post
  #1  
Old 02-02-2024, 17:39
argie argie is offline
Family
 
Join Date: Oct 2010
Posts: 278
Rept. Given: 85
Rept. Rcvd 86 Times in 38 Posts
Thanks Given: 267
Thanks Rcvd at 382 Times in 127 Posts
argie Reputation: 88
Packers and Microsoft Defender

Heya!

I recently have lot of issues with MSDefender deleting packed files. Packer is not pirated and there is no malware inside.

I literally wrote a "Hello World" program, packed it and immediately Defender flagged it as "Win32:Trojan-[pseudovariant] with threat level SEVERE.

This is quite annoying and I tried tons of different stuff to make it not detect but it is persistent like crazy. I even submitted the file to Microsoft and they marked it clean and removed from detection but after packing again and new 'pseudovariant' is detected. It's crazy.

Does anyone have any advice or atleast something to attempt to escape the Defender detection?

I tried the packed file on VirusTotal and it has like 13 detections (false postives) but nobody uses those AVs. But Defender is a bit different, it is used quite a lot.

Anyway, any tips would be welcome.
Reply With Quote