Skip to content

Concerning processes #706

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
EgoHeroic opened this issue Mar 5, 2025 · 1 comment
Open

Concerning processes #706

EgoHeroic opened this issue Mar 5, 2025 · 1 comment
Labels
bug Something isn't working

Comments

@EgoHeroic
Copy link

EgoHeroic commented Mar 5, 2025

Did analysis of main.exe file and what processes it creates:

https://www.virustotal.com/gui/file/889737aecd220ef035babd1576341dd070db41f9f044a225505d8720ffaaa7f7/detection

This file enables Microsoft Compatibility Appraiser. Why? Why do I need telemetry for this to work? Why it constantly connects to Microsoft?

Plus all files: main, theme customizer, etc. is being flagged by defender.

@EgoHeroic EgoHeroic added the bug Something isn't working label Mar 5, 2025
@mathoudebine
Copy link
Owner

The Microsoft Compatibility Appraiser file operations are unrelated to this program.
Microsoft Compatibility Appraiser is a Windows scheduled task that starts/stops on predefined triggers. It seems to be enabled on the Virustotal sandbox the program has been run on. It is possible that the telemetry automatically starts to collect information on the new program.

The DNS resolution for www.microsoft.com is just standard behavior for the Microsoft Sysinternals sandbox, you can find similar behaviors on other analysis like https://www.virustotal.com/gui/file/8279696c1d78b14618500e9135886a3667b9decc65946f3729002e4bfdbb20ab/behavior

As for the flagging I wrote this article https://github.com/mathoudebine/turing-smart-screen-python/wiki/Troubleshooting#windows-installer--portable-zip-are-flagged-by-my-anti-virus
I will try to work on it but it is not easy because of the way this program is packaged and how it loads external dll

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants