Live data from Hacker News

Windows Defender blocks qBittorrent

github.com

331–340 of 345 posts

Re: Windows Defender blocks qBittorrent

#331

Earlier quoted context omitted.

This happened to me as well. Even when those keygens were in zipped files, Defender would flag them as malware and remove them automatically. The only solution I found to this was to keep the keygens in a password protected zipped files.

Interesting ideas here: how antivirus becomes a form of censorship. Maybe that’s an extreme view but it feels like now that Microsoft supplies it’s own defender app. And like all forms of martial law beginning as a way to protect citizens! I also noticed that with win10 when apps crash it sends the data to Microsoft—as though they can fix 3rd party apps for us. Yeesh. I think I’ll skip out on Windows 11 TYVM.

> I also noticed that with win10 when apps crash it sends the data to Microsoft—as though they can fix 3rd party apps for us

I don't develop software for any Microsoft platforms, but on the platform I develop for it's actually common for the vendor to break something in their API, so that crashes in 3rd party apps are actually due to a regression in the platform frameworks. Analyzing third-party crash reports could guide them in catching those cases.

Re: Windows Defender blocks qBittorrent

#332
post #268

Earlier quoted context omitted.

'For the vast, vast majority of its customers, keygen files are going to be malware.' That's just not true though. They have the ability to detect malware. What they are doing is blindly labeling anything reslembling a keygen as malware , for no valid reason. This also doesn't just apply to Defender.

> What they are doing is blindly labeling anything reslembling a keygen as malware First of all, that's not true. You can test it: create an empty file and name it keygen.exe. It won't get deleted. The code inside the file has some similarly to one of the hundreds of thousands of malware used to train Defender, and there's a false positive. None of that matters, though, because you can just not use it if it causes pr…

The problem is that "the hundreds of thousands of malware used to train Defender" include keygen files that do not have any malicious behavior and just generate keys, mixing them together with actually malicious keygens that e.g. try to install some rootkits. It's not a false positive mistake, it's a whole class of intentionally misleading false positives, censoring a type of not-malware that is not wanted by Microsoft but potentially desired by users.

Re: Windows Defender blocks qBittorrent

#333
post #12

Earlier quoted context omitted.

You mean the act of torrenting on its own would cause you to fall victim to malware, or that the process of finding a torrent via certain sites would do so?

Both. Plenty of malware-infested executables in torrents.

So of course double-clicking Band.of.Brothers.mkv.exe will cause you to have a bad time. But I'm curious why just having a torrent client downloading something would cause anyone to get compromised. I haven't heard of this.

Re: Windows Defender blocks qBittorrent

#334
post #328

Earlier quoted context omitted.

> using a then-popular Windows IDE If you're referring to Delphi, this has been a common issue for a long time. Delphi seems to have been very popular with malware writers, and so AV companies keep flagging stuff from the standard libraries as malware. Got so bad at one time that some tried to get a deal with the major AV players to provide a suite of very basic Delphi applications they could use for false-positive t…

Delphi produced (produces?) quite small executables, which was very desirable for malware writers.

I'd add small stand-alone executables. IIRC it was also quite popular in Europe in general, due to Pascal or Delphi being used at universities etc.

In recent times your average Delphi application has gotten rather bloated, but that's mainly due to RTTI, generics and certain standard library stuff. It's still quite possible to make small executables.

Re: Windows Defender blocks qBittorrent

#335

Earlier quoted context omitted.

> using a then-popular Windows IDE If you're referring to Delphi, this has been a common issue for a long time. Delphi seems to have been very popular with malware writers, and so AV companies keep flagging stuff from the standard libraries as malware. Got so bad at one time that some tried to get a deal with the major AV players to provide a suite of very basic Delphi applications they could use for false-positive t…

What about pre-.NET VB?

Those required prerequisites in the form of the VB runtime, so AFAIK not so popular. Also more limited or difficult to use in terms of writing malware.

Re: Windows Defender blocks qBittorrent

#336

Earlier quoted context omitted.

Hmm, many Linux distro are distributed via Torrent. As well as many video platform also use webtorrent. It is a just protocol like http. And when one is downloading a really large file, torrent can arguably be much better than direct download.

Sure, I use BitTorrent for Linux isos at work in a highly controlled environment, but for every one of me there would be hundreds pirating software at work, and tens accidentally killing their businesses bandwidth/quota by seeding too much.

For sure, then set the seeding and upload rate limit. In general torrent is still the more reliable (decentralised) ways to share large files.

Re: Windows Defender blocks qBittorrent

#337
post #194

Earlier quoted context omitted.

> One simple terminal command out of curiosity will basically force you to reinstall the OS. You mean like `sudo rm -rf /`? Would an equivalent command run by an admin on Windows not cause the same types of issues? Sure, there might be some files that can't be deleted while the system is running (like kernel32.dll or whatever it's called), but you'll certainly break a lot of things which you can only reasonably fix b…

I just reinstalled gnome manjaro. Not even an hour in and there is a major issue. I right clicked on the dock to get to Dash To Dock. I hit the super key at the same time an while that menu was up, I hit the settings button for the dash to dock. My dock blew up to ~200% in size, all my icons increased in size and I can no longer enter the settings for dash to dock. It just opens up an error that is very long and I'm…

> My dock blew up to ~200% in size, all my icons increased in size and I can no longer enter the settings for dash to dock. It just opens up an error that is very long and I'm not willing to resolve.

Because you personally don't know how to use it, the Linux desktop will never be taken seriously?

Imagine if a tech-illiterate person was using Windows, and then they accidentally enabled the option to hide the taskbar. If they were to throw their hands up and complain about how this shit doesn't work, you would probably think they were overreacting.

And if you send them some instructions on how to restore the task bar, and they reply with "instructions too long; I'm not willing to read all that, I'll just reinstall the operating system", you would probably think they were being ignorant and lazy.

I think the problem is that not everyone reacts differently to being made to feel stupid (which software frequently does to us): some people approach the situation with humility, other people get defensive and angry.

I see this a lot with programmers, where someone inherits another person's code and rather than attempt to understand it, they proclaim that it's shit and decide to rewrite it.

That's the only explanation I have for why so many tech literate people (incl' engineers) seem to completely shutdown when confronted with seemingly trivial issues. It has to be something emotional like that, because doesn't take much time or effort to look up how to fix whatever problem you're having. Sure, you might not need to "look up" how to do something on Windows, but you've also (probably) been using Windows for a very long time.

And with all that said, I would recommend you use KDE Plasma instead of Gnome, and a mainstream distro like Ubuntu (or Kubuntu, which comes preinstalled with KDE instead of Gnome).

Aside: Idk why people keep recommending Gnome to Linux newcomers. Gnome is basically a hyper-opinionated attempt to copy the worst parts of Windows/macOS/Android/iOS, and a half-assed attempt at that. KDE Plasma is an actually usable and mature desktop, and it should be much more familiar to people coming from Windows (which is probably the vast majority of people). I've been using it without issues for the past 6~7 years (never had to fix a broken thing, never had to copy and paste a magic command, and certainly never had to reinstall the operating system)

Re: Windows Defender blocks qBittorrent

#338
post #58

Earlier quoted context omitted.

Apple's mice haven't been single button since ages ago. Right click works out of the box, and all of their own mice also supports right clicking in various ways

Yet they still build the Magic mouse as though it was a single button mouse so it doesn't actually have 2 separate switches, just 1 in the middle. This annoyingly means that clicks don't always click if you're too far from the center. Apple has never actually built a mouse with 2 distinct switches for left and right click. It's like they are too proud or something and "right" click needs to be faked for some reason.

Sure, but to be fair, most laptops these days does the same.

Re: Windows Defender blocks qBittorrent

#339
post #27

Earlier quoted context omitted.

Many NirSoft utilities get detected. Not sure if it's still true, but back in the day it was surprisingly common to find them embedded in password stealing malware, it'd basically run a few different password dumpers, make a zip and send it off to an FTP site. Minimal software development knowledge necessary as the whole operation could be done from a batch script. Particularly bad malware too since anyone who revers…

Then wmic.exe should also be listed as PUA, as you can get the product key with it. Not even mentioning Powershell and CMD — average user never runs them, while bad people do that all the time. Their appearance in the process list is a sure sign that the system WUZ HAKKED.

Yeah, I'm pretty sure I've had to ignore every PUA detection in the book. They're completely useless, especially if you pirate Microsoft stuff or use "hacking tools" like netcat.

I'm not defending the behaviour, it's incredibly stupid, but it might have caught some legitimate malware in some cases where Defender itself was unable to detect the actual malicious portion.

Re: Windows Defender blocks qBittorrent

#340
post #28

I recently unpacked an old archive from the time I was making some shareware few decades ago. Windows Defender instantly ate all keygen.exe files from it. Those keygens were my own keygens for my own software (I wrote them myself and used them to generate keys for my customers back in the day).

Not to condone it's stupid behavior, but I believe it put them in Quarantine. They keep moving the setting location around but I believe the menu option to located them is called "Protection History" where you can see what action was taken and undo it.
Post reply on HN