geekhack

geekhack Community => Other Geeky Stuff => Topic started by: vonCheerios on Thu, 06 June 2019, 21:28:11

Title: Win10 found Virus in QMK Toolbox v.0.0.10.exe installer?
Post by: vonCheerios on Thu, 06 June 2019, 21:28:11
hola!!
I was recently following a write up (https://github.com/dvdizon/kbd75-qmk-guide/blob/master/README.md) on how to flash my newly built kbd75, and when following the step to install QMK Toolbox (https://github.com/qmk/qmk_toolbox/releases), Windows cancelled the install saying it found Trojan:Win32/Occamy.C (Details: This program is dangerous and executes commands from an attacker.) I ended up using QMK Flasher, which worked fine.
I'm new (obviously), what QMK firmware utility is typically used?
Thanks!
-Matt
Title: Re: Win10 found Virus in QMK Toolbox v.0.0.10.exe installer?
Post by: Leslieann on Thu, 06 June 2019, 21:59:41
This one seems legit and it's a hassle to clean out if you get it because the firmware will just reinstall it.

That said, it's always good to question this sort of thing.
A/V programs have long been known to target anything that tries accessing bare metal hardware like firmware. This is why you are supposed to disable your A/V when flashing bios. They have also been known to target pirated software (claiming a virus, in a deal with software developpers), or even free/open source software (to get you to buy closed source software). So yeah, don't just outright believe what they say. Some, like AVG and now Avast will even continue scanning for this even if you disable it, I stopped installing AVG on customer systems years ago over this behavior and am now doing the same with Avast.

In this cased though, why was anyone recomending you use software that is 0.0.10, jeebus that's irresponsible.
Title: Re: Win10 found Virus in QMK Toolbox v.0.0.10.exe installer?
Post by: vonCheerios on Fri, 07 June 2019, 07:44:13


In this cased though, why was anyone recomending you use software that is 0.0.10, jeebus that's irresponsible.

This is my first build, I don't know **** from Shinola, ;) I Googled how to flash the PCB, this link was one of the first to come up, and I assumed the software / version were legit.

Good times.

I use some NirSoft apps working in IT, and everyone of their programs is classified as virus'. I with you on the false positives/mis-classifications and AV..