Trojan: Win32/Skeeyah.A!rfn

A place to report problems and bugs in SharpCap
Forum rules


If you have a problem or question, please check the FAQ to see if it already has an answer : https://www.sharpcap.co.uk/sharpcap-faqs

Please also read about Troubleshooting USB Issues before posting.

*** Please do not post license keys - please report any problems with licensing to 'admin' by private message ***

Please include the following details in any bug report:

* Version of SharpCap
* Camera and other hardware being user
* Operating system version
* Contents of the SharpCap log after the problem has occurred.
[If SharpCap crashes, please send the bug report when prompted instead of including the log]
Post Reply
perdrix
Posts: 4
Joined: Tue May 30, 2017 8:59 pm

Trojan: Win32/Skeeyah.A!rfn

#1

Post by perdrix »

Windows defender just reported it found the subject Trojan in the Sharpcap (un)installer.

Items:
file:C:\ProgramData\Package Cache\{990e3ac1-5282-4d65-a082-cd836a620e7e}\SharpCapInstall.exe
regkey:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{990e3ac1-5282-4d65-a082-cd836a620e7e}
uninstall:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{990e3ac1-5282-4d65-a082-cd836a620e7e}

I've no way to confirm this myself, but maybe you should contact MS about this?

HtH
Dave
perdrix
Posts: 4
Joined: Tue May 30, 2017 8:59 pm

Re: Trojan: Win32/Skeeyah.A!rfn

#2

Post by perdrix »

Web page for contact in this case is:

https://www.microsoft.com/en-us/securit ... actUS.aspx

Cheers
Dave
User avatar
admin
Site Admin
Posts: 13287
Joined: Sat Feb 11, 2017 3:52 pm
Location: Vale of the White Horse, UK
Contact:

Re: Trojan: Win32/Skeeyah.A!rfn

#3

Post by admin »

Thanks for letting me know... I am starting to *hate* antivirus... I have reported the false +ve with Microsoft, but also taken the quicker step of rebuilding the latest version of 2.9 with a new build number and Windows Defender is quite happy with that! Shows how brilliant anti-virus is when a change in the build number is all that is needed to stop the false positive...

For reference, it's the uninstaller for 2.9.3085 that's being flagged. The actual installed application runs fine!

cheers,

Robin
Post Reply