Windows Defender finds Win32/Wacepew.C!ml trojan horse in packed XLL

119 views
Skip to first unread message

Jiri Pik

unread,
Oct 31, 2023, 8:23:17 PM10/31/23
to Excel-DNA
For months, Windows Security has been removing the packed XLL from our build machine since it discovered there some alleged trojan horse - see below the screenshot. 

2023-11-01_08-15-31.png


The .dna definition is below. What is the best course of action ? 

<DnaLibrary Name="XXX.ExcelAddin.UDFs Add-In" RuntimeVersion="v4.0">
  <ExternalLibrary Path="XXX.ExcelAddin.UDFs.dll" LoadFromBytes="true" Pack="true" />
</DnaLibrary>

Jiri Pik

unread,
Nov 2, 2023, 1:37:37 AM11/2/23
to Excel-DNA
I have escalated to MS to stop flagging it as having a trojan horse. Let's see. 

Govert van Drimmelen

unread,
Nov 2, 2023, 11:20:03 AM11/2/23
to Excel-DNA
Hi Jiri,

This has been a problem for a while, since there were some malicious add-ins created with Excel-DNA.
It seems to be better with the current pre-release versions - 1.7.0-rc9 is the latest.
We tried some changes in the packing around version 1.5.1 that were particularly prone to being detected as problematic.
But with the current pre-release versions it does seem to depend a bit on what other code is in your add-in.

What version of Excel-DNA are you using?
Reporting the false positives to the anti-virus vendor is certainly the right plan, so they continue to improve their heuristics.

-Govert

Jiri Pik

unread,
Nov 3, 2023, 6:44:56 AM11/3/23
to Excel-DNA
We are using 1.6.0. The problem with Windows Security is that sometimes it detects it as a trojan and sometimes not. I believe that it is somehow associated with the speed of generation the xll files and CPU utilization of the build machine - the more CPU usage, the more likely it is to be labelled as a trojan horse.

Anyway, the latest version of Windows Security finds no problems and for now, all is good. 

Thanks, Govert, for all your help and the excellent library.

All my best from the sunny Singapore, 

Reply all
Reply to author
Forward
0 new messages