Question VMware isolation and AV block on Host??

Please provide comments and solutions that are helpful to the author of this topic.

simmerskool

Level 41
Thread author
Verified
Top Poster
Well-known
Apr 16, 2017
3,057
Running the current version VMware Workstation 17... host win10 -- fedora 42 is Guest. been running fedora many months, no issues. The AV on Host win10 is DeepInstinct. I do allow copy & paste between Host & Guest, but not "drag & drop." I opened firefox in fedora and purchased an item with paypal. During this transaction on Guest fedora, I used my iphone to get two factor authentication code (2fa) for paypal and entered the 6-digit code 2fa code into firefox on Guest and it was accepted and transaction completed and order confirmed. All good, but...

Contemporaneously during the transaction I got a Host DeepInstinct blockage alert > C:\Program Files\WindowsApps\Microsoft.YourPhone_1.25032.76.0_x64__8wekyb3d8bbwe\SharedUtilities.QrCodeGenerator.dll

How / why is the possible? I never touched the Host during this transaction. The 2fa code was on my iphone, it never touched the host, I manually typed the 2fa code from keyboard into federa Guest firefox to verify the paypal payment. How could DeepInstinct on Host even react to my eyeballs reading 2fa code on iphone and typing it into Guest OS. As far as I know, all computer are "clean" and my iphone is not linked to Host win10, never has been. And I maybe get one alert from DeepInstinct every 3 or 4 months, and never got one about QrCodeGenerator.dll before and I was NOT generating a QRcode during the transaction. Seems doubtful it was a coincidence and unrelated to the transaction, but WTF? Is it safe?
 

Bot

AI-powered Bot
Apr 21, 2016
4,890
It seems like a false positive from DeepInstinct. The alert might not be related to your transaction. The DLL in question is related to the "Your Phone" app in Windows 10, which is used to link your phone and PC. It's possible that DeepInstinct flagged it due to some routine operation. If you're not using the "Your Phone" app, you might consider disabling it. However, to be on the safe side, you should also run a full system scan to ensure there's no malware.
 
Upvote 0

bazang

Level 14
Jul 3, 2024
661
Running the current version VMware Workstation 17... host win10 -- fedora 42 is Guest. been running fedora many months, no issues. The AV on Host win10 is DeepInstinct. I do allow copy & paste between Host & Guest, but not "drag & drop." I opened firefox in fedora and purchased an item with paypal. During this transaction on Guest fedora, I used my iphone to get two factor authentication code (2fa) for paypal and entered the 6-digit code 2fa code into firefox on Guest and it was accepted and transaction completed and order confirmed. All good, but...

Contemporaneously during the transaction I got a Host DeepInstinct blockage alert > C:\Program Files\WindowsApps\Microsoft.YourPhone_1.25032.76.0_x64__8wekyb3d8bbwe\SharedUtilities.QrCodeGenerator.dll

How / why is the possible? I never touched the Host during this transaction. The 2fa code was on my iphone, it never touched the host, I manually typed the 2fa code from keyboard into federa Guest firefox to verify the paypal payment. How could DeepInstinct on Host even react to my eyeballs reading 2fa code on iphone and typing it into Guest OS. As far as I know, all computer are "clean" and my iphone is not linked to Host win10, never has been. And I maybe get one alert from DeepInstinct every 3 or 4 months, and never got one about QrCodeGenerator.dll before and I was NOT generating a QRcode during the transaction. Seems doubtful it was a coincidence and unrelated to the transaction, but WTF? Is it safe?
Hair on Fire

Coincidence

False Positive

Disconnect your iPhone if it is connected to your PC via the Phone App; just do not use it
 
Upvote 0

simmerskool

Level 41
Thread author
Verified
Top Poster
Well-known
Apr 16, 2017
3,057
Hair on Fire

Coincidence

False Positive

Disconnect your iPhone if it is connected to your PC via the Phone App; just do not use it
Well I suggested it could be a coincidence, just seems unlikely (to me). My iphone is not connected to my Host or to the Guest. Phone App on win10 was not running, I have never used it. Issue is not whether it is a DeepInstinct false positive, but how could DI react to it at all, unless it wasn't and it was a coincidence. seems unlikely. The event is being analyzed, by real IT person, will report more if I hear anything of value.
PS DI blocked it as a "dropper" using Deep Static Analysis.
 
Upvote 0

bazang

Level 14
Jul 3, 2024
661
Well I suggested it could be a coincidence, just seems unlikely (to me). My iphone is not connected to my Host or to the Guest. Phone App on win10 was not running, I have never used it. Issue is not whether it is a DeepInstinct false positive, but how could DI react to it at all, unless it wasn't and it was a coincidence. seems unlikely. The event is being analyzed, by real IT person, will report more if I hear anything of value.
PS DI blocked it as a "dropper" using Deep Static Analysis.
Coincidence

False positive

The two events are not connected in any way
 
  • Thanks
Reactions: simmerskool
Upvote 0

Vitali Ortzi

Level 30
Verified
Top Poster
Well-known
Dec 12, 2016
1,961
Running the current version VMware Workstation 17... host win10 -- fedora 42 is Guest. been running fedora many months, no issues. The AV on Host win10 is DeepInstinct. I do allow copy & paste between Host & Guest, but not "drag & drop." I opened firefox in fedora and purchased an item with paypal. During this transaction on Guest fedora, I used my iphone to get two factor authentication code (2fa) for paypal and entered the 6-digit code 2fa code into firefox on Guest and it was accepted and transaction completed and order confirmed. All good, but...

Contemporaneously during the transaction I got a Host DeepInstinct blockage alert > C:\Program Files\WindowsApps\Microsoft.YourPhone_1.25032.76.0_x64__8wekyb3d8bbwe\SharedUtilities.QrCodeGenerator.dll

How / why is the possible? I never touched the Host during this transaction. The 2fa code was on my iphone, it never touched the host, I manually typed the 2fa code from keyboard into federa Guest firefox to verify the paypal payment. How could DeepInstinct on Host even react to my eyeballs reading 2fa code on iphone and typing it into Guest OS. As far as I know, all computer are "clean" and my iphone is not linked to Host win10, never has been. And I maybe get one alert from DeepInstinct every 3 or 4 months, and never got one about QrCodeGenerator.dll before and I was NOT generating a QRcode during the transaction. Seems doubtful it was a coincidence and unrelated to the transaction, but WTF? Is it safe?
Probably 2fa was sent to an account connected to the PC specifically to the phone app and when the PC tried showing the 2fa deep instinct falsely saw the behavior as malicious
At least that's what I think happened
 
Upvote 0

simmerskool

Level 41
Thread author
Verified
Top Poster
Well-known
Apr 16, 2017
3,057
Probably a coincidence but since you don't use the Your Phone app, I suggest you to uninstall it.
I never directly intentionally installed Your Phone in first place. I assume it came with some MS update. Also very difficult to access C:\Program Files\WindowsApps\ -- chatGPT says it can be done but need to mess with Group Policies which I'm not using. But yes, ChatGPT also said uninstall it -- I will. Still waiting for more_feedback from DeepInstinct analyst who can inspect my portal.
 
Upvote 0

simmerskool

Level 41
Thread author
Verified
Top Poster
Well-known
Apr 16, 2017
3,057
Probably 2fa was sent to an account connected to the PC specifically to the phone app and when the PC tried showing the 2fa deep instinct falsely saw the behavior as malicious
At least that's what I think happened
sounds logical, but I have never used Your Phone on win10_Host (that I know of) and I checked Start Apps and Your Phone is/& was checked OFF (disabled). Maybe Quantum spooky action at a distance...
EDIT PS the win10_host running DeepInstinct is also running Cyberlock on smart-aggressive mode AND something triggered the DI block popup flag.
 
Last edited:
Upvote 0

SeriousHoax

Level 51
Verified
Top Poster
Well-known
Mar 16, 2019
4,024
I never directly intentionally installed Your Phone in first place. I assume it came with some MS update. Also very difficult to access C:\Program Files\WindowsApps\ -- chatGPT says it can be done but need to mess with Group Policies which I'm not using. But yes, ChatGPT also said uninstall it -- I will. Still waiting for more_feedback from DeepInstinct analyst who can inspect my portal.
Your Phone comes with Windows by default. I think you have HiBit Uninstaller, right? You can use it to uninstall the app. I think you would find it in HiBit's, Windows Store App Manager section in Tools.
 
Upvote 0

bazang

Level 14
Jul 3, 2024
661
Running the current version VMware Workstation 17... host win10 -- fedora 42 is Guest. been running fedora many months, no issues. The AV on Host win10 is DeepInstinct. I do allow copy & paste between Host & Guest, but not "drag & drop." I opened firefox in fedora and purchased an item with paypal. During this transaction on Guest fedora, I used my iphone to get two factor authentication code (2fa) for paypal and entered the 6-digit code 2fa code into firefox on Guest and it was accepted and transaction completed and order confirmed. All good, but...

Contemporaneously during the transaction I got a Host DeepInstinct blockage alert > C:\Program Files\WindowsApps\Microsoft.YourPhone_1.25032.76.0_x64__8wekyb3d8bbwe\SharedUtilities.QrCodeGenerator.dll

How / why is the possible? I never touched the Host during this transaction. The 2fa code was on my iphone, it never touched the host, I manually typed the 2fa code from keyboard into federa Guest firefox to verify the paypal payment. How could DeepInstinct on Host even react to my eyeballs reading 2fa code on iphone and typing it into Guest OS. As far as I know, all computer are "clean" and my iphone is not linked to Host win10, never has been. And I maybe get one alert from DeepInstinct every 3 or 4 months, and never got one about QrCodeGenerator.dll before and I was NOT generating a QRcode during the transaction. Seems doubtful it was a coincidence and unrelated to the transaction, but WTF? Is it safe?
VMWare Workstation and VirtualBox do not fully isolate the real physical system (Host) from the virtual machine (Guest). At least not by default, anyway.

You have to do the research and figure out all the hardening that is required to effectively isolate the Host system from the virtual machine (Guest).

Virtual machines write files to your Host file system by default - and I am not talking about file sharing. I am talking about files created by VMWare or VirtualBox on the Host during its operation - unknown by you.
 
  • Hundred Points
Reactions: simmerskool
Upvote 0

simmerskool

Level 41
Thread author
Verified
Top Poster
Well-known
Apr 16, 2017
3,057
Your Phone comes with Windows by default. I think you have HiBit Uninstaller, right? You can use it to uninstall the app. I think you would find it in HiBit's, Windows Store App Manager section in Tools.
well I discussed removing YourPhone with chatGPT and it suggested powershell commands as yourphone was in \program files\windowsapps\ which the system highly protects. I learned some stuff today! GPT also suggested O&O appbuster but it did not even see YourPhone. Has anyone used the O&O appbuster? Eventually we got YourPhone removed w/ps. & GPT suggested several ms apps that can be removed as unnecessary and rarely used that are listed by O&O.
 
Upvote 0

simmerskool

Level 41
Thread author
Verified
Top Poster
Well-known
Apr 16, 2017
3,057
VMWare Workstation and VirtualBox do not fully isolate the real physical system (Host) from the virtual machine (Guest). At least not by default, anyway.

You have to do the research and figure out all the hardening that is required to effectively isolate the Host system from the virtual machine (Guest).

Virtual machines write files to your Host file system by default - and I am not talking about file sharing. I am talking about files created by VMWare or VirtualBox on the Host during its operation - unknown by you.
chatGPT suggested that VMware Tools might have been doing something like that under the hood. But it was also "concerned" that DeepInstinct alerted to dll as as "dropper" & deep static analysis pe64. I removed yourphone.
 
Upvote 0

piquiteco

Level 14
Verified
Top Poster
Well-known
Oct 16, 2022
641
I am headed toward putting a linux distro on hardware. I've been practicing with linux in VM for several months. :D
Good to know, I've just installed VirtualBox on Linux Mint, it's super light, I believe that if you use it on Linux you'll get more performance depending on the distribution and that's an advantage, apart from the security you get if you do Malware tests. ;)
 
  • Like
Reactions: simmerskool
Upvote 0

simmerskool

Level 41
Thread author
Verified
Top Poster
Well-known
Apr 16, 2017
3,057
Good to know, I've just installed VirtualBox on Linux Mint, it's super light, I believe that if you use it on Linux you'll get more performance depending on the distribution and that's an advantage, apart from the security you get if you do Malware tests. ;)
I've used VB in more distant past, but then no vm's, then about a year or 2 ago I started with VMware Workstation 15 (paid) and learned it pretty quickly, and runs great. But open to trying VB again -- not testing malware, just trying to avoid it :LOL:
 
  • Like
Reactions: piquiteco
Upvote 0

piquiteco

Level 14
Verified
Top Poster
Well-known
Oct 16, 2022
641
I've used VB in more distant past, but then no vm's, then about a year or 2 ago I started with VMware Workstation 15 (paid) and learned it pretty quickly, and runs great.
I agree with you that Vmware is better than VB, but there is VMware for Linux and you can install it one day to try it out, as far as I know VMware for Linux is similar to VMware for Windows. ;)
 
Upvote 0

SeriousHoax

Level 51
Verified
Top Poster
Well-known
Mar 16, 2019
4,024
well I discussed removing YourPhone with chatGPT and it suggested powershell commands as yourphone was in \program files\windowsapps\ which the system highly protects. I learned some stuff today! GPT also suggested O&O appbuster but it did not even see YourPhone. Has anyone used the O&O appbuster? Eventually we got YourPhone removed w/ps. & GPT suggested several ms apps that can be removed as unnecessary and rarely used that are listed by O&O.
Yeah, in fact mine was deleted using O&O AppBuster. I use AppBuster for deleting Windows Store apps only. But since you had HiBit I thought that should do the job also. Using powershell commands to remove left some files behind when I tried a few years ago. But I think there are also powershell command that can completely get rid off it. Anyway, good to get the confirmation that DI detection was just a coincidence.
 
  • Like
Reactions: Gandalf_The_Grey
Upvote 0

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top