Menu

#5 A trojan virus for windows defender

1.2.0.0
closed
None
2016-10-21
2016-10-15
No

Hello,
I'm trying to use MaxLauncher 1.2 but each time the exe file is suppressed by Windows Defender because it is identified to be a trojan.

Discussion

  • madproton

    madproton - 2016-10-15
    • assigned_to: madproton
    • Milestone: 1.0.0.0 --> 1.2.0.0
     
  • madproton

    madproton - 2016-10-15

    Hi,

    Scan Results Summary(on my system):

    1. I am using Norton and NO virus was found. I think Sourceforge scans all uploads too.
    2. I scanned with Windows 10/Defender and NO virus was found.
      Windows 10 / Windows Defender Engine and Definitions versions:
      Antimalware Client Version: 4.10.14393.0
      Engine Version: 1.1.13103.0
      Antivirus definition: 1.229.1736.0
      Antispyware definition: 1.229.1736.0
      Network Inspection System Engine Version: 2.1.12706.0
      Network Inspection System Definition Version: 116.33.0.0

    Questions:

    1. Did you download the file from Sourceforge.net (https://sourceforge.net/projects/maxlauncher/files/MaxLauncher/1.2.0.0/)? Sorry, I just want to make sure.
    2. What version of Windows are you using?
    3. What is the Engine and Definitions versions? ( In Windows Defender window, click Help -> About)

    Verify Hashes to be sure:

    1. Download a Hashing program. I like Hashcodes (https://sourceforge.net/projects/hashcodes/?source=directory). It is a GUI, can me made portable, simple and easy to use. You can also try FCIV by Microsoft which is a command line tool(download at https://www.microsoft.com/en-us/download/details.aspx?id=11533). Documentation is at https://support.microsoft.com/en-us/kb/889768

    2. Compare hash values. The hash values of MaxLauncher files are on the download page (https://sourceforge.net/projects/maxlauncher/files/MaxLauncher/1.2.0.0/). Click the round icon with an "i" next to the file. I verified the version 1.2 files' hashes on the sourceforge download page with the hashes of the files on my local drive.

    This is the only practical way I know of, to check if a program/file is at least the same program/file the developer(me) created. Anti-virus programs seldom flag legitimate and clean files as having a virus or malware but it happens.

    The absolute way to verify if a program is clean is to download the source code (which is available for MaxLauncher), review every line of code and compile it yourself. This method however is very impractical but maybe necessary in some situations.

    Good luck!

     
  • Kamel Gharbi

    Kamel Gharbi - 2016-10-21

    Hello,
    Thank-you.

    Yes i download it from sourceforge but it was the portable version.

    I've donwload it again and analyzed it once again with virustotal, malwerbytes and windows defender and it's clean no problem at all.

    Now it works fine, sorry i don't know where the problem was coming from.

     
  • madproton

    madproton - 2016-10-21

    You're welcome.

     
  • madproton

    madproton - 2016-10-21
    • status: open --> closed
     

Log in to post a comment.

MongoDB Logo MongoDB