Author Topic: New user, malware identified?  (Read 3810 times)

Offline splinetime

  • Newbie
  • *
  • Posts: 2
New user, malware identified?
« on: February 11, 2017, 06:20:22 AM »
Greetings,
I downloaded the most recent exe, ran it through the "VirusTotal" website. It identifies 2 serious malware/virus signatures:
Endgame showed    malicious (high confidence)
Invincea showed    virus.win32.sality.at

What is the deal? Is this software legit???

Thank You,
Kevin

Offline azslow3

  • Administrator
  • Hero Member
  • *****
  • Posts: 1692
Re: New user, malware identified?
« Reply #1 on: February 11, 2017, 11:20:58 AM »
Hi Kevin and welcome!

This software is legit, it is hand written by me. It is cross-compiled on Linux.

What I think is not legit is accusing software developers in distributing malware, without any reason nor consequences for such accusations. It is for years known that some "companies" declare almost everything complied by (open source!) GCC and/or distributed with NSIS installer (open source!) as viruses/malware.

One time Bitdefender has declared my site as malware distributing... many people could not open it then. I have written Bitdefender and they have removed my site from the black list. Silently. No explanation, no excuse... Note that per rules any website has available in open information of responsible person, with (real!) name, address, etc. It is easy to inform this person automatically when something bad is detected, but they do not do this.

To give you an idea how "helpful" these antivirus sites are. This week we had crypto-trojana at work. Usual thing, all files encrypted with the text file in the near how to get everything back...
I have uploaded this trojana to VirusTotal... CLEAN!  :o Sure we have alarmed the antivirus company we use and several hours later the file could be detected as crypto-beast also online. But that obviously was too late. Digging a bit more, I have found that there was already a publication in the Internet about this concrete version, 3 days ago.

I do not want spend my time writing all these "engines" to whitelist my programs after every release. I am not commercial company, so I do not care.

It is up to you to trust some concrete person, with which you can communicate directly, or some questionable "company". You can try to write them (I mean f.e. Endgame) and ask what they think about the problem. It will be interesting to know how fast and how informative they are ready to communicate with people they try to "defend"  ;)

Cheers,
Alexey.

Offline splinetime

  • Newbie
  • *
  • Posts: 2
Re: New user, malware identified?
« Reply #2 on: February 11, 2017, 04:49:04 PM »
First, I appreciate the prompt reply.
Second I truly appreciate your creating this masterpiece.

I wasn't accusing you of distributing malware, I was asking if it false positive'd :)

Didn't ask correctly, I meant to say is this signature result legit. :)

Cheers,
Kevin

Offline azslow3

  • Administrator
  • Hero Member
  • *****
  • Posts: 1692
Re: New user, malware identified?
« Reply #3 on: February 11, 2017, 09:08:49 PM »
Hi Kevin,

Sorry, english is not my mother language. I was not writing that you has accused me. In fact I appreciate your question, if no one asked be before I could be still unaware there is a problem.
I was writing that these antivirus companies are accusing me, without reason, without warning, without an explanation.

I would like to sign my software, but that will cost me 300 euro for the certificate. I already pay for this site and I am spending quite some time for the project. Even if I publish my paypal and collect money from those who are ready to pay just for the signature (and so for safety, signing is in fact very good idea), I still think that is unfair.
I can not use any open source signing since my project is not open source.
In general, I still can not decide how to proceed with that.

Cheers,
Alexey.