Posted May 17, 2020

Wrеn
GOG sells trojan horse malware
Registered: May 2011
From Taiwan

sanscript
Ltd. DeepSeeker
Registered: Jul 2011
From Norway

§pec†re
Reeeeeeeeeee!!!
Registered: Sep 2008
From United Kingdom
Posted May 17, 2020
It also helps to look at the date it was last scanned. Sometimes they try to sneak it into older versions of programs.

gogamess
RPG's
Registered: Dec 2013
From Spain
Posted May 18, 2020
Post edited May 18, 2020 by gogamess

gogamess
RPG's
Registered: Dec 2013
From Spain
Posted May 18, 2020


In most of the cases programmers changes or adds features/code/algorithms that may look like malware, and since malware scanners are based on known patterns, they produce false-positives relatively often. Especially given the nature of such programs. There's nothing nefarious about that, and it's up to the programmer to either change it again or verify it so that these malware scanners don't mark it as unsafe.
Version 20200404
- SFX module: removed UPX compression and compiled it as console application because of antiviruses

Why obsess about an old file when the new one has been confirmed to be clean, even the maintainer himself have explained it. Like I wrote, unless the maintainer is proven by several sources / sec researcher to be malicious, then you just have to trust it. And most importantly, unlike proprietary programs, this is open source, meaning you can take the source and build it yourself. If you still don't trust it - why even use it?

or maybe the ImDisk driver link: http://www.ltr-data.se/opencode.html/#ImDisk

I prefer the old one because it runs very well, and I've checked the new one, that is not an .exe file. The new file it's a zip that includes a files.cab installer and install.bat.
I've made a scan on Virustotal for the newest version (the .cab file) and it shows 60 clean engines and 1 alert:
Antiy-AVL Trojan/MSIL.Crypt
https://www.virustotal.com/gui/file/40ae0478497aa16ea4cbed919a0dc51e74f7733d46b269303a5968d7e4ded863/detection
So I get the version I've installed. Also the new one don't have great improvements.
Thank you ^_^

rtcvb32
echo e.lolfiu_fefiipieue|tr valueof_pi [0-9]
Registered: Aug 2013
From United States
Posted May 18, 2020
I tend to get it from the official download link. Curious. If there's some good new features in an off-branch might consider it.
Edit: I see the link for the toolkit on the official page now.
At this point i say it doesn't have a virus. I use AHK (AutoHotKeys) and it can get flagged as a virus. So it's likely a false positive.
Edit: I see the link for the toolkit on the official page now.
At this point i say it doesn't have a virus. I use AHK (AutoHotKeys) and it can get flagged as a virus. So it's likely a false positive.
Post edited May 18, 2020 by rtcvb32

gogamess
RPG's
Registered: Dec 2013
From Spain
Posted May 19, 2020
Thank you everyone for all your answers ^_^