Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Shows as malware on VirusTotal #4306

Closed
CAINTECH opened this issue Apr 25, 2022 · 9 comments
Closed

Shows as malware on VirusTotal #4306

CAINTECH opened this issue Apr 25, 2022 · 9 comments
Labels
solution found workaround or user side solution avaiable win related to Windows pltform

Comments

@CAINTECH
Copy link

Gonna try MMEx for the first time. But the setup is showing as Malware in the VirusTotal Website

Link for the result - https://www.virustotal.com/gui/file/d69429294e937917271cf0384eba6e5b1c33e745a6cc2868b6b019b18db628f0/detection

@renato-mmex
Copy link

@CAINTECH
Copy link
Author

see: https://forum.moneymanagerex.org/viewtopic.php?p=22382&hilit=malware#p22382

I have no problem in installing the setup. I am only concerned about it being flagged by one of the AV. Just wanted to make sure if there is a virus or not. I can also see that malware reported by the person in the forum is different from what current Virustotal result shows.
Thanks

@PMaff
Copy link
Contributor

PMaff commented May 1, 2022

I get the same error when analyzing mmex-1.5.14-win64.exe :
VBA32 as the only one Antivirus says it is " Win32.Malware.Dropper.Heur" in his eyes.
"Heur" looks like some heuristic, which tend to make false positives.
Also if only 1 from 68 antivirus tools is flagging this, I tend to see it as false positive.

On the other hand one of the guys from VBA32 found Stuxnet virus...

@PMaff
Copy link
Contributor

PMaff commented May 1, 2022

@renato-mmex : do we know the libraries that are used in mmex for Windows?
Do we know the packing programs for mmex 1.5.14 ?

@whalley whalley added the win related to Windows pltform label May 2, 2022
@whalley
Copy link
Member

whalley commented May 3, 2022

Have reported the seemingly false positive to the VBA32 team. Will see what the response is.

@whalley
Copy link
Member

whalley commented May 4, 2022

VBA32 team has confirmed files are clean.... See below.

From: <feedback@anti-virus.by>
Date: Wed, 4 May 2022 10:47:08 +0300
Subject: Re: Potential false posiitive
Hello,
Files are clean. False positive will be removed in the next update.
Thank you.

03.05.2022 22:47, Mark Whalley пишет:

VirusTotal.com reports

VBA32 - Win32.Malware.Dropper.Heur

All other vendors report no issues, suspect this is a false positive.

For these files…

https://github.com/moneymanagerex/moneymanagerex/releases/download/v1.5.14/mmex-1.5.14-win32.exe
https://github.com/moneymanagerex/moneymanagerex/releases/download/v1.5.14/mmex-1.5.14-win64.exe

@ https://github.com/moneymanagerex/moneymanagerex/releases/tag/v1.5.14

Regards,
Mark

--
Best Regards, Alexey Gerasimenko,
mailto:feedback@anti-virus.by
VirusBlokAda Ltd., Minsk, Belarus

@whalley whalley added the solution found workaround or user side solution avaiable label May 4, 2022
@vomikan vomikan closed this as completed May 5, 2022
@PMaff
Copy link
Contributor

PMaff commented Jan 28, 2024

VBA32 still claims, that mmex has Win32.Malware.Dropper.Heur.
2 other also claim that there is malware for the exe:
1_7_0asmalware

Otoh I never heard of "Bkav Pro" or "Cynet". ;-)

@PMaff
Copy link
Contributor

PMaff commented Feb 5, 2024

I would not recommend to use scanners like "malwares.com URL checker", "URLQuery" or "URLhaus" for scanning exes on a webpage.
;-)
I'd rather scan the exe by uploading it to VirusTotal.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
solution found workaround or user side solution avaiable win related to Windows pltform
Projects
None yet
Development

No branches or pull requests

5 participants