-
Notifications
You must be signed in to change notification settings - Fork 173
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Virus; Trojan.Gen.MBT #56
Comments
Not sure what file the link is pointing to or if the file is packed such that the scanner does not detect it. When I downloaded mingwInstaller.exe, Norton said it was OK, see below. But after I ran it, Norton detected the virus. Filename: mingwInstaller.exe Developers Version Identified Last Used Startup Item Few Users Mature Good Source File: Performance Avg. Resource Usage: Moderate File Thumbprint - SHA: |
guys, mingwInstaller is a separate project hosted on: https://github.com/Vuniverse0/mingwInstaller so I think this is a false positive... |
Moreover, VirusTotal says that there are no problems: https://www.virustotal.com/gui/file/68214ff3d9ddd74538d7d96001173c952284b4c6b62608f6c3fcc447feca1a5d |
Norton said the same thing till I ran it. I guess the bad guy are really good at hiding their tracks |
Eset Endpoint (corporative) - no reaction |
Was Eset Endpoint & Eset Antivirus only used to check "mingwInstaller.exe" before it was run? |
I tried to run it under Endpoint. |
No, it definitely does not look like a false positive! Even Windows Defender is telling me it is a trojan malware. I put it to VirusTotal as well and 23 vendors marked it as a malware (compared to 10 in the screenshot above). I downloaded x86_64-13.2.0-release-win32-seh-msvcrt-rt_v11-rev0.7z. Here is my result from VirusTotal. |
Hmmm... |
this is definitely a false positive. |
@niXman The problem is that people will plain refuse to install something reported by popular antivirus software |
and? how can I affect this? |
guys, does anyone know where this dll comes from? |
I suppose this is just beginning of the end of the "free access" to the msvcrt. |
There are no problems with ucrt. |
openssl |
Hello, |
Just checked with Virustotal: no problems with gcov, padlock marked by AI of "Bkav Pro". |
Norton 360 found a the virus Trojan.Gen.MBT in your download mingwInstaller.exe
I downloaded from https://github.com/niXman/mingw-builds-binaries
See Norton's report below
Filename: padlock.dll
Threat name: Trojan.Gen.MBTFull Path: C:\Users\wmcre\mingw64\opt\lib\engines-3\padlock.dll
On computers as of
10/12/2023 at 2:31:20 AM
Last Used
10/12/2023 at 2:31:20 AM
Startup Item
No
Launched
No
Threat type: Virus. Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
padlock.dllThreat name: Trojan.Gen.MBT
Locate
Few Users
Fewer than 50 users in the Norton Community have used this file.
New
This file was released 10 days ago.
High
This file risk is high.
Source: External Media
File Actions
File: C:\Users\wmcre\mingw64\opt\lib\engines-3\padlock.dllBlocked
File Thumbprint - SHA:
Not available
File Thumbprint - MD5:
Not available
The text was updated successfully, but these errors were encountered: