mboxviewer icon indicating copy to clipboard operation
mboxviewer copied to clipboard

Trojan?

Open Girdauskas opened this issue 2 years ago • 6 comments

mboxview64.exe flagged this file as malicious

image

Girdauskas avatar Jul 22 '22 10:07 Girdauskas

Thanks for raising the issue. This seems to be similar to the latest issue that was closed, see the closed issues.

If you have problem with Windows Defender, please run Windows Update to update the Windows Defender rules. Let me know if Windows Defender prevents you from running MBox Viewer.

Note also that the MBox Viewer package is scanned for malware by Sourceforge and no issues are reported.

zigm avatar Jul 22 '22 12:07 zigm

I used https://www.virustotal.com/ to check it. I noticed that only 1.0.3.32 version has this problem. The previous version 1.0.3.31 has no problems so I am using that.

Girdauskas avatar Jul 22 '22 13:07 Girdauskas

This is the false positive detection by some tools. Great majority of tools didn't complain. The issue was reported also here

https://github.com/eneam/mboxviewer/issues/32

Not exactly sure why this tools report an issue. Obviously v1.0.3.32 has some new code which will be present in future releases.

zigm avatar Jul 22 '22 14:07 zigm

In general if 55 tools report no malware, you can assume software is safe. Note that software downloaded from Sourceforge is scanned by BitDefender and no risk is reported, BitDefender in the report by virustotal.com you provided flags Variant.Lazy warning which seems to be ignored by Sourceforge scan, likely as not important.

zigm avatar Jul 22 '22 20:07 zigm

Zero detections are safe :)

Girdauskas avatar Jul 22 '22 21:07 Girdauskas

Zero detection is safe(er) -:) and not necessarily safe. But not all tools have up to date rules as the latest case with Microsoft Defender illustrates. After the scan Microsoft Security decided that package is safe and updated the rules.

zigm avatar Jul 23 '22 00:07 zigm

Windows Defender no longer reports false detection. BitDefender utilized by Sourceforge never reported any issues.

zigm avatar Nov 23 '22 05:11 zigm