IgorMundstein / WinMemoryCleaner

This free RAM cleaner uses native Windows features to optimize memory areas. It's a compact, portable, and smart application.
GNU General Public License v3.0
2.21k stars 146 forks source link

Virus Trojan Windows 10 #68

Closed Immersiiv closed 9 months ago

Immersiiv commented 9 months ago

Checklist

App version

2.6

Windows version

Windows 10 (Win32)

Steps To Reproduce

After two days of almost constant use I started up my computer, and the "WinMemoryCleaner" application asked me to grant it administration rights on my computer, Thinking it was normal, I gave it the rights, and a few seconds later,

Windows Antivirus detected a "Trojan:Win32" after automatically launching the application

Current Behavior

Live with antivirus and Windows security activated to remove and eliminate the problem :(

Expected Behavior

No response

Anything else?

IMG_20231218_173318

(ps : It's in French, but "Cheval de Troie" is Trojan virus)

IgorMundstein commented 9 months ago

That's a common issue that persists every time a new app version is released. I constantly submit the executable to Microsoft. Usually, it takes 24 hours to 48 hours for Microsoft to remove the detection.

Meanwhile, you can follow this procedure. https://support.microsoft.com/en-us/windows/add-an-exclusion-to-windows-security-811816c0-4dfd-af4a-47e4-c301afe13b26

The app adds entries to the registry and task scheduler to run the app on startup. Windows doesn't "like" apps with admin privileges running on startup. I get that, but this is the way to do it. I apologize, but the app can not deep clean the memory without admin privileges.

It helps if more users submit the app to Microsoft analysis. https://www.microsoft.com/en-us/wdsi/filesubmission

Untitled

Microsoft feedback e-mail

At this time, the submitted files do not meet our criteria for malware or potentially unwanted applications. The detection has been removed. Please follow the steps below to clear cached detections and obtain the latest malware definitions.

Open the command prompt as administrator.

  1. cd "c:\Program Files\Windows Defender"
  2. MpCmdRun.exe -removedefinitions -dynamicsignatures
  3. MpCmdRun.exe -SignatureUpdate

image

Similar reports

IgorMundstein commented 9 months ago

Added to Frequently Asked Questions (FAQ)