LiEnby / FlashPatcher

.NET program to remove timebomb from Adobe Flash Player
MIT License
125 stars 19 forks source link

Trojan #7

Closed JManiaGitHub closed 3 years ago

JManiaGitHub commented 3 years ago

i need explanations for this, i downloaded the file, and 27 engines verified as a trojand and wen i downloaded it windows defender (windows 10) detected as a trojan. I was happy about you made this to help people scape from the flash kill switch, if youre trying to spy, stole information or corrupt people sistem youre a jerk, I WANT THIS TO BE FIXED IN NEW VERSIONS, my pc verified it as a: Trojan:Win32/Ymacco.AA4F and virus total verified and it says 27 ENGINES recognises as a trojan, i downloaded the open source, compiled it, and windows defender didnt verified it as a trojand but virus total did, i order you to remove the malware,i see the otheer trojan issue, and the ´´MSIL Heracles´´ youre talk about IS A VIRUS, remove it. I DEMAND IT

LiEnby commented 3 years ago

no shit its a virus- and i cant remove what im not adding lol?

im interested in how ur compiling it when i compile it it comes up w the same stuff in virustotal every time- its possible my computer is infected w one of those viruses and adding its code to my executable every time i build-

wether i build it as debug or release, the only difference is when i build it it doesnt get detected by Windows Defender but the results on say virustotal.com are the same,

image so i had a look in ILSpy to be sure but cant find anything- u could take a look if u want, going by the name "MSIL." suggests its a .NET based trojan so it should be in there if there was anything,

anyway, im not quite sure whats causing this. or how to fix it u say to remove something but im not adding anything into it .

JManiaGitHub commented 3 years ago

thanks for the reply, lattely i tryed to run the program while windows defender detects the thing, just for testing, i downloaded and runned your file and windows defender detected it, i runned anyway and after some time it says 1 .tmp file is infected by the trojan, and 1 dll file but that 2 was in the recicle bin directory like this: C:\$Recycle.Bin\S-1-5-21-4049534216-3128172814-432659357-1001\$RX88E1C\S6ML_SETUP\msimg32.dll. Then i just wipe the data in the recicle bin and windows defender got calm again, idk why is at the recicle bin but the flash worked at my browser, thanks for the program but im fearing your software is doing something to my pc. (obs: i discovered your software a month ago and maked a tuturial with your program)

LiEnby commented 3 years ago

i commented out all the functions in the program and compiled it and it still says its trojan shit wtf

then i changed the GUID to something new and now it claiming its a completely different 'trojan' xD

LiEnby commented 3 years ago

EDIT2: changed the namespace name, guid and some other random shit and now its only detected by 4/67 rather than 47/67,

this makes me question how effective AV really is tbh, if all thats required is to rename some shit, but whatever it wasnt a vius to begin with so-

i dont understand why but, resolved!

https://www.virustotal.com/gui/file/e42ed7cd4aa13bf2f897046b5217b75f92cfa20e822657c40bdd93840a7485db/detection