eneam / mboxviewer

A small but powerfull app for viewing MBOX files
Other
432 stars 24 forks source link

Trojan? #33

Closed Girdauskas closed 2 years ago

Girdauskas commented 2 years ago

mboxview64.exe flagged this file as malicious

image

zigm commented 2 years ago

Thanks for raising the issue. This seems to be similar to the latest issue that was closed, see the closed issues.

If you have problem with Windows Defender, please run Windows Update to update the Windows Defender rules. Let me know if Windows Defender prevents you from running MBox Viewer.

Note also that the MBox Viewer package is scanned for malware by Sourceforge and no issues are reported.

Girdauskas commented 2 years ago

I used https://www.virustotal.com/ to check it. I noticed that only 1.0.3.32 version has this problem. The previous version 1.0.3.31 has no problems so I am using that.

zigm commented 2 years ago

This is the false positive detection by some tools. Great majority of tools didn't complain. The issue was reported also here

https://github.com/eneam/mboxviewer/issues/32

Not exactly sure why this tools report an issue. Obviously v1.0.3.32 has some new code which will be present in future releases.

zigm commented 2 years ago

In general if 55 tools report no malware, you can assume software is safe. Note that software downloaded from Sourceforge is scanned by BitDefender and no risk is reported, BitDefender in the report by virustotal.com you provided flags Variant.Lazy warning which seems to be ignored by Sourceforge scan, likely as not important.

Girdauskas commented 2 years ago

Zero detections are safe :)

zigm commented 2 years ago

Zero detection is safe(er) -:) and not necessarily safe. But not all tools have up to date rules as the latest case with Microsoft Defender illustrates. After the scan Microsoft Security decided that package is safe and updated the rules.

zigm commented 2 years ago

Windows Defender no longer reports false detection. BitDefender utilized by Sourceforge never reported any issues.