snowie2000 / mactype

Better font rendering for Windows.
https://mactype.net
GNU General Public License v3.0
9.78k stars 439 forks source link

mt64agnt.exe Trojan by McAfee #916

Open phillipenzo opened 1 year ago

phillipenzo commented 1 year ago

Hi,

I used v1.2022.801.0 preview. McAfee detected mt64agnt.exe as trojan. Trojan: GenericRXAA-AA!41BBD07E13D0 Is anyone facing the same problem?

snowie2000 commented 1 year ago

It's just a heuristic detection.

phillipenzo commented 1 year ago

Thank you. McAfee directly deleted the file just after detected Trojan. I could not use it now. Suppose I have to file a false detection to McAfee, right?

snowie2000 commented 1 year ago

Thank you,that will be helpful.

phillipenzo commented 1 year ago

I tried to file to McAfee. Hope to get reply soon.

wmjordan commented 1 year ago

White list that file.

I have application firewall and MacType installed for years. MacType never connects to the Internet without confirmation. I don't think it is a malware.

snowie2000 commented 1 year ago

First thing first, mt64agnt.exe never connects to the internet. It is only a proxy program for the main tray program because only x64 executables can have full access to other x64 apps.

Secondly, currently, only mactype updater requires an internet connection to check for updates periodically, and it can be disabled. However, the action of injecting codes into other programs is certainly suspicious, so if not whitelisted beforehand by the AV company, some AV software will heuristically think, ney, it's a bad one, but I don't exactly know what it is, let's just call it "GenericXXX"

phillipenzo commented 1 year ago

Hi, Really thanks for support. Already confirmed this is not Trojan and should be OK to use.

sydbarrett74 commented 1 month ago

MalwareBytes is also flagging it, despite my having put it on the allow list.