1.10.8 windows virus?

Everything related to MakeMKV
Post Reply
offbeatmammal
Posts: 4
Joined: Thu May 25, 2017 8:46 pm

1.10.8 windows virus?

Post by offbeatmammal »

just tried to update to 1.10.8, and after .7 had uninstalled Windows Defender told me 10.8 contained a virus and trashed it!
is it a false positive, or has badness happened? :evil: :?:
Woodstock
Posts: 10332
Joined: Sun Jul 24, 2011 11:21 pm

Re: 1.10.8 windows virus?

Post by Woodstock »

99% chance it is a false positive, but it is worth checking. There are sites that will accept a URL to a file download, and submit it to multiple antivirus testers, and give you an overall report of the findings.

https://www.virustotal.com is one such site. You can submit the URL for the download ( http://makemkv.com/download/Setup_MakeMKV_v1.10.8.exe in this case) and it will give a report. No problems were found when I ran the test, just before posting this.
RCGNET
Posts: 1
Joined: Thu Nov 30, 2017 2:15 pm

Re: 1.10.8 windows virus?

Post by RCGNET »

Exactly the same thing happened to me - reported as Trojan:Win32/Azden.A!cl, zapped the executable and the shortcuts...

It seems to have been able to remove it OK, bur REALLY bizarrely, when I put the name into the search bar in chrome, I ended up at a CraigsList page ?!?!?? (Different machine otherwise I would've feared something nefarious!)
offbeatmammal
Posts: 4
Joined: Thu May 25, 2017 8:46 pm

Re: 1.10.8 windows virus?

Post by offbeatmammal »

grrr! even told Windows Defender to ignore the MakeMKV app but ... it still deleted it over night!
d00zah
Posts: 1586
Joined: Mon Jun 06, 2016 8:23 pm

Re: 1.10.8 windows virus?

Post by d00zah »

VirusTotal (et al) think it's clean:

https://www.virustotal.com/#/url/fdface ... /detection

Also passed local Avast & MalwareBytes scans, FWIW.

You might want to report a 'false positive' to your AV provider.
Starhawk
Posts: 10
Joined: Thu Mar 31, 2011 12:28 am

Re: 1.10.8 windows virus?

Post by Starhawk »

I downgraded to 1.10.7 because of this and haven't had any issues.
Starhawk
Posts: 10
Joined: Thu Mar 31, 2011 12:28 am

Re: 1.10.8 windows virus?

Post by Starhawk »

Woodstock wrote:99% chance it is a false positive, but it is worth checking. There are sites that will accept a URL to a file download, and submit it to multiple antivirus testers, and give you an overall report of the findings.

https://www.virustotal.com is one such site. You can submit the URL for the download ( http://makemkv.com/download/Setup_MakeMKV_v1.10.8.exe in this case) and it will give a report. No problems were found when I ran the test, just before posting this.
If I scan the file via the link, it reports as fine.

If I download the file and then upload it to VirusTotal, it sees:

Code: Select all

eGambit      Unsafe.AI_Score_89%
Woodstock
Posts: 10332
Joined: Sun Jul 24, 2011 11:21 pm

Re: 1.10.8 windows virus?

Post by Woodstock »

Did you verify the hash check for the file matches the hash file on the download page?

It should also match the hash generated by virustotal - I just verified that virustotal gave the same SHA256 hash as is published on the MakeMKV download page.

Interestingly, "eGambit" isn't even listed in the results page if you use the "check a URL" option.
WAYFLIX
Posts: 140
Joined: Fri Jun 27, 2014 11:59 pm

Re: 1.10.8 windows virus?

Post by WAYFLIX »

I’m getting the same thing now with 1.10.9. Downgrading to 1.10.8 solved this. Windows defender reports a Trojan virus.
Post Reply