Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VirusTotal reports 4 files detected as positive. Be carefull !! #4

Open
amontero opened this issue Oct 5, 2020 · 4 comments
Open

Comments

@amontero
Copy link

amontero commented Oct 5, 2020

Warning, binaries files are positive in VirusTotal.

I have analyzed at VT source code files one by one file and them seem clean, folder RLECViewer-master\RLECViewer .

But binaries files are not safe. Here VT reports:

5 detections:
RLECViewer-master\Install\Product\RLECViewer.exe
https://www.virustotal.com/gui/file/193bcde12039e0a1f3d55d0e2f2a236dbcf701e1f18b8620cbb94cd3713775f1/detection

1 detection:
RLECViewer-master\bin(Release)\ClevoEcInfo.dll
https://www.virustotal.com/gui/file/f1fa68742b86022ce436d9998c3a7de34d64866eefc95e40c12f6439328ba656/detection

1 detection:
RLECViewer-master\bin(Release)\RLECViewer
https://www.virustotal.com/gui/file/b6bc3e6fdc4b5d0ec7988695059114161eeac37585b31f49d464042a3b213ff2/detection

3 detections:
RLECViewer-master\bin(Debug)\RLECViewer
https://www.virustotal.com/gui/file/785c59b5046eb5c58f609fdadcb83929e1caa96c54199779a67bbf0beb9a4317/detection

@amontero amontero changed the title VirusTotal reports. 10 Binaries are detected by VT as positive. Be carefull !! VirusTotal reports. 4 files are detected by VT as positive. Be carefull !! Oct 5, 2020
@amontero amontero changed the title VirusTotal reports. 4 files are detected by VT as positive. Be carefull !! VirusTotal reports 4 files detected as positive. Be carefull !! Oct 5, 2020
@zuyan9
Copy link
Owner

zuyan9 commented Oct 5, 2020

Yes, be careful is always a good idea.

Unfortunately I don't know what's causing this. For example, ClevoEcInfo.dll is directly from Clevo and I do not any any control over.

You can get this dll file from Clevo control software.

I suggest compiling from the source code.

@amontero
Copy link
Author

amontero commented Oct 7, 2020

Yes, be careful is always a good idea.

Unfortunately I don't know what's causing this. For example, ClevoEcInfo.dll is directly from Clevo and I do not any any control over.

You can get this dll file from Clevo control software.

I suggest compiling from the source code.

Maybe ClevoEcInfo.dll could be secure because there is only one detection by only one VT engine and it could be a false-positive. This another project (https://github.com/Marqis/BtoFanControl) uses same dll file.

But the others exe binaries files are 3 and 5 detections by remarkable VT engines and also I have checked that when I run RLECViewer.exe something is trying to change my Windows 10 UAC security policy and this behavior is very strange.

@zuyan9
Copy link
Owner

zuyan9 commented Mar 3, 2021

Added warning the readme

@fcayre
Copy link

fcayre commented Aug 29, 2023

You can get this dll file from Clevo control software.

Can you be a bit more specific? I cannot find this file in any of the Clevo Control Center versions available here : https://www.clevo.com.tw/load_page/service

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants