Page 1 of 1

Reported virus in CSBwin

Posted: Thu Jun 02, 2016 2:02 am
by Paul Stevens
I have a report of a virus (Maltule) in:

http://dianneandpaul.net/CSBwin/Games/D ... 151213.zip

I cannot duplicate this observation.
I scanned the zip file, its contents, and my entire computer.
Could some kind soul see if they can detect a virus in this file?

Re: Reported virus in CSBwin

Posted: Thu Jun 02, 2016 3:35 am
by Zyx
Nothing found with AVAST.

Re: Reported virus in CSBwin

Posted: Thu Jun 02, 2016 3:57 am
by Paul Stevens
Thanks, zyx. I am using AVG. Anyone else using a third anti-virus program?

Re: Reported virus in CSBwin

Posted: Thu Jun 02, 2016 6:46 pm
by Gambit37
I can check with Eset NOD32 when I'm back from holiday next week.

Re: Reported virus in CSBwin

Posted: Fri Jun 03, 2016 10:30 pm
by ChristopheF
I just scanned with Windows Defender on Windows 10, and indeed it detects "Trojan:Win32/Maltule.C!cl" in this archive.
The same is true for CSB_Windows_x86-32_20151213.zip and Conflux_Windows_x86-32_20151214.zip
As the other antivirus do not detect anything, this is probably a false positive with the latest virus definitions. Still annoying, though...

Re: Reported virus in CSBwin

Posted: Sat Jun 04, 2016 1:17 am
by Paul Stevens
Thanks much, Christophe.

Is it possible to determine if the reported virus is confined to
the .exe file? If so, I could re-compile with different
options (optimizations, perhaps?) that might make
Windows Defender happier. Perhaps I can find someone
else who can compile the program and see if they get
the same result. Or did the virus get added during
the process of creating the zip file.

Any idea how to determine if this is indeed a false
positive? I have no idea how these things work. Is there
anywhere to go to verify such things? To report them?
This is a pretty ugly situation, whether it be true or false.

Re: Reported virus in CSBwin

Posted: Sat Jun 04, 2016 1:44 am
by Paul Stevens
I just asked 'VirusTotal' to check the .zip file.
It ran 56 different virus checkers and they all reported
the file to be clean. Windows Defender was not one of them.

Hmmmmm....

I reported this as a false positive to:
https://www.microsoft.com/en-us/securit ... ubmit.aspx
with a few comments.

Re: Reported virus in CSBwin

Posted: Sat Jun 04, 2016 10:16 am
by ChristopheF
Yes the "virus" is confined to csbwin.exe.