So, recently I've been having some problems with my computer randomly freezing and then not starting Windows after initial log in attempts outside of safe mode. After a few scans with different antivirus programs, I've found that the newest build of MUSHclient contains a trojan inside the .exe, apprently. Below is the log of the last scan of mushclient472.exe downloaded directly from the mushclient website.
I had deleted it and all of the files associated with it, then redownloaded it just a few minutes, but before installing it I scanned it with Malwarebytes just to avoid the trouble of having to get rid of it after installation and low and behold, it was there again.
To be on the safe side, I sent the installer through Jotti's multi-service scanner. Everything turned up clean. There are a few possibilities I can think of:
1) Jotti's scanner missed the malware. Unlikely, as it uses twenty different services including AVG and Kaspersky to scan uploads.
2) Jess's computer is infected with a virus that modifies downloads to contain viruses. Just a thought.
3) Jess is spamming convincing advertisments. I'd rather not believe this one.
In any case, Jess, try running Trend Micro's HouseCall [1] scanner on your computer. I use it every now and then and I'm pretty happy with it.
(For reference, the results of the multi-service scan are public. [2])
MUSHclient 4.72 was released on 4th February 2011. A few months back. No complaints have been received.
The virus scanner done by Twisol shows it is clean. The source is a matter of public record.
I smell a rat, because this post is saying "hey, your MUSHclient might be infected! Download xxx.exe and you will be saved!". Maybe the scanner is the problem.
I thought of that but when he said "Below is the log of the last scan of mushclient472.exe downloaded directly from the mushclient website." I assumed that was not the case.
I play MUDs with Jess and downloaded MalwareBytes to test if what he was saying is true. MalwareBytes (a program I have used several times on several machines when I worked in IT support) does show MUSHclient as having a Trojan.
However, I have not had any issues whatsoever with my operating system or anything and have had no adverse affects. Additionally, software such as AntiVir, AVG, show nothing.
Also to note, MalwareBytes ONLY shows the Trojan when scanning the installer itself. Upon scanning the MUSHclient directory after installation, I am finding no trojans.
I am not sure whats going on, but I definitely think this is a misread by MB.
I'm not trying to plug the program or anything like that, it's just that out of all of the programs I did run, it's the only one that picked it up. Each time I deleted the file, the computer started working properly again. Before I downloaded that build of Mush, I hadn't had any problems. It wasn't until after I had the problem that I downloaded the program that found the trojan, too, and it was only because a friend of mine told me to. I actually scanned the entire computer with Avast, AVG, the standard Windows security program and SpyBot before downloading the Malwarebytes.
I ran the MD5 check and it checked out just fine, but I still get the trojan and random Windows freezes after running the 4.72 exe.
Its not completely improbable that it detected what it thought was one, for some reason. This happens some times. Often a scanner ends up having to have an exclusion added, to stop false positives. Usually this happens with installers, and usually ones that go online to download more stuff (though not always, sometimes the actual compressed file simply by chance accident has a set of bytes that are looked for as a signature of a virus, which is likely the case here, since the installer doesn't download anything).
Its the reason, in fact, a lot of games suggest disabling anti-virus when installing. Not because they have malware, but because they can trip alarms, or have, on some scanners, while running, but, in that case, not the installer exe, or the complete game. I imagine its quite annoying for people that run into it.
I was going to mention false-positives (something is claimed to have a virus when it doesn't) and false-negatives (a virus slips through undetected).
Virtually any test (eg. medical ones) suffer from a certain percentage of both false-positives and false-negatives. The idea is to keep them low, of course.
Unfortunately with more and more viruses being released, and the detection method being to scan for "signature bytes" the likelihood of genuine uninfected software raising a false-positive increases.
Jess said: I'm not trying to plug the program or anything like that, it's just that out of all of the programs I did run, it's the only one that picked it up.
If 20 different scanners don't see anything, and only one does, I'd say it's a false alarm. I can also say with confidence that my computer doesn't have those problems, and I have MUSHclient installed. Have you tried running HouseCall?
I'm not trying to plug the program or anything like that, it's just that out of all of the programs I did run, it's the only one that picked it up.
I went to Doctor #1, he said I was fine. I went to Doctor #2, he said I was fine. Finally after visiting 20 doctors I found one who told me there was something wrong. Finally! Now I'm happy. ;)
Look at it another way, there is only a 5% chance there is something wrong with me.