← Back to context

Comment by dannyw

1 year ago

I purchased the Windows version and uploaded the file to VirusTotal. It gave me two detections: https://www.virustotal.com/gui/file/4da40fd5c643e9c7e771b896...

Nah, virustotal does that stuff all the time. Two detections is low out of all the malware scanners it used. I usually just use malwarebytes.

  • Many times this warnings are triggered by the packager, but if one ignore them, what is the purpose of the scan?

    The software author should take a look if this is the case, for to change the packager's configuration (no encryption [if some algorithms in the programs are important, to protect them with through implementation, not packager ], or if the binary is small to not compress, or to adjust other params, etc), or to change of packager, or to contact with the antivirus company.

  • I understand, I’m not accusing or implying the product is malicious.

    However, I have password managers, access banking websites, etc so I’m cautious of exes from smaller developers.

    I wasn’t able to easily find the real identity of OP but the binary is code signed by a registered company it seems.

    • I will submit a request for exception/deeper review to the vendor that flagged the exe. I can also offer a full refund and reversal of the sale if you can not make use of the software at the moment due to your security concern. The exe and the installer are signed by the company I established for the project Refractify LLC.

      1 reply →