Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Antiviruses Keep Flagging Supermium as malware. #315

Open
ExiledCourtney94 opened this issue Mar 5, 2024 · 6 comments
Open

Antiviruses Keep Flagging Supermium as malware. #315

ExiledCourtney94 opened this issue Mar 5, 2024 · 6 comments

Comments

@ExiledCourtney94
Copy link

ExiledCourtney94 commented Mar 5, 2024

Hello just figured I would let you know that anti viruses keep flagging supermium as malware.

Virus total
https://www.reddit.com/r/windows7/comments/1b5ej7z/is_supermium_safe/

This person said comodo anti virus flaged supermium since it was making unusual IP address pings so no idea what was going on there.
https://www.reddit.com/r/windows7/comments/1awpn0j/supremium_migration_from_brave_ff_pops_up_odd/

Than just recently I installed malwarebytes & malwarebytes is flagging supermium's firewall access as malware. I had to manually look in the registry to find out what malwarebytes was flagging.

Which was this Adware.Ghokswa.Generic, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{B3E6F332-3127-46DA-9F0A-AFCAA7DE2A51}

So I went to where malwarebytes said there was a virus. I opened up the registry than I saw this

c=Inbound rule for Chromium to allow mDNS traffic.|EmbedCtxt=Supermium|

so immediately knew it definitely wasn't malware:

So I told malwarebytes to ignore it but I am just wondering if there's anything you can do on your end? To get antiviruses to read or register supermium as safe?

@Blaukovitch
Copy link

So I told malwarebytes to ignore it but I am just wondering if there's anything you can do on your end? To get antiviruses to read or register supermium as safe?

For antivirus companies, this issue is solved by digital signatures (cert) for PE COFF files.
Or the author should write to the antivirus companies themselves to include his software in a package of testing for false positives - such testing is always done when antivirus updates are released.

@win32ss
Copy link
Owner

win32ss commented Mar 5, 2024

Supermium 122 appears to be in a good state as no vendors appear to be tagging the 122 executables and binaries.

@Marek33
Copy link

Marek33 commented Mar 12, 2024

Supermium 122 appears to be in a good state as no vendors appear to be tagging the 122 executables and binaries.

I don't want to be the bearer of bad news, but the Norton Power Eraser says that multiple things are viruses. At least the Roguekiller, and Malwarebytes (the older version) do not report it.

@Anton-V-K
Copy link

Supermium 122 appears to be in a good state as no vendors appear to be tagging the 122 executables and binaries.

Well, Supermium 122.0.6261.152 (R6) is still flagged by some engines at VirusTotal:

@Anton-V-K
Copy link

With 124.0.6367.245 the situation became even worse for 32-bit on VirusTotal - 18/63 false detections for supermium_124_32_setup.exe, no change for supermium_124_64_setup.exe (2/69).
Now even BitDefender raises an alarm, which is a bad sign.
Some AV engines may be referencing each other when detecting malware, so this spiral won't go away on its own :(

@docrR docrR mentioned this issue Jul 27, 2024
@AroKol78
Copy link

AroKol78 commented Aug 4, 2024

For the first time today, Avira (installed) marked it as a trojan TR/Redcap.qnssu.
I don't know if it's false or true, but do something about it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants