Jump to content

All my products and services are free. All my costs are met by donations I receive from my users. If you enjoy using any of my products, please donate to support me. My bare hosting costs are currently not met so please consider donating by either clicking this text or the Patreon link on the right.

Patreon

Recommended Posts

Posted

I woke up this morning to see a popup message from Malwarebyte's Anti Malware.

the log:

07:36:17 t0adphr0g DETECTION E:\GameEx\Mame Mapping Magician.exe Trojan.Backdoor

the scan pic:

mbammame.jpg

Should I be worried, or is this a false positive?

Posted

Good morning! I would not be concerned about it and would ignore the warning. Mame Mapping Magician.exe is a compiled script that comes as part of the GameEx package. It is not uncommon for programs such as these to throw a "false positive" with anti-malware/anti-virus programs.

Posted

It's detecting a signature of an AHK script. You can view the source code for it in the GameEx folder (Mame Mapping Magician 1.0.ahk). False alarm.

Posted

Wonder why my MBAM doesn't pick it up?

Posted

Its almost certainly a false positive. Im surprised anything picks such things up as a virus these days. I know sometimes exes packed with UPX are sometimes falsely detected but I thought I had recompiled it without UPX because of that. Could be wrong though.

Posted

Actually there are a couple false positives I get on my machine that my AV software blocks. Most notably certain Future Pinball tables and iRotate. You can set them to 'ignore' though. Not a big deal so long as you trust the source.

Posted

Actually there are a couple false positives I get on my machine that my AV software blocks. Most notably certain Future Pinball tables and iRotate. You can set them to 'ignore' though. Not a big deal so long as you trust the source.

Same here for FP Tables but mine is also set to ignor, as you say if you trust the source and for GameEx stuff i do :)

Posted

Its almost certainly a false positive. Im surprised anything picks such things up as a virus these days. I know sometimes exes packed with UPX are sometimes falsely detected but I thought I had recompiled it without UPX because of that. Could be wrong though.

I forgot that compiling an AutoHotkey script will UPX it. I checked the Mame Mapping Magician 1.0.exe and it's still UPX'ed (you can tell in the first 100 bytes or so in a Hex editor looking for "UPX"). Anyway you might want to decrypt it for the next release.

Guest
This topic is now closed to further replies.
×
×
  • Create New...