why my computer consider MQL5 a virus Win32/Themida ? - page 2

 
jjc:

So, what's your hypothesis for why AVG flags up this MT5 build? Are they just being dumb? Why would they block something like this if it's possible and practical to work only on a known-problem basis?

Maybe they are. Being the most popular free anti-virus does not make it the best.

 
blogzr3:

Not at all. There are things such as false positives and bugs. If they don't work on known problems (or very likely ones), they would have to flag everything they don't know as a "problem". Everytime you compile and run a new program, it would be flagged because the virus-checker software "doesn't know". That would make the software unusable.

I'm suppose what I'm proposing is that AVG class Themida as what you're calling a "known problem". In other words, I'm hypothesising that they've had sufficient problems in the past with things protected by Themida that they feel they have to work on the assumption that anything Themida-protected is dangerous. They may then, as gordon is proposing, operate a whitelist of trusted, Themida-protected executable signatures.


I'll add a further ingredient into our speculative pot. I've downloaded some other code protection in the past (not Themida) and tried it out on an ad hoc executable of my own (i.e. something which I'd just compiled, and had never been seen in the world before). The AVG scanner immediately flagged it up as a possible threat. This could, as you suggest, be another "false positive", but the coincidences would then be multiplying. I've never, ever had any other false positives from AVG. It seems more likely that the virus scanner has decided that it can't trust various code-obfuscation packages.

 
jjc:

I'm suppose what I'm proposing is that AVG class Themida as what you're calling a "known problem". In other words, I'm hypothesising that they've had sufficient problems in the past with things protected by Themida that they feel they have to work on the assumption that anything Themida-protected is dangerous. They may then, as gordon is proposing, operate a whitelist of trusted, Themida-protected executable signatures.

... I've not tried MT4 build 226 myself, but see https://www.mql5.com/en/forum/124812. Appears to support the notion that there's a whitelist. Someone's claiming that "AVG antivirus identifies Win32/Themida in new terminal.exe" for build 226 of MT4.

 
orebil:

i'd like to launch metatrader 5 but my computer refused to do so. Is there anything that i can do?

why my computer consider MQL5 a virus Win32/Themida ?

Are you using 'Spyware Doctor' from PC Tools?

It gives false positives of infections with MT4/MQL4 software.

If so close Spyware Doctor down and then try it, preferably change the default so that Spyware Doctor doesn't start when windows starts up. Then TURN YOUR COMPUTER OFF for at least one minute and restart it without Spyware Doctor starting as well and then try your MQ software.

If this works, eMail PC-Tools and report the problem and then they will have the information to fix the problem.

Reason: