www.virustotal.com reports some vendors find the MT4 or MT5 terminal program as malicious.

 

I tried to have the MT5 terminal64.exe analyzed at https://www.virustotal.com and found 2 security vendors flagging it as malicious. See https://www.virustotal.com/gui/file/a7eb5f198b9f00201fbc20789e626ec986832221c179b4db5b839f7a5b9d68db

I also have the MT4 terminal.exe analyzed and 5 security vendors found it malicious too. See https://www.virustotal.com/gui/file/748c27557dc2dcda70cfcb823082f00b14d2a482c82d712b7dece200792f120b

Are these vendors crying wolf? I ran the Microsoft AV scanner within Windows 2019 server and it found no viruses.
VirusTotal
  • www.virustotal.com
VirusTotal
 

It was discussed many times in past: terminal64.exe and terminal.exe do not have viruses.
It is false alarm.

It is one of the most recent explanation -

Forum on trading, automated trading systems and testing trading strategies

Errors, bugs, questions

Renat Fatkhullin , 2023.03.26 00:24

Occasionally, due to polymorphic protection, some file signatures can be similar to malicious .

Please note that I just cursed at an attempt to save an encrypted and signed update package (it cannot be launched), and not at the launch of an unpacked exe file. That is, it is not a reaction to an executable file.

All update packages are signed with our additional RSA private key and cannot be saved to disk unless the package is verified with the public key. Therefore, there is no risk of getting the left file at all.

In addition, all executable files are digitally signed by our Code Signing

In general, as usual, a false alarm.


 

more -

Forum on trading, automated trading systems and testing trading strategies

Initialization Error 4 Windows 10 Home

Sergey Golubev, 2017.01.22 15:11

Hi DeMike17,

No. This is a false alarm on a polymorphic engine protection of MT4/MT5, and it is not Metatrader related (this 'false' is not related to metatrader). 

It was discussed some time ago and it was already replied by MetaQuotes (MQ) many times it was one of the reply from MQ:

"The installer has no virus - this is another false alarm on a polymorphic engine protection.
Open the properties of any of our executable file to view digital signatures - they are signed (and hence files unchanged since inception)."

read this thread for more information.

------------------

So, it is false alarm.


 
Sergey Golubev #:

more -

------------------

So, it is false alarm.


Thank you
Reason: