This forum has been archived. All content is frozen. Please use KDE Discuss instead.

Trojan reported while installing windows version

Tags: None
(comma "," separated)
melonwater
Registered Member
Posts
3
Karma
0
Hi,

I've just downloaded the windows version of kdenlive from *https://kdenlive.org/download/*, and then I downloaded the FFmpeg shared 64bit build and swapped the files about as instructed;

1 Unzip the downloaded Kdenlive version using the 7-Zip app.
2 Download the FFmpeg shared 64bit build from Zeranoe.com.
3 Unzip the FFmpeg download.
4 Copy the contents of the FFmpeg “bin” subfolder (containing .dll and .exe files) into the kdenlive-windows folder – overwriting some existing files from the Kdenlive package with the ones from the FFmpeg package.
5 Copy the FFmpeg “presets” subfolder inside kdenlive-windows folder.
6 Start Kdenlive from kdenlive.exe in kdenlive-windows folder, close it and re-open it.


Everything was going fine until step 6.

I opened the kdenlive-windows folder and searched for *kdenlive.exe*, and then executed it.
Suddenly Windows AV (most recent for windows 10) popped up with a 'severe' warning about a trojan- 'libtiff-5.dll' and/or 'Win32/Azden.A!cl'!
I loved using kdenlive and donated a few pennies back in the day, but I've moved away from linux for the present and I'm well aware of the security problems for windows machines so this really threw me. I've decided to halt installation for now.
Anyone know what is going on?
User avatar
bartoloni
Moderator
Posts
1510
Karma
4
OS
just a false positive, sources of this project are completely "open" i tried to suggest to some Antivirus Company to stop to "mark" kdenlive as a virus... they maybe fix and old version "alarm" but when a new build come out... again some antiviruses mark it a virus.

BTW.. no virus on main executable.
melonwater
Registered Member
Posts
3
Karma
0
bartoloni wrote:just a false positive, sources of this project are completely "open" i tried to suggest to some Antivirus Company to stop to "mark" kdenlive as a virus... they maybe fix and old version "alarm" but when a new build come out... again some antiviruses mark it a virus.

BTW.. no virus on main executable.


Thankyou for your answer. Could you, or anyone else, explain why it is flagged as a virus?

I will try to get some answers from microsoft too- I'm sure they have official forums too.

I'm not saying that I don't believe you that it's just a false positive, but if somebody as open and supportive as I am of kdenlive (and linux/open source in general) is put off by the warnings of it being a "Severe Trojan" capable of "taking control of your system", then people completely new to kdenlive will run a mile!

I ended up deleting it in the end, yet when I search my windows 10 for 'kdenlive', lots of files are found- including the .exe file. Do I need a special tool to uninstall/clean up properly?

This isn't right. People will obviously choose not to use this [color=#0000FF]excellent video editing suite
immediately if it's wrongly flagged as a virus. If it really is clean, this looks like they are forcing you out of the market.
How could we kick up a fuss about it? Is what they are doing lawful? If somebody has info please do post it.

Thanks :-\ >:( 8) xD
User avatar
bartoloni
Moderator
Posts
1510
Karma
4
OS
i'm also a developer (and also i have build 2 antivirus software) .. and a lot of my application (not developed by Visual studio) are reported as a virus from Microsoft (and some times from Avira/Avast)
for example the UPX ultimate packer (that is an open source tool for .exe compression) ... make EXE files that are ALL quarantined by MS/Avira/Avast. (and thsi tool is on development from 1998 .... 20 years!.. before AVAST/AVIRA/MICROSOFT DEFENDER creation.)

every AV has an Heuristic component that try to find NEW VIRUSES based on sospicious headers (for example MINGW generated header.. that is usual form a lot of linux/ported win-application).. the Libreoffice and Openoffice project have changed compilation from MinGW to VisualC to avoid (also) these type of false-positives.

P.S. if you want to ask to change compilation from MinGw to VisualC ... please don't ask for this.. VisualC binaries need a VISUAL C RUNTIME (that MINGW not require) this mean that in some cases Kdenlive can't start. (old RUNTIMEs... changed/modified RUNTIMEs.), VisualC is a way faster than MinGW... but switching to VisualC (huge amount of work BTW) .. is a step to do on future.. when Kdenlive for windows become a standard for opensource videoediting (on Windows).
melonwater
Registered Member
Posts
3
Karma
0
bartoloni wrote:i'm also a developer (and also i have build 2 antivirus software) .. and a lot of my application (not developed by Visual studio) are reported as a virus from Microsoft (and some times from Avira/Avast)
for example the UPX ultimate packer (that is an open source tool for .exe compression) ... make EXE files that are ALL quarantined by MS/Avira/Avast. (and thsi tool is on development from 1998 .... 20 years!.. before AVAST/AVIRA/MICROSOFT DEFENDER creation.)

every AV has an Heuristic component that try to find NEW VIRUSES based on sospicious headers (for example MINGW generated header.. that is usual form a lot of linux/ported win-application).. the Libreoffice and Openoffice project have changed compilation from MinGW to VisualC to avoid (also) these type of false-positives.

P.S. if you want to ask to change compilation from MinGw to VisualC ... please don't ask for this.. VisualC binaries need a VISUAL C RUNTIME (that MINGW not require) this mean that in some cases Kdenlive can't start. (old RUNTIMEs... changed/modified RUNTIMEs.), VisualC is a way faster than MinGW... but switching to VisualC (huge amount of work BTW) .. is a step to do on future.. when Kdenlive for windows become a standard for opensource videoediting (on Windows).


Thankyou for your informative answer, I appreciate the detail you've included.


With regards to the last part;

"but switching to VisualC (huge amount of work BTW) .. is a step to do on future.. when Kdenlive for windows become a standard for opensource videoediting (on Windows)."


That is all well and good, and it makes sense except that kdenlive will never have the chance to become popular if it's flagged as a virus!!

lol

>:( :( :o :-\ :| :| :| :| :| :| :| :| :|


Bookmarks



Who is online

Registered users: Bing [Bot], Google [Bot], Sogou [Bot], Yahoo [Bot]