Nsudo 8.0 - Virustotal Reports Infections In Download File

Discussion in 'Software' started by Tom-R, May 19, 2020.

  1. Tom-R

    Tom-R Private E-2

    The NSudo 8.0 zip file posted here on MajorGeeks (https://m.majorgeeks.com/files/details/nsudo.html) apparently has some kind of infection. Both Firefox and Chrome block the file when you attempt to download it. And when I override the block to download it anyway, I can submit the zip file to VirusTotal, and find that they report 19 engines detecting threats in the file -- nearly half of them finding some kind of Trojan.

    VirusTotal reports these threats regardless of whether you download NSudo 8.0 from MajorGeeks or from the author's site on GitHub. For comparison, I went back on GitHub and downloaded the previously released version of NSudo, which is version 6.2.1812.31 from December 2018. That earlier 6.2 version on NSudo is squeaky clean; VirusTotal shows no threats at all in version 6.2.

    I sent a message to the MajorGeeks reporting address (mgnews@majorgeeks.com); but I've heard nothing back from anyone regarding this apparently infected software. Has anyone else noticed this problem with the new version of NSudo? Is there any way to get someone here at MajorGeeks to look into the issue?
     
  2. satrow

    satrow Major Geek Extraordinaire

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have reached out to Tim.
     
    Tom-R and satrow like this.
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Tom-R and satrow like this.
  5. Tom-R

    Tom-R Private E-2

    Thanks for the quick reply. I've always downloaded NSudo from your site; and as noted above the previous version (6.2.1812.31) had no issues. It's only the latest version (8.0) that appears infected, at least based on VirusTotal. Digging into the NSudo zip file shows three files in the download that are triggering the threat alerts. The most concerning of the three is a DLL file named "NSudoDM.dll", which VirusTotal shows has threats detected by 20 different engines, including BitDefender, McAfee, and TrendMicro among the major vendors. And 7 of those 20 threats are listed as Trojans of some sort. I've uploaded a screenshot of the VirusTotal results for that DLL file.
    NSudo DLL VirusTotal Results.PNG
    I understand how utilities like NSudo can trigger warnings as potentially unwanted or dangerous programs. But I've also used NSudo for quite a while, and never run into warnings of threats like this before with it -- not until this latest release of version 8.0. And I've never been blocked by Firefox or Chrome from downloading any file from MajorGeeks before. This is the first time ever for me on your site. I'd really appreciate it if someone there could just double-check the latest NSudo download file to ensure that it's not really infected.
     
  6. Tom-R

    Tom-R Private E-2

    I haven't done that yet. I was interested in hearing back from someone here at MajorGeeks first. But I may follow up with trying to reach the author later.
     
    satrow likes this.
  7. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I've checked as soon as I got your report. This is one that requires a leap of faith considering it's never been flagged before and we can't find any suspicious activity beyond what's expected (keyloggers, additional executables, etc).
     
  8. Eldon

    Eldon Major Geek Extraordinaire

  9. Anon-469e6fb48c

    Anon-469e6fb48c Anonymized

    I ran several virus and malware software and got no detection.Not even a pup.Safe to say it's clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds