Hello Guest, Welcome to Apnea Board !
As a guest, you are limited to certain areas of the board and there are some features you can't use.
To post a message, you must create a free account using a valid email address.

or Create an Account


New Posts   Today's Posts

Antivirus Flagging Sleepyhead as Trojan
#1
Exclaimation 
It seems that some Antivirus software, Kaspersky for example, flags the Sleepyhead installer as a Trojan.MSIL.CoinStealer.gk. This is a false positive.

I have scanned both installers, Singapore and Sleepfiles. Neither is flagged with MSSE (Win 7) or Bitdefender (Win 10). Mark has submitted a sample to Kaspersky for exclusion. Hopefully it will be included in a future definition update.

For now, if you have AV such as Kaspersky, you can temporarily disable it to install SleepyHead. It is not a trojan.



Using FlashAir W-03 SD card in machine. Access through wifi with FlashPAP or Sleep Master utilities.

I wanted to learn Binary so I enrolled in Binary 101. I seemed to have missed the first four courses. Big Grinnie

Reply
#2
I saw this in Mark's Facebook post. If anyone installing Sleepyhead is having issues with their anti-virus throwing warnings, he wants to know information about the anti-virus program name and warning that it is giving. Here are Mark's comments:

Quote:Has anyone else had the SleepyHead installer flagged by any anti-virus software on Windows?

I've had a (single) report Kaspersky's (2016) heuristic engine is flagging the .exe installer package as crapware... this is most likely a false positive because of the Qt Installer Frameworks being binary packed, and heuristic scanners don't like that.

So far, myself or anyone else who tested this today for me has been able to replicate this, but this kinda stuff always gets me more than a little on edge.

More than likely it's just a hypersensitive scanner, or perhaps this guys computer is compromised, and that's why it's flagging it on him, but I just want to make sure Qt installer framework isn't causing unnecessary ugliness that breaks anti-virus/malware
unsure emoticon

Qt Installer Framework is safe, it's a legitimate part of the Qt project that SleepyHead is built on top of.

My windows box is kept up to date and protected, and only used for SleepyHead testing and builds, and there is no way in heck I'd let any form of crapware get in. (I'd never live it down!)

My server is kept secure and up to date.. I can verify the SHA1 sums shown on sleepyhead.jedimark.net still matches the hosted files, as well as what the local copy I built and uploaded from here.

Anyway, if you've had to shut your AV software up to install SleepyHead, please let me know.
______________________________________________
Organize your SleepyHead Data
Post your SleepyHead Data from Imgur
Robysue's Beginner's Guide to Sleepyhead
Reply
#3
I have been trying to download the installation file from your site and Norton Security is quarantining it and deleting it before I can even see the file in my downloads. It says it is a Trojan.Gen.2 and is high risk

Doug


Attached Files Thumbnail(s)
   
Reply


#4
That's Norton for you!
Reply
#5
Can you click on Restore? That should put the file back. I would disable Norton before running the installer. Re-enable it after. Or just "white list" the installer.


Using FlashAir W-03 SD card in machine. Access through wifi with FlashPAP or Sleep Master utilities.

I wanted to learn Binary so I enrolled in Binary 101. I seemed to have missed the first four courses. Big Grinnie

Reply
#6
I am having the same issue, Nortons keeps deleting it saying it has Trojan.Gen.2 in it .... am i meant to ignore that result ?
Reply


#7
I think that it's safe to say that SleepyHead is not a trojan. This is just one of those over-reactions by anti-virus software that is designed to "play it safe" and mark a legitimate software program as a trojan simply because it doesn't "know for sure" rather than risk someone getting infected.

Sort of like you telling a doctor that your arm hurts, and you tell them you drank a glass of milk an hour before it started hurting. Then the doctor says, "I think you should stop drinking milk". Most likely, the milk had nothing to do with your arm hurting.

Coffee

SuperSleeper
Apnea Board Administrator
www.ApneaBoard.com


INFORMATION ON APNEA BOARD FORUMS OR ON APNEABOARD.COM SHOULD NOT BE CONSIDERED AS MEDICAL ADVICE. ALWAYS SEEK THE ADVICE OF A PHYSICIAN BEFORE SEEKING TREATMENT FOR MEDICAL CONDITIONS, INCLUDING SLEEP APNEA. INFORMATION POSTED ON THE APNEA BOARD WEB SITE AND FORUMS ARE PERSONAL OPINION ONLY AND NOT NECESSARILY A STATEMENT OF FACT.



Reply
#8
I am getting this message, so I can't load the software. What do I do now?

Connection is not secure. Go Back
Reply
#9
packtheknife,
The jedimark.net site, the one linked at the top of the page, is currently producing an error until Mark updates his site security certificate. In the interim, please use one of the following links:

1.0.0-beta-2 for WinXP/Vista/7/8/10:
http://www.SleepFiles.com/SH/files/snaps...160422.exe
note:You need to uninstall the old version first if you want to install from this download.


1.0.0-beta-2.2 for MacOSX 10.7+:
http://www.SleepFiles.com/SH/files/snaps...160421.dmg

You may want to disable your anti-virus program before downloading.

Statistics prove that people who have more birthdays live longer.
Reply


#10
Red, your links don't work, since you copied the truncated version. Here's the full working links:


1.0.0-beta-2 for WinXP/Vista/7/8/10:

http://www.SleepFiles.com/SH/files/snaps...160422.exe
note:You need to uninstall the old version first if you want to install from this download.


1.0.0-beta-2.2 for MacOSX 10.7+:
http://www.SleepFiles.com/SH/files/snaps...160421.dmg


NOTE: to copy a longer link properly, you'd have to click on REPLY and copy the entire code from there, since copying the code from the post itself will result in the "..." truncated link, not the actual URL.

SuperSleeper
Apnea Board Administrator
www.ApneaBoard.com


INFORMATION ON APNEA BOARD FORUMS OR ON APNEABOARD.COM SHOULD NOT BE CONSIDERED AS MEDICAL ADVICE. ALWAYS SEEK THE ADVICE OF A PHYSICIAN BEFORE SEEKING TREATMENT FOR MEDICAL CONDITIONS, INCLUDING SLEEP APNEA. INFORMATION POSTED ON THE APNEA BOARD WEB SITE AND FORUMS ARE PERSONAL OPINION ONLY AND NOT NECESSARILY A STATEMENT OF FACT.



Reply


Forum Jump:

New Posts   Today's Posts




About Apnea Board

Apnea Board is an educational web site designed to empower Sleep Apnea patients.

For any more information, please use our contact form.