http://www.virustotal.com/file-scan/report.html?id=06a4bd0fab9c0d759efac9bd5b9213d890f922dccb6d48ef305f0d38ba4cbda4-1319729174
for the 1.6 beta 3: marked as clean by all 42 virus scanners including AVG 10.0.0.1190
http://www.virustotal.com/file-scan/report.html?id=e329ad4813102a722dcf36b16da9378556981b5c9658260f93c7ea88b1732499-1318239991
for the 1.5 release: marked as clean by 41 of 42 scanners. This is typically indicative of a false positive. For sake of full information that positive was "
| SUPERAntiSpyware |
4.40.0.1006 |
2011.10.08 |
Trojan.Agent/Gen-FraudPack |
". AVG marked it as clean. Additionally the Virus Total community rated it as "goodware" with 100% safety score. I have no idea how many people were needed to give it that vote, and if those people need any particular qualifications to make that assessment,
so feel free to take that info with a grain of salt.
I have resubmitted this file to VirusTotal for a fresh analysis (as the last time it was run was over a month ago - just in case other virus scanners caught up with SAS or SAS corrected some of their virus signatures) - and I obtained exact same overall results.
the question regarding the gateway was regarding if you had a domain-level virus scanner that was detecting vs your private computer's virus scanner. As your report didn't specify what detected it and how, I was covering my bases. I assumed you were using
windows, but sometimes gateway scanners use something like clam on linux. In any case, that seems irrelevant to this report.
As to installing a firewall? You've got windows 7, so you don't need to install jack.
start orb->type firewall. Select "windows firewall with advanced security"
select "outbound rules" on the left panel, then "new rule" on the right panel. Leave the top "Program" selected and set up your filter as appropriate to block mDesktop.
Again, this is completely unnecessary - this program has no virus and doesn't communicate anything other than basically "this is my current version, what do you have?". But if you are absolutely paranoid that this program, the author, me, and the tens of other
people have posted here are "out to get you" then so be it - there are still ways to protect yourself if this program has features you'd like to use and other programs don't support those methods.
What could have happened to you 1) is you downloaded it from an "unsafe location" (other than the linked google code page) 2) you had another live infection on your system that attached itself to the mDesktop setup after download. I have no idea why this wouldn't
have infected every .exe or .msi you downloaded.
Again, what was the "severe" issue reported?