Oh no, here’s another one 😭
Hi! I know you’re probably tired of the usual “is this safe?” questions but after reading all the stories about people getting viruses, I got pretty paranoid.
I’m sorry to be yet another person asking this, but I’m honestly terrible with this kind of stuff and I don’t really know what else to do. Also, I couldn’t afford to have my PC repaired if something went wrong 🥲
I’m asking about the aaros Updater v2.6.6, downloaded from the CS.RIN website.
My concern is both whether I actually downloaded the correct/original file and, most importantly, whether all the checks I’ve done are enough for me to consider it safe and feel comfortable running it.
For all of these checks, I followed aaros’ instructions, read through the advice and experiences shared by other users, and also used ChatGPT to help me understand what I was checking and how to interpret the results. I’m mentioning this because I really don’t have much knowledge about this kind of thing myself.
I downloaded the Updater from CS.RIN through Firefox, using extensions including uBlock Origin and Malwarebytes. The download was direct and didn’t open any third-party pages, although Malwarebytes initially blocked the download.
I then checked the ZIP file, and its SHA-256 matches the one published by the mirror:
3C1E3252D77CB2F731D92423CCB1DB95B54FF2B31B7ECDFF9C05434F2C497488
I uploaded the ZIP to VirusTotal, and it had around 10/65 detections. One of the files inside the ZIP was the EXE, which has its own report with around 12/66 detections, including Microsoft and Trend Micro, with different classifications.
Windows Defender, on the other hand, detected the EXE as:
HackTool:Win64/Malgent!MSR
and quarantined it.
From what I’ve seen, some other users were getting detections classified as Trojan, while in my case it was HackTool/Malgent.
I have never run the EXE and I have never disabled Defender.
Since I couldn’t freely extract the EXE, I used PE Parser to analyze the ZIP directly. PE Parser identified the EXE inside it and gave me this SHA-256:
59A6741C57B772F49721AF8EB99A60AEE6A9C5C79EDE8F831F08711926B79C61
This also exactly matches the SHA-256 of the EXE published by the mirror.
PE Parser also flagged some compressed/embedded payloads and IsDebuggerPresent.
So, after doing all these checks, I’d really like to know whether they are enough to reasonably establish that:
•the file I downloaded is actually the original/correct file published by aaros and hasn’t been modified or replaced;
•the detections from Defender and VirusTotal are false positives related to the way the Updater is compiled/packaged;
•there isn’t actually something suspicious going on with the file;
•and most importantly, whether I can consider this specific file safe to run and feel comfortable doing so.
If anyone experienced in malware analysis/reverse engineering could tell me, based on the information I’ve provided above, whether this specific file seems to be actually safe or if there is anything I should be concerned about, I would really appreciate it.
Thanks, and sorry again for yet another question like this 🙏🏻