uTorrent is flagged as malicious by several antivirus engines currently
#1
Information 
Quote:
[Image: utorrent-optional-offer.png]

If you check the latest uTorrent setup file on Virustotal or other virus checking services, or run local checks using security solutions, you may notice that it is being flagged.

Both uTorrent Classic -- the local version of uTorrent -- and uTorrent Web -- the new web-based solution -- and BitTorrent are flagged by multiple antivirus solutions at the time of writing. The main release, uTorrent Classic, is detected by ten antivirus engines including Microsoft Defender, Sophos, Eset Nod32, GData, and Dr.Web.

Note: BitTorrent was sold in 2018.

Being flagged does not necessarily mean that a program is malicious or problematic; false positives happen but the likelihood is reduced when mainstream security solutions flag a program.

What is being detected? Most engines list "PUA or potentially unwanted application" as the reason and that indicates some sort of software bundling or file dropping on user systems. ESET lists Web Companion as a reference and that leads to Ad-Aware's Web Companion application. Whether that program has been offered as part of uTorrent's installation is unclear at this point.

A test download and installation revealed the following:

* uTorrent Classic downloaded fine in Microsoft Edge on Windows 10 with Windows Defender enabled. The program was not blocked from being downloaded.

* The software installed fine on the same machine. Windows Defender did not prevent the installation.

* It did include an offer to install the password manager Dashlane, but that offer was not checked.

* It did include another offer, this time for WinZip and that checkbox was checked (and very tiny in comparison to the big next button).

* There was also an add for NordVPN on the installation succeeded screen.

It is reasonable to assume that offers are switched at times, e.g. based on region, time or incentive to put them up. The flagging of the executable file that is downloaded from the official website by Microsoft but the inactivity during download or installation is puzzling but only on first glance.

Windows Defender does not detect or block potentially unwanted programs by default. You need to enable the option first before it checks executable files for that. The security solution prevented the download of utorrent.exe after I enabled the option on the Windows 10 system. Other security solutions that flag the executable may block its download or execution automatically.

Users who have installed uTorrent may notice that the program is blocked from execution. The beta release is flagged by just two antivirus engines. One possible reason for that is that it does not include nearly as many offers as the release version.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread:
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
(PC Game - Epic) Hogwarts Legacy (Dec 12...
  Hogwarts Legacy ...Mehdi — 18:56
AdGuard for Android 4.12.2
AdGuard for Androi...harlan4096 — 09:01
Brave Browser is testing agentic AI brow...
Brave Browser is t...harlan4096 — 08:27
Ventoy 1.1.09
Ventoy 1.1.09 ...harlan4096 — 08:25
What happens to data stolen using phishi...
We follow the trai...harlan4096 — 08:23

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (43)ivyhuv

[-]
Online Staff
There are no staff members currently online.

>