DMG is Damaged? Zip File contains Trojan? Creating a Standalone for Download...

S4racen's icon

Hi All,

We've created standalones for Mac and Windows, the windows file goes into a zip file and the Mac is a DMG which has been signed as an Apple Developer...

Some users have reported that when downloading the windows version some Anti Virus software's are reporting a trojan is included in the file, theres not...

And on the Mac some users have reported that an error message appears stating the DMG is damaged and cannot be opened. This is fixed by Changing the security preferences to allow Apps Downloaded from anywhere but understandably some users don't want to select this option...

Has anyone come across these issues before and has found a reliable fix??

Both files can be found here - www.isotonikstudios.com/novation-x-isotonik/novation-circuit-editor/

Cheers
D

Juha Partanen's icon

I couldn't get Max 6.1 installed in Win7 because of trojan alert given by ZoneAlarm (latest version). Couple months earlier no issues on Win10.

ZA log:
LOCK,2016/04/05,19:58:28 +3:00 GMT,Host Process for Windows Services,192.168.0.101,N/A
AV/treatment,2016/04/05,19:58:32 +3:00 GMT,PDM:Trojan.Win32.Generic,c:\program files\cycling '74\max 6.1\max.exe,Deleted,Auto
LOCK,2016/04/05,19:58:36 +3:00 GMT,Host Process for Windows Services,,N/A
FWOUT,2016/04/05,19:59:08 +3:00 GMT,169.254.16.87:0,224.0.0.22:0,IGMP (type:34),http://fwalerts.zonealarm.com/fwalerts/fwanalyze.jsp?V103=Aan+EFfgAAAWAAAAAAAAAAABAAAAAQAAAAQAAAABAAAAoYYBADAyMDILBAIAAQINAQA+AAAAIgAAAAABAAAA//8B+ZLN123011807834932-1001,,,,Windows+7-6.1.7601-Service+Pack+1-SMP,14.1.11.0,ELock,j5hvqhisiu3s4he7bhx644bu4g0,2,,&CL=en&OEM=1025&SKU=0&Mode=6&Product=ZoneAlarm
LOCK,2016/04/05,19:59:08 +3:00 GMT,Host Process for Windows Services,169.254.16.87,N/A
LOCK,2016/04/05,19:59:08 +3:00 GMT,Host Process for Windows Services,169.254.16.87,N/A
LOCK,2016/04/05,19:59:10 +3:00 GMT,Host Process for Windows Services,255.2.0.0,N/A
LOCK,2016/04/05,19:59:10 +3:00 GMT,Host Process for Windows Services,224.0.0.252,N/A
AV/treatment,2016/04/05,19:59:34 +3:00 GMT,PDM:Trojan.Win32.Generic,c:\program files\cycling '74\max 6.1\max.exe,Changes rolled back,Auto

FWIN,2016/04/05,20:49:26 +3:00 GMT,192.168.0.254:0,224.0.0.1:0,IGMP (type:17),http://fwalerts.zonealarm.com/fwalerts/fwanalyze.jsp?V103=AcCoAP7gAAABAAAAAAAAAAABAAAAAQAAAAQAAAABAAAAooYBADAyMDILBAIAAQINAQAiAQAAEQAAAAASQAAA//8Q+ZLN123011807834932-1001,,,,Windows+7-6.1.7601-Service+Pack+1-SMP,14.1.11.0,ELock,j5hvqhisiu3s4he7bhx644bu4g0,2,,&CL=en&OEM=1025&SKU=0&Mode=6&Product=ZoneAlarm
OSFW,2016/04/05,20:49:54 +3:00 GMT,UNKNOWN(0),Max (32-bit),C:\Program Files\Cycling '74\Max 6.1\MaxRT.exe,PROCESS,OPENPROCESS,,C:\Windows\Explorer.EXE,http://osalerts.zonealarm.com/osanalyze.jsp?Product=ZoneAlarm&ProductVersion=14.1.11.0&HU100=ZLN123011807834932-1001&CL=en&OEM=1025&SKU=0&Mode=6&QSRC=2&OS=Windows+7-6.1.7601-Service+Pack+1-SMP&LANG=1035&PN=Max+(32-bit)&VER=6.1.10.26bd7fb&FN=MaxRT.exe&Created=467f569a&Size=10239488&MD5=777ccb077a8231833cd2be0b0b6a35a3&SKIMP=d677ca4b9340fa0369605eb57058e16e&&CT=6001&EV=1&SUB=1&SEV=3&ARG1=C%3A%5CWindows%5CExplorer.EXE
LOCK,2016/04/05,20:49:56 +3:00 GMT,Host Process for Windows Services,,N/A
LOCK,2016/04/05,20:49:56 +3:00 GMT,Host Process for Windows Services,239.255.255.250,N/A
LOCK,2016/04/05,20:49:58 +3:00 GMT,Host Process for Windows Services,255.2.0.0,N/A
LOCK,2016/04/05,20:49:58 +3:00 GMT,Host Process for Windows Services,255.255.255.255,N/A
AV/treatment,2016/04/05,20:52:00 +3:00 GMT,PDM:Trojan.Win32.Generic,c:\program files\cycling '74\max 6.1\max.exe,Deleted,Auto
AV/treatment,2016/04/05,20:52:32 +3:00 GMT,PDM:Trojan.Win32.Generic,c:\program files\cycling '74\max 6.1\max.exe,Changes rolled back,Auto

malware_detected_disinfection.png
png
Andrew Pask's icon

Hello

This seems like a ZoneAlarm issue - false positive. Can the app be white listed in ZoneAlarm?

That's pretty much your only hope here.

Cheers

0ctal's icon

for the mac standalone, I guess you need to sign the app instead of the dmg, I signed the app and packaged to a dmg and so far it works fine.