Win.dropper.generic in 64-bit installer

111 views
Skip to first unread message

tdel...@gmail.com

unread,
Dec 25, 2019, 2:40:40 PM12/25/19
to UtilFr
When downloading 64-bit installer version of Clavier+  Cisco's Advanced Malware Protection (AMP) reports trojan Win.dropper.generic::90.lp.ret.sbx.tg and quarantines the installer. 
Portable zip is OK and 32-bit installer is OK.

Guillaume

unread,
Dec 27, 2019, 6:35:20 PM12/27/19
to UtilFr
The sha256 hash of https://github.com/guilryder/clavier-plus/releases/download/release10.8.3/ClavierSetup64.exe is: 0D8E7F30C3367DDFC0FCB90F994838DFC805B6BC32A3A8D9FEC3B417DDEE7975

If the hash matches your file, then the issue is a false positive of AMP. I recommend following up with AMP to report the false positive. I cannot do it myself as I'm not a Cisco customer (source).

Guillaume

tdel...@gmail.com

unread,
Jan 3, 2020, 1:42:20 AM1/3/20
to UtilFr
I'll ask Cisco TALOS team to look at it and will advise.
Reply all
Reply to author
Forward
0 new messages