Home
JAQForum Ver 24.01
Log In or Join  
Active Topics
Local Time 17:09 03 Sep 2025 Privacy Policy
Jump to

Notice. New forum software under development. It's going to miss a few functions and look a bit ugly for a while, but I'm working on it full time now as the old forum was too unstable. Couple days, all good. If you notice any issues, please contact me.

Forum Index : Microcontroller and PC projects : Virus warning received

Author Message
circuit
Senior Member

Joined: 10/01/2016
Location: United Kingdom
Posts: 282
Posted: 02:14pm 09 Aug 2025
Copy link to clipboard 
Print this post

I have just tried to download a copy of MMEdit from Geoff's Website and Microsoft Defender sprang into action;



Is this a real threat?  I have downloaded MMEdit on many occasions and although Defender warns about it being unknown software and so on, this is the first and only time that I have found it to be automatically quarantined and flagged up in this manner.  

Geoff, Jim, is this a real issue?
 
circuit
Senior Member

Joined: 10/01/2016
Location: United Kingdom
Posts: 282
Posted: 06:53pm 09 Aug 2025
Copy link to clipboard 
Print this post

Before you chaps in the Southern Hemisphere wake up, I checked with Co-Pilot and this is what it said;

"The file you're referring to—MMEdit from Geoff's Projects—is a well-known IDE for MMBasic, developed and maintained by Jim Hiley. It’s designed to simplify development for platforms like the Maximite, Micromite, and PicoMite, and it’s widely used in the MMBasic community.

🧠 Why Defender Might Flag It
Script-heavy installer: MMEdit includes scripts and executables that interact with serial ports and microcontrollers. These can resemble malware behavior heuristically.

Low reputation score: Because it’s a niche tool, it may not have widespread reputation data in Microsoft’s cloud protection system.

Packed or compressed format: The ZIP archive might contain byte sequences that resemble known malware signatures, especially when compressed.

✅ What We Know About MMEdit
Legitimate developer: Jim Hiley is active on TheBackShed forum, where MMEdit is regularly discussed and supported.

Free and open: The software is free to use and targets multiple MMBasic platforms.

No known malicious behavior: There’s no credible evidence that MMEdit contains malware. Several users have reported false positives with Defender, especially on the ZIP file itself."


How frustrating.  I guess that there is something in the latest Defender Update that has got itchy with the zip file.  I found no flagging of issues when I had de-zipped the content.
Edited 2025-08-10 04:55 by circuit
 
Geoffg

Guru

Joined: 06/06/2011
Location: Australia
Posts: 3297
Posted: 09:16pm 09 Aug 2025
Copy link to clipboard 
Print this post

No, the download of MMEdit is not a virus or dangerous.  
From time to time a virus scanner will sound a false alarm.  The reason is unknown but I like Co-Pilot's opinion... "Script-heavy installer".

Geoff
Edited 2025-08-10 07:25 by Geoffg
Geoff Graham - http://geoffg.net
 
TassyJim

Guru

Joined: 07/08/2011
Location: Australia
Posts: 6299
Posted: 09:55pm 09 Aug 2025
Copy link to clipboard 
Print this post

I used to be able to submit the ZIP to VirusTotal and they usually gave a 70 out of 71 success or similar.
Now if I try and submit the ZIP, VirusTotal is not happy with it being in a ZIP.
Just testing the exe files individually would be a pain and not much use so I gave up.

Most AV programs get upset at times, usually because they are too lazy to do genuine testing.

The script I use is inno installer, a well known and well respected installer but your AV seems to be upset with the Linux tar file which is NOT a script.
MMEdit does use TCPIP etc to interact with Webmites and between it's parts. That is why Windows asks for permission on first run.

I gave up caring about what AV programs think a long time ago.

I do have some concern for the reputation of Geoff's website if it gets flagged by one of the major AV programs due to my file.

Jim
VK7JH
MMedit
 
Grogster

Admin Group

Joined: 31/12/2012
Location: New Zealand
Posts: 9631
Posted: 11:57pm 09 Aug 2025
Copy link to clipboard 
Print this post

Yes, I too have seen this from time to time, but not for a LONG time now.
False-positives are an annoyance, but I suppose it is better to have a known safe thing being tagged as something it's not, rather then a nasty NOT being detected at all, cos there are some really horrible nasties out there these daze.....
Smoke makes things work. When the smoke gets out, it stops!
 
TassyJim

Guru

Joined: 07/08/2011
Location: Australia
Posts: 6299
Posted: 12:25am 10 Aug 2025
Copy link to clipboard 
Print this post

  Grogster said  
False-positives are an annoyance, but I suppose it is better to have a known safe thing being tagged as something it's not, rather then a nasty NOT being detected at all,


Not when the F...ing A...les tag your whole web site as nasty and then refuse to tell you why.
"We will get back to you within 2 weeks" No they didn't get back at all.

It will only get worse as they rely even more on AI.
Artificial yes, Intelligent, no way.

My stupid phone likes to create "stories" from my photos.
We have a new dog so lots of photos.
This morning it created a story titled "kitties in xxx"
AI Ba.. Humbug..

Jim
VK7JH
MMedit
 
Grogster

Admin Group

Joined: 31/12/2012
Location: New Zealand
Posts: 9631
Posted: 02:11am 10 Aug 2025
Copy link to clipboard 
Print this post

  TassyJim said  Not when the F...ing A...les tag your whole web site as nasty and then refuse to tell you why.
"We will get back to you within 2 weeks" No they didn't get back at all.

It will only get worse as they rely even more on AI.


THAT.....I did not know.
I was only referring to the downloaded file itself.
Was totally unaware that your entire site was tagged.  
Smoke makes things work. When the smoke gets out, it stops!
 
Print this page


To reply to this topic, you need to log in.

The Back Shed's forum code is written, and hosted, in Australia.
© JAQ Software 2025