# GlassWire/uninstall.exe Virus/Trojan?

Can you try clearing your browser cache or try a different browser? Can you send us a screenshot please via our bugs email? We’d really appreciate it.
https://www.glasswire.com/contact/

I downloaded the latest version about 10 mins ago, and BitDefender is still flagging the installer and also the uninstall.exe file as a trojan, so your new update is either really infected or if it’s a false positive and BitDefender have yet to update this in their definitions.

I’ve quarantined the whole Glasswire folder until it can be proved safe.

I had this same issue with a game on Steam, the developers insisted time after time that it was a false positive. It turned out to be a real threat.

Hope you get this sorted as Glasswire is an excellent app.

Thanks guys! We’re working with them via their support and via Twitter even to try to get this solved ASAP. Your screenshots really helped. Thanks again!

If you’d like to submit us as a false positive here http://www.bitdefender.com/site/Main/automaticSampleUploader/ it may expedite the process. Thank you.

Guess what? Bitdefender confirmed it’s a false positive and said they would remove the false alert within 48 hours. Thanks for all your help! Please try to install again in 48 hours and let me know if you still have an issue. We’ll test on our end also. I’ll post a screenshot of the email from them to help make you feel at ease that we’re not really infected.

Thanks Servo/Ken.

Just doing a definitions update via Bitdefender will fix the issue once they have added it to the list. If Glasswire is already installed, running a scan (or even reinstalling) should be fine.

Maybe someone can confirm it’s fixed if they have time. Thanks!

I just did an update and then scanned the folder and it still got flagged!

http://i.michaelmknight.co.uk/images/2014/09/19/2014-09-19_13-05-10.png (Sorry, still can’t post images).

I will keep checking though throughout the day and will let you know if it’s fixed for me.

Mike.

Wow, that’s really disappointing! If you could try again on Sunday I’d really appreciate it. We’ll keep trying on our end also. Thanks again.

Sure, no problem. It was 1pm my time (UK) when I posted my last post above, it’s now just after 5pm and still no change. I’ll keep trying though and will post when it gets the all clear.

Saturday 20 sept 12.50 pm UK time … im getting worried !

Also
Computer name . . . . ******************
Windows . . . . . . . : 6.1.1.7601.X64/4
User name . . . . . . : *****************
UAC . . . . . . . . . : Enabled
License . . . . . . . : *******

Scan date . . . . . . : 2014-09-20 12:40:59
Scan mode . . . . . . : Normal
Scan duration . . . . : 44s
Disk access mode . . : Direct disk access (FsdHigh)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No

Threats . . . . . . . : 1
Traces . . . . . . . : 2

Objects scanned . . . : 1,156,083
Files scanned . . . . : 9,115
Remnants scanned . . : 257,396 files / 889,572 ke

Malware _____________________________________________________________________

C:\Program Files (x86)\GlassWire\uninstall.exe
Size . . . . . . . : 151,203 bytes
Age . . . . . . . : 2.2 days (2014-09-18 08:05:05)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 1055DE05502AB270653C5D8A993D098FEE760F1793C620B5F8E6D957FBCAF71A
Product . . . . . : GlassWire Setup
Publisher . . . . : SecureMix LLC
Description . . . : GlassWire Setup
Version . . . . . : 1,0,25,764
LanguageID . . . . : 1033
> Bitdefender . . . : Gen:Trojan.Heur2.FU.amX@aG1D6Ng
Fuzzy . . . . . . : 102.0
References
Forensic Cluster
-13.3s C:\Program Files (x86)\GlassWire
-13.3s C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
-12.4s C:\Program Files (x86)\GlassWire\GWIdlMon.exe
-11.4s C:\Program Files (x86)\GlassWire\GlassWire.exe
-11.0s C:\Program Files (x86)\GlassWire\Qt5Concurrent.dll
-11.0s C:\Program Files (x86)\GlassWire\Qt5Core.dll
-10.7s C:\Program Files (x86)\GlassWire\Qt5Gui.dll
-10.5s C:\Program Files (x86)\GlassWire\Qt5Svg.dll
-10.5s C:\Program Files (x86)\GlassWire\Qt5Widgets.dll
-10.2s C:\Program Files (x86)\GlassWire\Qt5WinExtras.dll
-10.1s C:\Program Files (x86)\GlassWire\icudt52.dll
-9.2s C:\Program Files (x86)\GlassWire\icuin52.dll
-9.0s C:\Program Files (x86)\GlassWire\icuuc52.dll
-8.9s C:\Program Files (x86)\GlassWire\msvcp110.dll
-8.9s C:\Program Files (x86)\GlassWire\msvcr110.dll
-8.8s C:\Program Files (x86)\GlassWire\platforms
-8.8s C:\Program Files (x86)\GlassWire\platforms\qwindows.dll
-8.7s C:\Program Files (x86)\GlassWire\imageformats
-8.7s C:\Program Files (x86)\GlassWire\imageformats\qico.dll
-8.7s C:\Program Files (x86)\GlassWire\imageformats\qico.dll
-8.7s C:\Program Files (x86)\GlassWire\imageformats\qjpeg.dll
-8.6s C:\Program Files (x86)\GlassWire\fonts
-8.6s C:\Program Files (x86)\GlassWire\fonts\OFL.txt
-8.6s C:\Program Files (x86)\GlassWire\fonts\Oswald-Regular.ttf
-8.6s C:\Program Files (x86)\GlassWire\driver\x86
-8.6s C:\Program Files (x86)\GlassWire\driver\x86\gwdrv.cat
-8.6s C:\Program Files (x86)\GlassWire\driver\x86\gwdrv.inf
-8.6s C:\Program Files (x86)\GlassWire\driver\x86\gwdrv.sys
-8.6s C:\Program Files (x86)\GlassWire\driver
-8.6s C:\Program Files (x86)\GlassWire\driver\x64
-8.6s C:\Program Files (x86)\GlassWire\driver\x64\gwdrv.cat
-8.6s C:\Program Files (x86)\GlassWire\driver\x64\gwdrv.inf
-8.6s C:\Program Files (x86)\GlassWire\driver\x64\gwdrv.sys
0.0s C:\Program Files (x86)\GlassWire\uninstall.exe

Strange. I just uploaded the file again for our latest release and it gave me the all clear here https://www.virustotal.com/en/file/83878af3b0379941f99e7c7d3c31ec5eca92e64b86140e1885caac62e8ec3ce9/analysis/ Can you give me the link for this? Also a lot of these companies use the same scanning engine so maybe this is from before Bitdefender updated. Perhaps all these companies use the Bitdefender engine.

Unfortunately false positives are not unusual these days for signature based antivirus products. It’s very frustrating for us.

Hi Servo
Your link is testing “GlassWireSetup.exe” mine is testing uninstall.exe (C:\Program Files (x86)\GlassWire)

https://www.virustotal.com/en/file/1055de05502ab270653c5d8a993d098fee760f1793c620b5f8e6d957fbcaf71a/analysis/1411219910/

The Glasswire.exe file is fine for me:

But as of today (Saturday) UK Time, the uninstall.exe still gets flagged. I will keep checking.

Also, I cannot post any links or images still, it’s a real pain when I’m trying to help you guys!

Thanks.

Michael, I made a change to your account. I think the link/image feature should work now. I will contact Bitdefender yet again and see if they have any ideas. Thank you.

@Servo_GlassWire Thanks, I’ll test it now with this post.

Sunday Morning, 8:44am and still not fixed. Still getting a trojan warning in the uninstaller .exe file.

Thanks, and thanks for fixing the Image issue, seems to be working now.

I couldn’t sleep so I thought I’d stop by and try downloading GW again. As of 2:45 AM MT Bitdefender is showing the all clear! Looks like I’m good-to-go! Keep up the great work!

1 Like

I just installed this a few minutes ago from the link provided at Gizmos freeware and it is still flagged up in my bitdefender, despite a definition update.