1. Welcome to Tacoma World!

    You are currently viewing as a guest! To get full-access, you need to register for a FREE account.

    As a registered member, you’ll be able to:
    • Participate in all Tacoma discussion topics
    • Communicate privately with other Tacoma owners from around the world
    • Post your own photos in our Members Gallery
    • Access all special features of the site

OVTune is a virus until proven otherwise

Discussion in '3rd Gen. Tacomas (2016-2023)' started by flat_tire, Jul 6, 2019.

Thread Status:
Not open for further replies.
  1. Jul 6, 2019 at 5:31 PM
    #1
    flat_tire

    flat_tire [OP] Well-Known Member

    Joined:
    Aug 8, 2016
    Member:
    #194113
    Messages:
    125
    Gender:
    Male
    First Name:
    John
    Independence, KY 41051
    Vehicle:
    2016 Tacoma TRD Off-road ACLB blue, 2018 Tacoma TRD Sport DCSB white, 2020 supercharged Tacoma Limited DCSB magnetic grey metallic, 1993 AMGE HMMWV, 1993 Ford Mustang GT 5.0 supercharged
    2020 Tacoma: Icon stage 9, Magnuson supercharger, URD full exhaust, solar 2018 Tacoma; OME 2in suspension 2016 Tacoma: Falcon front and rear rate adjustable suspension, rear airbag lift
    I just received my $799 purchase of OVTune, downloaded their application from www.ovtuned.com and immediately my antivirus software quarrantined it as a trojan.

    I uploaded the file to virustotal.com and here are the results
    p5flash_V1.2.2.exe
    https://www.virustotal.com/gui/file...2ee3c9c62729c099c40469129f9bc566426/detection

    p5flash_V1.2.1.exe
    https://www.virustotal.com/gui/file...161aa9ee1bd2475c39ff80c78afbb86fee3/detection

    I have reached out to OVtune and also submitted samples of both files above to Cisco AMP Symantec for deep analysis. I'll post the reports once they come back..
     
    09 Redneck and EatSleepTacos like this.
  2. Jul 6, 2019 at 5:34 PM
    #2
    PvilleJohn

    PvilleJohn SVT Raptor

    Joined:
    Aug 10, 2015
    Member:
    #161469
    Messages:
    5,344
    Gender:
    Male
    First Name:
    John
    Powdersville SC
    Vehicle:
    SVT Raptor
    Hmmm, I’m sure there’s an explanation on this. Lots of people are running the tune problem free. :notsure:
     
  3. Jul 6, 2019 at 5:35 PM
    #3
    MESO

    MESO Major Modder Vendor

    Joined:
    Feb 16, 2015
    Member:
    #148809
    Messages:
    16,294
    Gender:
    Male
    State of Jefferson
    Vehicle:
    2016 DCLB TRD HELLCAT SWAP
    Just disable antivirus on your computer and install the tune. There is nothing harmful in the package. OV is not trying to hack you lol
     
  4. Jul 6, 2019 at 5:36 PM
    #4
    EatSleepTacos

    EatSleepTacos Well-Known Member

    Joined:
    Mar 24, 2015
    Member:
    #151688
    Messages:
    59,830
    Gender:
    Male
    First Name:
    Randy
    West Valley, AZ
    Vehicle:
    2017 4Runner
    This is most likely the case, but it never hurts to be cautious. I’m curious to hear the report back on the deeper analysis.
     
  5. Jul 6, 2019 at 5:37 PM
    #5
    12TRDTacoma

    12TRDTacoma Powered by Ford, GM, VW, and Mercedes

    Joined:
    Aug 20, 2012
    Member:
    #85133
    Messages:
    16,665
    Gender:
    Male
    First Name:
    Rob
    Concordia
    Vehicle:
    12 TRD Sport DCLB 4x4 Supercharged
    Boosted
    That sounds like something an OVTune fanboy would say. o_O



























    Just kidding brotha. :D
     
    PvilleJohn, Lawfarin and MESO[QUOTED] like this.
  6. Jul 6, 2019 at 5:38 PM
    #6
    MESO

    MESO Major Modder Vendor

    Joined:
    Feb 16, 2015
    Member:
    #148809
    Messages:
    16,294
    Gender:
    Male
    State of Jefferson
    Vehicle:
    2016 DCLB TRD HELLCAT SWAP
    It’s probably scraping the names and sees “VIRUS” because the name of the company. A ton of people had it pop up with windows defender(me included). DISABLE, INSTALL, RE-ENABLE.
     
  7. Jul 6, 2019 at 5:38 PM
    #7
    su.b.rat

    su.b.rat broken truck

    Joined:
    Jul 30, 2016
    Member:
    #193316
    Messages:
    9,869
    how do you prove it otherwise? how about hundreds of users with zero issues...

    really should read up on all available info before drawing so much attention, OP. not necessary or helpful. all answers available, always have been.
     
  8. Jul 6, 2019 at 5:38 PM
    #8
    cstern1

    cstern1 Well-Known Member

    Joined:
    May 2, 2018
    Member:
    #252343
    Messages:
    534
    Gender:
    Male
    First Name:
    Caleb
    KCK
    Vehicle:
    2017 DCSB Sport
    Its because some of the code in the flash utility is locked so it can't be stolen. Virus scanners can't read the code so they flag it as a virus.

    Most likely the deep analysis will still say virus unless they take the time to crack and decompile the code.
     
  9. Jul 6, 2019 at 5:38 PM
    #9
    EatSleepTacos

    EatSleepTacos Well-Known Member

    Joined:
    Mar 24, 2015
    Member:
    #151688
    Messages:
    59,830
    Gender:
    Male
    First Name:
    Randy
    West Valley, AZ
    Vehicle:
    2017 4Runner
    Maybe, maybe not. I’m still curious to hear back on the report.
     
    PvilleJohn likes this.
  10. Jul 6, 2019 at 5:39 PM
    #10
    Paul631

    Paul631 Well-Known Member

    Joined:
    May 31, 2016
    Member:
    #188352
    Messages:
    2,451
    Gender:
    Male
    Vehicle:
    2016 4x4 5-spd Utility Package
    Bilstein 6112/5160 Grabber X3's
  11. Jul 6, 2019 at 5:39 PM
    #11
    MESO

    MESO Major Modder Vendor

    Joined:
    Feb 16, 2015
    Member:
    #148809
    Messages:
    16,294
    Gender:
    Male
    State of Jefferson
    Vehicle:
    2016 DCLB TRD HELLCAT SWAP
    that was just my guess. But @cstern1 description sounds more plausible
     
    Inferno__Taco likes this.
  12. Jul 6, 2019 at 5:41 PM
    #12
    EatSleepTacos

    EatSleepTacos Well-Known Member

    Joined:
    Mar 24, 2015
    Member:
    #151688
    Messages:
    59,830
    Gender:
    Male
    First Name:
    Randy
    West Valley, AZ
    Vehicle:
    2017 4Runner
    Yeah that seems like a plausible cause for it. I know nothing about tune coding though so not sure if it’s accurate.

    What I can guarantee though is this threads about to be filled with a lot of hate towards OP and people speculating some ridiculous shit in the meantime. This is TW after all.
     
  13. Jul 6, 2019 at 5:41 PM
    #13
    cstern1

    cstern1 Well-Known Member

    Joined:
    May 2, 2018
    Member:
    #252343
    Messages:
    534
    Gender:
    Male
    First Name:
    Caleb
    KCK
    Vehicle:
    2017 DCSB Sport
    Its what @OVTune has said and it makes sense. Either that, or its because it is a utility that can flash code to something that supposedly couldn't be hacked. So that implies the utility is malicious. Sort of like how antivirus quarantines keygens and other fun utilities one may have.
     
  14. Jul 6, 2019 at 5:42 PM
    #14
    snickers

    snickers My new, overpriced heaping pile of shit

    Joined:
    Nov 22, 2017
    Member:
    #236679
    Messages:
    2,218
    Gender:
    Male
    Vehicle:
    2024 Tacoma Tailhunter 5ft bed Bronze Oxide
    I assume you haven't submitted for the reg key yet? I would wait for the results before going past the point of no money return.
     
  15. Jul 6, 2019 at 5:42 PM
    #15
    Steves104x4

    Steves104x4 Well-Known Member

    Joined:
    Apr 17, 2010
    Member:
    #35468
    Messages:
    17,078
    Gender:
    Male
    First Name:
    Steve
    Buffalo NY
    Vehicle:
    2010 RC 2.7 4x4
    BUCKLE UP! It makes it harder for Aliens to pull you out of your Truck.
     
    stealthmode and Paul631 like this.
  16. Jul 6, 2019 at 5:45 PM
    #16
    wahoobie

    wahoobie TidewaterCustoms.com

    Joined:
    Nov 6, 2016
    Member:
    #201692
    Messages:
    2,183
    Gender:
    Male
    First Name:
    chris
    Suffolk, VA
    Vehicle:
    2016 DCLB 4x4 SR5ish
    VA/Remote Elite Performance Tuning Services
    OVT is the virus remover that cleaned my Tacomas crap factory tune. Your virus scanner just didn't want to be 1-uped.
    :broccoli:
     
    4x2maury, Saeros, Shellshock and 7 others like this.
  17. Jul 6, 2019 at 5:47 PM
    #17
    FloridaSon

    FloridaSon Well-Known Member

    Joined:
    Mar 23, 2019
    Member:
    #287615
    Messages:
    96
    Gender:
    Male
    Vehicle:
    White SR Gen 3
    This is a known issue in the OVTune instructions online and on Tacomaworld. Many software installs require the virus program to be disabled. Like tax software, etc. However, of course it is your absolute right to question and check it. Me, I am taking the risk.
     
  18. Jul 6, 2019 at 5:52 PM
    #18
    GrittyTaco

    GrittyTaco Well-Known Member

    Joined:
    Jun 7, 2016
    Member:
    #189029
    Messages:
    409
    Gender:
    Male
    Hatboro, pa
    Vehicle:
    2017 dclb trd or
    Two messages total... mhmmm looks like @OVTune started a new profile just to enjoy some popcorn on a Saturday night ..
     
    stealthmode likes this.
  19. Jul 6, 2019 at 5:54 PM
    #19
    flat_tire

    flat_tire [OP] Well-Known Member

    Joined:
    Aug 8, 2016
    Member:
    #194113
    Messages:
    125
    Gender:
    Male
    First Name:
    John
    Independence, KY 41051
    Vehicle:
    2016 Tacoma TRD Off-road ACLB blue, 2018 Tacoma TRD Sport DCSB white, 2020 supercharged Tacoma Limited DCSB magnetic grey metallic, 1993 AMGE HMMWV, 1993 Ford Mustang GT 5.0 supercharged
    2020 Tacoma: Icon stage 9, Magnuson supercharger, URD full exhaust, solar 2018 Tacoma; OME 2in suspension 2016 Tacoma: Falcon front and rear rate adjustable suspension, rear airbag lift
    I'm only reporting exactly what I found. I'm a retired computer security professional, I know these AV tools sometimes have false positives however to have 23 different antivirus vendors flag the two latest versions of OV tune as malware is not a good thing.

    I'm not suggesting OVTune is intentionaly putting malware in their application, it's possible that a hacker has altered their software.
     
  20. Jul 6, 2019 at 5:57 PM
    #20
    flat_tire

    flat_tire [OP] Well-Known Member

    Joined:
    Aug 8, 2016
    Member:
    #194113
    Messages:
    125
    Gender:
    Male
    First Name:
    John
    Independence, KY 41051
    Vehicle:
    2016 Tacoma TRD Off-road ACLB blue, 2018 Tacoma TRD Sport DCSB white, 2020 supercharged Tacoma Limited DCSB magnetic grey metallic, 1993 AMGE HMMWV, 1993 Ford Mustang GT 5.0 supercharged
    2020 Tacoma: Icon stage 9, Magnuson supercharger, URD full exhaust, solar 2018 Tacoma; OME 2in suspension 2016 Tacoma: Falcon front and rear rate adjustable suspension, rear airbag lift
    I have access to very expensive malware analysis services, the files are being analyzed. As soon as I have results I will post. Anyone is also free to repeat these tests.

    Filename MD5
    p5flash_V1.2.1.exe f064c5b93b1f8c01d404f04c3bdadc8c


    Filename MD5
    p5flash_V1.2.2.exe 2d600ee1c16c273262fd16429711e238
     
Thread Status:
Not open for further replies.

Products Discussed in

To Top