You are here

Security Apps Support

NSIS vulnerable to Dll hijacking SHFOLDER.DLL

Submitted by FIlipe Oliveira on August 8, 2016 - 5:06pm

I found out that NSISPortableANSI 2.5.1 loads a DLL (SHFOLDER) without supplying the absolute path, thus vulnerable to DLL Hijack. It may be possible for an attacker to place an arbitrary DLL in specific paths in order to execute malicious code in the context of the loading process.
I found this while analyzing wireshark portable and skype portable, the issue might affects other portable apps.

ClamWin: Can't download virus updates since version 0.99

Submitted by getco on May 31, 2016 - 12:01pm


I can't seem to be able to automatically download virus updates (from withing the program) since version 0.99. Same thing with the latest version 0.99.1. No problems with with 0.98.7. I can also download manually the DB's and add them to the folder and the program recognizes them OK. Any ideas what might have changed in v .99 compared to v .98.7 that could be affecting the updating process?

ClamWin: False alarm or actual worm in PortableChrome?

Submitted by liar666 on March 27, 2016 - 12:44pm


I recently ran ClamWin on a friend's win7 computer and it found a Worn in Chrome Portable. This application was never used, so I assume there is either a bug in the detection of ClamWin or the application came with the worm out-of-the-box :{

C:\PortableApps\PortableApps\GoogleChromePortable\App\Chrome-bin\47.0.2526.106\nacl64.exe: Win.Worm.Nimda-59 FOUND

ClamWin: No definitions updates coming through any more

Submitted by old_man on March 16, 2016 - 9:19pm

For about a week now, whenever I try to update the clamwin definitions nothing is being updated. After a blank reinstall of ClamwinPortable I'm getting the message that the database mirrors are probably all out, and not even the main database is being downloaded. The program is constantly telling me that I should update my virus definitions. Is there something wrong at ClamAV's end?. There were rumours last week that the main database file was going to be renewed. Is this what causes all this?

KeePass: lastest Update deleted database

Submitted by LastSamurai on March 8, 2016 - 3:45pm

The last update of my keepassPortable deleted my .kdbx database file which was stored directly inside KeePassPortable/ main folder. I realize that thats not the best location for that but still and update should not do that.
Of course I can't garantue that the update deleted the file but I was using it before and right after the update I restarted the app and the file was gone.

When downloading Keepass updates, anti-virus blocks it because it matches signature BehavesLike.Win32.Suspicious.xm

Submitted by eroussel on February 3, 2016 - 9:25am

As the subject says, I've been unable to download updated versions of Keepass as the anti-virus blocks it.

Is there something that can be done about this given that in my case, disabling the anti-virus is not an option?

KeePass: Rev 2

Submitted by Manly1138 on January 21, 2016 - 3:13pm

PortableApps posted the Keepass 1.3 update when it came out and a few days later posted a Rev 2 update. Since there is no Rev 2 update on the Keepass website I take it Rev 2 is just a PortableApps update? I can't find any reference to what Rev 2 is ,does ,or why it was needed. I'm just curious as I run Keepass on my laptop and desktop and Flash drive and don't want to get out of sequence on releases.

Just curious. Thank you.

ClamWin: clam false virus detection

Submitted by lillonewolf12 on January 19, 2016 - 5:19am

Hi, I have the latest version of clamwin portable installed and on the hwinfo.paf.exe file it keeps showing it as a virus
when scanned. Also all the new jre java stand alone installers offline (jre-8u66-windows-i586.exe) and updates 60 and 65
keeps showing up as virus`s when scanned. I scanned them with windows defender and virus total and they say no virus.
I tried to contact the database guys but have had no luck.
Thanks, sincerely