Software Security Report

Software: BuffGod
Report Date: August 14, 2026
Components: This report covers two components — Agent (agent.exe), the core component that modifies game memory and the primary target of security software detection; and Frontend (BuffGodTrainer.exe), a UI program that does not modify memory.

Important Prerequisite (read first): This software is currently not digitally signed. This means:
Summary: We have submitted this software's entire codebase to all major security software except 360 for whitelist approval, none detect it as a virus, all confirming this software contains no malicious code. However, some will show "trainer/HackTool/PUA" warnings — this is the essential work of game trainers modifying game memory, unavoidable, requiring user approval; 360 will detect and delete agent.exe, requiring restoration from quarantine. This software does not use packing/obfuscation techniques.
Pass No virus, no warning Warning No virus, but PUA/HackTool warning Virus Detected and deleted

Actual Behavior by Security Software

Security Software Whitelist Detection Possible Prompts User Action
Windows Defender (Microsoft) Approved Clean No virus detection. But unsigned exe will trigger SmartScreen blue dialog "Windows protected your PC". This is a separate system, independent from Defender whitelist. Click "More info" → "Run anyway"
360 Cannot submit Virus (Trojan) Virus detected, silently deletes agent.exe, no prompt Restore from quarantine and whitelist (see below)
McAfee Approved PUA (Potentially Unwanted) No virus detection. May show "potentially unwanted program" or "risk program" warning on first run Choose "Allow" or "Trust"
Norton Approved HackTool / Trainer No virus detection. May show "hacking tool/trainer detected" warning Choose "Allow" or add to "Exclusions"
Avast Approved PUA No virus detection. PUA detection enabled by default, may show "potentially unwanted program" warning Choose "Allow" or whitelist
AVG (Gen Digital) Approved PUA No virus detection. Same engine as Avast, identical behavior Choose "Allow" or whitelist
Bitdefender Approved PUA / Risk Tool No virus detection. Strict PUA detection, may show "trainer tool detected" prompt Choose "Allow" or whitelist
Kaspersky Approved HackTool / Riskware No virus detection. Risk software detection enabled by default, may show "risk software HackTool" warning Choose "Allow" or temporarily disable PUA detection
ESET NOD32 Approved Clean / Unknown No virus detection. Relatively friendly, may show "unknown publisher" due to lack of signature Choose "Allow"

* Based on public policies of each security software. Actual behavior may vary depending on software version, user configuration (e.g. "auto-resolve threats" enabled, PUA detection sensitivity), and detection engine updates.

About "Whitelist Approved ≠ No Warnings"

This is an inherent limitation of unsigned software. Please understand:

Frontend (BuffGodTrainer.exe) Possible Prompts

The frontend is a clean UI program that does not modify memory and is generally not detected as virus. However, due to being unsigned, users may encounter when double-clicking:

agent.exe is launched by frontend via ShellExecuteW (not double-clicked by user), so it does not trigger SmartScreen, but is still subject to antivirus PUA/HackTool detection.

For 360 Total Security Users

Due to policy restrictions of 360 and all Chinese security software, we cannot submit whitelist application. 360 users may find agent.exe silently deleted when running this software. If this happens, follow these steps:

Why No Packing / Obfuscation?

This software needs to submit whitelist applications to security software. If we use packing (VMProtect, Themida, etc.) or code obfuscation:

Therefore, this software runs transparently with plaintext code + whitelist application, not packing/obfuscation.

Software Behavior Report (Submitted to Security Vendors)

This section truthfully declares all behaviors of agent.exe for verification by users and security software.

1. Behaviors This Software Does NOT Perform (including legitimate but unwelcome items)

Malicious/Risky behaviors  Legitimate but unwelcome behaviors

BehaviorStatus
Self-replication / propagationNone
BackdoorNone
Rootkit hidingNone
Disabling / damaging AVNone
Code packing / obfuscationNone
KeyloggingNone
Screenshot uploadNone
Stealing browser passwords/cookiesNone
Stealing system credentialsNone
Stealing user filesNone
Reading clipboardNone
Stealing contacts/chatsNone
Network sniffingNone
DDoS attackNone
Port scanningNone
Brute forceNone
Exploit / privilege escalationNone
Lateral movementNone
Botnet nodeNone
Backdoor port listeningNone
Ransomware encryptionNone
Deleting / damaging filesNone
Damaging system bootNone
Disk formattingNone
Crypto miningNone
Ad popup hijackingNone
Browser homepage/DNS hijackingNone
Modifying system proxyNone
Silent software installNone

Legitimate but unwelcome behaviors (many legitimate software does these, but this software does not):

BehaviorStatus
Modifying registryNone
Writing to system directoriesNone
Modifying system filesNone
Installing kernel driversNone
Installing system servicesNone
AutostartNone
Modifying startup entriesNone
Creating scheduled tasksNone
Modifying system timeNone
Creating/modifying user accountsNone
Modifying hosts fileNone
Modifying firewall rulesNone
Modifying environment variablesNone
Modifying system PATHNone
Modifying file associationsNone
Modifying default programsNone
Creating desktop shortcuts (not user-initiated)None
Creating Start Menu entriesNone
Injecting non-target processes (browser/IM/system)None
Modifying game save filesNone
Modifying game config filesNone
Resident after exitNone
Creating daemon processesNone
Reporting usage statistics / behavior analyticsNone
Collecting and uploading crash logsNone
Collecting installed software listNone
Collecting network info (IP/MAC/SSID)None
Popup notifications / pushNone
Modifying browser settingsNone
Writing to system temp directoryNone
Leaving config file residueNone

2. Behaviors This Software Performs

⚠ Key point: All modification operations of this software are in-memory only, cleared on power off. No files modified, nothing written to system, no persistent traces.
BehaviorReason
Read/write target game memoryImplements trainer functionality, target single-player game only
Run helper code inside gameTriggered only for encrypted games, not used by normal features
Allocate temporary memory inside gameFor installing feature code, target game only
Temporarily rewrite game instructionsImplements "freeze/lock", auto-restored on exit
Read hardware ID (CPU/motherboard serial)Derives key to prevent cross-machine piracy, read-only, not uploaded
Decrypt modification instructionsDecrypted in memory, plaintext never written to disk
Local key verification when downloadingWhen downloading trainer data, the software verifies with the server using an automatically generated local random key, ensuring data is only issued to this software. Fully automatic, no account registration, no personal information collected
One-time online authorization on first useFirst use requires a one-time connection to the official server to complete authorization; afterwards the software works offline long-term. The server only recognizes an anonymous local key — no account registration, no personal information collected
Writing local authorization filesThe authorization key and credential are stored inside the software's own directory; deleting the software directory removes them completely, and they automatically become invalid on another computer
Verifying software integrityComputes the hash of the frontend program file and compares it with the official value, preventing tampered counterfeit versions from obtaining trainer data
Communicate with frontendReceives operation commands from BuffGodTrainer.exe
Request admin privilegesOnly needed during injection, frontend always runs as standard user
Read target game versionVerifies version match before injection, prevents wrong injection
Write log fileFor debugging, written to own directory, not uploaded
Crash protectionAuto-restores on error, not triggered normally
Close the game or restart the computer, all modifications disappear instantly, game returns to original. This software leaves no permanent traces. No installation required, deleting the software's directory = uninstalling all related data. It's that simple. (Also remember to delete the software's cache folder: C:\Users\YourUsername\AppData\Local\com.buffgod.trainer\)

Security Commitment

Back