Software Security Report

Software: BuffGod
Report Date: August 14, 2026
Components: This report covers two components — Agent (agent.exe), the core component that modifies game memory and the primary target of security software detection; and Frontend (BuffGodTrainer.exe), a UI program that does not modify memory.

Important Prerequisite (read first): This software is currently not digitally signed. This means:
  • We cannot guarantee "no prompts at all" — we can only guarantee no virus detection (no deletion, no quarantine)
  • Unsigned exe will trigger Windows SmartScreen blue dialog (frontend) and UAC "unknown publisher" prompt on first run
  • Each security software has independent PUA/HackTool detection for "game trainer" software. Whitelisting only resolves "virus detection", not "warning prompts"
Summary: We have submitted this software's entire codebase to all major security software except 360 for whitelist approval, none detect it as a virus, all confirming this software contains no malicious code. However, some will show "trainer/HackTool/PUA" warnings — this is the essential work of game trainers modifying game memory, unavoidable, requiring user approval; 360 will detect and delete agent.exe, requiring restoration from quarantine. This software does not use packing/obfuscation techniques.
Pass No virus, no warning Warning No virus, but PUA/HackTool warning Virus Detected and deleted

Actual Behavior by Security Software

Security Software Whitelist Detection Possible Prompts User Action
Windows Defender (Microsoft) Approved Clean No virus detection. But unsigned exe will trigger SmartScreen blue dialog "Windows protected your PC". This is a separate system, independent from Defender whitelist. Click "More info" → "Run anyway"
360 Cannot submit Virus (Trojan) Virus detected, silently deletes agent.exe, no prompt Restore from quarantine and whitelist (see below)
McAfee Approved PUA (Potentially Unwanted) No virus detection. May show "potentially unwanted program" or "risk program" warning on first run Choose "Allow" or "Trust"
Norton Approved HackTool / Trainer No virus detection. May show "hacking tool/trainer detected" warning Choose "Allow" or add to "Exclusions"
Avast Approved PUA No virus detection. PUA detection enabled by default, may show "potentially unwanted program" warning Choose "Allow" or whitelist
AVG (Gen Digital) Approved PUA No virus detection. Same engine as Avast, identical behavior Choose "Allow" or whitelist
Bitdefender Approved PUA / Risk Tool No virus detection. Strict PUA detection, may show "trainer tool detected" prompt Choose "Allow" or whitelist
Kaspersky Approved HackTool / Riskware No virus detection. Risk software detection enabled by default, may show "risk software HackTool" warning Choose "Allow" or temporarily disable PUA detection
ESET NOD32 Approved Clean / Unknown No virus detection. Relatively friendly, may show "unknown publisher" due to lack of signature Choose "Allow"

* Based on public policies of each security software. Actual behavior may vary depending on software version, user configuration (e.g. "auto-resolve threats" enabled, PUA detection sensitivity), and detection engine updates.

About "Whitelist Approved ≠ No Warnings"

This is an inherent limitation of unsigned software. Please understand:

  • Whitelist resolves "virus detection": After whitelist approval, security software will not flag agent.exe as virus/trojan, will not delete or quarantine it
  • Whitelist does not resolve "classification warnings": Each vendor has independent PUA/HackTool detection for "game trainers". Even with whitelist, may still show "this is a trainer tool" warning for user confirmation
  • Whitelist does not resolve SmartScreen: SmartScreen is a separate reputation system. Unsigned exe will trigger blue dialog regardless of antivirus whitelist
  • To completely eliminate all prompts, code signing is required (I am an individual, no enterprise qualification and no money to buy), which will resolve SmartScreen and "unknown publisher" prompts

Frontend (BuffGodTrainer.exe) Possible Prompts

The frontend is a clean UI program that does not modify memory and is generally not detected as virus. However, due to being unsigned, users may encounter when double-clicking:

  • Windows SmartScreen blue dialog: "Windows protected your PC" — click "More info" → "Run anyway"
  • UAC "unknown publisher" prompt: Standard prompt for unsigned exe, click "Yes" to continue
  • Some strict security software may perform heuristic scans on unsigned downloaded exe, but the frontend is a clean program and generally not flagged

agent.exe is launched by frontend via ShellExecuteW (not double-clicked by user), so it does not trigger SmartScreen, but is still subject to antivirus PUA/HackTool detection.

For 360 Total Security Users

Due to policy restrictions of 360 and all Chinese security software, we cannot submit whitelist application. 360 users may find agent.exe silently deleted when running this software. If this happens, follow these steps:

  • Open 360 → Trojan Scan → "Restore Area" at bottom left → find agent.exe → click Restore and check "Trust this file"
  • Or go to 360 → Settings → Trust Zone → manually add agent.exe directory
  • After restoration, re-run the software to use normally
  • Recommendation: Temporarily disable 360's "auto-resolve threats" before running to prevent re-deletion

Why No Packing / Obfuscation?

This software needs to submit whitelist applications to security software. If we use packing (VMProtect, Themida, etc.) or code obfuscation:

  • Packed programs cannot pass security software review — security software will reject whitelist application for "attempting to hide code"
  • Already-approved security software will re-detect due to changed file hash
  • Packing itself triggers more heuristic detections

Therefore, this software runs transparently with plaintext code + whitelist application, not packing/obfuscation.

Software Behavior Report (Submitted to Security Vendors)

This section truthfully declares all behaviors of agent.exe for verification by users and security software.

1. Behaviors This Software Does NOT Perform (including legitimate but unwelcome items)

Malicious/Risky behaviors  Legitimate but unwelcome behaviors

BehaviorStatus
Self-replication / propagationNone
BackdoorNone
Rootkit hidingNone
Disabling / damaging AVNone
Code packing / obfuscationNone
KeyloggingNone
Screenshot uploadNone
Stealing browser passwords/cookiesNone
Stealing system credentialsNone
Stealing user filesNone
Reading clipboardNone
Stealing contacts/chatsNone
Network sniffingNone
DDoS attackNone
Port scanningNone
Brute forceNone
Exploit / privilege escalationNone
Lateral movementNone
Botnet nodeNone
Backdoor port listeningNone
Ransomware encryptionNone
Deleting / damaging filesNone
Damaging system bootNone
Disk formattingNone
Crypto miningNone
Ad popup hijackingNone
Browser homepage/DNS hijackingNone
Modifying system proxyNone
Silent software installNone

Legitimate but unwelcome behaviors (many legitimate software does these, but this software does not):

BehaviorStatus
Modifying registryNone
Writing to system directoriesNone
Modifying system filesNone
Installing kernel driversNone
Installing system servicesNone
AutostartNone
Modifying startup entriesNone
Creating scheduled tasksNone
Modifying system timeNone
Creating/modifying user accountsNone
Modifying hosts fileNone
Modifying firewall rulesNone
Modifying environment variablesNone
Modifying system PATHNone
Modifying file associationsNone
Modifying default programsNone
Creating desktop shortcuts (not user-initiated)None
Creating Start Menu entriesNone
Injecting non-target processes (browser/IM/system)None
Modifying game save filesNone
Modifying game config filesNone
Resident after exitNone
Creating daemon processesNone
Reporting usage statistics / behavior analyticsNone
Collecting and uploading crash logsNone
Collecting installed software listNone
Collecting network info (IP/MAC/SSID)None
Popup notifications / pushNone
Modifying browser settingsNone
Writing to system temp directoryNone
Leaving config file residueNone

2. Behaviors This Software Performs

⚠ Key point: All modification operations of this software are in-memory only, cleared on power off. No files modified, nothing written to system, no persistent traces.
BehaviorReason
Read/write target game memoryImplements trainer functionality, target single-player game only
Run helper code inside gameTriggered only for encrypted games, not used by normal features
Allocate temporary memory inside gameFor installing feature code, target game only
Temporarily rewrite game instructionsImplements "freeze/lock", auto-restored on exit
Read hardware ID (CPU/motherboard serial)Derives key to prevent cross-machine piracy, read-only, not uploaded
Decrypt modification instructionsDecrypted in memory, plaintext never written to disk
Local key verification when downloadingWhen downloading trainer data, the software verifies with the server using an automatically generated local random key, ensuring data is only issued to this software. Fully automatic, no account registration, no personal information collected
One-time online authorization on first useFirst use requires a one-time connection to the official server to complete authorization; afterwards the software works offline long-term. The server only recognizes an anonymous local key — no account registration, no personal information collected
Writing local authorization filesThe authorization key and credential are stored inside the software's own directory; deleting the software directory removes them completely, and they automatically become invalid on another computer
Verifying software integrityComputes the hash of the frontend program file and compares it with the official value, preventing tampered counterfeit versions from obtaining trainer data
Communicate with frontendReceives operation commands from BuffGodTrainer.exe
Request admin privilegesOnly needed during injection, frontend always runs as standard user
Read target game versionVerifies version match before injection, prevents wrong injection
Write log fileFor debugging, written to own directory, not uploaded
Crash protectionAuto-restores on error, not triggered normally
Close the game or restart the computer, all modifications disappear instantly, game returns to original. This software leaves no permanent traces. No installation required, deleting the software's directory = uninstalling all related data. It's that simple. (Also remember to delete the software's cache folder: C:\Users\YourUsername\AppData\Local\com.buffgod.trainer\)

Security Commitment

  • No malicious code: No trojans, no backdoors, no data theft
  • Only modifies single-player game memory: Does not affect online games or other players
  • No personal data collection: See Privacy Policy
  • Transparent code: No packing or obfuscation, accepts security software review
  • Free forever: No charges in any form