Menu
Software: BuffGod
Report Date: August 14, 2026
Components: This report covers two components — Agent (agent.exe), the core component that modifies game memory and the primary target of security software detection; and Frontend (BuffGodTrainer.exe), a UI program that does not modify memory.
| Security Software | Whitelist | Detection | Possible Prompts | User Action |
|---|---|---|---|---|
| Windows Defender (Microsoft) | Approved | Clean | No virus detection. But unsigned exe will trigger SmartScreen blue dialog "Windows protected your PC". This is a separate system, independent from Defender whitelist. | Click "More info" → "Run anyway" |
| 360 | Cannot submit | Virus (Trojan) | Virus detected, silently deletes agent.exe, no prompt | Restore from quarantine and whitelist (see below) |
| McAfee | Approved | PUA (Potentially Unwanted) | No virus detection. May show "potentially unwanted program" or "risk program" warning on first run | Choose "Allow" or "Trust" |
| Norton | Approved | HackTool / Trainer | No virus detection. May show "hacking tool/trainer detected" warning | Choose "Allow" or add to "Exclusions" |
| Avast | Approved | PUA | No virus detection. PUA detection enabled by default, may show "potentially unwanted program" warning | Choose "Allow" or whitelist |
| AVG (Gen Digital) | Approved | PUA | No virus detection. Same engine as Avast, identical behavior | Choose "Allow" or whitelist |
| Bitdefender | Approved | PUA / Risk Tool | No virus detection. Strict PUA detection, may show "trainer tool detected" prompt | Choose "Allow" or whitelist |
| Kaspersky | Approved | HackTool / Riskware | No virus detection. Risk software detection enabled by default, may show "risk software HackTool" warning | Choose "Allow" or temporarily disable PUA detection |
| ESET NOD32 | Approved | Clean / Unknown | No virus detection. Relatively friendly, may show "unknown publisher" due to lack of signature | Choose "Allow" |
* Based on public policies of each security software. Actual behavior may vary depending on software version, user configuration (e.g. "auto-resolve threats" enabled, PUA detection sensitivity), and detection engine updates.
This is an inherent limitation of unsigned software. Please understand:
The frontend is a clean UI program that does not modify memory and is generally not detected as virus. However, due to being unsigned, users may encounter when double-clicking:
agent.exe is launched by frontend via ShellExecuteW (not double-clicked by user), so it does not trigger SmartScreen, but is still subject to antivirus PUA/HackTool detection.
Due to policy restrictions of 360 and all Chinese security software, we cannot submit whitelist application. 360 users may find agent.exe silently deleted when running this software. If this happens, follow these steps:
This software needs to submit whitelist applications to security software. If we use packing (VMProtect, Themida, etc.) or code obfuscation:
Therefore, this software runs transparently with plaintext code + whitelist application, not packing/obfuscation.
This section truthfully declares all behaviors of agent.exe for verification by users and security software.
Malicious/Risky behaviors Legitimate but unwelcome behaviors
| Behavior | Status |
|---|---|
| Self-replication / propagation | None |
| Backdoor | None |
| Rootkit hiding | None |
| Disabling / damaging AV | None |
| Code packing / obfuscation | None |
| Keylogging | None |
| Screenshot upload | None |
| Stealing browser passwords/cookies | None |
| Stealing system credentials | None |
| Stealing user files | None |
| Reading clipboard | None |
| Stealing contacts/chats | None |
| Network sniffing | None |
| DDoS attack | None |
| Port scanning | None |
| Brute force | None |
| Exploit / privilege escalation | None |
| Lateral movement | None |
| Botnet node | None |
| Backdoor port listening | None |
| Ransomware encryption | None |
| Deleting / damaging files | None |
| Damaging system boot | None |
| Disk formatting | None |
| Crypto mining | None |
| Ad popup hijacking | None |
| Browser homepage/DNS hijacking | None |
| Modifying system proxy | None |
| Silent software install | None |
Legitimate but unwelcome behaviors (many legitimate software does these, but this software does not):
| Behavior | Status |
|---|---|
| Modifying registry | None |
| Writing to system directories | None |
| Modifying system files | None |
| Installing kernel drivers | None |
| Installing system services | None |
| Autostart | None |
| Modifying startup entries | None |
| Creating scheduled tasks | None |
| Modifying system time | None |
| Creating/modifying user accounts | None |
| Modifying hosts file | None |
| Modifying firewall rules | None |
| Modifying environment variables | None |
| Modifying system PATH | None |
| Modifying file associations | None |
| Modifying default programs | None |
| Creating desktop shortcuts (not user-initiated) | None |
| Creating Start Menu entries | None |
| Injecting non-target processes (browser/IM/system) | None |
| Modifying game save files | None |
| Modifying game config files | None |
| Resident after exit | None |
| Creating daemon processes | None |
| Reporting usage statistics / behavior analytics | None |
| Collecting and uploading crash logs | None |
| Collecting installed software list | None |
| Collecting network info (IP/MAC/SSID) | None |
| Popup notifications / push | None |
| Modifying browser settings | None |
| Writing to system temp directory | None |
| Leaving config file residue | None |
| Behavior | Reason |
|---|---|
| Read/write target game memory | Implements trainer functionality, target single-player game only |
| Run helper code inside game | Triggered only for encrypted games, not used by normal features |
| Allocate temporary memory inside game | For installing feature code, target game only |
| Temporarily rewrite game instructions | Implements "freeze/lock", auto-restored on exit |
| Read hardware ID (CPU/motherboard serial) | Derives key to prevent cross-machine piracy, read-only, not uploaded |
| Decrypt modification instructions | Decrypted in memory, plaintext never written to disk |
| Local key verification when downloading | When downloading trainer data, the software verifies with the server using an automatically generated local random key, ensuring data is only issued to this software. Fully automatic, no account registration, no personal information collected |
| One-time online authorization on first use | First use requires a one-time connection to the official server to complete authorization; afterwards the software works offline long-term. The server only recognizes an anonymous local key — no account registration, no personal information collected |
| Writing local authorization files | The authorization key and credential are stored inside the software's own directory; deleting the software directory removes them completely, and they automatically become invalid on another computer |
| Verifying software integrity | Computes the hash of the frontend program file and compares it with the official value, preventing tampered counterfeit versions from obtaining trainer data |
| Communicate with frontend | Receives operation commands from BuffGodTrainer.exe |
| Request admin privileges | Only needed during injection, frontend always runs as standard user |
| Read target game version | Verifies version match before injection, prevents wrong injection |
| Write log file | For debugging, written to own directory, not uploaded |
| Crash protection | Auto-restores on error, not triggered normally |