To all that keep asking/complaining about viruses of this tool.
Instead of a yes or no, I'll describe what it does (without getting in the obfuscated code, or the files flagged as viruses)
- it adds "winmm.dll" in your registry
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
more info here
You must be registered to see the links
- it copies your hosts file
%SystemRoot%\System32\drivers\etc\hosts
more info here
You must be registered to see the links
- it starts a web server (not talking about the miniweb.exe that listens on port 24148)
- it bypasses your firewall and opens incoming port 54871 for winmm.dll
all the above actions should be considered as red flags, if it does not warn you about them.
So to the question is it malicious?
The answer is that it can definitely become malicious:
- if the dev wants it to be
or
- if another malicious program targets/injects it's code in winmm.dll