A small handful of the 70+ engines flag the installer — and every one of them is an automated AI / heuristic guess, not a match against a known virus. The live count and exact labels are on the VirusTotal report linked above. Here's how to read them so you can judge for yourself.
How to decode a flag's name
...!ml, .ml.score, 'ML', 'machine learning' — an AI guess. The engine's model thinks the file might be something; it did not match any actual virus.malicious_confidence_60% and similar — the engine telling you how unsure it is. 60% is barely better than a coin flip; a genuine detection is definitive and names the real malware.- 'Heur', 'Suspicious', 'Suspected' — 'heuristic': it looks a little unusual, that's all. Not a known threat.
Wacatac, susgen, Trojan.Malware.<numbers>, W32.Malware — generic catch-all buckets vendors drop unknown, unsigned files into. Wacatac.B!ml in particular is one of the most common false positives on the internet — search it and you'll find it hitting countless legitimate installers.
Why ROID trips them
ROID's installer is tiny (~300 KB) and downloads the app straight from this site when you run it. That 'small program that fetches and runs more' shape is exactly what a malware downloader looks like, so AI models can flag the pattern — not anything actually inside the file. It's now code-signed (publisher: Dawson Stanczyk, verified by Microsoft), which clears most of these guesses, but a new file can take a little while to build reputation with every engine.
How you can tell it's a false positive
A real virus lights up 40–60+ engines at once, all naming the same known malware by signature. A false positive looks exactly like ROID's report: a scattered few engines, all 'ml' / 'heuristic' / 'confidence' guesses, none agreeing on what it supposedly is — while the large majority pass it clean.
What we do about it
The installer is code-signed through Microsoft's Trusted Signing — the one thing that actually clears these flags. On top of that: updates download from this site over HTTPS and are cryptographically signed (Ed25519); there's no bundled adware, miners, or trackers; and you can verify the exact file yourself with the SHA-256 above, the live VirusTotal report, or by running it in a VM. Still unsure? Contact us or ask in Discord.