Of course, he will steal all your data and personally sell it to someone.

There is a source code on GitHub, you can see what is in it and compile the program yourself) and on VirusTotal, you can see which antiviruses show Trojans)
This might be a stupid question, but if I have, say, two or three viruses and a Trojan on a Windows machine, could I end up infecting an EXE file that I compiled myself?
