MSEndpointMgr / IntuneDebugToolkit

MIT License
70 stars 15 forks source link

There is a trojan in your MSI. Trojan:Script/Wacatac.B!ml #4

Closed bgb-wa closed 1 year ago

bgb-wa commented 1 year ago

Trojan:Script/Wacatac.B!ml This program is dangerous and executes commands from an attacker. Affected items: file: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSEndpoingMgr\Intune Debug Toolkit\AUTOPILOT Pre-provisioning Readiness (Run as Admin).lnk startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSEndpoingMgr\Intune Debug Toolkit\AUTOPILOT Pre-provisioning Readiness (Run as Admin).lnk

mmelkersen commented 1 year ago

Hey, no there are no trojans in the lnk files or powershell scripts. The new version has been digital signed now. That will help a lot :)

bgb-wa commented 1 year ago

[like] Brian Beaton reacted to your message:


From: Mattias Melkersen @.> Sent: Saturday, September 23, 2023 10:34:45 PM To: MSEndpointMgr/IntuneDebugToolkit @.> Cc: Brian Beaton @.>; Author @.> Subject: Re: [MSEndpointMgr/IntuneDebugToolkit] There is a trojan in your MSI. Trojan:Script/Wacatac.B!ml (Issue #4)

Hey, no there are no trojans in the lnk files or powershell scripts. The new version has been digital signed now. That will help a lot :)

— Reply to this email directly, view it on GitHubhttps://github.com/MSEndpointMgr/IntuneDebugToolkit/issues/4#issuecomment-1732423974, or unsubscribehttps://github.com/notifications/unsubscribe-auth/A6GXRYSFCCDTB5AIHBO5MADX35PYLANCNFSM6AAAAAAXNYOKRE. You are receiving this because you authored the thread.Message ID: @.***>

NOTICE: This email and any attachments are for the sole use of the intended recipients and may be privileged or confidential. Any distribution, printing or other use by anyone else is prohibited. If you are not an intended recipient, please contact the sender immediately, and permanently delete this email and attachments. If you no longer wish to receive commercial electronic messages from Wellington-Altus Private Wealth Inc., please send an email to @.*** Please note that we may still send messages for which we do not require consent.