ucarno / ow-league-tokens

Bot that farms Overwatch League tokens by pretending you watch league streams
https://discord.gg/kkq2XY4cJM
193 stars 24 forks source link

windows defender detected a trojan #65

Closed Sergo1217 closed 1 year ago

Sergo1217 commented 1 year ago

Toryan is found in the folder with temporary files when the program is started. image

ucarno commented 1 year ago

Nothing found: Screenshot_6

ZIP: https://www.virustotal.com/gui/file/36e3f5cdd35aaba2f6213e577c3cfe416916c5e1092c0bdec0fc9595018c6f1d Only EXE: https://www.virustotal.com/gui/file/fecf53121e4b0705fad3b94abb41383c1ff6a12eca6c1f641b5246666f84b84c

Maybe your file got infected by trojan on your PC? Upload ZIP and EXE to https://virustotal.com and send links here, do these files have same hashes?

Closing this issue not to scare other people.

Sergo1217 commented 1 year ago

You misunderstood me. There is no virus in the program itself. The virus appears in the temp folder when farm starts. I checked this on a laptop with a freshly installed Win 11, downloaded from the official site.

The problem started with version 2.0. It was fine on previous versions

BurnerAcc8 commented 1 year ago

I tried to redownload the program to upload it on virustotal, but chrome won't let me download it as it says it has found a virus, same for windows defender. The previous version seems to be clean though

BurnerAcc8 commented 1 year ago

https://www.virustotal.com/gui/url/bd62a711d7b20d26a0a90452bd43ddd2f1982880f85a133229702f1658028c64/detection

This is the only thing that virustotal has found. I got the link from the windows security protection history, as it said that's one of the sources (Besides the zip file itself)

Sergo1217 commented 1 year ago

for 2.0.2 zip https://www.virustotal.com/gui/file/858aa87518d6e1bda6ec9355e95f29c815ec45972544ae499720256dfeb7ed56 SHA-1 b1a52de99eb3f5ae285db51fceee3f2b1877d006

exe https://www.virustotal.com/gui/file/cfc025f6d644ad6b46f2e20e0cf29abaa5b11d9bbd9828fb1f53be2a0522f20b SHA-1 1b1d7c805e73aaa11908f57b2628fe3232eae0a9

Sergo1217 commented 1 year ago

As I said, the problem is not with the program itself, but with some of the files that appear at runtime (probably undetected-chromedriver or something else)