vpinball / b2s-backglass

B2S Backglass Server for use with Visual Pinball
Other
50 stars 7 forks source link

B2S Server v2.1.1 download detected with theTrojan Wacatac.B!ml #97

Closed layby2k closed 7 months ago

layby2k commented 7 months ago

The latest version v2.1.1 zip archive is detected by both Chrome and Windows Defender as having the Wacatac.B!ml trojan. Version 2.1.0 is fine.

image

image

JockeJarre commented 7 months ago

I have regenerated 2.1.1 and now it should be "clean". For sure a virus scanner false negative. Thanks for the finding.

layby2k commented 7 months ago

No worries, tried to download the new B2S Server v2.1.1 RC2 release but it too is also detected by both Google Chrome and Defender. Very Strange

JockeJarre commented 7 months ago

I have now reported to Max "Secure" and received the same answer as the examples I found on the net. Then I also reported directly to VirusTotal.com this:

Max "Secure" is the only out of 60 Virus Scanners which reports our open source software as infected. The file can be found here https://github.com/vpinball/b2s-backglass/releases/tag/b2s-backglass-bfab24d Here is the report: https://www.virustotal.com/gui/file/8044d85be010a849a4651d654d198c7e2c96105d0a8fbab89c813088dd46b8de

What can I do about it?

Kind regards

We'll see what and IF we get an answer

JockeJarre commented 7 months ago

Seems we aren't the only scammed by Max "Secure":

https://github.com/ruffle-rs/ruffle/issues/5050 https://github.com/bleachbit/bleachbit/issues/948 https://github.com/lian/msfs2020-go/issues/14 https://steamcommunity.com/app/605740/discussions/0/1642041886380081322/

JockeJarre commented 7 months ago

A few days later. I have contacted both Max "Secure" and virustotal. Max "Secure" has yet to get back to me, whereas virustotal responded promptly and professionally.

JockeJarre commented 7 months ago

Max "Secure" have finally changed their mind:

image