-
Notifications
You must be signed in to change notification settings - Fork 444
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Last release is marked with a Trojan Wacatac.B!ml #1024
Comments
As long as you got the file from GitHub,it should be fine. |
Hi Snowie2000, thanks in advance, yes, I got the file from GitHub, I wonder why, two engines refuse to deal with it, NordVPN, blocks the download, I turn off the protection and later, whe run the instalation, MS Security Defender refuse to run the instalation process, which or what component is identify as a Trojan? |
ESET did the same thing, the problem is not about whether it is trojan or not, the file just vapoured as soon as the downloading is completed, it's so annoying to turn off the protection before using it. This prevents the soft from popularizing. |
Because of the nature of the MacType, it can cause false positive for many AV softwares, bacause:
I think why it is more common to be mistakenly detected if because this is the first version that has easyhook/detours statically linked which is more like a malware behavior while previously they were distributed separately as DLLs. |
I've been using MacType for more than a decade. |
yeah but why preivous build doesnt trigger the alarm? what is the differernce you've made on Version 2024.9.14 that might triggered those engines ? |
Nobody knows. My guess is that the statically linked mactype.core looks somewhat like many trojan malwares. |
The laste release MacType v1.2024.9.14 is marked by NordVPN and MS Security Defender with the troyan:
Trojan:Win32/Wacatac.B!ml
Any idea?
The text was updated successfully, but these errors were encountered: