- Jan 8, 2022
- 155
- 166
bin folder staysIf i don't have the bin folder it means I'm safe? Or the virus deleted the folder too?
but they rolled back to build4 what i have seen so no longer the latest
bin folder staysIf i don't have the bin folder it means I'm safe? Or the virus deleted the folder too?
Doesn't hurt to do a full scan of your pc just to be safe.If i don't have the bin folder it means I'm safe? Or the virus deleted the folder too?
So I guess it never downloaded the virus for some reason?bin folder stays
but they rolled back to build4 what i have seen so no longer the latest
Did you had the game run more than 10 minutes? Or your Antivir/Win Defender blocked it.So I guess it never downloaded the virus for some reason?
with me it actually responded in less than 1 minute, so woudn't count on the 10 minute rule imoDid you had the game run more than 10 minutes? Or your Antivir/Win Defender blocked it.
Its in the script though.with me it actually responded in less than 1 minute, so woudn't count on the 10 minute rule imo
casn it be counting up, so lets say multiple runs of 1 or 2 minutes that triggers it ? (after 10 minutes in total ? )Its in the script though.
Actually it creates a timestamp file. (thats prob what your antivir detected)
Then if the the timestamp file exist after another 10 minutes it downloads stuff.
10 minutes twice:casn it be counting up, so lets say multiple runs of 1 or 2 minutes that triggers it ? (after 10 minutes in total ? )
if datetime.now() - first_run < timedelta(minutes=10):
Which file has this script?10 minutes twice:
if datetime.now() - first_run < timedelta(minutes=10):
it was the leaked latest update for r3, you can safely download the old r3 versionWhich file has this script?
Maybe only R3 is affected? I played R1-R2
Yes only R3 was affected.Which file has this script?
Maybe only R3 is affected? I played R1-R2
The links are now fine I cleaned it up and reuploaded PC (that was the only version affected).it was the leaked latest update for r3, you can safely download the old r3 version
It can hide from VM"s and the like.Hmm. I used a Sandbox to test and check, got no warnings etc. It also list every try to connect to the internet, etc. Gonna inform Sam.
WELL MOTHER FUCKER
Trojan:Win32/Wacatac.H!ml can evade detection by performing checks to ensure it is not being executed in a debug environment, on a virtual machine, or in a banned country. While being present in nearly any malware, country checks are most commonly seen in malware that originates from ex-USSR countries.
Additionally, it establishes persistence in the attacked environment by creating a randomly named copy in a random directory in the AppData or LocalAppData folder of a user directory and adding a corresponding value to the Run entry of the system registry. By doing this, malware makes itself harder to stop and remove, ensuring that its execution will not be interrupted by restarts or file deletion.
Machine Learning or Artificial Intelligence detection.
Machine Learning is a system at your antivirus developer that tries to identify features common to malware. It could be any kind of malware, could be a potentially unwanted program(ie. adware), could be a false positive.
So as long as you're running the game on a sandbox or VM it won't activate?It can hide from VM"s and the like.
Wacatac.H!ml is also a false positive in a lot of cases as well due to the nature of machine learning, it was the one that was going around during the last "big" outbreak and most, if not, all were false positives.
It can from what I've read, if you want to do a deep dive, just Google/Bing the name.So as long as you're running the game on a sandbox or VM it won't activate?
For firewall to monitor or allow connections (I've said and some others) some good add-on apps for Windows Firewall.
You must be registered to see the links- Can watch everything and see where it goes to, free just has monitor.
You must be registered to see the links- Gives more control and can allow/block as everything is blocked at first and you have to allow
You must be registered to see the links- Same as above, both small and lightweight, basically zero footprint.
In sandboxie I have it so anything running in the sandbox can't connect to the internet. Would that be enough?It can from what I've read, if you want to do a deep dive, just Google/Bing the name.
You will see it can be dangerous and as you can see on the A/V threads on Reddit be the worst pita false positive possible.
You can also use something like this and have more control of what access's the internet.
The links have been udpated to a clean version so it is safe to download now. If you want to be extra safe, you can download a sandbox software and run the game from there.I read a few pages back coz of the commotion and I believe it's something urgent.
Question, is this game safe to download as of this time? Has there been a remedy already to the situation or should we hold off for a bit until the f95 team sort this threat out or at least get a non-virus copy of the latest game?
thank you.
Download malwarebytes or bitdefender and do a full scan with one of those.I did a full scan with Windows Defender and it said 0 threats detected but my PC restarted randomly, am I just being paranoid or is my PC still infected?