[4.2.0] Trojan found [Windows defender]

Report & discuss bugs found in SABnzbd
Forum rules
Help us help you:
  • Are you using the latest stable version of SABnzbd? Downloads page.
  • Tell us what system you run SABnzbd on.
  • Adhere to the forum rules.
  • Do you experience problems during downloading?
    Check your connection in Status and Interface settings window.
    Use Test Server in Config > Servers.
    We will probably ask you to do a test using only basic settings.
  • Do you experience problems during repair or unpacking?
    Enable +Debug logging in the Status and Interface settings window and share the relevant parts of the log here using [ code ] sections.
Post Reply
Nitroglycerine
Newbie
Newbie
Posts: 2
Joined: January 4th, 2024, 5:34 am

[4.2.0] Trojan found [Windows defender]

Post by Nitroglycerine »

In the latest version of Sabnzdb (version 4.2.0) Windows defender found a serious trojan: Win32/Wavatac.B!ml . This was not present in 4.1.0
User avatar
sander
Release Testers
Release Testers
Posts: 8832
Joined: January 22nd, 2008, 2:22 pm

Re: [4.2.0] Trojan found

Post by sander »

The usual:

* report to Microsoft it's not a virus/trojan
* wait 2 weeks and try again
Nitroglycerine
Newbie
Newbie
Posts: 2
Joined: January 4th, 2024, 5:34 am

Re: [4.2.0] Trojan found

Post by Nitroglycerine »

Sorry but the "usual" is basically trusting the development team that it is
A) not a trojan
B) if it would be a trojan it would not be (mis)used.
A seperat scan of the file proved that there is indeed a trojan present in the executable.
User avatar
sander
Release Testers
Release Testers
Posts: 8832
Joined: January 22nd, 2008, 2:22 pm

Re: [4.2.0] Trojan found [Windows defender]

Post by sander »

Nitroglycerine wrote: January 4th, 2024, 6:15 am Sorry but the "usual" is basically trusting the development team that it is
A) not a trojan
B) if it would be a trojan it would not be (mis)used.
A seperat scan of the file proved that there is indeed a trojan present in the executable.
Then you have to decide for yourself:
trust the SABnzbd development team it's not a trojan
or trust Microsoft it is a trojan, and don't use 4.2.0 and stay on 4.1.0

And really, that is the usual: each time there is a new SABnzbd release, during the first days / first week after a release, some anti virus software think it's a virus / trojan. That alert will go away after one or two weeks. You can follow that on virustotal.

EDIT

You can see the jury's verdict here: https://www.virustotal.com/gui/file/a30 ... ?nocache=1

" 6 security vendors and no sandboxes flagged this file as malicious" , including Microsoft
and ... 62 anti-virus setups that say "Undetected", so clean & safe.

So: 6 against 62.

In the coming days: each day you could click on that virustotal link, click Reanalyse (top right corner), and see how the jury verdict develops.
User avatar
safihre
Administrator
Administrator
Posts: 5366
Joined: April 30th, 2015, 7:35 am
Contact:

Re: [4.2.0] Trojan found [Windows defender]

Post by safihre »

https://sabnzbd.org/wiki/faq#virusscanners

It's the same with every release we make. See above for some explanation why and the same info sander already gave, to check virus total.
It's already down from 6 false positives to 5.
If you like our support, check our special newsserver deal or donate at: https://sabnzbd.org/donate
User avatar
sander
Release Testers
Release Testers
Posts: 8832
Joined: January 22nd, 2008, 2:22 pm

Re: [4.2.0] Trojan found [Windows defender]

Post by sander »

safihre wrote: January 4th, 2024, 10:10 am https://sabnzbd.org/wiki/faq#virusscanners

It's the same with every release we make. See above for some explanation why and the same info sander already gave, to check virus total.
It's already down from 6 false positives to 5.
And Microsoft now says it's OK. That is nice & fast:

Microsoft Undetected
domiget
Newbie
Newbie
Posts: 3
Joined: January 4th, 2024, 12:46 pm

Re: [4.2.0] Trojan found [Windows defender]

Post by domiget »

Hello,
I have the same problem. Trying to install 4.2.0 but Windows defender erase the file before the end of installation ! On windows 11 defender seems to be stubborn ! I know defender is wrong but it, it doesn't know. Don't know what to do ...
User avatar
sander
Release Testers
Release Testers
Posts: 8832
Joined: January 22nd, 2008, 2:22 pm

Re: [4.2.0] Trojan found [Windows defender]

Post by sander »

domiget wrote: January 4th, 2024, 12:53 pm Hello,
I have the same problem. Trying to install 4.2.0 but Windows defender erase the file before the end of installation ! On windows 11 defender seems to be stubborn ! I know defender is wrong but it, it doesn't know. Don't know what to do ...
Wait.
domiget
Newbie
Newbie
Posts: 3
Joined: January 4th, 2024, 12:46 pm

Re: [4.2.0] Trojan found [Windows defender]

Post by domiget »

I found a solution :
I've excluded the file Sabnzbd from defender. It's ok now.
jupiter
Newbie
Newbie
Posts: 4
Joined: October 3rd, 2021, 12:02 pm

Re: [4.2.0] Trojan found [Windows defender]

Post by jupiter »

I saw GrayWare/Win32.Wacapew in 4.2.1. I can wait a little bit.
domiget
Newbie
Newbie
Posts: 3
Joined: January 4th, 2024, 12:46 pm

Re: [4.2.0] Trojan found [Windows defender]

Post by domiget »

sander wrote: January 4th, 2024, 1:06 pm
domiget wrote: January 4th, 2024, 12:53 pm Hello,
I have the same problem. Trying to install 4.2.0 but Windows defender erase the file before the end of installation ! On windows 11 defender seems to be stubborn ! I know defender is wrong but it, it doesn't know. Don't know what to do ...
Wait.
Okay, i wait. I've uninstall the 4.2.0 and 4.2.1 after, scanned with defender and re install the 4.1.0.
Thanks for helping.
User avatar
sander
Release Testers
Release Testers
Posts: 8832
Joined: January 22nd, 2008, 2:22 pm

Re: [4.2.0] Trojan found [Windows defender]

Post by sander »

Good news: on https://sabnzbd.org/downloads there is a new version 4.2.1 ... built in a different way ... which does not trigger Microsoft Defender.

So can you try that and feedback if Defender is happy?
pinn
Jr. Member
Jr. Member
Posts: 85
Joined: September 18th, 2011, 4:08 am

Re: [4.2.0] Trojan found [Windows defender]

Post by pinn »

sander wrote: January 6th, 2024, 5:41 am Good news: on https://sabnzbd.org/downloads there is a new version 4.2.1 ... built in a different way ... which does not trigger Microsoft Defender.

So can you try that and feedback if Defender is happy?
Triggered it for me today on 4.2.1 , whitelisted and then installed fine
User avatar
safihre
Administrator
Administrator
Posts: 5366
Joined: April 30th, 2015, 7:35 am
Contact:

Re: [4.2.0] Trojan found [Windows defender]

Post by safihre »

When did you download it? I updated the release about 6 hours ago.
If you like our support, check our special newsserver deal or donate at: https://sabnzbd.org/donate
pinn
Jr. Member
Jr. Member
Posts: 85
Joined: September 18th, 2011, 4:08 am

Re: [4.2.0] Trojan found [Windows defender]

Post by pinn »

safihre wrote: January 6th, 2024, 12:32 pm When did you download it? I updated the release about 6 hours ago.
About 9am GMT on 6th
Post Reply