Falcon BMS Forum
    • Categories
    • Unread
    • Recent
    • Popular
    • Website
    • Wiki
    • Discord
    • Contact
    • Register
    • Login

    Trojan:Script/Wacatac.B!ml

    Scheduled Pinned Locked Moved Documentation
    11 Posts 8 Posters 519 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      Dufus
      last edited by

      Found attached to Falcon BMS 4.37.exe. Anyone else find this? A vulnerability maybe?

      ? 1 Reply Last reply Reply Quote 0
      • hooverH Offline
        hoover
        last edited by

        Antivirus isn’t. I’m still wondering anyone is still using AV software (and even worse, trusting it to do anything useful 😉 )

        Safe browsing using a decent browser and as safe OS (Linux is a good choice here) and the usual plugins (ublock origin, noscript, privacy badger) and general common-sense usage of the internet will keep you safer than blindly “trusting” any AV vendor and accepting all the negative side effects that AV control over your system brings.

        Just my 2c (online since 1989 and I’ve never had any issues with viruses / virii).

        Cheers, Uwe

        System specs: win10pro / Linux Mint 21.x, 32GB RAM, RTX3070, 2x1 TB SSD, 1x2TB NVMe, 1x4TB SATA; HOTAS Warthog Stick(DX), WinWing Orion2 Throttle w/ f16 grip, TM MFDs, CH Pro Flight Pedals w/ custom USB controller; CPU: AMD Ryzen 7 3700X 8-Core; MoBo: X570-A PRO (MS-7C37); Display: 42" LG Nano 42 (2560x1440), 19" Fujitsu-Siemens (1280x1024) used for DE /w YAME64 beta; DelanClip /w PS Eye, opentrack; GameTrix JetSeat /w SimShaker Wings; Stream Deck XL (32 buttons) as ICP

        J 1 Reply Last reply Reply Quote 3
        • ? Offline
          A Former User @Dufus
          last edited by

          @Dufus
          I’ve had the same thing, antivirus (ESET NOD32) found something “potentially dangerous” in the launcher. However, it’s obviously a false alarm. For me, I’m not known of any infections through BMS (Of course, only if you downloaded it from the official site). I’ve been playing BMS for a relatively long time, and like thousands of other people haven’t experienced any security issues. I think you can ignore this warning.

          1 Reply Last reply Reply Quote 0
          • MaxWaldorfM Offline
            MaxWaldorf Global Moderator
            last edited by

            you can also sublit it to the AV company so they improve their scan…

            Benchmarksims Developer - Falcon Lounge Founder
            MaxWaldorf Signature

            1 Reply Last reply Reply Quote 1
            • D Offline
              Dufus
              last edited by

              Thanks. I was just trying to help everyone else. I only use Edge, and it was Microsoft Defender that found it. Not likely an error. I’m not saying that this trojan was there before. I’m saying that it must have attached itself to Falcon BMS 4.37.exe after gaining access to my system or network. I had to re-install Falcon. I already use uBlock Origin. I suspect it was a Chinese device software I installed a month before. It’s the only thing I had installed since Falcon a month before that.

              IcarusI 1 Reply Last reply Reply Quote 0
              • IcarusI Offline
                Icarus @Dufus
                last edited by

                @Dufus Actually more likely a Microsoft error than not. I had this for launcher and IVC I have exceptions for everything BMS.

                System Specs:

                Main: i7-3930K @ 4.0 GHz, 32Gb Corsair 2133-DDR3 RAM, RTX 2080ti, 1Tb Samsung SSD + 5x Samsung SSD's, 1.0KW Corsair PSU, SB Fatal1ty Recon3D Professional, Sennheiser PC360, 30" Dell LED/24" Acer LED, Corsair K70, Cougar MFDs, Cougar FSSB-R2 + WH grip, TUSBA TQS + CubPilot HALL mod, 4x CH MFP's, BU036A, BU036X, TrackIR5 + DelanClip, Simpeds, Gametrix KW-908 Jetseat + Buttkicker Gamer2, 3rd Space vest.

                Secondary: 2x 19" LED, 2x 8" VGA, 2x 7" USB, 14" LED, MFDE.

                1 Reply Last reply Reply Quote 0
                • Flow32F Offline
                  Flow32
                  last edited by

                  Had the same feedback from the Windows 10 defender. Same message, from just a mission .ini file.
                  Submitted the file to an online antivirus : nothing found.
                  I believe there is something in those mission ini files that Microsoft does not like.

                  1 Reply Last reply Reply Quote 1
                  • D Offline
                    Dufus
                    last edited by

                    Well, it’s fine now after reinstall. Thanks…

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      jcook @hoover
                      last edited by

                      @hoover always curious about the security background of people recommending not using AV. Hoover do you have any professional background in networking, system administration or computer security?

                      MaxWaldorfM airtex2019A 2 Replies Last reply Reply Quote 0
                      • MaxWaldorfM Offline
                        MaxWaldorf Global Moderator @jcook
                        last edited by

                        @jcook just submit the file to the AV company for them to update their DB…

                        Benchmarksims Developer - Falcon Lounge Founder
                        MaxWaldorf Signature

                        1 Reply Last reply Reply Quote 0
                        • airtex2019A Offline
                          airtex2019 Global Moderator @jcook
                          last edited by airtex2019

                          @jcook
                          I was involved with infosec at both msft and amzn, for couple decades. I’d stop short of broadly recommending everyone on earth to disable AV… But for reasonably tech savvy users, honestly, yeah it’s a reasonably close call.

                          The AV situation is grim. They use probabilistic detection filters (like https://en.wikipedia.org/wiki/Bloom_filter) to detect “signatures” of malware. But that means occasional false-positives, especially when scanning huge 4Gb+ payloads. And these bloom-filters run as part of the file system driver stack… so that means you burn a lot of CPU with every disk I/O operation, to wash every I/O buffer through the filter. The performance cost is real – have a look at “MsMpEng.exe” in taskmgr, on a stock Windows system… unless you’re mining crypto or doing AI stuff it is typically the highest cumulative CPU and RAM usage of any system service.

                          And the annoyance factor is real, as we see in these threads – over the longer term, false-positives create a “crying wolf” effect that is harmful to the cause.

                          Then, consider all this with the context that (most?) modern browsers have builtin malware scanning, for downloaded files… so, classic AV is (a) partially redundant, (b) moderately perf intensive, and (c) cries wolf, with false positives.

                          Reasons to keep AV: if you live or work in an untrusted network environment (college campus, small business etc) or if you regularly exchange files with others/strangers via email attachments or similar… or if you share a PC with someone in your house… or you’re a gamer downloading dodgy mods from dodgy sources… especially from sources like torrent that bypass browser-based layer of defense.

                          Ok that last example could be said to cover BMS 🙂 but like others here have said… there have been no problems in its ~20 year history.

                          I personally do still run Windows Defender, just with an exclusion-rule for ‘C:\Falcon BMS’.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post

                          25

                          Online

                          9.3k

                          Users

                          19.2k

                          Topics

                          329.0k

                          Posts
                          Benchmark Sims - All rights reserved ©