Page 1 of 1

Virus in ver 2.9.0.0?

Posted: 17 Sep 2020, 09:58
by G4AON
Bitdefender reports the following when installing:
The file C:\Program Files (x86)\IW3HMH\Log4OM NextGen\is-0MO28.tmp is infected with Gen:Variant.Barys.8268

Uploading the full 2_9_0_0.exe to virus total (https://www.virustotal.com/gui/), reports Trojan:Win32/Wacatac.C!ml in the file as detected by Microsoft A/V but none of the others detected it.

Version 2.8.0.0 shows nothing at virus total, and it installs without incident.

It might all be false indications, any thoughts?

73 Dave

Re: Virus in ver 2.9.0.0?

Posted: 17 Sep 2020, 11:39
by DF5WW
There is no Virus elsewhere in Log4OM. Those AV software is well known to give false reports.
We all using Log4OM since years, the only programmer and uploader to the Log4OM website
is Lele (IW3HMH) so there“s nearly no chance for other guys to infect Log4OM with a virus.
Nobody except Lele has the raw code of the software.

;) ;)

Re: Virus in ver 2.9.0.0?

Posted: 18 Sep 2020, 08:36
by OH3FVP
After installing v. 2.9.0.0 today, Windows Defender alerted Torjan:Win32/Zpevdo:B found in file: C:\Program Files (x86)\IW3HMH\Log4OM NextGen\L4ONG.ConfigManager.exe. Previous versions didn't give any alerts after installation. Should I be concerned?

73 de Teemu OH3FVP

Re: Virus in ver 2.9.0.0?

Posted: 18 Sep 2020, 09:08
by G4POP
No its another false positive report

Re: Virus in ver 2.9.0.0?

Posted: 18 Sep 2020, 10:54
by G4AON
I added an exception to my Bitdefender AV and installed 2.9.0.0 The net control "lookup" option tick box is most welcome!

There has been a subtle change between the files in 2.8xxx and 2.9xxx as Bitdefender doesn't find anything in 2.8xxx.

73 Dave

Re: Virus in ver 2.9.0.0?

Posted: 21 Sep 2020, 10:34
by IW3HMH
It's amazing on how heuristic scan works...
i'm able to add a different virus on code at each release :)
Everything could happens, someone may crack my website and place a virus in the zip, and that's beyond my control (and this could happens on every application you download from the web)

On my side no, i'm not intentionally adding virus to the application :)
Each release is passed to a couple of online antivirus scans, so they can "know" and identify the signature of the new release, limiting false positive.