Jump to content
Sign in to follow this  
sfgiants13

FFTF Dynamic Trojan

Recommended Posts

I've never had this before but after the latest version update I got an alert from Windows Defender about a trojan.  

 

Trojan:Win32/Wacatac.D!ml

 

Anyone else noticed this?


5800x3d Asus 4090 ROG Strix OC 2TB SSD 32GB Ram

Share this post


Link to post

offensive initials not allowed.  2nd addon this week with a virus


5800X3D, Gigabyte X570S MB, 4090FE, 32GB DDR4 3600 CL14, EVO 970 M.2's, Alienware 3821DW  and 2  22" monitors,  Corsair RM1000x PSU,  360MM MSI MEG, MFG Crosswind, T16000M Stick, Boeing TCA Yoke/Throttle, Skalarki MCDU and FCU, Saitek Radio Panel/Switch Panel, Spad.Next

Share this post


Link to post

Since last week's Calvi update Trojan I'm a bit paranoid so I renamed the FFTF executable after Microsoft Defender flagged it this morning. This is fun!


-J

13700KF | RTX 4090 @ 4K | 32GB DDR5 | 2 x 1TB SSDs | 1TB M.2 NVMe

Share this post


Link to post

I emailed simmarket support on the installer.  I didn't know where else to email since their website doesn't exist anymore.


5800x3d Asus 4090 ROG Strix OC 2TB SSD 32GB Ram

Share this post


Link to post
3 minutes ago, sfgiants13 said:

I emailed simmarket support on the installer.  I didn't know where else to email since their website doesn't exist anymore.

https://www.fspsstore.com/


 

Raymond Fry.

PMDG_Banner_747_Enthusiast.jpg

Share this post


Link to post

Simmarket support forwarded my ticket to the developer so we’ll see.


5800x3d Asus 4090 ROG Strix OC 2TB SSD 32GB Ram

Share this post


Link to post

I got it as well.. and have chosen to ignore the warning.. until further notice..

Edited by Bert Pieke

Bert

Share this post


Link to post
7 hours ago, sfgiants13 said:

I emailed simmarket support on the installer.  I didn't know where else to email since their website doesn't exist anymore.

https://www.fspsstore.com/

For support, you can open a ticket here:

https://support.thefsps.com/index.php

Cheers, Ed

 


Cheers, Ed

MSFS Steam - Win10 Home x64 // Rig: Corsair Graphite 760T Full Tower - ASUS MBoard Maximus XII Hero Z490 - CPU Intel i9-10900K - 64GB RAM - MSI RTX2080 Super 8GB - [1xNVMe M.2 1TB + 1xNVMe M.2 2TB (Samsung)] + [1xSSD 1TB + 1xSSD 2TB (Crucial)] + [1xSSD 1TB (Samsung)] + 1 HDD Seagate 2TB + 1 HDD Seagate External 4TB - Monitor LG 29UC97C UWHD Curved - PSU Corsair RM1000x - VR Oculus Rift // MSFS Steam - Win 10 Home x64 - Gaming Laptop CUK ASUS Strix - CPU Intel i7-8750H - 32GB RAM - RTX2070 8GB - SSD 2TB + HDD 2TB // Thrustmaster FCS & MS XBOX Controllers

Share this post


Link to post
25 minutes ago, Bert Pieke said:

I got it as well.. and have chosen to ignore the warning.. until further notice..

This could be very dangerous. The virus that came with Calvi Airport scenery placed a file into the Windows folder in your C drive and once activated it could spread over all your exe files, making necessary a clean re-install of those affected files/applications.

Cheers, Ed

Edited by edpatino

Cheers, Ed

MSFS Steam - Win10 Home x64 // Rig: Corsair Graphite 760T Full Tower - ASUS MBoard Maximus XII Hero Z490 - CPU Intel i9-10900K - 64GB RAM - MSI RTX2080 Super 8GB - [1xNVMe M.2 1TB + 1xNVMe M.2 2TB (Samsung)] + [1xSSD 1TB + 1xSSD 2TB (Crucial)] + [1xSSD 1TB (Samsung)] + 1 HDD Seagate 2TB + 1 HDD Seagate External 4TB - Monitor LG 29UC97C UWHD Curved - PSU Corsair RM1000x - VR Oculus Rift // MSFS Steam - Win 10 Home x64 - Gaming Laptop CUK ASUS Strix - CPU Intel i7-8750H - 32GB RAM - RTX2070 8GB - SSD 2TB + HDD 2TB // Thrustmaster FCS & MS XBOX Controllers

Share this post


Link to post
21 minutes ago, edpatino said:

This could be very dangerous. The virus that came with Calvi Airport scenery placed a file into the Windows folder in your C drive and once activated it could spread over all your exe files, making necessary a clean re-install of those affected files/applications.

Cheers, Ed

OK - disabled it.. :cool:


Bert

Share this post


Link to post

I also created a ticket on the above site. I’ll advise when I get a response.


5800x3d Asus 4090 ROG Strix OC 2TB SSD 32GB Ram

Share this post


Link to post
17 hours ago, edpatino said:

This could be very dangerous. The virus that came with Calvi Airport scenery placed a file into the Windows folder in your C drive and once activated it could spread over all your exe files, making necessary a clean re-install of those affected files/applications.

Cheers, Ed

It's way, way worse than having to re-install a few files/applications. If you have malicious files on your C drive it means that someone can have complete remote control over your computer. Like stealing all files, installing ransomware, attacking other devices on your local network, activating the mic or webcam, and so on.

As for the Win32/Wacatac.D!ml malware, here is a summary from https://malwarefixes.com/threats/trojanwin32-wacatac-dml/:

Quote

Trojan:Win32/Wacatac.D!ml is a detection by Windows Defender for a computer threat that can perform a number of malicious actions as commanded by remote attacker. Trojan:Win32/Wacatac.D!ml is so dangerous because it has this backdoor capability that will allow a hacker to control and dominate the infected computer.

I think these issues should be taken VERY seriously and the vendor and distributors should investigate this issue and take actions immediately and let us know what went wrong and how their actions will prevent this from happening again. It's totally unacceptable..

Share this post


Link to post

But, for me only Defender detected it. Malwarebytes did not detect it


Vincent Rouleau

AMD Ryzen 7950X3d / 32.0GB G.SKILL Neo DDR5 6000 / Gigabyte  GeForce® RTX 4080 16Gig / / Samsung C49RG9 49' /ASUS  PB287QQ ‑ 27" UHD / AGAMMIX 2TB / Samsung 970 PRO 1TB /  PNY SSD 1TB / Windows 11 / Gigabyte B650M Elite Motherboard

Share this post


Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  
  • Tom Allensworth,
    Founder of AVSIM Online


  • Flight Simulation's Premier Resource!

    AVSIM is a free service to the flight simulation community. AVSIM is staffed completely by volunteers and all funds donated to AVSIM go directly back to supporting the community. Your donation here helps to pay our bandwidth costs, emergency funding, and other general costs that crop up from time to time. Thank you for your support!

    Click here for more information and to see all donations year to date.
×
×
  • Create New...