infected waptserver package

Questions about WAPT Server / Requests and help related to the WAPT server
Forum Rules
Community Forum Rules
* English support on www.reddit.com/r/wapt
* French community support is available on this forum
* Please prefix the topic title with [RESOLVED] if it is resolved.
* Please do not edit a topic that is tagged [RESOLVED]. Open a new topic referencing the old one.
* Specify the installed WAPT version, full version, and build number (2.2.1.11957 / 2.2.2.12337 / etc.) as well as the Enterprise/Discovery edition.
* Versions 1.8.2 and earlier are no longer supported. The only questions accepted regarding version 1.8.2 are related to upgrading to a supported version (2.1, 2.2, etc.).
* Specify the server OS (Linux/Windows) and version (Debian Buster/Bullseye - CentOS 7 - Windows Server 2012/2016/2019).
* Specify the OS of the administration/package creation machine and the machine with the problematic agent, if applicable (Windows 7/10/11/Debian 11/etc.).
* Avoid asking multiple questions when opening a topic, otherwise it may be ignored. If there are multiple topics, open separate topics, preferably one after the other and not all at the same time (i.e., do not spam the forum).
* Include code snippets, screenshots, and other images directly in the post. Links to Pastebin, Bitly, and other third-party sites will be systematically removed.
* As with any community forum, support is provided voluntarily by members. If you require commercial support, you can contact Tranquil IT's sales department at 02.40.97.57.55
Locked
TheBarz
Messages: 5
Registration: August 1, 2018 - 3:51 PM

August 1, 2018 - 3:57 PM

Hello,
I'm writing to inform you that the package is (apparently) infected with a virus. I just downloaded it, and Symantec is detecting it as a virus.
I downloaded version 1.5.23 a few weeks ago, and it worked fine. (Except that it no longer works now.:( )
User avatar
agauvrit
WAPT Expert
Messages: 238
Registration: Nov 17, 2016 - 10:25
Location: Nantes
Contact :

August 1, 2018 - 4:29 PM

Hello,

which package are you referring to?
From which URL did you download it?

It's possible this is a false positive caused by nssm.exe – this is discussed in the documentation: https://www.wapt.fr/fr/doc/Frequent-pro ... -antivirus.

I'm waiting for your information to understand why your antivirus is malfunctioning.
TheBarz
Messages: 5
Registration: August 1, 2018 - 3:51 PM

August 1, 2018 - 4:46 PM

Coming from this link: https://wapt.tranquil.it/wapt/releases/ ... rsetup.exe
Note that the working package does not have this problem.
Note that the error reported by Symantec is: Infected by PU1.Gen.2

I wondered about nssm. But the installation binaries are on a volume excluded by the antivirus, which surprises me...

https://www.symantec.com/security-center ... 4294907775
agauvrit wrote: August 1, 2018 - 4:29 PM Hello,

Which package are you referring to?
From which URL did you download the package?

It's possible this is a false positive caused by nssm.exe - this topic is covered in the documentation: https://www.wapt.fr/fr/doc/Frequent-pro ... -antivirus

I'm waiting for your information to understand why your antivirus is malfunctioning.
User avatar
agauvrit
WAPT Expert
Messages: 238
Registration: Nov 17, 2016 - 10:25
Location: Nantes
Contact :

August 1, 2018 - 5:20 PM

It's strange that Symantec is only taking action for a generic signature like this.

The VT analysis results are here: https://www.virustotal.com/fr/file/4987 ... /analysis/

We're looking into why.

Thanks for your feedback.
TheBarz
Messages: 5
Registration: August 1, 2018 - 3:51 PM

August 1, 2018 - 5:25 PM

If this is confirmed, I can raise this issue with Symantec.
Locked