CSpect V2.12.22

Struggling with Fuse or trying to find an emulator with a specific feature. Ask your questions here.
Post Reply
User avatar
PeterJ
Site Admin
Posts: 6878
Joined: Thu Nov 09, 2017 7:19 pm
Location: Surrey, UK

CSpect V2.12.22

Post by PeterJ »

Just to let you know that there seems to be an issue with the latest version of CSpect

http://dailly.blogspot.com/2020/04/cspect-v21221.html

I downloaded it and Windows Defender reports 'Trojan:Win32/Wacatac.C!ml' which is also mentioned in the posts below the release. I'm sure it will be fixed soon.
User avatar
Seven.FFF
Manic Miner
Posts: 744
Joined: Sat Nov 25, 2017 10:50 pm
Location: USA

Re: CSpect V2.12.22

Post by Seven.FFF »

There’s no malware in CSpect and nothing to fix. Some virus checkers with aggressive heuristics give false positives for independently released software with lots of different versions, for obfuscated dot net software, packed exes, or software not signed with the type of cert you can only get as an large organisation.
Robin Verhagen-Guest
SevenFFF / Threetwosevensixseven / colonel32
NXtel NXTP ESP Update ESP Reset CSpect Plugins
User avatar
PeterJ
Site Admin
Posts: 6878
Joined: Thu Nov 09, 2017 7:19 pm
Location: Surrey, UK

Re: CSpect V2.12.22

Post by PeterJ »

Interesting I've never had this previously until this version. Unless I disable Defender, which I'm not willing to do, I can't use it.

I've come across these false positives before, but not one that actually lists the included Trojan.
User avatar
Seven.FFF
Manic Miner
Posts: 744
Joined: Sat Nov 25, 2017 10:50 pm
Location: USA

Re: CSpect V2.12.22

Post by Seven.FFF »

It’s been happening right since Mike released the first Next version of CSpect a few years ago. They really don’t like that that he obfuscates to protect his intellectual property. I’m guessing that at some point a virus writer used the same obfuscater he uses, and the sloppy virus checkers are just detecting the obfuscator.

Honestly I would switch to a more trustworthy checker. Defender has a terrible reputation for false positives. And last time I got a real virus, Defender let it straight through without detecting it.
Robin Verhagen-Guest
SevenFFF / Threetwosevensixseven / colonel32
NXtel NXTP ESP Update ESP Reset CSpect Plugins
User avatar
Seven.FFF
Manic Miner
Posts: 744
Joined: Sat Nov 25, 2017 10:50 pm
Location: USA

Re: CSpect V2.12.22

Post by Seven.FFF »

If you google it, there are loads of people complaining Defender is doing this with their software releases too. Some of the answers say that any Defender virus designation with an exclamation mark in the name has been detected by machine learning techniques, and there’s nothing Microsoft are willing to do to exclude these blanket false positives.
Robin Verhagen-Guest
SevenFFF / Threetwosevensixseven / colonel32
NXtel NXTP ESP Update ESP Reset CSpect Plugins
User avatar
PeterJ
Site Admin
Posts: 6878
Joined: Thu Nov 09, 2017 7:19 pm
Location: Surrey, UK

Re: CSpect V2.12.22

Post by PeterJ »

I can't understand that. I first came across the emulator in early March, and didn't have that issue then.

viewtopic.php?f=33&t=2375

I know Windows Defender used to be complete rubbish, but MS have improved it vastly over the years. I know it's not the best, but I try and avoid installing additional software where I can. I prefer the clean experience and go for portable apps where possible.

Just to note that Avast and AVG (both now owned by AVG) both apparently reporting the same with this release according to the blog comments.

Edit. Also Malware Bytes
User avatar
PeterJ
Site Admin
Posts: 6878
Joined: Thu Nov 09, 2017 7:19 pm
Location: Surrey, UK

Re: CSpect V2.12.22

Post by PeterJ »

Hi [mention]Seven.FFF[/mention]

I downloaded the file on my Ubuntu 20.04 box and ran it through TotalVirus and this is the results:

Image

Ive never used this tool before, but 14/62 sounds more positive, but there are big names in there like Panda Security, Bitdefender and Norton (Symantec).

I've gone back and tested previous versions, and the one from April 13th seems fine on my Windows with no reports:

http://dailly.blogspot.com/2020/04/cspect-v21218.html

I'm sure you are right [mention]Seven.FFF[/mention], but it just seems odd. It seems to be something that has happened since the release on the 14th April.
User avatar
PeterJ
Site Admin
Posts: 6878
Joined: Thu Nov 09, 2017 7:19 pm
Location: Surrey, UK

Re: CSpect V2.12.22

Post by PeterJ »

Hi [mention]Seven.FFF[/mention]

Just to let you know that I downloaded CSpect V2.12.23 (29th April 2020), and this latest version does not cause my virus scanner or TotalVirus any issues. Good news.

http://dailly.blogspot.com/2020/04/cspect-v21223.html
User avatar
Seven.FFF
Manic Miner
Posts: 744
Joined: Sat Nov 25, 2017 10:50 pm
Location: USA

Re: CSpect V2.12.22

Post by Seven.FFF »

It does trigger a W32.Malware.Gen alert in mine though. Like I say, take these alerts with a massive pinch of salt. They're worth almost nothing, and Mike scans everything he publishes for actual viruses.

I add exclusions for every CSpect version, and have never once had any reason to believe my machine is infected or infecting other machines.
Robin Verhagen-Guest
SevenFFF / Threetwosevensixseven / colonel32
NXtel NXTP ESP Update ESP Reset CSpect Plugins
User avatar
PeterJ
Site Admin
Posts: 6878
Joined: Thu Nov 09, 2017 7:19 pm
Location: Surrey, UK

Re: CSpect V2.12.22

Post by PeterJ »

Interesting [mention]Seven.FFF[/mention]. Which AV are you using?

Just to add I've no reason to believe the software is infected, just want to know what it is that triggers AVs on some versions. Why one version triggers my AV and others, the next release a few days later is fine.

It's a magnificent emulator, and one I will continue using.
cthutu
Drutt
Posts: 14
Joined: Wed May 30, 2018 6:18 pm

Re: CSpect V2.12.22

Post by cthutu »

Why can't anti-virus software ask you first before deleting, or move the software to a vault where you can retrieve it?
Post Reply