Noob install 'ransomware' flagged

Thoughts, Help, Feature Requests, Bug Reports, Developing code for...

Moderators: dorpond, trevor, Azhrei

Forum rules
PLEASE don't post images of your entire desktop, attach entire campaign files when only a single file is needed, or generally act in some other anti-social behavior. :)
Post Reply
SynapseRanger
Kobold
Posts: 3
Joined: Tue Sep 08, 2020 4:37 pm

Noob install 'ransomware' flagged

Post by SynapseRanger »

Hi all

As the title suggests, I'm a noob to Maptools. Just tried to install it and Bitdefender just flagged the following:
'Ransomware behavior remediated
The process MapTool-1.7.0.exe manifests ransomware behavior and was blocked.'

It then mentions restoring some files:
NVIDIA file called nvdrssel.bin
and MapTool\unins000.dat

I'm assuming this is all fine and I should just click 'except application' and it's just my antivirus worrying unnecessarily, but wanted to check first because I'm super paraonoid!

Any reassurance would be welcomed!

Thanks

Phergus
Deity
Posts: 7132
Joined: Fri May 12, 2006 8:56 pm
Location: Middle of Nowhere, NM
Contact:

Re: Noob install 'ransomware' flagged

Post by Phergus »

This is the first I've heard of this happening for 1.7. Did you download the installer from the Github site?

The MapTool install doesn't include a nvdrssel.bin file nor would it directly access it.

This is the SHA-1 for the installer:
Screenshot 2020-09-09 06.36.04.png
Screenshot 2020-09-09 06.36.04.png (13.29 KiB) Viewed 738 times

SynapseRanger
Kobold
Posts: 3
Joined: Tue Sep 08, 2020 4:37 pm

Re: Noob install 'ransomware' flagged

Post by SynapseRanger »

Hi

Thanks for replying. I downloaded it directly from the rptools site on this page:

https://www.rptools.net/download-rptools-products/

I've not got my computer with me right now so can't check the other details.

I've been assuming it's just bitdefender being overly 'efficient' and finding something it didn't like in the download. I'm pretty sure it's fine but I couldn't find anything online about similar issues and want to be sure before I let it through.

Phergus
Deity
Posts: 7132
Joined: Fri May 12, 2006 8:56 pm
Location: Middle of Nowhere, NM
Contact:

Re: Noob install 'ransomware' flagged

Post by Phergus »

The links on that page are from GitHub so that's good.

As you say, it's probably just a false positive from BitDefender though I would have expected enough folks that use BitDefender have already downloaded and installed 1.7.0 to keep that from happening.

Being cautious is still a good idea. I checked file on GitHub and it's valid so nothing weird happened there.

SynapseRanger
Kobold
Posts: 3
Joined: Tue Sep 08, 2020 4:37 pm

Re: Noob install 'ransomware' flagged

Post by SynapseRanger »

Brilliant thanks for your help, you're probably right. I'll let it through and try the software out. Looking forward to it!

Post Reply

Return to “MapTool”