Windows found/quarantined offending file containing severe "Trojan:Win32/Wacatac.B!ml" malware in the 2023.09.15 update Topic is solved

Board for discussions around the Basilisk web browser.

Moderator: Basilisk-Dev

User avatar
Pallid Planetoid
Knows the dark side
Knows the dark side
Posts: 4279
Joined: 2015-10-06, 16:59
Location: Los Angeles CA USA

Windows found/quarantined offending file containing severe "Trojan:Win32/Wacatac.B!ml" malware in the 2023.09.15 update

Unread post by Pallid Planetoid » 2023-09-19, 14:00

Posted here (as well) for better exposure.
Windows found and quarantined severe malware in the 2023.09.15 release involving the Basilisk "plugin-container.exe" file -- see linked topic: Basilisk 2023.09.15 Released! for details.

Threat quarantined by Windows 10 (at time of update):
malware threat updating Basilisk.png
Edited to correct misspelling of the reference to the "plugin-container.exe" above (removed typo "t" in "plugin-containter.exe").
You do not have the required permissions to view the files attached to this post.
Last edited by Pallid Planetoid on 2023-09-19, 15:06, edited 2 times in total.
Current Pale Moon(x86) Release | WIN10 | I5 CPU, 1.7 GHz, 6GB RAM, 500GB HD[20GB SSD]
Formerly user Pale Moon Rising - to provide context involving embedded reply threads.
Good judgment comes from experience and a lot of that comes from bad judgment. - Will Rogers
Knowing Pale Moon is indisputably #1 is defined by knowing the totality of browsers. - Pale Moon Rising

User avatar
Night Wing
Knows the dark side
Knows the dark side
Posts: 5174
Joined: 2011-10-03, 10:19
Location: Piney Woods of Southeast Texas, USA

Re: Windows found/quarantined offending file containing severe "Trojan:Win32/Wacatac.B!ml" malware in the 2023.09.15 upd

Unread post by Night Wing » 2023-09-19, 14:43

Since you state Windows found a trojan in a Basilisk update, I'm assuming you are taking about Windows Defender, have you considered this might be a false positive?
Linux Mint 21.3 (Virginia) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
MX Linux 23.2 (Libretto) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
Linux Debian 12.5 (Bookworm) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox

User avatar
Pallid Planetoid
Knows the dark side
Knows the dark side
Posts: 4279
Joined: 2015-10-06, 16:59
Location: Los Angeles CA USA

Re: Windows found/quarantined offending file containing severe "Trojan:Win32/Wacatac.B!ml" malware in the 2023.09.15 upd

Unread post by Pallid Planetoid » 2023-09-19, 14:55

Night Wing wrote:
2023-09-19, 14:43
Since you state Windows found a trojan in a Basilisk update, I'm assuming you are taking about Windows Defender, have you considered this might be a false positive?
Of course I have considered the possibility of a "false" positive - I'm simply reporting my findings (a "false" positive is always a possibility).

As to how and when Windows quarantined the threat - it occurred while doing the current Basilisk update (hence did not involve a scan). Since it is Windows 10 Security that acted on this it would of course be the Microsoft Windows Defender presumably that is involved in the quarantine of the file. (I do not have any other Anti-Virus software on my Win10 machine, otherwise Windows Defender would have been turned off, if I did). It's worth noting that I've not had this occur on any previous Basilisk updates - so something unique has occurred this time (we would assume there is a reason for this to occur this time presumably).

There are probably ways to submit this file for further review.

These are the kind of questions I have (posted in linked topic) regarding this event (I'm certainly not going to assume anything either way as to whether it is legitimate or not) - and until I can determine the credibility of what Windows has done, I'll leave it the way Windows has addressed the issue.

One of my (several) questions was - leaving the executable file quarantined like it is ("plugin-container.exe") - how is Basilisk impacted? - I cannot see any visible issues using the browser as it is.

That is to say, I need advise as to what to "safely" do.... I'm assuming just because no one else has had this event occur does not necessarily mean it is not legitimate in my case - simply based on the fact that my machine would not likely be identical to any other machine as to how the executable could be regarded as a specific "threat" by my OS. (it's always better "safe" than "sorry" - so I'm not going to risk infecting my computer by simply drawing unfounded assumptions either way)
Last edited by Pallid Planetoid on 2023-09-19, 15:17, edited 1 time in total.
Current Pale Moon(x86) Release | WIN10 | I5 CPU, 1.7 GHz, 6GB RAM, 500GB HD[20GB SSD]
Formerly user Pale Moon Rising - to provide context involving embedded reply threads.
Good judgment comes from experience and a lot of that comes from bad judgment. - Will Rogers
Knowing Pale Moon is indisputably #1 is defined by knowing the totality of browsers. - Pale Moon Rising

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35651
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Windows found/quarantined offending file containing severe "Trojan:Win32/Wacatac.B!ml" malware in the 2023.09.15 upd

Unread post by Moonchild » 2023-09-19, 15:16

Pallid Planetoid wrote:
2023-09-19, 14:55
That is to say, I need advise as to what to "safely" do...
search.php?keywords=antivirus+plugin-container
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
Pallid Planetoid
Knows the dark side
Knows the dark side
Posts: 4279
Joined: 2015-10-06, 16:59
Location: Los Angeles CA USA

Re: Windows found/quarantined offending file containing severe "Trojan:Win32/Wacatac.B!ml" malware in the 2023.09.15 upd

Unread post by Pallid Planetoid » 2023-09-19, 15:31

Thanks for the link - but the search results (above) produced just one post which was over 6+ years old and all other posts were 9+ years old or older (not of very much value it would seem....).

When I get more time, I'll look into a way to submit the file to confirm whether the executable is an actual threat or not (with that said, I'm thinking a way of submitting "exe" files might be a bit more difficult to find).

Absent that, it appears Basilisk functions just fine without the "plugin-container.exe" file, hence perhaps (considering it is not a primary browser of mine anyway) maybe I'll simply see what happens as of the next Basilisk update.... :think:
Current Pale Moon(x86) Release | WIN10 | I5 CPU, 1.7 GHz, 6GB RAM, 500GB HD[20GB SSD]
Formerly user Pale Moon Rising - to provide context involving embedded reply threads.
Good judgment comes from experience and a lot of that comes from bad judgment. - Will Rogers
Knowing Pale Moon is indisputably #1 is defined by knowing the totality of browsers. - Pale Moon Rising

User avatar
Pallid Planetoid
Knows the dark side
Knows the dark side
Posts: 4279
Joined: 2015-10-06, 16:59
Location: Los Angeles CA USA

Re: Windows found/quarantined offending file containing severe "Trojan:Win32/Wacatac.B!ml" malware in the 2023.09.15 upd

Unread post by Pallid Planetoid » 2023-09-20, 00:44

I've submitted a request to MS for an analysis of the executable file - further details here: viewtopic.php?f=61&t=30300&p=243519#p243519.
Current Pale Moon(x86) Release | WIN10 | I5 CPU, 1.7 GHz, 6GB RAM, 500GB HD[20GB SSD]
Formerly user Pale Moon Rising - to provide context involving embedded reply threads.
Good judgment comes from experience and a lot of that comes from bad judgment. - Will Rogers
Knowing Pale Moon is indisputably #1 is defined by knowing the totality of browsers. - Pale Moon Rising

User avatar
Pallid Planetoid
Knows the dark side
Knows the dark side
Posts: 4279
Joined: 2015-10-06, 16:59
Location: Los Angeles CA USA

Re: Windows found/quarantined offending file containing severe "Trojan:Win32/Wacatac.B!ml" malware in the 2023.09.15 upd

Unread post by Pallid Planetoid » 2023-09-20, 14:15

Final analysis determination from MS posted: viewtopic.php?f=61&t=30300&p=243554#p243554.
Current Pale Moon(x86) Release | WIN10 | I5 CPU, 1.7 GHz, 6GB RAM, 500GB HD[20GB SSD]
Formerly user Pale Moon Rising - to provide context involving embedded reply threads.
Good judgment comes from experience and a lot of that comes from bad judgment. - Will Rogers
Knowing Pale Moon is indisputably #1 is defined by knowing the totality of browsers. - Pale Moon Rising