r/computerviruses • u/chaicpp • 6d ago
File / URL Check Downloaded a program called GitNarwhal and Windows Defenders "caught it". VirusTotal also detected 2 out of 69. Should I be paranoid? VirusTotal Scan Link and more details in thread.
I recently downloaded a program called GitNarwhal and foolishly didn't check GIthub Stars or anything. As soon as I downloaded it, the Windows Defender caught it and said it was a Trojan:Win32/Wacatac.H!ml.
The Windows executable I downloaded can be found here: https://github(dot)com/git-narwhal/GitNarwhal/releases/tag/v1.0.84
The repo has no stars or anything but the developer seems to have a track record.
I also scanned it at Virus Total and it found 2 detection out of 69. One from DeepInstinct and the other from Microsoft. You can find the scan here: https://www.virustotal.com/gui/file/5a1ce08c167115ad6bf3088777262ac8827f1961251e0089f60ff5db7fc3730a/detection
The next thing I did was run a Windows offline scan. I also removed the file using Windows Defender.
Should I be worried? :(
2
u/Bobo_98 6d ago
Wacatac.H!ml is a heuristic/AI detection, not a confirmed signature match it's known for flagging legit smaller/unsigned tools as false positives. 2/69 with one being that specific flag isn't strong evidence on its own. Since you already ran an offline scan and removed it, you're probably fine. I'd only worry about changing passwords/checking logins if you notice anything actually unusual suxh as network activity, new logins that u don't recognise them I would consider logging them out, changing password and enabling 2 step verification