Tor Browser Bundle on Windows 11 Flagged as malware today

Very weird, this is the TBB direct from Tor.

Trojan:Win32/Malgent!MTB

....Tor Browser\Browser\TorBrowser\Tor\tor.exe

And it links to : https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3AWin32%2FMalgent!MTB&threatid=2147836816

Anyone else having issues with TBB?

102 points · 16 comments · view on lemmy.world

16 Comments

nottheengineer@feddit.de · 84 pts · 2y (5 replies)

Classic Microsoft. They regularly use defender to harrass users of software they don't like.

grue@lemmy.world · 45 pts · 2y (1 reply)

grayman@lemmy.world · 5 pts · 2y

Ha. I forgot about that episode of the view.

jet@hackertalks.com · 30 pts · 2y (1 reply)

Yeah, I don't see the issue in the Tor Forum, but I see other people reporting it on Reddit.

I've verified the TBB signatures, its a authentic app from Tor.

Guess its another iteration of : https://support.torproject.org/tbb/antivirus-false-positive/

Just weird to see it from Windows Defender

nottheengineer@feddit.de · 26 pts · 2y

I wouldn't call that weird. Microsoft's track record for anything involving security is absolutely atrocious, to a point where you now have to assume everything in azure and every single windows computer is compromised: https://news.ycombinator.com/item?id=37702095

ReversedCookie@feddit.de · 2 pts · 2y
[ removed ]
AureumTempus@lemmy.world · 34 pts · 2y (2 replies)
[ removed ]
yoz@aussie.zone · 4 pts · 2y

Lol true

wholeofthemoon@lemmy.world · 3 pts · 2y
[ removed ]
possiblylinux127@lemmy.zip · 15 pts · 2y (9 replies)

Upload to virus total and show the result. Also its not a good idea to run Tor on windows.

krolden@lemmy.ml · 12 pts · 2y (5 replies)

Why not

possiblylinux127@lemmy.zip · 17 pts · 2y (3 replies)

Because windows is full of telemetry and has lots of malware developed for it.

Not to mention the NSA will know you visited the Tor page and have Tor installed.

Its best to use it from Tails

Boring@lemmy.ml · 3 pts · 2y

if the NSA knows I shitpost on dread then why do my posts have zero likes?

Roy@sopuli.xyz · 2 pts · 2y (1 reply)

But doesn’t NSA also by that logic know that you have visited Tails download page and have downloaded the ISO at some point?

Qvest@lemmy.world · 7 pts · 2y

by the same logic, they won't know what you do inside Tails, nor when you boot it up

Custodian1623@lemmy.world · 10 pts · 2y

too easy for Microsoft or third-parties to collect telemetry data would be my guess

jet@hackertalks.com · 2 pts · 2y

https://www.virustotal.com/gui/file/3807d96998a15aed25ec9a95c3183385c6c73f6dde811ef2452c30f5f7df2810

Bkav Pro W32.AIDetectMalware.64

Microsoft Trojan:Win32/Malgent!MTB

Rising Trojan.Malgent!8.10C33 (CLOUD)

The rest are green.

Lexicon_Duckie@lemmy.ca · 1 pts · 2y (1 reply)
[ removed ]
grayman@lemmy.world · 1 pts · 2y

Quack

jet@hackertalks.com · 5 pts · 2y