82
submitted 4 days ago by alessandro@lemmy.ca to c/pcgaming@lemmy.ca
you are viewing a single comment's thread
view the rest of the comments
[-] Agent_Karyo@lemmy.world 1 points 3 days ago* (last edited 2 days ago)

I didn't know that Windows Defender essentially blocked the vulnerability.

I will also note that there can be situations when Windows Defender doesn't work.

I got hit by a WinRAR zero day exploit (the archive was supposed to be just images) that installed master Monero minor that disabled Windows Defender and blocked installation of other tools. I was able to clean my computer, but I only found through a non-english site (and I happen to speak that language so it was easier to validate that it was legit).

[-] Barracuda@lemmy.zip 3 points 3 days ago

Well yeah it's a zero day, so not much an AV can do. I'm just quoting the article.

[-] Agent_Karyo@lemmy.world 4 points 3 days ago* (last edited 2 days ago)

For sure, I missed that (and the fact Valve seems to be deploying protections as well).

The commentary about Windows Defender was just a random remark in passing. I wasn't expecting the WinRAR zero day to be addressed (it's a zero day after all), but the malware itself (the Monero miner) was around for a while (current version at the time was at least a year old) and WD had zero protections against its methods (that did not use the WinRAR zero day, that was the entry point).

That being said, I do think this more of an edge case. WD works pretty well in my experience (especially for non-power users).

this post was submitted on 04 Oct 2025
82 points (100.0% liked)

PC Gaming

12462 readers
484 users here now

For PC gaming news and discussion. PCGamingWiki

Rules:

  1. Be Respectful.
  2. No Spam or Porn.
  3. No Advertising.
  4. No Memes.
  5. No Tech Support.
  6. No questions about buying/building computers.
  7. No game suggestions, friend requests, surveys, or begging.
  8. No Let's Plays, streams, highlight reels/montages, random videos or shorts.
  9. No off-topic posts/comments, within reason.
  10. Use the original source, no clickbait titles, no duplicates. (Submissions should be from the original source if possible, unless from paywalled or non-english sources. If the title is clickbait or lacks context you may lightly edit the title.)

founded 2 years ago
MODERATORS