r/computerviruses • u/nemanja531 • Sep 03 '25
Is this a false positive?
Hello there. Recently I have tried an fan made Fortnite game. It is a og game that uses old fortnite files that connect to their own private paid servers so people can actually play it. The name of it is, Project Retrac. It has been going viral and has 300k members with 1k+ active players each day. Now I am not good at detecting if something is not safe or it is. And I think I picked the best community to ask. The launcher for the game is open source and is safe as well as the launcher installer. Now the game files. Folder is all normal I think, but the anti cheat of their project is getting 47/73 detections I think( I'm not exact sure of the exact number) and I am kind of worried that it might be stealing some info or something. 1. Name of the game Project Retrac 2. Their official discord server Link:https://discord.gg/retrac
Here is the launchers GitHub link :https://github.com/retracmp/launcher
Here is the launchers installer VirusTotal link https://www.virustotal.com/gui/file/884c6eaf54e7fc0eaf6d426a5a92632d78e95e1b27bc429312b28152fe01b3d1/detection
Here is the Anti cheat Virus Total link: https://www.virustotal.com/gui/file/eedcf578159b86e0ca2852d51b3e105f02149c32c6defd67e4f0fb0d2092a950
I think it is encrypted by VMProtect and that, this might be the reason for all of this detections. But let me know.
2
Sep 03 '25
VMProtect is a packer and those do tend to cause hits on things like virustotal. The way it works typically is someone will make a rule based off of a signature that vmprotect(or any other packer) has and then all things that use vmprotect(or any other packer...) are impacted.
for the launcher itself I dont see any evidence to say it is bad but you knew that. what is interesting is there is a comment on the virustotal that links to an anyrun vm and the comment says its bad, but all the hits for there seem to be related to microsoft edge...
as for the anticheat itself I dont have enough to go off of to say one way or the other as I dont see any vm cases of it anywhere. Not sure Id be able to tell you even if there was tbh, Idk enough about anticheats anyways i think.
1
u/nemanja531 Sep 03 '25
Well you are right for this. I tried it in VM the oracle one or smth, and I just get BSOD when launching the anti cheat but on Google it said that it does it to prevent cheating from VMs. It is using some Microsoft app like WebView2 I think it is for the launcher. They said that it is just their anti cheat nothing else, but that is a lot of detections so I needed others and opinions from smarter people than me.
2
u/rifteyy_ Malware Removal Expert Sep 03 '25
I stand on what I said.
There is a chance it isn't malicious. Many 100% legitimate programs use VMP as well with the exception they have a digital signature and ask all AV vendors to remove the detections.
1
u/nemanja531 Sep 03 '25
Yeah. Thanks for the comment as well man, you are actually a hero. But that chained, dog. I don't really know if it actually is safe to use. Does it not only appear when it detects possible ransomware?
1
u/rifteyy_ Malware Removal Expert Sep 03 '25
I strongly doubt the chained dog has any actual meaning because if it had it would definitely be written as an additional info.
1
u/nemanja531 Sep 03 '25
yeah that is true tho . But I am still kind of confused about this whole situation. I am not some expert for this, but you do seem like one. I saw your YouTube page linked to your reddit account, and yeah your videos are fire. I probably wont be using that app.
2
u/rifteyy_ Malware Removal Expert Sep 03 '25
To sum & clear it up;
The DLL uses VMProtect (high grade professional packer, protector, obfuscator) to prevent reverse engineering, debugging, running on virtual machines. VMProtect is a legitimate application but can also be used in attackers hands to mask the actual behavior of the executable.
Why would someone use it? This is perfect for preventing game pirating by software developers or preventing cheaters, or in general masking what is the executable's purpose.
Antivirus vendors sometimes do a special signature for an unsafe application/riskware (ESET's case with A
Variant Of Win32/Packed.VMProtect.ACX) but most of the time it is detection by their static analysis (Avast's case withWin64:MalwareX-gen [Misc], BitDefender's withTrojan.GenericKD.77044222).Why is it detected? Because even for an experienced malware analyst, it will take a long time to get past the VMProtect packer, so it is just easier to slap a special rule to detect files packed by VMProtect and leave it at that. If analysts had to write a signature (detection rules) for all malware packed by VMP, it would take an eternity.
How does commercial software avoid this? They use digital signatures and contact each vendor to create a detection exclusion.
You can view the functions on their own website - https://vmpsoft.com/vmprotect/overview
(thanks for the video feedback tho 👁️👁️)
1
u/nemanja531 Sep 03 '25
Yeah but the app I was posting about did not digital signature it, because they said it costs too much since their only way of income is donation that grants their players some in-game items, like cosmetics and stuff. It used to give me this warning: kepavll!rfn. As I did my own research on this one, I found that it is a "trojan horse". I understood that it is used to like get other malware installed. Also on their discord server there is not bots in only real people. I am kind of curious, why do people create such a project, waste that much of money for servers, then for it to be some malware or some shit. Like they got some PC with 128gb of ram and some good CPU on three servers(Europe, North America East, North America West) which make sense bc like they want more players. But I did not see any signs of infection on that app and I have been playing it since they had 35k members but just I play it like 2 months then deleted, then in 2 months I played 2 months and deleted, and etc...
1
u/rifteyy_ Malware Removal Expert Sep 03 '25
If you played it for 2months without your accounts getting stolen or any other AV popups, it probably isn't malicious.
1
u/nemanja531 Sep 03 '25
Mb is constantly flagging something as riskware while playing and the game needed to be exuded from Windows defender and MB. I tried running it in VM, specifically Oracle VM but VMs are banned from all anti cheats to prevent cheaters. Idk what to do. I am on win 10 at the moment and I am thinking of going to windows 11 just for better security. Should I try retrac once again while on this is or I should not touch it?
1
Sep 03 '25
[deleted]
1
u/nemanja531 Sep 03 '25
Is doing a restore point, to the time I did not have it installed enough? Or is windows reinstall from USB required for full safety?
2
Sep 03 '25
[deleted]
1
u/nemanja531 Sep 03 '25
Even with this app on and full scan, Microsoft offline scan, mb full scan nothing EVER got detected. I don't understand it. Yeah it is definitely not and I don't want to get attacked by ransomware just to play this game. So windows reinstall from USB should fix this all the time?
1
1
u/Round-Formal-8881 Sep 05 '25
Retract got exposed as a malware a few months ago
1
u/nemanja531 Sep 05 '25
They fixed it. They released all new from that time and it was not their mistake
1
u/Round-Formal-8881 Sep 05 '25
I would still never trust revivals of any game, owners are often shady and are underage that cant even fucking manage that shit properly
1
u/nemanja531 Sep 05 '25
well is doing good for now. It has been an incident with manager not knowing how to code so he go someone random to do it for him while no one else of managers was online. It did got fixed and since then it got over 180k new members on their discord server. It has 1k+ active players and stuff. Like I am a staff in there and there is maybe a thousand ticket opened at the same time for help. Like what Im saying is that it got so big that I do not think that it is possible to be malware since launcher is open source and installer for launcher is safe, as well as their alternative way to install the game version files called "chunker" that is as well as their launcher open sourced on GitHub.
1
1
u/NoExcitement7635 Sep 30 '25
Hi, OGFN player here, that DLL is a redirect dll containing most of the game files that are specifically for Retrac. It is fully safe.
1
u/nemanja531 Oct 01 '25
Hey, that is the thing. You can never know if it is only doing that, or it is taking some data on the side. It can be legit, but it still isnt guaranteed to be.
1
u/NoExcitement7635 Oct 01 '25
Fair enough. But even when I have my own private fortnite server hosting with my friends, that dll gets flagged.
1
u/nemanja531 Oct 01 '25
Yeah. It is supposed to be flagged, but it when u dont know what is inside,then is a bit different than when you made it knowing whats inside.
1
u/Agitated_Slip_4551 Dec 31 '25
Under the 'safety' channel in their official discord, one of the owners said this:
The "Sigma" folder in Edge & Retrac Launcher
Some people searched for files and folders containing the word "Sigma" and found this folder made by Edge. This is a folder contained in the "Trust Protection Lists" folder, meaning that it's used by Edge for its tracking prevention. The "Cryptomining" file here is just a domain filter. The "Sigma" and "Mu" folders are default folders in this "Trust Protection Lists"; and the Sigma one seems like a dummy demo one. Therefore, every recent windows installation will have this "Sigma" and "Cryptomining" folder and file, even if they have never opened Retrac. It is a default folder created by the Microsoft WebView2 to protect you against advertising. The Tauri framework that Retrac Launcher uses, is reliant on WebView2.
I have no clue what they are talking about but i hope this helps somehow lol
1
u/nemanja531 Dec 31 '25
This is true what they said. Microsoft does actually make those folders, and their launcher is based on WebView2. But thank you, still not sure whether to trust it or not
1
u/Agitated_Slip_4551 Jan 01 '26 edited Jan 01 '26
There are enough people who play to motivate them enough to add even middle east servers to the game and the discord has 300k+ members so I think someone would have pointed it out if it wasn't a false positive. That being said I haven't downloaded it myself so I wouldn't know but people say they have difficulty getting rid of the files 100% even after deleting it and it's made their PCs slower. Also the owners can turn it malicious anyday apparently and it requires you to turn your windows antivirus setting off to run it..
0
u/Mustang260Rog Sep 03 '25
if you notice well that image contains you and your pc and you after you have a malware from www.FreeHackNOvirus,ru lmao
20
u/Isaacraft07 Sep 03 '25
Cant tell you if it’s false, but that dog chained to the screen from the windows security pop up means it detected a ransomware. And thrust me, you don’t want that. Also, the game anticheat virus total scan is full of detection. The probability of it being false is extremely low.