DreymaR / BigBagKbdTrixPKL

"DreymaR's Big Bag of Keyboard Tricks" for Windows with EPKL
Other
326 stars 32 forks source link

Didn't find EPKL.exe (existence implied by the README tutorial). Compiled it with Compile_EPKL, but my antivirus deleted it. #81

Closed carbon-starlight closed 6 months ago

carbon-starlight commented 6 months ago

Windows 10 Pro

README.md file suggests to execute EPKL.exe -- it wasn't anywhere in the foulder. I guessed I should launch Compile_EPKL.bat, and it did make the file appear, but my antivirus (default Microsoft Defender) said it is a trojan (Trojan:Win32/Bearfoos.B!ml) and deleted the file automatically before I could to anything.

Detected: Trojan:Win32/Bearfoos.B!ml
Status: Quarantined
Quarantined files are in a restricted area where they can't harm your device. They will be removed automatically.
Date: 06.02.2024 3:32
Details: This program is dangerous and executes commands from an attacker.
Affected items:
file: C:\Users\qwert\AppData\Local\Temp\RCX4EB2.tmp
file: C:\Users\qwert\Downloads\BigBagKbdTrixPKL-master\BigBagKbdTrixPKL-master\EPKL.exe

I can't run CompileEPKL again (p.s.: except for a one time)_ (when I run the program info about successful compilation appears, but when I press any key to launch EPKL it says that expected to run file wasn't found).

The error window:

[Window Title]
C:\Users\qwert\Downloads\BigBagKbdTrixPKL-master\BigBagKbdTrixPKL-master\EPKL.exe

[Content]
Windows cannot find 'C:\Users\qwert\Downloads\BigBagKbdTrixPKL-master\BigBagKbdTrixPKL-master\EPKL.exe'. Make sure you typed the name correctly, and then try again.

[OK]

P.S.: One time it rebooted and I was able to compile again, and I even managed to click on allow threat button in time, but the Defender deleted it nevertheless.

carbon-starlight commented 6 months ago

Sorry, accidentally closed the issue. Reopening

Update: managed to somewhat combat the issue by clicking Protection historyThreat quarantinedActionsRestore

DreymaR commented 6 months ago

This issue is described in the README. It's a long readme so things can be hard to find at first though.

https://github.com/DreymaR/BigBagKbdTrixPKL?tab=readme-ov-file#known-issues

Yes, sometimes virus software can be really stupid. If you have to play it safe, use a Release download instead of the current commit. Releases include the epkl.exe file. However, they aren't quite up-to-date so it's sometimes more fun to compile yourself.

Hope you make it work! My Microsoft Defender can get skittish, especially if I compile many times in succession, but it usually can be coaxed into ignoring my temp files as described. Failing that, you can turn it off temporarily and back on after compiling.