MyShiLingStar / ACNHPoker

Animal Crossing New Horizons Item Spawning Tool
https://dev.azure.com/MyShiLingStar/ACNHPoker/_build
BSD 2-Clause "Simplified" License
87 stars 22 forks source link

Windows Defender Detecting Trojan:Win32/Wacatac.B!ml in ACNH Poker Release188.zip #30

Open Doctor-Pokemon opened 2 years ago

Doctor-Pokemon commented 2 years ago

I have been using the 188 release of Poker since it was released. TODAY, Windows Defender tells me it has detected "Trojan:Win32/Wacatac.B!ml" in the .exe file.

I tried to delete it & re-download the 188 release again, but Windows Defender tell me I can't download Release188.zip because it's detecting this Trojan:Win32/Wacatac.B!mlvirus in the .zip its self.

HELP?! Pleeeaaase?!

image image

MyShiLingStar commented 2 years ago

Same as #25 Your Windows Defender looks unfamiliar to me. Are you running in on an outdated version of Windows?

Doctor-Pokemon commented 2 years ago

Windows 8.1 Can't afford a new computer to upgrade & this one can't run any Windows higher than 8.1

Doctor-Pokemon commented 2 years ago

Release187.zip has no such problem. Neither does its .exe, but 187's .exe can't connect to version 2.0.4. So am I just S.O.L.?

MyShiLingStar commented 2 years ago

Like what I said in #25, it's a false positive.

I have no idea what triggered the false positive. I have spent countless hours removing code and it still triggers it eventually. (To be more specific, once the .exe file reaches the size of over 1.5MB, it gets marked.) I have submitted the false positive reports to Microsoft multiple times and I have not received any reply from them.

If you trust the program, you can add the program to "Allowed items" so that it will run. You can also try to download it from Microsoft Azure at Here

GMR0110 commented 2 years ago

I have Bitdefender and I get a similar Trojan warning. It warns me prior to even downloading as it says the page I'm being redirected to is a trojan and the file trojan is Threat name: IL:Trojan.MSILZilla.12272. I ended up running it in a VM and have not detected anything so far. It does seem like a false positive so far. Hopefully it remains that way

MyShiLingStar commented 2 years ago

image

Here are the major ones by virustotal: BitDefender : IL:Trojan.MSILZilla.12272 Kaspersky : Not-a-virus:VHO:AdWare.MSIL.Convagent.gen Malwarebytes : Malware.AI.3948632825 McAfee : GenericRXRE-TJ!7BE1226EE793

image Kaspersky online scan does not detect anything.

Ad-Aware and Avast might be in there as well, but it depends on the build. Windows Defender is not shown on the list but it also appears on some of the builds.

I use Avira myself and I don't get any false positives at all. I have another machine running ESET-NOD32 and Symantec (Norton) and they also report the files are clean. It used to have problems with Symantec (Norton) too, but once I submitted the false positive to them, it seems they have fixed it on the recent build. It might still pop up again when I change something.

GMR0110 commented 2 years ago

I definitely appreciate your quick response and testing! I submitted it as an exception for my antivirus software. Great software.

acnhmama96 commented 2 years ago

Thank you for asking this question, and thank you to @MyShiLingStar for quickly following up.

As of today, Windows Defender for Windows 10 is still voiding the download due to a virus attached.

I did allow it. Just commented to make you aware it is still an issue.

Also, it pulled it from downloading on MS Azure stating the same problem.

MyShiLingStar commented 2 years ago

I have a fix on the way but that requires a LOT of time. I mean A LOT. No ETA at the moment but I am working on it.

Doctor-Pokemon commented 2 years ago

I went ahead & made an exception in Defender because I trust you, @MyShiLingStar...especially now that I know you're on the case. Take all the time you need, Boss.

Thank you so much for the effort you put into keeping ACNH Poker updated, functional, and full of helpful features. My favorite recent addition is the Freezer...it works much better in Poker than in some OTHER applications.

Thanks again. Stay shiny ^.^