gta-chaos-mod / Trilogy-ASI-Script

The ASI script for the GTA Trilogy (SA only for now, 3 and VC may follow later on)
GNU General Public License v3.0
141 stars 21 forks source link

Windows Safety detected the file "TrilogyChaos.SA.asi" as an serious trojan virus!!! #122

Closed dova61 closed 3 years ago

dova61 commented 3 years ago

Well hello there Lordmau5,

I registered today on GitHub just to post this issue! First of all I'm a big fan of your chaos mods! Even though they give me a hard time they are really fun! Today I wanted to install gta san andreas once again to play your awesome chaos mod, I think it's been a year since I've played it. So I downloaded the Gta Trilogy Chaos Mod zip from here:

https://github.com/gta-chaos-mod/Trilogy-ASI-Script/releases/tag/v2.3.4

and tried to install it. After installing the mod it didn't work so I've checked and noticed that the file "TrilogyChaosMod.SA.asi" in the "scripts" folder was detected as a serious trojan virus! I also tried deactivate antivrus to see if I could get the mod to work but it still didn't... Now the Windows Safety can't even delete or put it in quarantine since it's appearing right after I do one of these actions!

Now I'm stressed out and a bit annoyed because it tells me that the status of this virus is active and the threat is seroius! Can you please explain me why and how this file is a virus instead of the mod and how can I get rid of it??? Windows Saftey detected it as "Trojan:Win32/Wacatac.D7!ml"

I just wanted to play this awesome chaos mod, not getting infected with virus!

Pls any help would be appreciated!

Kind regards dova61

Sorry for the picture being in german:

problem copy

Lordmau5 commented 3 years ago

It's a false positive, allow it and move on.

I should elaborate a bit further: The way I'm handling communication between the mod and the GUI (the .exe you need to have open while playing) is through so called Named Pipes.

For whatever reason Windows decides that I somehow am not using them the right way or whatever.

Either way: As long as you download the mod from THIS repository, and not some Russian mod website, then you are safe (despite this "trojan" warning). If you want to be extra safe you could build the mod from it's source - the result would be the same, Windows will complain about the .asi being a virus, but at least you can be 100% sure it's safe then.

I should really see about making a contribution readme so people know how to build it themselves and such...

dova61 commented 3 years ago

This is what I thought aswell that the report would be a false positive, that's why I tried installing it while having firewall turned off. Somehow it still didn't work, the mod seems to not be active in the game. Also yes I tried a download from a different site but with the same result... That was my mistake... I think I shouldn't have done that... A few days later I turned on my pc, just to realize almost all of my files were deleted, my desktop looked like my pc was reseted and nothing worked... windows safety app was removed from the pc aswell as microsoft store didn't wanted to open... Recovery points were also deleted so there was no chance in getting all my stuff back. My only possibility was to reset the pc clean and install a new fresh windows system..... that's the end of the story... I know you or your mod wasn't the fault for all of this happening to me, despite that I'm not going to mess arround with gta san andreas mods or mods in particular for the time being.... Gonna miss the fun sessions with theses mods...

Have a nice day

kind regards dova61

Lordmau5 commented 3 years ago

Completely disabling Windows Defender or your firewall is a horrible idea anyway. Please never EVER do that again.

Effectively all you would've needed to do was click on "Aktionen" in that screenshot and then "Erlauben" (or whatever it shows in German) - It could be that it still deleted it and all you would've needed to do is redownload it from this repository (I can't vouch for any rehosting websites. There is ALWAYS the chance that they might include ACTUAL viruses)

freakster-yt commented 2 years ago

How do download it for my gta edition