Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dalamud launcher now classified as Malware on MalwareBytes #1455

Open
1 task done
Xaaali opened this issue Mar 20, 2024 · 4 comments
Open
1 task done

Dalamud launcher now classified as Malware on MalwareBytes #1455

Xaaali opened this issue Mar 20, 2024 · 4 comments
Labels
bug A bug or something not working as intended triage Needs triage

Comments

@Xaaali
Copy link

Xaaali commented Mar 20, 2024

Update disclaimer

  • Yes, I have checked and my issue is not related to the game updating and plugins not working correctly.

What did you do?

Tried booting XIVLauncher after recent patch, and now MalwareBytes is classifying XIVLauncher.exe as Malware, immediately quarantining on startup. Doing this with both versions 6.3.10, and the newest 6.3.16. Never happened before latest patch, now having to add all versions to MalwareBytes allow list.

Platform

Windows

Wine/Proton runner version

No response

Relevant log output

No response

@Xaaali Xaaali added bug A bug or something not working as intended triage Needs triage labels Mar 20, 2024
@tommadness
Copy link

This happens every time we update XIVLauncher. This is the reason we don't update it unless absolutely necessary. It's a false positive, either make exceptions or remove MalwareBytes entirely.

@Xaaali
Copy link
Author

Xaaali commented Mar 20, 2024

This happens every time we update XIVLauncher. This is the reason we don't update it unless absolutely necessary. It's a false positive, either make exceptions or remove MalwareBytes entirely.

Gotcha, Ill keep it in mind. Ive made the entire install folder as an exception.

@Bombarding
Copy link

Bombarding commented Mar 20, 2024

This happens every time we update XIVLauncher. This is the reason we don't update it unless absolutely necessary. It's a false positive, either make exceptions or remove MalwareBytes entirely.

Gotcha, Ill keep it in mind. Ive made the entire install folder as an exception.

Funny thing is yesterday's release wasn't quarantined or anything like that, only started happening just now when i booted up. But yea, C:\Users\<Username>\AppData\Local\XIVLauncher to the mbam allowlist will fix it.

@Bombarding
Copy link

Bombarding commented Mar 20, 2024

https://forums.malwarebytes.com/topic/309643-false-positive-xivlauncher-final-fantasy-xiv-unofficial-game-launcher/?do=findComment&comment=1624537

Confirmed false positive on MBAM side, expect to be resolved soon. Can remove the allowlist exception whenever.

Edit: Looks like mbam has already whitelisted it

image
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug A bug or something not working as intended triage Needs triage
Projects
None yet
Development

No branches or pull requests

3 participants