Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BizHawk 2.5 release gets quarantined by Microsoft Defender Antivirus #2370

Closed
patrickhlauke opened this issue Sep 3, 2020 · 2 comments
Closed
Labels
App: EmuHawk Relating to EmuHawk frontend Meta Relating to code organisation or to things that aren't code

Comments

@patrickhlauke
Copy link

Summary

Microsoft Defender Antivirus flags the BizHawk 2.5 release download on windows as having a virus: Trojan:Win32/Emali.A!cl

The downloaded zip is usually deleted. If you're fast enough to unzip it, EmuHawk.exe and DiscoHawk.exe are deleted.

Repro

  1. In Windows 10, with Defender enabled, download the 2.5 release
  2. Note that Defender will delete the zip after download
  3. In Settings > Virus & Threat Protection, under Protection History, see the output/reason for the deletion/quarantine.

Output

Detected: Trojan:Win32/Emali.A!cl

containerfile: C:\Users\redux\Desktop\BizHawk-2.5.0.zip
file: C:\Users\redux\Desktop\BizHawk-2.5.0.zip->DiscoHawk.exe
file: C:\Users\redux\Desktop\BizHawk-2.5.0.zip->EmuHawk.exe

Host env.

  • BizHawk 2.5; Win10 (OS Build: 19041.450) / Microsoft Defender Antivirus (Security intelligence version: 1.323.424.0)

screenshot of virus and threat protection history

@YoshiRulz
Copy link
Member

Duplicate of #2356, which I've unlocked in case anyone has helpful info to add. Not sure there's anything we can do about malware signatures in our executables other than recompiling with fingers crossed.

@YoshiRulz YoshiRulz added App: EmuHawk Relating to EmuHawk frontend Meta Relating to code organisation or to things that aren't code labels Sep 3, 2020
@patrickhlauke
Copy link
Author

apologies for the dupe...searched issues, but clearly not well enough

@TASEmulators TASEmulators locked and limited conversation to collaborators Sep 3, 2020
@TASEmulators TASEmulators unlocked this conversation Oct 11, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
App: EmuHawk Relating to EmuHawk frontend Meta Relating to code organisation or to things that aren't code
Projects
None yet
Development

No branches or pull requests

2 participants