Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows defender classifies the renpy 8.2.0 sdk exe as a trojan #5314

Closed
Galo223344 opened this issue Jan 27, 2024 · 10 comments
Closed

Windows defender classifies the renpy 8.2.0 sdk exe as a trojan #5314

Galo223344 opened this issue Jan 27, 2024 · 10 comments

Comments

@Galo223344
Copy link
Contributor

On windows 10 64 bits.

The virus is clasified as a Trojan:Script/Wacatac.B!ml
image

@renpytom
Copy link
Member

This is a faulty detection. Please report it. I'm going to be making a new build shortly, but you should let microsoft know their antivirus is faulty.

(How do I know? Ren'Py builds don't use windows.)

@Galo223344
Copy link
Contributor Author

I marked it as a false positive

@renpytom
Copy link
Member

I've also uploaded a new version, and scanned that on my windows box, and it came out clean. It also came out clean on virustotal, save for one spurious detection by a no-name company.

@KiloOscarSix
Copy link
Contributor

KiloOscarSix commented Jan 28, 2024

So you're aware, updating to 8.2 also resulted in Windows Defender blocking and quarantining renpy.
All threats detected Trojan:Win32/Wacatac.B!ml same as OP

@renpytom
Copy link
Member

That certainly isn't happening with me, with Windows Defender, with "Security Intelligence Version 1.403.2818.0, created on 1/27/2024." I scanned the file, and it was clear.

@KiloOscarSix
Copy link
Contributor

My defender versions:
image

Running latest Windows 11 pro

@Galo223344
Copy link
Contributor Author

That certainly isn't happening with me, with Windows Defender, with "Security Intelligence Version 1.403.2818.0, created on 1/27/2024." I scanned the file, and it was clear.

Could it be that you're scanning the direct build instead of a downloaded/extracted one? I know that windows defender is harsher on downloaded files, so it could be that.

@Galo223344 Galo223344 reopened this Jan 28, 2024
@mal
Copy link
Member

mal commented Jan 28, 2024

I just downloaded and scanned with Windows (10 x64, same as reported in OP) Defender the self-extracting exe (renpy-8.2.0-sdk.7z.exe), the zip archive (renpy-8.2.0-sdk.zip), and for good measure then extracted the zip and scanned the resulting directory. All came up clean.

@renpytom
Copy link
Member

I've had two peop scan it on the Ren'Py discord, and both found it clean. I'm going to close this - feel free to comment, but this seems more likely to be an issue with your computer than a problem with Ren'Py.

@renpytom
Copy link
Member

From Microsoft:

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants