amakvana/EzYuzu

New version 1.6 detected as a trojan in Windows Defender

Closed this issue · 4 comments

Describe the bug
Windows Defender has flagged EzYuzu as a "TrojanScript/Wacatac.H!ml"

To Reproduce
Steps to reproduce the behavior:

  1. Download or try to open EzYuzu
  2. See the error

Screenshots
Screenshot 2023-05-24 113525

Desktop

  • OS: Windows 11 Pro
  • 22H2 10.0.22621 Build 22621

Definitely a false positive. More than likely flagged up because it's a newly generated executable

https://www.virustotal.com/gui/file/f5210703d567eac4ba7e31419b59b5fe65dd9f97117ac8c029223c9f6f705694

I have submitted a report to Microsoft to rectify this

image
Same flagged before download even finished

Version 10.0.22621 Build 22621

Click on Actions and allow. It's a false positive

Closed - Windows Defender has picked up EzYuzu as a false positive. A copy of EzYuzu 1.6.1.0 has been sent to Microsoft to add into their heuristics.

These are the URL's EzYuzu connects to

App Version Checking (checks if EzYuzu is latest version):
https://raw.githubusercontent.com/amakvana/EzYuzu/master/version

Json Data:
https://api.github.com/repos/pineappleEA/pineapple-src/releases
https://api.github.com/repos/yuzu-emu/yuzu-mainline/releases

Dependencies:
https://raw.githubusercontent.com/amakvana/EzYuzu/master/assets/7z/22.01/7z.zip
https://aka.ms/vs/16/release/vc_redist.x64.exe

VirusTotal reports back as safe

https://www.virustotal.com/gui/file/c7bf833d7f066ee1e041ecd106d8a832f2716e0e04cdd038586146b179f64024?nocache=1