HeroicGamesLauncher icon indicating copy to clipboard operation
HeroicGamesLauncher copied to clipboard

Trojan:Win32/Znyonm

Open KN592 opened this issue 11 months ago • 15 comments

Describe the bug

happened just now as of writing, heroic was open and running

Add logs

The app was automatically deleted.

Steps to reproduce

  1. Go to '...'
  2. Click on '...'
  3. Scroll down to '...'
  4. See error

Expected behavior

Not have this problem.

Screenshots

image

Heroic Version

Latest Stable

System Information

Windows 10 64-bit

Additional information

No response

KN592 avatar Mar 09 '24 02:03 KN592

same here. Workaround: gogdl.exe has been added to the list of names in windows defender.

CLKRUN avatar Mar 09 '24 14:03 CLKRUN

Are you guys using the setup or the portable version?

flavioislima avatar Mar 09 '24 15:03 flavioislima

I ask because the portable version is not signed yet, only the setup is. So might be that some antiviruses detect it as a virus because of that.

The problem with antiviruses on windows is that most of them when does not know the file because the lack of signing or because they don't recognize the file type is that they say is a virus.

Might be good for the user to be honest but lead to false positives as well.

flavioislima avatar Mar 09 '24 15:03 flavioislima

Are you guys using the setup or the portable version?

set up

KN592 avatar Mar 09 '24 16:03 KN592

Are you guys using the setup or the portable version?

Setup version

Tommy2678 avatar Mar 09 '24 18:03 Tommy2678

I am running the setup version on Windows 11 and got this from Windows Defender also.

ultramookie avatar Mar 09 '24 18:03 ultramookie

We will try to sign gogdl, legendary, nile from the next release to see if these errors are gone.

But they are definitely false positives from windows defender since Heroic is a signed app and before signing the authority always checks for viruses, malmware, etc.

You can help also by reporting this to the antivirus as a safe.

flavioislima avatar Mar 09 '24 18:03 flavioislima

I use the portable version on Win 10 and get the same issue.

LeTumme avatar Mar 09 '24 19:03 LeTumme

Virustotal also detecting 9/73. https://www.virustotal.com/gui/file/cdbc96a95eb029f8a59e7a6aeb4b5dda9d6296328dc666655f7bbe2196cf2f06

Helluuu avatar Mar 09 '24 22:03 Helluuu

I found a solution for this issue untill gogdl.exe isn't signed officially. First you need to restore gogdl.exe if defender already quarantined or removed it. After that follow this guide - https://youtu.be/zGiNGnX5dYg?si=XQaKWWn2e2CWYpPJ Instead of adding folder to exclusion, you need to select file to add to exclusion list. After clicking file you will be asked to select file to add to exclusion list. Locate file in this directory ( C:\Users"YourUserName"\AppData\Local\Temp\nsuB633.tmp\7z-out\resources\app.asar.unpacked\build\bin\win32 ). In this directory you will find gogdl.exe click on it and click on open. 👍 🎉Hurray your file is added in defender's virus definition list. :( be cautious while adding file or folder other than gogdl.exe if you accidentally selected a virus defender will skip to scan it. And your data will be compromised. Enjoy🎉

rairay91 avatar Mar 10 '24 05:03 rairay91

Virustotal also detecting 9/73. https://www.virustotal.com/gui/file/cdbc96a95eb029f8a59e7a6aeb4b5dda9d6296328dc666655f7bbe2196cf2f06

nile.exe even worse, 11 red in VT https://www.virustotal.com/gui/file/b05cac62bc4b4615ca6eb4e1ff03d379a34ede7ff71bcab7e427e672e4682eec

How can you people advise other to whitelist files with such negative scores? This is shady

ZdziczalyMops avatar Mar 10 '24 06:03 ZdziczalyMops

We've explained this situation many times.

Legendary, Nile and gogdl are all python programs packaged using pyinstaller. Since python code is in plain text, anti virus programs flag it after seeing it makes http connections. This is a false positive

If you are concerned about all this you can always verify the checksums of binaries compared to the ones our CI builds. And if you don't find it trustworthy you can audit the source code of each tool and even build the binaries yourself.

imLinguin avatar Mar 10 '24 08:03 imLinguin

We've explained this situation many times.

Legendary, Nile and gogdl are all python programs packaged using pyinstaller. Since python code is in plain text, anti virus programs flag it after seeing it makes http connections. This is a false positive

If you are concerned about all this you can always verify the checksums of binaries compared to the ones our CI builds. And if you don't find it trustworthy you can audit the source code of each tool and even build the binaries yourself.

what does gogdl affect?

KN592 avatar Mar 10 '24 08:03 KN592

Same for me. Opened fortnite with heroic yesterday and Windows Defender came up with it. I am using setup version

astrysm avatar Mar 11 '24 08:03 astrysm

have the same issue too after updating, set up version.

yesterdays-jam avatar Mar 11 '24 11:03 yesterdays-jam