protonscr

Windows Defender detects Occamy.c trojan in steam proton 5.0 folder

protonclosed
ValveSoftware/Proton#3593 · opened 2020-02-26 by ghost · updated 2020-07-16 · 3 comments · github
?ghost 2020-02-26 github

Your system information

  • Steam client version (build number or date):
  • Distribution (e.g. Ubuntu): arcolinux/windows 10
  • Opted into Steam client beta?: [Yes/No] Yes
  • Have you checked for system updates?: [Yes/No] Yes

Please describe your issue in as much detail as possible:

I installed steam on arcolinux to try a game via proton the game did not work, so i reinstalled windows but i backed up my steam folder i had on linux and was in the process to copy it over to another internal backup drive since i copied it to an external backup drive initially, during the copy windows defender popped up with a "severe threat" warning with the name of Trojan:Win32/Occamy.C it found it in: D:\Steam games\steamapps\common\Proton 5.0\dist\share\wine\mono\wine-mono-4.9.4\support\installinf-x86.exe Obviously i am unsure if this is a false possitive but defender seems to think it is a severe threat. Just informing you guys. Thank you for all your work.

Steps for reproducing this issue:

  1. install a proton game and copy it to a ntfs partition drive
  2. then run a updated windows 10 and copy that linux steam folder to
    Untitled
    another ntfs partition using windows
?ghost 2020-02-26 github

That actually looks to be a part of wine-mono aka mono. Shouldn't really be a Proton issue.

And one can also say that its a problem with Windows Defender.

And one can also say that Proton isn't meant for Windows so its not something to think about.

I would expect this to be won't fix / not an issue.

Aaeikum 2020-03-03 github

Anti-virus programs have been very snippy about our conversion to PE files. You can report it to your anti-virus vendor as a false positive.

GGitCaps 2020-07-16 github

I know this is closed but I did run into this, this morning and submitted the file and false-positive user opinion to the Microsoft Windows Defender team, and the report back is that they have concurred and 'removed this detection' from the client and cloud side. Screenshot attached.
mono-proton-mw-submission

Proton versions