Hacking DevkitPro updater 2.0.0 Trojan.Win32:Occamy.B

I noticed your Hybrid Analysis in-depth results showed the installer would "reboot the computer".

Maybe it's just me, but I don't recall devkitPro requesting to reboot computer once installed.

But if it did, then it's for setting up the environment variables to point $DEVKITPRO and $DEVKITARM to the correct installation paths, in order for Makefiles to work. And it may be the cause for virus scanners to flag it as suspicious, which is frankly a false positive.

Completely harmless.

I'm not sure what or why other parts are flagged as suspicious for, so maybe others have better insights on why a normal installation procedure gets flagged as suspicious, and it's really not?
 
Last edited by delete12345,
This is the first version that Windows Defender isn't shutting down right off the bat upon downloading from Chrome. Looks good now!

EDIT - I take that back...

That's 1.7.0 which wasn't signed. Latest is 2.1.1 which is.

If 2.1.1 is there in c:\devkitPro and wasn't immediately quarantined then it's all good.
 
I wouldn't just do that. The OP should run it in a sandbox environment or better yet, in a virtual machine to prevent the spread of potential infection.
Usually I wouldn't do that, but if I know who the developer is, then I can feel safe to disable the av (if the setup file is legit)
 

Site & Scene News

Popular threads in this forum