PKHeX Wacatac.H!ml virus

  • Thread starter Thread starter badblood08
  • Start date Start date
  • Views Views 4,662
  • Replies Replies 19

badblood08

Well-Known Member
Newcomer
Joined
Feb 5, 2022
Messages
48
Reaction score
24
Trophies
0
XP
247
Country
United States
I tried downloading the latest PKHeX from here: https://projectpokemon.org/home/files/file/1-pkhex/

Windows Security got this virus:
1670004007188.png

1670003920198.png


Is this a false positive virus? Should I disregard this. Please advise.

Thanks!
 
Pop the file into VirusTotal or Hybrid-Analysis and it'll tell you whether if this is the case or not. Microsoft Defender generates tons of false positives, so you shouldn't worry about anything.
Only 1 vendor found it as a virus
1670004273980.png

I'm not sure if this is an isolated case that can be disregarded
 
I'm totally going to trust my guts here, and download this anyway. I better have some god damn luck XD
 
no matter what i scan virustotal always has at least 1-2 vendors mark it as a false positive. i've uploaded empty archives, blank raw text documents and random images and photos and there's always at least one.

i would be more concerned if several caught it. additionally if you google the name of said malware you'll see that every single post and thread mentions it being an extremely common false positive. windows defender seems to mark benign python and c++ scripts as being infected with this quite frequently.

you're probably fine but if you're ever super paranoid maybe consider putting a linux distro on a flash drive and performing your mods on that. it wouldn't 100% protect you unless you also physically disconnected any other mountable media but it would certainly add a layer of protection and teach you some new skills.
 
no matter what i scan virustotal always has at least 1-2 vendors mark it as a false positive. i've uploaded empty archives, blank raw text documents and random images and photos and there's always at least one.

i would be more concerned if several caught it. additionally if you google the name of said malware you'll see that every single post and thread mentions it being an extremely common false positive. windows defender seems to mark benign python and c++ scripts as being infected with this quite frequently.

you're probably fine but if you're ever super paranoid maybe consider putting a linux distro on a flash drive and performing your mods on that. it wouldn't 100% protect you unless you also physically disconnected any other mountable media but it would certainly add a layer of protection and teach you some new skills.
PKhex doesn't work really well with Mono according to PKhex themselves.
 
PKhex doesn't work really well with Mono according to PKhex themselves.
Oh, wild. Windows only. How bizzare... guess it's due to their choice of language. (C#).

That's... actually really lame. Guess the 2nd best would just be a windows virtual machine with stuff like PAE/NX and shared clipboards/drag and drops disabled. That said it's most definitely a false positive but for those who are worried it's at least a way to accommodate for their concerns.

Still. Dang.
 
Only 1 vendor found it as a virus
View attachment 341145
I'm not sure if this is an isolated case that can be disregarded
Probably. Even the 1 detection is vague/heuristics and not a real detection.
It appears it's scanning the URL as a website though, rather than scanning the file. You'd get better results if you downloaded the file and manually uploaded it.
 
  • Like
Reactions: SylverReZ
No you don’t. You need common sense. Defender has been fine for ages and alerting him fine. As someone has said it’s alerting on that URL.

Common sense would be to find a more reputable download link.

There is no problem downloading it from projectpokemon.org, I been downloading pkhex from there for years and no issues. Just that he got a false detection.
 
See here

I tried myself, but I didn't have the patience to make heads or tails of it. A lot of duplicate implementations seem to exist in the source itself. Maybe I'll try again later.
 

Site & Scene News

Popular threads in this forum