Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Defender detects Occamy.c trojan in steam proton 5.0 folder #3593

Closed
ghost opened this issue Feb 26, 2020 · 3 comments
Closed

Windows Defender detects Occamy.c trojan in steam proton 5.0 folder #3593

ghost opened this issue Feb 26, 2020 · 3 comments

Comments

@ghost
Copy link

ghost commented Feb 26, 2020

Your system information

  • Steam client version (build number or date):
  • Distribution (e.g. Ubuntu): arcolinux/windows 10
  • Opted into Steam client beta?: [Yes/No] Yes
  • Have you checked for system updates?: [Yes/No] Yes

Please describe your issue in as much detail as possible:

I installed steam on arcolinux to try a game via proton the game did not work, so i reinstalled windows but i backed up my steam folder i had on linux and was in the process to copy it over to another internal backup drive since i copied it to an external backup drive initially, during the copy windows defender popped up with a "severe threat" warning with the name of Trojan:Win32/Occamy.C it found it in: D:\Steam games\steamapps\common\Proton 5.0\dist\share\wine\mono\wine-mono-4.9.4\support\installinf-x86.exe Obviously i am unsure if this is a false possitive but defender seems to think it is a severe threat. Just informing you guys. Thank you for all your work.

Steps for reproducing this issue:

  1. install a proton game and copy it to a ntfs partition drive
  2. then run a updated windows 10 and copy that linux steam folder to
    Untitled
    another ntfs partition using windows
@ghost
Copy link

ghost commented Feb 26, 2020

That actually looks to be a part of wine-mono aka mono. Shouldn't really be a Proton issue.

And one can also say that its a problem with Windows Defender.

And one can also say that Proton isn't meant for Windows so its not something to think about.

I would expect this to be won't fix / not an issue.

@kisak-valve kisak-valve transferred this issue from ValveSoftware/steam-for-linux Mar 2, 2020
@aeikum
Copy link
Collaborator

aeikum commented Mar 3, 2020

Anti-virus programs have been very snippy about our conversion to PE files. You can report it to your anti-virus vendor as a false positive.

@aeikum aeikum closed this as completed Mar 5, 2020
@GitCaps
Copy link

GitCaps commented Jul 16, 2020

I know this is closed but I did run into this, this morning and submitted the file and false-positive user opinion to the Microsoft Windows Defender team, and the report back is that they have concurred and 'removed this detection' from the client and cloud side. Screenshot attached.
mono-proton-mw-submission

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants