Search Unity

Unity producing Malware under Windows10?

Discussion in 'Windows' started by Stefan-Laubenberger, Aug 2, 2016.

  1. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    Looks like windows defender got rid of "C:\Program Files\Unity\Editor\Data\PlaybackEngines\windowsstandalonesupport\Variations\win64_nondevelopment_mono\player_win.exe", and that's why your builds are failing (I assume you are building 64-bit non development build?). We're talking with Microsoft about this and investigating what's causing it.

    In the mean time, you can workaround it by disabling windows defender and reinstalling Unity.
     
  2. smoothtrooper16

    smoothtrooper16

    Joined:
    Jan 20, 2017
    Posts:
    5
    That seemed to work, thanks for the workaround!
     
  3. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    Microsoft got back to me and said they deployed an update to windows defender that fixes this issue. It should go away on the next defender definition update.
     
  4. Kingblade

    Kingblade

    Joined:
    Jan 15, 2014
    Posts:
    16
    So... A nice and small bump to this thread.
    I just built a prototype game on unity 5.5.0p4 and sent the build to a friend.

    His WD alerted him for "Trojan:Win32/Manrele.K!cl" and deletes the file immediately.
    After finding this thread he tried to update his WD (running on windows 10) and reset and... it did not work.

    I am technically in no rush since this build is not for consumers, but it is pretty annoying and I would like to avoid trouble for testers / other people who might run into the problem.
     
  5. VoidFish

    VoidFish

    Joined:
    Nov 27, 2012
    Posts:
    31
    Hey, I just wanted to say that I ran into this issue. Thank you Unity team for dealing with Microsoft to fix it. I got a lot of bug reports from users about this..
     
  6. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    Was that yesterday? I'll ask Microsoft when they're gonna push out the update.
     
  7. Kingblade

    Kingblade

    Joined:
    Jan 15, 2014
    Posts:
    16
    Yup. it happened when I wrote the post.
     
  8. VoidFish

    VoidFish

    Joined:
    Nov 27, 2012
    Posts:
    31
    Hey, I just got this now, any word when Microsoft will have the update ready?
     
  9. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    Apparently they pushed the update out on friday (at least that's what they told me). Are you still seeing the issue after updating the definitions?
     
  10. Kingblade

    Kingblade

    Joined:
    Jan 15, 2014
    Posts:
    16
    Update: The update works now. Thank you for the support :)
     
  11. vrjordan

    vrjordan

    Joined:
    Feb 14, 2017
    Posts:
    2
    We had this issue two weeks ago with our build and then it resolved itself, however it's popped up again. I've triple checked that our definitions have been updated as of 2/13, but Windows Defender is still nabbing it as malware. Any more information about this?
     
  12. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    Microsoft gave me this link last time after resolving it in case the issue was back again:

    https://www.microsoft.com/en-us/security/portal/submission/submit.aspx

    Can you upload your executables that get detected there? They said they look at it within 24 hours. I haven't tried uploading anything there yet, but should be fairly straightforward.
     
  13. vrjordan

    vrjordan

    Joined:
    Feb 14, 2017
    Posts:
    2
    Ack - I tried submitting but their site keeps timing out on file upload despite being under 10MB. Will try other methods.
     
    Last edited: Feb 14, 2017
  14. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    You can also email me the binary and I'll send it myself. My email is in this thread somewhere.
     
  15. Strompy

    Strompy

    Joined:
    Apr 12, 2013
    Posts:
    2
    FWIW: This just started happening for us as well today, out of nowhere. Windows defender started flagging all of our .exes as malware and then eventually it flagged player_win and deleted it. We are legally prohibited from sending a build out, but I wanted to give any information we could to possibly help the cause.

    Using Unity 5.5.1f1
    Window Defender definitions were updated today (morning of February 14th)

    Cheers!

    EDIT: I managed to fix this issue. Though I will say it's very odd. We uninstalled Unity, then to be safe checked for virus definitions updates 5 times in Windows Defender. It kept saying it was up to date BUT on the 5th or 6th try, the definitions randomly updated again, to what appears to be the same update we already had. (no clue what that was about) When we re - installed Unity,everything worked fine.

    So I'm wondering if Defender is having trouble updating for some people. For example saying it's updated when it's not. It might explain some of these issues. and the randomness of the problem showing up also leads me to believe it is WD definition problem. Just my two cents!
     

    Attached Files:

    • pic1.jpg
      pic1.jpg
      File size:
      120.1 KB
      Views:
      1,019
    Last edited: Feb 15, 2017
  16. HadynTheHuman

    HadynTheHuman

    Joined:
    Feb 15, 2017
    Posts:
    14
    We're experiencing the same issue when building from Unity 5.5.1f1 - though in our case it's flagging it as Detplock.

    upload_2017-2-15_14-23-29.png
     
  17. Strompy

    Strompy

    Joined:
    Apr 12, 2013
    Posts:
    2
    Has your player_win file been flagged as malware yet or can you still build an executable?

    EDIT I see you've already lost your player file, so, when did you update your virus definitions last?
     
  18. HadynTheHuman

    HadynTheHuman

    Joined:
    Feb 15, 2017
    Posts:
    14
    They'd updated within the past day - not sure exactly what time, but it was before the failed build attempts. Windows Defender said it's up to date, etc.

    Edit: I've been able to grab another copy of the quarantined file from a different computer, so I'll try that out and let you know how I go later on.
     
    Last edited: Feb 15, 2017
  19. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    I pinged Microsoft personally about this... stay tuned.
     
  20. HadynTheHuman

    HadynTheHuman

    Joined:
    Feb 15, 2017
    Posts:
    14
    In the meantime, in case it helps any one; I was able to complete a build by replacing the quarantined file with a copy from another computer, and disabling WD during the build.
     
  21. ToniGreco

    ToniGreco

    Joined:
    Mar 3, 2017
    Posts:
    4
    Today I had virus problem installing the Unity 5.5.2f1 version.
    Free Avira Antivirus found the TR/Crypt.XPACK.Gen inside file UnityExampleProjectSetup.exe.

    It is a false positive or there are really a problem?

    Thank you for help
     
  22. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    Did you get that from Unity's installer from our website?
     
  23. ToniGreco

    ToniGreco

    Joined:
    Mar 3, 2017
    Posts:
    4
    Yes, i got it from this page: https://store.unity.com/download?ref=personal
    Then the installer downloaded some executable files and then executed them.
    Avira put UnityExampleProjectSetup.exe in her quarantene folder where I repeat the test and Avira confirm .TR/Crypt.XPACK.Gen.

    It's possible to dowload again this specific file only?
     
  24. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
  25. ToniGreco

    ToniGreco

    Joined:
    Mar 3, 2017
    Posts:
    4
    I dowloaded it, no problem for Avira.
    Maybe was a problem of "man in the middle"? I don't know.
    I will write updates here if other problems of this kind will happen again.

    Thank you for you kind help
     
  26. ToniGreco

    ToniGreco

    Joined:
    Mar 3, 2017
    Posts:
    4
    Opening the example in Unity alert me that this is an older version (5.5.0b10) than the editor (5.5.2f1), but after clicking "Continue" it work well.
     
  27. Fireshore

    Fireshore

    Joined:
    Aug 4, 2016
    Posts:
    2
    I had the same issue happen to me. Windows 8, PC build. SmartScreen claims "Unknown Publisher". Unity version 5.5.2f1, does have custom icon. This is quite embarrassing.
     
  28. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    That is not the same issue. It claims Unknown Publisher because you haven't signed your application with a trusted certificate.
     
  29. Strangiato

    Strangiato

    Joined:
    Oct 24, 2014
    Posts:
    18
    FYI, Windows Defender began flagging the Unity Player executable from our game as Vundo.gen!D starting on Monday. We hadn't updated the game on Steam since January, but we had numerous reports from users that is was happening. We contacted Microsoft, were directed to use the same submission link above, and the problem was resolved within 24 hours, with the following note from their support engineer:

    The signature fix was added (3/21/2017 8:01:31 PM)

    Add Exception:Vundo.gen!D attribute to fix FP on memory detection of a Unity file.
    sample: 759f4883620bb44d46b774c651235d9a5c6f8995

    It's not detected anymore as of Signature Version 1.237.1811.0
     
  30. Nihil688

    Nihil688

    Joined:
    Mar 12, 2013
    Posts:
    503
    Happened again today
     
  31. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    ^ Which Unity version are you on?
     
  32. Nihil688

    Nihil688

    Joined:
    Mar 12, 2013
    Posts:
    503
    5.4.3
     
  33. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    Is that 5.4.3f1 or a patch release? Can you show a screenshot of windows defender detecting it?
     
  34. Nihil688

    Nihil688

    Joined:
    Mar 12, 2013
    Posts:
    503
  35. Torshall

    Torshall

    Joined:
    Sep 8, 2013
    Posts:
    2
    This started happening to us as well yesterday.

    Our cloud build gives the false positive Vundo alert. I've managed to pin-point quite exactly when the issue occurred on https://developer.cloud.unity3d.com/ as the the build between one that worked and one that didn't is like 20 minutes. It was ~17h ago, using Unity 5.4.3f1

    Worst part is... we are scheduled to release our game today.

    windows defender screendump:
    https://ibb.co/daGZ0a
     
    Last edited: Apr 7, 2017
  36. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    Thanks, we're onto it.
     
  37. Torshall

    Torshall

    Joined:
    Sep 8, 2013
    Posts:
    2
    Any updates or eta on this?

    Or perhaps anything we can do as a workaround?

    Edit:
    Found workaround as mentioned previously. removed our custom icon as that was causing the issue.
     
    Last edited: Apr 8, 2017
  38. KoverasAlvane

    KoverasAlvane

    Joined:
    Dec 7, 2016
    Posts:
    1
    Can confirm that removing the custom icon fixes the false malware alert from MSE. My team is using 5.4.3f1 (x64) on Win7, and it started getting false alerts for "Trojan:Win32/Vundo.gen!D" last week (probably earlier, but we only noticed then). Weirdly enough, the problem only occurs with the x86 build -- when we build for x86_x64, no alarm is triggered, even with the custom icon enabled. This will be our workaround from now on, although I do hope for an official fix for this.
     
  39. ravey_451

    ravey_451

    Joined:
    Apr 6, 2015
    Posts:
    3
    Getting a threat alert from Windows Defender on Windows 10.

    Trojan:Win32/Mulrolu.C!cl

    Alert level: Severe

    Affected items:
    mono-boehm.exe
    mono-sgen.exe
    mono.exe​

    Affected releases:
    5.6.1p3
    5.6.1p4
    5.6.2f1
    update: no alerts with this morning's threat definition update ^^
     
    Last edited: Jun 22, 2017
  40. Kingblade

    Kingblade

    Joined:
    Jan 15, 2014
    Posts:
    16
    Well, that happened again. This time when trying to send to someone I don't know (which makes the whole experience a bit embarrassing).

    Anyway, here is the build i've sent him (it's temporary for 30 days but should suffice):
    https://ufile.io/2ctze

    Again, windows 10 - got an alert from windows defender.
     
  41. td-lambda

    td-lambda

    Joined:
    Jul 14, 2011
    Posts:
    14
    Ok just ran into the same issue here with Windows Defender on Win 10 also getting Trojan:Win32/Vundo.gen!D

    Any progress on fixing this problem?

    Edit: This only occurs when I set the custom icon in the Player Settings (Build Window)

    upload_2017-7-14_16-4-3.png
     
    Last edited: Jul 15, 2017
  42. ebookerd1

    ebookerd1

    Joined:
    Feb 3, 2018
    Posts:
    1
    An easy Simple solution is to move your project outside of your documents folder move it to something like this "c;\projects\unityWorkspace". Defender detects changes to to system folders creating a folder somewhere wont trigger the change event monitor.
     
  43. MostHated

    MostHated

    Joined:
    Nov 29, 2015
    Posts:
    1,235
    Hello,

    I just wanted to throw it out there that I updated to 2018.2.8f1, not long after I did that Malwarebytes took hold of Unity and locked it out from access. I went back and excluded the whole Unity folder and of coures, it was fine after that, I just wanted to make sure it was known.

    Thanks,
    -MH

     
  44. Tautvydas-Zilys

    Tautvydas-Zilys

    Unity Technologies

    Joined:
    Jul 25, 2013
    Posts:
    10,674
    It isn't known. Which Unity version did you update from? Where did you download Unity from? If you right click on that executable, is "Unity Technologies" signature valid on it? It should look something like this:

    upload_2018-9-14_12-54-50.png
     
  45. MostHated

    MostHated

    Joined:
    Nov 29, 2015
    Posts:
    1,235
    Thanks for the reply. I went from 2018.2.7f1 to 8f1 and I just downloaded it through the hub.



     
  46. Zipper1954

    Zipper1954

    Joined:
    Oct 26, 2018
    Posts:
    3
     
  47. Zipper1954

    Zipper1954

    Joined:
    Oct 26, 2018
    Posts:
    3
    The Unity setup is riddled with Trojans and this is todays update Unity.JPG
     
  48. Zipper1954

    Zipper1954

    Joined:
    Oct 26, 2018
    Posts:
    3
    Please Does Anyone Know What Is Happening About This Malware PROBLEM?
     
  49. Deleted User

    Deleted User

    Guest

    I know this is an older post but it still occurs sometimes. The best thing you can do is 1, click on Windows Defender and go to Virus protection. Select Ransomware and where it says controlled folder access simply switch it off. This eliminated a lot of headaches with the program because you are disabling that feature from messing with your build settings. Simply use other programs for protection against such things like another anti-maleware provider. You wont get all these different files being red flagged and auto encrypted automatically.
     
  50. wwaero

    wwaero

    Joined:
    Feb 18, 2020
    Posts:
    42
    Hey I recently hit this issue on a internally distributed app which was zipped up. Do I just need to specify a publisher to avoid the issue?