TMM icon indicating copy to clipboard operation
TMM copied to clipboard

Microsoft Defender flags 2KAN as Trojan

Open Loki-Lokster opened this issue 2 years ago • 1 comments

This is a false positive that is caused by pyinstaller packaging the python interpreter and included libraries into a single executable which causes some anti virus to think this is a trojan.

We sent the executable into Microsoft as a false positive, and they returned saying that they did not find anything malicious and have exempted 2KAN.exe from Microsoft Defender. As this can sometimes take time to roll out these changes, if you are encountering Microsoft Defender flagging 2KAN as malware or trojan, please update your malware definitions following these steps:

1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender 
2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
3. Run "MpCmdRun.exe -SignatureUpdate"```

This should force the malware definitions to update and 2KAN will no longer be flagged as a trojan.

Loki-Lokster avatar Mar 26 '23 09:03 Loki-Lokster

Alternatively I have added a update_defender_definitions.bat file to the release. Simply run as an administrator and it will automatically update to the newest malware definitions.

Loki-Lokster avatar Mar 29 '23 07:03 Loki-Lokster