Trojan horse virus found in SWL patch from Steam and during installation using install file from SWL website

I’m still getting the error on SecretWorldLegendsDX11.exe with a very recent definition update (1.331.1390, created 10:23am feb 19th)

Tried this “solution”…didnt work,still getting alert and game refuses to start :frowning:

I’ll follow up with Microsoft on Monday. What .exe, specifically, are folks using that’s still getting an error? I see one using the dx11 client.

I use steam launcher…so whichever that uses …o.O

edit: error msg says secretworldslegendsDX11.exe…so that one :smiley:

Microsoft got back to us about the DX11 client and said they’ve cleared it as of this writing. They recommend updating your definitions and trying again.

1 Like

Well it is NOT fixed and before I did my latest Windows Update I could at least still play now I can’t even play. So I found this thread. I did the remove and update and got …
PS C:\Program Files\Windows Defender> .\MpCmdRun.exe -removedefinitions -dynamicsignatures

Service Version: 4.18.2101.9
Engine Version: 1.1.17800.5
AntiSpyware Signature Version: 1.331.1456.0
AntiVirus Signature Version: 1.331.1456.0

Starting Dynamic Signature removal.
Done!

Service Version: 4.18.2101.9
Engine Version: 1.1.17800.5
AntiSpyware Signature Version: 1.331.1456.0
AntiVirus Signature Version: 1.331.1456.0

Then I tried to add in but that fails or is not required.

PS C:\Program Files\Windows Defender> .\MpCmdRun.exe -SignatureUpdate
Signature update started . . .
Signature update finished. No updates needed

and I tried again and checked for viruses first, none.
start game and get the error after SWL tests the files and stuff and says OK you can start.
I then get a message that I’m infected and attempts to start fail with the following.
DX11.exe
operation did not complete successfully because the file contains a virus or potentially unwanted software. I guess I will try and tell my AV to ignore DX11.

Are you using Steam? The Steam version specifically appears to still be giving folks trouble, while the standalone version should be clear. We’ve submitted the Steam DX11.exe and are awaiting a response.

Still have the problem this morning with updated signatures.

The files identified were: SecretWorldLegends.exe and SecretWorldLegendsDx11.exe

I’m using the Steam version.

My signatures are update to 1.331.1467.0 which is more recent than the manual download on the MS definitions prage.

"Still have the problem this morning with updated signatures.

The files identified were: SecretWorldLegends.exe and SecretWorldLegendsDx11.exe

I’m using the Steam version."

Same…all recent updates to security…still no luck… :confused:

Yeah, I’m so sorry yall. We’re still waiting on a response from Microsoft after submitting the Steam clients for review. You should be able to allow SWL as an exception to Defender. If defender has quarantined the files, you can recover them by following this guide:

We received a response from Microsoft and they said they’ve cleared the Steam DX11 .exe with version 1.331.1487.0. Fingers crossed this works for folks; please let me know if the issue persists.

2 Likes

1.331.1525.0 detects it in secretworldlegends.exe on the steam version.

Ack, okay, thanks. Is that the plain .exe and not the dx11 one? When we submitted the plain steam .exe to Microsoft, they said it didn’t even trip detection. We’ll try again if that’s the case.

Yes, the non-dx11 one.

(<= Zerachilde)

This fixes Windows Defender, but it’s up to you how much you want to exclude.
Just for fixing the game, exclude your Funcom folder -, or if you use Steam, your Program Files (x86)\Steam folder, OR if using an extern disk the SteamLibrary folder there.

Please press
Win + i
to open your Windows 10 Settings…, then:








… alternatively, it’s also published here if you can’t see the troubleshooting-screenshots:
https://forums.omnedatumoptimum.red/t/the-swlpedia-collections-guidelines-42/1414/

Alternate solution (it will solve Windows Defender issues, as well as all Windows issues) (may also bring luck and make your loved one come back)
Switch to Linux Classic_flat_look_3D.svg

I’m still having this problem trying to patch the game after not playing for a while, defender flags the following file and the launcher reports a fatal error trying to download the latest patcher.

D:\Games\Funcom\Secret World Legends\PatcherSetup.exe.tmp

Security Intelligence Version is 1.331.1622.0 created on 22/02/2021 20:22

Trojan:Win32/Wacatac.DE!ml

Yup, its still bringing a Trojan, but its not Emotet now, its another one:

Trojan:Win32/Wacatac.DE!ml

WIN10
Newest Defender update from today
file: D:\Games\Steam\steamapps\common\Secret World Legends\PatcherSetup.exe.tmp

At this point the best course of action is to add an exception for the game to Windows Defender. We’ve already sent just about every single possible client to Microsoft and had them confirm they’re all clear.

1 Like

Thank you for the fast response AndyB!
Well, its just strange that before it was Emotet now its a different one and it flags as “Serious” in Defender which shouldn’t be the case for a false positive, or if they adjusted their definition base. Can you please maybe have them check again and come back with a confirmation and case number where it was confirmed?