2 years ago
Windows Defender detects "trojan" in cache when opening the EA app
Title sums it up pretty nicely.
Two different "threats" pop up in quick succession when opening the EA app, one around the time the first pop-up window appears and the second as the window for inserting my user and password is opening. Happened three times, consistently.
Detected: Trojan:Script/Phonzy.B!ml
file: \AppData\Local\cache\qtshadercache-x86_64-little_endian-llp64\e24592d8d235339875cae31851ad680a190a7cc6
file: \AppData\Local\cache\qtshadercache-x86_64-little_endian-llp64\e24592d8d235339875cae31851ad680a190a7cc6.hoayha
(the AppData is in my user folder naturally)
The six final letters in the second file ("hoayha") change whenever the detection happens, the rest doesn't.