VideoHelp Forum





Try StreamFab Downloader and download streaming video from Netflix, Amazon!



+ Reply to Thread
Results 1 to 8 of 8
  1. Member
    Join Date
    Apr 2012
    Location
    Hungary
    Search PM
    I am using this fork to run yt-dlp on Windows 7. After updating today (with command --update) When running it my virus scanner flagged it as trojan.win64.silverfox.avg and removed it. Do I need to worry or it is only false positive? This never happened before

    This is the fork link:
    https://github.com/nicolaasjan/yt-dlp/releases

    If it is risky to run this one above what other options do I have? Is it possible an older "original" version of yt-dlp.exe would still run on Windows 7? I guess not because of not updating, right?
    Quote Quote  
  2. That's a false positive. Search the issues at the yt-dlp repo, there have been numerous reports - e.g. https://github.com/yt-dlp/yt-dlp/issues/15415

    I'm sure you can trust the binary and @nicolaasjan - he's also a member here in the forum.
    Quote Quote  
  3. Member
    Join Date
    Apr 2012
    Location
    Hungary
    Search PM
    The only thing I did differently this time is that after updating it I pasted wrong text from the clipboard into my .bat file configuring it. Maybe due to the false input the fork crashed and it triggered a flagging? The bat is configured to ask for the link and I just pasted plain text there.
    Quote Quote  
  4. Member nicolaasjan's Avatar
    Join Date
    Dec 2025
    Location
    the Netherlands
    Search Comp PM
    As @Obo said, this must be a false positive.

    See also this comment on VirusTotal:

    YARA Signature Match - THOR APT Scanner

    RULE: SUSP_PyInstaller_Gen_Pattern_Feb25
    RULE_TYPE: THOR APT Scanner's rule set only
    RULE_LINK: https://valhalla.nextron-systems.com/info/rule/SUSP_PyInstaller_Gen_Pattern_Feb25
    DESCRIPTION: Detects patterns in compiled PyInstaller binaries. This rule is a generic rule that might generate false positives. A match should be further investigated.
    RULE_AUTHOR: Florian Roth

    Detection Timestamp: 2026-08-16 22:26
    AV Detection Ratio: 9 / 71
    Use these tags to search for similar matches: #pyinstaller #pattern #susp_pyinstaller_gen_pattern_feb25
    More information: https://www.nextron-systems.com/notes-on-virustotal-matches/
    Last edited by nicolaasjan; 18th Aug 2026 at 13:40.
    Quote Quote  
  5. Member
    Join Date
    Apr 2012
    Location
    Hungary
    Search PM
    Originally Posted by nicolaasjan View Post
    As @Obo said, this must be a false positive.

    See also this comment on VirusTotal:

    YARA Signature Match - THOR APT Scanner

    RULE: SUSP_PyInstaller_Gen_Pattern_Feb25
    RULE_TYPE: THOR APT Scanner's rule set only
    RULE_LINK: https://valhalla.nextron-systems.com/info/rule/SUSP_PyInstaller_Gen_Pattern_Feb25
    DESCRIPTION: Detects patterns in compiled PyInstaller binaries. This rule is a generic rule that might generate false positives. A match should be further investigated.
    RULE_AUTHOR: Florian Roth

    Detection Timestamp: 2026-08-16 22:26
    AV Detection Ratio: 9 / 71
    Use these tags to search for similar matches: #pyinstaller #pattern #susp_pyinstaller_gen_pattern_feb25
    More information: https://www.nextron-systems.com/notes-on-virustotal-matches/
    Thanks!
    Quote Quote  
  6. Member
    Join Date
    Apr 2012
    Location
    Hungary
    Search PM
    Originally Posted by nicolaasjan View Post
    As @Obo said, this must be a false positive.

    See also this comment on VirusTotal:

    YARA Signature Match - THOR APT Scanner

    RULE: SUSP_PyInstaller_Gen_Pattern_Feb25
    RULE_TYPE: THOR APT Scanner's rule set only
    RULE_LINK: https://valhalla.nextron-systems.com/info/rule/SUSP_PyInstaller_Gen_Pattern_Feb25
    DESCRIPTION: Detects patterns in compiled PyInstaller binaries. This rule is a generic rule that might generate false positives. A match should be further investigated.
    RULE_AUTHOR: Florian Roth

    Detection Timestamp: 2026-08-16 22:26
    AV Detection Ratio: 9 / 71
    Use these tags to search for similar matches: #pyinstaller #pattern #susp_pyinstaller_gen_pattern_feb25
    More information: https://www.nextron-systems.com/notes-on-virustotal-matches/
    Something that is strange is that after restoring with your latest version it is asking for a python dll from the _internal library. Before it never asked for that, I didn't copy that to the directory where I operate yt-dlp from. Is it possible it never needed that dll so far?
    Quote Quote  
  7. I have Windows 7 32-bit & the yt-dlp for it is just an .exe file.
    There is not a .zip file like for the Windows 7 64-bit.
    That one has .dll files in the internal folder.
    So I guess it depends on the version of Windows used.

    The newest version for my OS seems to work fine.
    No virus warnings from Avast.
    Virus total had detection by 6 out of 71 virus scanners. That usually means a false positive.
    Quote Quote  
  8. Member
    Join Date
    Apr 2012
    Location
    Hungary
    Search PM
    Originally Posted by cholla View Post
    I have Windows 7 32-bit & the yt-dlp for it is just an .exe file.
    There is not a .zip file like for the Windows 7 64-bit.
    That one has .dll files in the internal folder.
    So I guess it depends on the version of Windows used.

    The newest version for my OS seems to work fine.
    No virus warnings from Avast.
    Virus total had detection by 6 out of 71 virus scanners. That usually means a false positive.
    Maybe I downloaded the same exe file as well back in the days that's why I did not need the additional library.
    Quote Quote  



Similar Threads

Visit our sponsor! Try DVDFab and backup Blu-rays!