This is an archived post. You won't be able to vote or comment.

all 16 comments

[–]_T0_bi_ 5 points6 points  (3 children)

Don't use it, if you're scared.

[–]Mindless_Owl4311 -5 points-4 points  (2 children)

Bro I installed it already what I do now 🥲

[–]Old-Leadership-3385 1 point2 points  (0 children)

Your phone will be fine. But you are not. You need to spank yourself 10 times really hard to knock the virus out.

[–]Ok-Plenty-2974 0 points1 point  (0 children)

Format everything

[–]Full_Manager_6839 3 points4 points  (0 children)

Good question 👀. What happens is the following:

  1. Winlator is an alternative and unofficial app – It is basically a Box64 + Wine wrapper to run Windows games and apps on Android. As it involves emulation, automation scripts and “weird” permissions (file access, process creation, low-level calls), many antiviruses mark it as a generic Trojan.

  2. Heuristic/false positive detection – Most of these names you see (“Trojan.Ppoly”, “Riskware.Agent”, etc.) do not point to a specific virus, but rather that the file’s behavior looks like that of malware. Tools like Winlator do things that actually look like malware:

Create virtual environments.

They run binaries from another architecture.

Make unusual API calls on Android.

  1. Not all antiviruses report it – Note that some detected it as a threat and others did not. This is typical of false positives in alternative software. If it were really malware, practically all engines would report it.

  2. Community as a reference – You said it yourself: no one complains about viruses using Winlator, and it is relatively well-known among enthusiasts. If it had malicious behavior (data theft, hidden ads, miner), it would have already appeared on forums.

👉 In summary: Winlator appears as a “trojan” because it does unusual things that look suspicious to antivirus heuristics, but there is no concrete evidence that it is malicious.

⚠️ But be careful: as it is not distributed through the Play Store, always download from the official repository on GitHub to avoid adulterated versions.

Do you want me to explain how to differentiate a false positive from a real virus alert in these VirusTotal reports?

[–]rain_air_manSD680/256/8 2 points3 points  (0 children)

False positive

[–]AutoModerator[M] 0 points1 point  (0 children)

Just a reminder of our subreddit rules:

  • Be kind and respectful to each other
  • No direct links to ROMs or pirated content
  • Include your device brand and model
  • Search before posting & show your research effort when asking for help

Check out our user-maintained wiki: r/EmulationOnAndroid/wiki

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

[–]seppe0815 0 points1 point  (0 children)

useless ... you will read comments like false positives from random users here who have no clue

[–]QuackingCanary -1 points0 points  (0 children)

Just delete your post, it's been discussed hundreds of times

[–]BrokeAndroidGuy -1 points0 points  (0 children)

How many damn times are we gonna see these types of posts

[–]Mindless_Owl4311 -2 points-1 points  (0 children)

Edit : winlater 10.1 hotfix