Aurora

Help & troubleshooting

Why is my antivirus saying Aurora is a virus?

An antivirus can mistake a legitimate game modification for a threat. This is called a false positive. If Aurora is flagged, check the affected file and release before allowing it to run.

Why is this happening?#

Aurora brings classic FIFA games back to community servers using compatibility changes and game modifications. Antivirus software can flag behaviour like this, and unfamiliar files can also trigger reputation-based warnings.

That does not establish the cause of every detection. A name such as Wacatac is useful information for a report, but it does not by itself prove that a particular file is safe or harmful.

Before you make a change#

Check that your download came from the project links in the official Aurora Discord. Note the Aurora version, affected filename and exact detection name. If you are unsure, leave the file quarantined and ask for support.

How do I resolve this? (Windows Defender)#

  1. Open Windows Security → Virus & threat protection → Protection history and select the detection.
  2. Update your security intelligence and scan again. If it is still flagged, share the detection details with Aurora support so the specific release can be checked.
  3. Only after the exact file has been verified as a false positive, follow the guidance for that release. Protection history offers recovery actions for quarantined files.

If you choose an exclusion for a verified file, go to Virus & threat protection → Manage settings → Exclusions → Add or remove exclusions → Add an exclusion → File, then select that file. An exclusion stops Defender checking it in real time; keep the scope as narrow as possible.

Microsoft’s guides: Protection history ↗ · Scans and exclusions ↗

How do I resolve this? (Other antivirus)#

Open your antivirus’s detection history or quarantine screen and find the Aurora entry. Update the antivirus, record the detection details and ask Aurora support to check the file and release.

Once a false positive has been confirmed for that file, use your antivirus vendor’s official instructions for restoring or allowing it. Menu names vary between products. Choose a file-specific exception where available rather than excluding your Downloads folder or an entire drive.

You do not need to uninstall your antivirus or switch off protection for the whole computer.

Other notes#

  • A new release is a new file. A previous false-positive report does not automatically verify a later download.
  • Keep reports specific. Include the antivirus name, Aurora version, detection name and filename. Hide personal details in paths or logs before sharing them.
  • Vendor reviews help. A suspected false positive can be submitted to the antivirus vendor for analysis.

Still stuck? Visit Get support and we’ll help you work out the next step.

Join the Discord