Winget-AutoUpdate icon indicating copy to clipboard operation
Winget-AutoUpdate copied to clipboard

[Bug]: WAU-Configurator triggering anti-virus products (various)

Open Quitch opened this issue 1 year ago • 2 comments

The problem

Attempting to open the WAU-Configurator zip on Windows 11 with the latest definition files causes Windows Defender to block it, detecting it as Trojan:AndroidOS/ZkarletFlash.

VirusTotal shows that the following products also detect it as a trojan:

Aracit BitDefender Emsisoft Fortinet GData Google Ikarus Lionic MAX Rising SentinelOne (Static ML) Trellix (FireEye) VIPRE Zoner

I also replicated this on Windows 10 using the latest definition files.

What version of WAU has the issue?

1.19.1

What version of Windows are you using (ex. Windows 11 22H2)?

11 23H2

What version of winget are you using?

1.7.10661

Log information

No response

Additional information

No response

Quitch avatar Mar 19 '24 16:03 Quitch

Yep, same issue here.

AusomeOllie10 avatar Mar 20 '24 22:03 AusomeOllie10

This issue is stale because it has been open for 30 days with no activity.

github-actions[bot] avatar Apr 20 '24 02:04 github-actions[bot]

This issue was closed because it has been inactive for 14 days since being marked as stale.

github-actions[bot] avatar May 04 '24 02:05 github-actions[bot]

This issue persists. It is still being detected as a Trojan virus (A serious threat) and automatically removed by Microsoft Defender.

martijnw1986 avatar May 29 '24 07:05 martijnw1986

The problem is also with SentinelOne

dominikmeier99 avatar Nov 05 '24 19:11 dominikmeier99

This issue persists. It is still being detected as a Trojan virus (A serious threat) and automatically removed by Microsoft Defender.

What did you do as a solution? Exclusion with AV?

dominikmeier99 avatar Nov 05 '24 19:11 dominikmeier99

WAU-Configurator.zip doesn't exist anymore. Use the current MSI

KnifMelti avatar Nov 05 '24 19:11 KnifMelti

WAU-Configurator.zip doesn't exist anymore. Use the current MSI

I must have missed something :) Where do you get them from?

dominikmeier99 avatar Nov 05 '24 21:11 dominikmeier99

https://github.com/Romanitho/Winget-AutoUpdate/releases or: winget install Romanitho.Winget-AutoUpdate https://github.com/microsoft/winget-pkgs/tree/master/manifests/r/Romanitho/Winget-AutoUpdate/2.0.0

KnifMelti avatar Nov 05 '24 21:11 KnifMelti