Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] All shims reported as malware #5910

Closed
joaoricarte opened this issue Apr 19, 2024 · 3 comments
Closed

[Bug] All shims reported as malware #5910

joaoricarte opened this issue Apr 19, 2024 · 3 comments
Labels

Comments

@joaoricarte
Copy link

joaoricarte commented Apr 19, 2024

Bug Report

Current Behavior

All shims created after 18/04/2024 are being reported as malware, specifically HEUR.AdvML.B by Symantec Endpoint Protection.
It only affects the files in the shims folder: %USERPROFILE%\scoop\shims\

Expected Behavior

Shims not being identified as malware.

Additional context/output

Symantec Endpoint Protection Version 14.3 RU8 build 10148 (14.3.10148.8000)
scoop version: 0.4.0
Screenshot 2024-04-19 104835
Screenshot 2024-04-19 104902

Possible Solution

System details

Windows version: 10 (22h2)

OS architecture: 64bit

PowerShell version: 7.4.2
Additional software:
Symantec Endpoint Protection version: 14.3 RU8 build 10148 (14.3.10148.8000)
scoop version: 0.4.0

Scoop Configuration

{
  "aria2-enabled": true,
  "last_update": "2024-04-19T10:26:29.6173068+01:00",
  "alias": {
    "wsa": "scoop-wsa",
    "updheld": "scoop-updheld"
  },
  "scoop_repo": "https://github.com/ScoopInstaller/Scoop",
  "scoop_branch": "master"
}
@chawyehsu
Copy link
Member

I believe it relates to #5730, the patched shim was reported a false positive

@joaoricarte
Copy link
Author

I believe it relates to #5730, the patched shim was reported a false positive

It seems related.

@goyalyashpal
Copy link

though this issue was filed earlier, but that one has more input over there.
so, if these issues are duplicates, then i'd suggest closing this one in favour of that one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants