Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The “WinUtil.Ink” shortcut is detected as “Trojan:Script/Phonzy.B!ml” #2965

Closed
FoxyLoon opened this issue Oct 21, 2024 · 11 comments
Closed
Labels
bug Something isn't working

Comments

@FoxyLoon
Copy link

FoxyLoon commented Oct 21, 2024

Describe the bug

Today, Windows Defender said that the shortcut “WinUtil.Ink” was a trojan.

I've had this shortcut for a long time. To create the shortcut, I ran the tool from the “Launch Command - Stable Branch (Recommended)” on the homepage and then clicked the button to create the shortcut on the desktop.

To Reproduce

Steps to reproduce the behavior:
I haven't reproduced the bug. In fact, I haven't even opened the tool for a long time.

I suppose the closest thing to getting the same result is:

  1. Run the command “irm ‘https://christitus.com/win’ | iex” from the home page;
  2. Go to the “Config” category;
  3. Create the shortcut;
  4. Wait for Windows Defender to detect it as a virus? Or check with Windows Defender? I don't know...

Expected behavior

Not being caught as a Trojan and just existing in the desktop

Screenshots

(Note: The language below is Portuguese)

Quarantined:
imagem

Immediately after quarantine, it was deleted or blocked:
imagem

Additional context

I just opened the computer on a normal day and today it decided that the shortcut is a trojan. I didn't do anything special, it just happened. I didn't even open the shortcut.

@FoxyLoon FoxyLoon added the bug Something isn't working label Oct 21, 2024
@Atlantis-23
Copy link

I can confirm I have just received the same automatic quarantine of the "WinUtil.lnk" shortcut detecting it as "Trojan:Script/Phonzy.B!ml" stating "This program is dangerous and executes commands from an attacker."

@nikola-godzilla
Copy link

I can confirm too.
After run the tool I've clicked the "create shortcut" button.
Result - win defender immediately detected it as trojan and move it to quarantine.

@ii-46
Copy link

ii-46 commented Oct 23, 2024

Last week i created short cut, but win defender didn't detected it as trojan.
It only detected after windows security update
image

image

@AndreyGasik
Copy link

If you will be use defender, you will never can use powershell scripts without signature. Just switch off realtime defend if you want use normal software. Defender is your boss now, he say what you can use what not.

@FatBastard0
Copy link

I can't have the same issue with Bitdefander. So what I do is I go in turn bit defender off when I'm running the application script whatever

@FoxyLoon
Copy link
Author

FoxyLoon commented Oct 24, 2024

@FatBastard0

I can't have the same issue with Bitdefander. So what I do is I go in turn bit defender off when I'm running the application script whatever

This is not about BitDefender, but about Windows Defender. And yes, you could do the same thing with Windows Defender without any problem, but that's not the point or problem in question

@xpl01ter
Copy link

I can confirm too, but with a different type of threat (Map/DownLink-D). When i try to run the command, the powershell window closes itself almost instantaneously. I only have time to create the shortcut.

image

@AndreyGasik
Copy link

and what? This tread for calculating people who cant stop his antivirus. Need denied that people use freeware soft.

@ChrisTitusTech
Copy link
Owner

I'll remove the shortcut creation and that will fix this flag.

@ChrisTitusTech
Copy link
Owner

Fixed in latest commit, will go live at the next release.

@NotYourAverageGamer
Copy link

I have created a discussion with a step-by-step tutorial on adding the Winutil shortcut manually, in a way that replicates the previous (now removed) shortcut.
See: #3127

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

9 participants