MS Defender Detects Portable ccsetup629.zip as Trojan:Win32/Sonbokli.A!cl

Hi @CCleaner_Admin :

Has anyone from Piriform / Avast escalated this with Microsoft? Some sort of official status update would be appreciated.

Even if this turns out to be a false positive I would hope Piriform / Avast would do a better job of following up on this type of detection, especially after the CCleaner v5.33 / Trojan.Floxif fiasco in 2017 (see my 18-Sep-2027 topic Traces of Floxif Malware From Infected CCleaner v5.33 Installer).

Microsoft Defender removed yet another copy of ccstup629.zip from my C:\Users<myusername>\Downloads\ folder on 27-Oct-2024 while I was running my weekly data backup of C:\Users<myusername>\ to an external backup drive. I logged in to the Microsoft Security Intelligence Portal at https://www.microsoft.com/en-us/wdsi/filesubmission/ today and my 20-Oct-2024 false positive submission still has a Status of Submitted, so it doesn’t appear that anyone from Microsoft has even bothered to review my submission.

ASIDE: Someone marked this topic as Solved a few days ago so I’ve changed it back to Unsolved.

Windows Defender MSI False Positive FP Submission ccsetup629_zip as of 29 Oct 2024


Dell Inspiron 15 5584 * 64-bit Win 10 Pro v22H2 build 19045.5011 * Firefox v131.0.3 * Microsoft Defender v4.18.24080.9-1.1.24080.9 * Malwarebytes Premium v5.2.0.140-1.0.5073 * Macrium Reflect Free v8.0.7783 * CCleaner Free Portable v6.29.11342