MS Defender Detects Portable ccsetup629.zip as Trojan:Win32/Sonbokli.A!cl

Hi hazelnut:

If you’re referring to the warning shown below I captured while I was downloading ccsetup629.zip with my Firefox browser on 18-Oct-2024, I haven’t seen that “not commonly downloaded” warning for a few days now. I simply clicked the information icon (white letter “i” inside the blue dot) and chose to allow the download to proceed. A VirusTotal upload indicated the saved ccsetup629.zip was safe (1/66 detection rate) so I went ahead and unzipped it and updated the CCleaner64.exe excutable in my CCleaner Free Portable folder to v6.29.

The problem with the quarantine of ccsetup629.zip by MS Defender as Trojan:Win32/Sonbokli.A!cl is a new issue that started last night on 19-Oct-2024 during a scheduled MS Defender Quick Scan, so a recent change to the MS Defender virus definition sets is likely the culprit. I can download a fresh copy of ccsetup629.zip to my hard drive but it will be quarantined during the next Quick Scan, or when I right-click (or double-click) the saved ccsetup629.zip file to try to unzip the file.

It’s not a huge problem for me since I had already updated my portable CCleaner64.exe excutable to v6.29, but as I mentioned in my original post, I went ahead and filed a false positive detection report with Microsoft just in case other CCleaner Portable users run into the same problem unzipping ccsetup629.zip.


Dell Inspiron 15 5584 * 64-bit Win 10 Pro v22H2 build 19045.5011 * Firefox v131.0.3 * Microsoft Defender v4.18.24080.9-1.1.24080.9 * Malwarebytes Premium v5.1.11.139-1.0.5072 * Macrium Reflect Free v8.0.7783 * CCleaner Free Portable v6.29.11342