abbodi1406 / KMS_VL_ALL_AIO

Smart Activation Script
GNU General Public License v3.0
8.48k stars 1.1k forks source link

Getting flagged by Windows Defender #6

Closed shironekomimi closed 3 years ago

shironekomimi commented 3 years ago

I have just tried to use the latest v41r and Windows Defender raised a flag. I remember that it didn't happen when I tried with an older version few months ago. To check that, I downloaded a few older ones and kept on checking. It seems till v40, everything is okay, Defender doesn't raise anything. But since v41, it's being flagged as virus or unwanted program.

kms-aio-v41r

shdf2 commented 3 years ago

Same problem here.

undercovernormie commented 3 years ago

It was flagged for me in Defender as well, and strangely after I whitelisted it, the file was missing and the .7z was seemingly corrupted ('unsupported method'). Yet I was still able to run the .cmd directly from the archive and activate my volume successfully.

Macleykun commented 3 years ago

It seems to work on version v41 (working withoud any detection) but v41f doesn't. So the issue happend in these changes (which fixes the Get geniune banner): https://github.com/abbodi1406/KMS_VL_ALL_AIO/compare/v0.41.0...v0.41.2

Futhermore, if only one of these 3 lines are commented out with rem. It will no longer be detected. It's only when all 3 are uncommented.

I hope this helps with the troubleshooting.

renesansz commented 3 years ago

So far I don't get this kind of issue, what I would advise is to only run the script on fresh installation and without getting the windows updates first.

Then immediately remove it from the system to avoid Microsoft from getting a sample of this scripts on their end .

ghost commented 3 years ago

Then immediately remove it from the system to avoid Microsoft from getting a sample of this scripts on their end .

Microsoft owns GitHub; they're the ones who are hosting this repository.

saeed205 commented 3 years ago

KMS_VL_ALL v42 https://www.virustotal.com/gui/file/a95d641dbfb49d32fd215c8bf839d849b876ac2dbcd937f2aa145bbf3a74a27d/detection

Macleykun commented 3 years ago

Issue can be closed. Don't get any warnings (just like saeed205 shows). @shironekomimi

abbodi1406 commented 3 years ago

It will be always false-positive :)