pbatard / rufus

The Reliable USB Formatting Utility
https://rufus.ie
GNU General Public License v3.0
29.34k stars 2.6k forks source link

The 4.6 Beta triggered Avast and placed several svcHOST files in my USER/public directory #2583

Closed Michaelmyers1958 closed 1 month ago

Michaelmyers1958 commented 1 month ago

<!-- PLEASE READ THIS CAREFULLY:

  1. You MUST read and complete the steps from the checklist below, by placing an x into each [ ] (so that it shows '[x]', NOT '[ x]' or '[x ]'), BEFORE clicking on 'Submit new issue'.

  2. Failure to perform these steps, WHICH ARE ONLY THERE TO HELP YOU, will usually result in your issue being dismissed without notice.

  3. If you are reporting an issue when trying to run Rufus, or when trying to boot a media created by Rufus, you MUST provide a log, period. Please do not assume that the developer(s) will be able to "guess" the specifics of your environment, what image you used, what type of media you used it with or the many many other critical parameters that the log provides data for. To investigate an issue, a log from Rufus is ALWAYS required.

  4. If you still choose not to provide a log when reporting a problem, you agree that your issue will be closed without any further investigation.

YOU HAVE BEEN WARNED. -->

Checklist

Additionally (if applicable):

Issue description

After downloading the Beta I attempted to make an image. My antivirus went off and added the files in the title. I can't remember the exact wording of the error but it said something about a website. I am sorry but I have no logs because I had to reinstall my OS to get rid of that continuing error message.

Log

<FULL LOG>
Michaelmyers1958 commented 1 month ago

After downloading the Beta I attempted to make an image. My antivirus went off and added the files in the title. I can't remember the exact wording of the error but it said something about a website. I am sorry but I have no logs because I had to reinstall my OS to get rid of that continuing error message.

pbatard commented 1 month ago

https://github.com/pbatard/rufus/wiki/FAQ#user-content-Antivirus_X_reports_that_Rufus_contains_malware

Please report the false positive to your AV vendor, knowing that it can be FORMALLY VERIFIED that the Rufus executable that produces the alert can NOT contain anything that doesn't come from the public code at https://github.com/pbatard/rufus/tree/4d42b7a73a036a01bf3676852f9eb10fd9f1a16c, and therefore that, if your AV vendor does not want to resolve the issue as a false positive, they will have no problem to point where exactly in the code the malicious behaviour. If not, then they must declare the report as a false positive.

Also, for those who may think that the new false positives are triggered by the new setup.exe wrappers, it's very doubtful that this is the case when the wrappers themselves do not produce any false positive (and one would expect AV to at least have some level of consistency there).

So it's the usual bullshit of AV vendors seeing new perfectly legitimate code in Rufus that they don't happen to like.

pbatard commented 1 month ago

Also, since there are multiple malicious clones of our website, that attempt to peddle malware, please be sure to only download Rufus from https://rufus.ie or this repository.

If you downloaded it from a different website, you probably downloaded malware.

Michaelmyers1958 commented 1 month ago

I just wanted to leave a final comment. I downloaded the program directly from the Rufus update and opted in for the Beta, so I'm certain it wasn't malware. I have the free edition of Avast on my laptop, and yesterday I disabled my antivirus, and used the Rufus Beta, and the program functioned perfectly. Afterward, I utilized the USB drive created to install Windows 11 24H2 on my laptop. Everything is operating as expected, and I would like to express my gratitude for your response and this excellent program!

I am unsure if Avast will change anything about their virus definitions. In the future I will just disable Avast before using Rufus.