Skip to content

Flagged as malware because files are improperly installed to %WinDir% #4136

@JW0914

Description

@JW0914

Before reporting your issue

  • I have confirmed that this issue does not happen when ExplorerPatcher is not installed
  • I do not have "register as shell extension" enabled
  • I have tried my best to check existing issues

Repro ExplorerPatcher versions

Relating to documentation here

Repro Windows Versions

Relating to documentation here

3rd party tweak software installed

Relating to documentation here

Describe the bug

Per this, several things are installed into %WinDir%, which is off liimits to all installers, except driver installers. This is likely why ExplorerPatcher is flagged as malware, because it's acting like malware by doing this.

There are several reasons why %WinDir% is off limits to developers' installers, one of which is any modification done to %WinDir% is seen as corruption to %WinDir% (excl. Registry hives, drivers, the etc directory) and will be undone upon running SFC (which is recommended to be regularly run). I cover this in more depth here.

Expected outcome

Software needs to be corrected to install in sane locations within any of the following:

  • %LocalAppData%
  • %AppData%
  • %ProgramData%
  • %ProgramFiles%
  • %ProgramFiles(x86)%

Actual outcome

Doing this should stop the program being flagged as malware once corrected and submitted for review to have it no longer flagged as malware

Additional info

No response

Crash Dumps

No response

Media

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    duplicateThis issue or pull request already exists

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions