View Issue Details

IDProjectCategoryView StatusLast Update
0000116WoR ImagerGeneralpublic2020-08-26 18:28
Reportern16ht Assigned ToMario  
PriorityhighSeverityblockReproducibilityalways
Status closedResolutionwon't fix 
Product Version2.0.0-alpha.3 
Summary0000116: Trojan positive
Description

On patched version of 2.0.0-alpha.3 two active antiviruses (Windows Defender and Kaspersky Cloud Security) marked one of proccess during windows installations as malicious (Trojan Generic). I think this needs fix or just make a notice to someone who downloading this version, do tempoarily disable antiviruses tools.

Additional Information

Last three lines in WoR.log:

2020-08-25 14:03:12.5693 [info] The BCD has been created!
2020-08-25 14:03:12.5872 [info] Setting testsigning and nointegritychecks on...
2020-08-25 14:03:12.5872 [debug] Launch bcdedit.exe with the following arguments: /store T:\EFI\Microsoft\Boot\BCD /set {default} testsigning on

TagsNo tags attached.

Activities

n16ht

n16ht

2020-08-25 12:12

reporter  

WoR.log (6,618 bytes)   
2020-08-25 13:28:16.4340 [info] Windows on Raspberry 64-bit (version 2.0.0-alpha.3)
2020-08-25 13:28:16.5053 [info] OS: Windows 10 Pro ver 2004 (19041.1.amd64fre.vb_release.191206-1406)
2020-08-25 13:28:16.8410 [info] Loaded language: en-US
2020-08-25 13:28:16.8974 [info] Checking for updates...
2020-08-25 13:28:17.4384 [info] No updates found.
2020-08-25 13:28:22.8488 [info] Loading disks...
2020-08-25 13:28:32.1313 [info] Disk 0 - WDC WD10SPZX-24Z10T0 - Fixed hard disk media - 931 GB
2020-08-25 13:28:32.1313 [info] Disk 1 - SDXC Card - Removable Media - 58 GB
2020-08-25 13:28:32.1313 [info] 2 disk(s) found
2020-08-25 13:28:35.4188 [info] Selected device: Raspberry Pi 4
2020-08-25 13:28:45.0998 [info] Selected disk: Disk 1 - SDXC Card - Removable Media - 58 GB
2020-08-25 13:29:01.1576 [info] Selected image (ISO): 19041.450.200805-1850.VB_RELEASE_SVC_PROD1_CLIENTPRO_OEMRET_A64FRE_SR-LATN-RS.ISO
2020-08-25 13:29:01.3132 [info] Mounting the ISO image...
2020-08-25 13:29:10.2691 [info] ISO file mounted on: G:\
2020-08-25 13:29:10.2755 [info] Found WIM image: G:\sources\install.wim
2020-08-25 13:29:10.6471 [info] Selected edition: Windows 10 Pro build 19041.450
2020-08-25 13:29:17.7769 [info] Drivers package source: server
2020-08-25 13:29:17.7879 [debug] Drivers package remote repository: worproject/RPi-Windows-Drivers
2020-08-25 13:29:17.9836 [debug] Getting the latest release from "worproject/RPi-Windows-Drivers"
2020-08-25 13:29:18.8195 [debug] Release name: "Version 0.2", ID: "29928144"
2020-08-25 13:29:18.8195 [debug] Getting the latest asset from release "29928144"
2020-08-25 13:29:18.8195 [debug] Asset name filter: "RPi4_Windows_ARM64"
2020-08-25 13:29:18.8195 [debug] Asset name: "RPi4_Windows_ARM64_Drivers_v0.2.zip", ID: "24123900"
2020-08-25 13:29:18.9141 [debug] Downloading asset "RPi4_Windows_ARM64_Drivers_v0.2.zip" with ID "24123900"
2020-08-25 13:29:20.8077 [debug] The selected asset is ZIP-archived. Extracting...
2020-08-25 13:29:21.0985 [debug] Cleaning up...
2020-08-25 13:29:21.0985 [debug] Updating the local asset ID...
2020-08-25 13:29:21.0995 [debug] Done!
2020-08-25 13:29:39.7217 [info] UEFI package source: server
2020-08-25 13:29:39.7367 [info] UEFI package remote repository: pftf/RPi4
2020-08-25 13:29:39.7485 [debug] Getting the latest release from "pftf/RPi4"
2020-08-25 13:29:39.9302 [debug] Release name: "v1.19", ID: "29673660"
2020-08-25 13:29:39.9302 [debug] Getting the latest asset from release "29673660"
2020-08-25 13:29:39.9302 [debug] Asset name: "RPi4_UEFI_Firmware_v1.19.zip", ID: "23895774"
2020-08-25 13:29:39.9302 [debug] Downloading asset "RPi4_UEFI_Firmware_v1.19.zip" with ID "23895774"
2020-08-25 13:29:41.9976 [debug] The selected asset is ZIP-archived. Extracting...
2020-08-25 13:29:42.0669 [debug] Cleaning up...
2020-08-25 13:29:42.0669 [debug] Updating the local asset ID...
2020-08-25 13:29:42.0689 [debug] Done!
2020-08-25 13:30:04.7277 [info] The installation process has started!
2020-08-25 13:30:04.7467 [info] Formatting the target device...
2020-08-25 13:30:04.7606 [debug] Launch diskpart.exe with the following commands: select disk 1 , clean , exit
2020-08-25 13:30:09.9597 [debug] diskpart.exe process output: 
Microsoft DiskPart version 10.0.19041.1

Copyright (C) Microsoft Corporation.
On computer: DESKTOP-4715TVM

DISKPART> 
Disk 1 is now the selected disk.

DISKPART> 
DiskPart succeeded in cleaning the disk.

DISKPART> 
Leaving DiskPart...

2020-08-25 13:30:13.4751 [info] The target device has been erased!
2020-08-25 13:30:13.4751 [info] Allocated partition letters:
2020-08-25 13:30:13.4931 [info] Windows partition: S
2020-08-25 13:30:13.4931 [info] Boot partition: T
2020-08-25 13:30:13.5091 [info] Creating the partitions...
2020-08-25 13:30:13.5091 [debug] Launch diskpart.exe with the following commands: select disk 1 , convert mbr , create partition primary size=128 , format fs=fat32 quick label=BOOT , assign letter=T , active , create partition primary , format fs=ntfs quick label=Windows , assign letter=S , exit
2020-08-25 13:30:23.7687 [debug] diskpart.exe process output: 
Microsoft DiskPart version 10.0.19041.1

Copyright (C) Microsoft Corporation.
On computer: DESKTOP-4715TVM

DISKPART> 
Disk 1 is now the selected disk.

DISKPART> 
DiskPart successfully converted the selected disk to MBR format.

DISKPART> 
DiskPart succeeded in creating the specified partition.

DISKPART> 

    0 percent completed
    0 percent completed
  100 percent completed


DiskPart successfully formatted the volume.

DISKPART> 
DiskPart successfully assigned the drive letter or mount point.

DISKPART> 
DiskPart marked the current partition as active.

DISKPART> 
DiskPart succeeded in creating the specified partition.

DISKPART> 

    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
    0 percent completed
  100 percent completed


DiskPart successfully formatted the volume.

DISKPART> 
DiskPart successfully assigned the drive letter or mount point.

DISKPART> 
Leaving DiskPart...

2020-08-25 13:30:23.7727 [info] The partitions have been created!
2020-08-25 13:30:23.7727 [info] Applying the WIM image to: S
2020-08-25 13:30:23.8116 [trace] Started Windows Imaging
2020-08-25 14:02:41.6208 [trace] Windows Imaging finished the task successfully!
2020-08-25 14:02:41.6956 [info] The image has been applied to: S
2020-08-25 14:02:41.6956 [info] Installing the drivers...
2020-08-25 14:03:04.3348 [info] The drivers have been installed!
2020-08-25 14:03:04.3348 [info] Installing the boot files on: T
2020-08-25 14:03:04.8455 [info] The boot files have been copied to: T
2020-08-25 14:03:04.8525 [info] Creating the BCD...
2020-08-25 14:03:04.8525 [debug] Launch bcdboot.exe with the following arguments: S:\Windows /s T: /f UEFI
2020-08-25 14:03:12.5693 [debug] bcdboot.exe process output: Boot files successfully created.

2020-08-25 14:03:12.5693 [info] The BCD has been created!
2020-08-25 14:03:12.5872 [info] Setting testsigning and nointegritychecks on...
2020-08-25 14:03:12.5872 [debug] Launch bcdedit.exe with the following arguments: /store T:\EFI\Microsoft\Boot\BCD /set {default} testsigning on
WoR.log (6,618 bytes)   
n16ht

n16ht

2020-08-25 15:11

reporter   ~0000182

It also locked my sd card with write protection :/

Mario

Mario

2020-08-25 17:56

administrator   ~0000183

Last edited: 2020-08-25 17:57

Archive: https://www.virustotal.com/gui/file/8b3042f6d7a5a44bcc4372cb784c2ab21fa3d6ec3d1f45cfc50a29457219daf1/detection (clean)
WoR.exe: https://www.virustotal.com/gui/file/6083da64dce36f12c817b086fd1a01c49e5875b14acd094f9270cf3ab5c69e2c/detection (the result returned by SecureAge APEX is false-positive.)

I have Windows Defender enabled and it didn't complain at all.

As for the write-protected SD card, WoR (and the tools used by it) can't intentionally damage it. If the card is too worn out, it will lock itself in an attempt to prevent data loss.

It may just be a superficial protection, which can be easily disabled with 2 commands in diskpart:
select disk X (where X is the disk number of your SD card)
attr disk clear readonly

n16ht

n16ht

2020-08-25 18:02

reporter   ~0000184

Well, i fixed sd card problem (some bug unrelated to this). My antivirus I think detects some proccess as malicious and keeps doing it, and then needed to add to exclusion list. Note that my settings are same to most users. I see this virustotal, just don't have answer why this is happening.

Mario

Mario

2020-08-25 18:54

administrator   ~0000185

Can you reproduce this issue on the non-patched version?

n16ht

n16ht

2020-08-25 19:00

reporter   ~0000186

Nothing happens on unpatched version. Everything works as it should.

Mario

Mario

2020-08-26 18:28

administrator   ~0000188

I think I know the root cause of the issue, but I won't do any updates to the patched version as it's not an official release.
The final v2.0.0 release shouldn't be affected by this.

Issue History

Date Modified Username Field Change
2020-08-25 12:12 n16ht New Issue
2020-08-25 12:12 n16ht File Added: WoR.log
2020-08-25 15:11 n16ht Note Added: 0000182
2020-08-25 17:56 Mario Note Added: 0000183
2020-08-25 17:57 Mario Note Edited: 0000183
2020-08-25 18:02 n16ht Note Added: 0000184
2020-08-25 18:54 Mario Note Added: 0000185
2020-08-25 19:00 n16ht Note Added: 0000186
2020-08-26 18:28 Mario Assigned To => Mario
2020-08-26 18:28 Mario Status new => closed
2020-08-26 18:28 Mario Resolution open => won't fix
2020-08-26 18:28 Mario Note Added: 0000188