Forum Discussion

Doant's avatar
Doant
Copper Contributor
Dec 09, 2025

System Center Configuration Manager : Trojan QGIS software false detection ?

Hi,

I’m not sure where to report or ask about this alert, so I’m posting here.

I use SCCM to deploy the software QGIS (an open-source GIS application) to users’ computers using .msi installers.

Recently, SCCM removed my installer and reported the following alert:


System Center Endpoint Protection a détecté un programme malveillant sur un ou plusieurs ordinateurs de votre organisation

Nom de la collection : _Tous les serveurs

Nom du programme malveillant : Trojan:Win64/ScarletFlash.ASA!MTB Nombre d'infections : 1 Heure de la dernière détection (heure UTC) : 03/12/2025 02:14:24

Voici les infections de ce programme malveillant :

Nom de l'ordinateur : xxx.xxxxxxx.xxxx Domaine : xxxx Heure de détection (heure UTC) : 03/12/2025 02:14:24 Chemin d'accès au fichier du programme malveillant : containerfile:_E:\Sources_Packages\QGIS\3.40.10\QGIS-OSGeo4W-3.40.10-1.msi;containerfile:_E:\Sources_Packages\QGIS\3.40.12-1\QGIS-OSGeo4W-3.40.12-1.msi;file:_E:\Sources_Packages\QGIS\3.40.10\QGIS-OSGeo4W-3.40.10-1.msi->application.cab->filD90E2F766C2B1014B0D199BDDDF46963;file:_E:\Sources_Packages\QGIS\3.40.12-1\QGIS-OSGeo4W-3.40.12-1.msi->application.cab->fil338C30DA73AC1014AF5482D1DA910BA5

Action de correction : Aucune action

État des actions : Réussi

Pour afficher d'autres informations sur l'activité des programmes malveillants dans votre organisation, exécutez le rapport des détails du programme malveillant.

I contacted QGIS security team that says it's probably a false detection.

How can I report this to Microsoft and request an update to their detection signatures to prevent this installer from being deleted?

Sincerly,

1 Reply

  • Hi ​ Doant​ 

    This looks like a Defender false positive, not an actual QGIS infection.

    The detection name Trojan:Win64/ScarletFlash.ASA!MTB indicates a machine-learning–based signature, and the alert is triggered inside the MSI CAB, not by executed code. This is common with large MSI installers like QGIS / OSGeo4W.

    SCCM scans source and content locations, so Defender can flag installers even before deployment.

    What to do:

    • Verify the MSI hash matches the official QGIS release.
    • Submit the file to Microsoft as a false positive via:
      https://www.microsoft.com/wdsi/filesubmission
      (Select Incorrect detection and include the detection name.)
    • Optionally add a temporary Defender exclusion for the source path or file hash until signatures are updated.

    Once Microsoft confirms it, updated Defender signatures will stop removing the installer.

     

Resources