Forum Discussion
System Center Configuration Manager : Trojan QGIS software false detection ?
Hi,
I’m not sure where to report or ask about this alert, so I’m posting here.
I use SCCM to deploy the software QGIS (an open-source GIS application) to users’ computers using .msi installers.
Recently, SCCM removed my installer and reported the following alert:
System Center Endpoint Protection a détecté un programme malveillant sur un ou plusieurs ordinateurs de votre organisation
Nom de la collection : _Tous les serveurs
Nom du programme malveillant : Trojan:Win64/ScarletFlash.ASA!MTB Nombre d'infections : 1 Heure de la dernière détection (heure UTC) : 03/12/2025 02:14:24
Voici les infections de ce programme malveillant :
Nom de l'ordinateur : xxx.xxxxxxx.xxxx Domaine : xxxx Heure de détection (heure UTC) : 03/12/2025 02:14:24 Chemin d'accès au fichier du programme malveillant : containerfile:_E:\Sources_Packages\QGIS\3.40.10\QGIS-OSGeo4W-3.40.10-1.msi;containerfile:_E:\Sources_Packages\QGIS\3.40.12-1\QGIS-OSGeo4W-3.40.12-1.msi;file:_E:\Sources_Packages\QGIS\3.40.10\QGIS-OSGeo4W-3.40.10-1.msi->application.cab->filD90E2F766C2B1014B0D199BDDDF46963;file:_E:\Sources_Packages\QGIS\3.40.12-1\QGIS-OSGeo4W-3.40.12-1.msi->application.cab->fil338C30DA73AC1014AF5482D1DA910BA5
Action de correction : Aucune action
État des actions : Réussi
Pour afficher d'autres informations sur l'activité des programmes malveillants dans votre organisation, exécutez le rapport des détails du programme malveillant.
I contacted QGIS security team that says it's probably a false detection.
How can I report this to Microsoft and request an update to their detection signatures to prevent this installer from being deleted?
Sincerly,
1 Reply
Hi Doant
This looks like a Defender false positive, not an actual QGIS infection.
The detection name Trojan:Win64/ScarletFlash.ASA!MTB indicates a machine-learning–based signature, and the alert is triggered inside the MSI CAB, not by executed code. This is common with large MSI installers like QGIS / OSGeo4W.
SCCM scans source and content locations, so Defender can flag installers even before deployment.
What to do:
- Verify the MSI hash matches the official QGIS release.
- Submit the file to Microsoft as a false positive via:
https://www.microsoft.com/wdsi/filesubmission
(Select Incorrect detection and include the detection name.) - Optionally add a temporary Defender exclusion for the source path or file hash until signatures are updated.
Once Microsoft confirms it, updated Defender signatures will stop removing the installer.