Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

windows defender blocks qbittorrent - PUA and/or Trojan detection #14489

Closed
kabaid opened this issue Mar 4, 2021 · 137 comments
Closed

windows defender blocks qbittorrent - PUA and/or Trojan detection #14489

kabaid opened this issue Mar 4, 2021 · 137 comments
Labels
Not an issue User error, problem unrelated to qBittorrent, feature already implemented, etc OS: Windows Issues specific to Windows

Comments

@kabaid
Copy link

kabaid commented Mar 4, 2021

Please provide the following information

qBittorrent version and Operating System

4.3.3, Windows 10 20H2,

What is the problem

Windows Security / Virus & threat protection - blocks / removes existing install of qbittorrent and blocks reinstall as well.
Marks it as PUA (potentially unsafe application)
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=PUA%3aWin32%2fQBitTorrent&threatid=292801

image

What is the expected behavior

not to get blocked

Steps to reproduce

Try to install qbittorrent on a Windows 10 20H2

Extra info(if any)

updated with additional info from below & other sources
https://www.reddit.com/r/qBittorrent/comments/lwqjm9/qbitborrent_flagged_as_malware_by_microsoft/

also this may be connected to
#12047
, with defender's protection actually targeting this package which includes qbittorrent:
https://www.microsoft.com/en-us/p/qbitorrent/9nlcd0qxd3ss

@glassez glassez added the Invalid Issues that fail to comply with the contributing guidelines and/or issue template requirements label Mar 5, 2021
@glassez
Copy link
Member

glassez commented Mar 5, 2021

There is no enough/useful info in Issue description. Will be closed soon unless fixed.

@nienkevanunen
Copy link

Been having this issue since today too, and I'm on v4.2.5. Tried to start a torrent via magnet, and it gave me some error about not having a client for the magnet (don't really remember). Then I tried starting qBitTorrent manually and it just wouldn't respond. Restarted my PC and noticed my Windows Defender had given me some pop ups in the sidebar. I'm on Windows 10 Education version 20H2 build 19041.804.
image

@ELHugoCK
Copy link

ELHugoCK commented Mar 5, 2021

Hello, same issue right here, the problem starts today around 9am EST, I have the version qbittorrent_4.3.3_x64_setup, I am on Windows 10 pro, 64 bits. As a quicks troubleshooting I uninstalled, restart and install again the software, but the problem remain.

SS01

@FranciscoPombal
Copy link
Member

What the fuck, Microsoft.

https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=PUA:Win32/QBitTorrent!torrent&threatId=236113
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=PUA%3aWin32%2fQBitTorrent&threatid=292801

Summary

Windows Defender Antivirus detects and removes this threat.

Technical details are not available.

Reddit thread: https://www.reddit.com/r/qBittorrent/comments/lwqjm9/qbitborrent_flagged_as_malware_by_microsoft/

@FranciscoPombal FranciscoPombal added OS: Windows Issues specific to Windows and removed Invalid Issues that fail to comply with the contributing guidelines and/or issue template requirements labels Mar 5, 2021
@glassez
Copy link
Member

glassez commented Mar 6, 2021

It looks like another campaign against BitTorrent software. When I started typing "PUA:Win32" in the search engine, I noticed several occurrences related to different BitTorrent applications.

@athelas64
Copy link

App can be allowed in Windows Defender, but will not connect and appear offline despite being allowed in the firewall... It was working flawlessly before.

@sledgehammer999
Copy link
Member

oh come on! Microsoft is being a massive bag of dicks. From the reddit post it seems they even flag older versions.

I am a bit angry now. If I was a little bit less sane, I would make qbt detect if Windows Defender was running and open a messagebox urging the user to use another AV suite because MS is being a massive back of dicks, linking to the appropriate proof.

@xavier2k6
Copy link
Member

I wonder, does that false app of qBittorrent on the windows store have anything to do with this as well?!

@sledgehammer999
Copy link
Member

I wonder, does that false app of qBittorrent on the windows store have anything to do with this as well?!

Well they still have it on their store, so I assume they haven't flagged it at all yet.

@xavier2k6
Copy link
Member

xavier2k6 commented Mar 8, 2021

Not an issue for me on Microsoft Windows [Version 10.0.19042.844] (20H2) with latest definitions

EDIT: I downloaded 4.3.3 from fosshub & re-installed over my previous installation etc.

Screenshot 2021-03-08 125606

Screenshot 2021-03-08 125730

Screenshot 2021-03-08 125701

@athelas64
Copy link

For me, the qBittorrent is working now after being enabled in Windows Defender (which silently removed the app before).
However, I am using DEV version of Windows (21327.1000), so I guess it was a glitch.

@FranciscoPombal
Copy link
Member

Whether it happens to some people and not others is not really relevant, as it does not change the fact that Microsoft has registered qBittorrent as malware in their database... #14489 (comment)

@space-orca
Copy link

Has there been any word from Microsoft about why qBittorent was blacklisted? Seems ridiculous to ban open source software as a threat, when its code is publicly available

@athelas64
Copy link

Cannot comment on whether there is word from Microsoft, but Windows Defender keeps silently removing the software despite being explicitly allowed on the machine. This error in not reported on Windows Insiders Feedback Hub.
After allowing the quarantined software, qBittorrent works.... until the next restart.

@armaguedes
Copy link

Has anyone tried running the PortableApps version of qBT? I would assume the end result would be the same, but it may be worth checking. [I'm running qBT v4.3.3x64 without issue, but WinDef has taken a backseat as I'm running Bitdefender AV (free edition).]

@fsmith9999
Copy link

I had the same issue, where I was able to use utorrent as recently as yesterday. deleted and qbtorrent also blocked from installing.
However I did make a change in Windows Security (running Windows 10 Pro) to turn off the Check apps and files and the Potentially unwanted app blocking. This allowed be to install qbtorrent and run it. Don't know that I am going to stick with that long term, but at least it is a workaround for now.
Cheers.
image

@xavier2k6

This comment has been minimized.

@Chocobo1
Copy link
Member

In the news: https://torrentfreak.com/utorrent-continues-to-be-flagged-as-severe-threat-and-its-not-alone-210318/

@Seeker2
Copy link

Seeker2 commented Mar 23, 2021

This important enough to make it a pinned issue?

@glassez
Copy link
Member

glassez commented Mar 23, 2021

This important enough to make it a pinned issue?

How can we really fix it?

@xavier2k6

This comment has been minimized.

@rafi-d
Copy link

rafi-d commented Mar 23, 2021

This important enough to make it a pinned issue?

How can we really fix it?

Easy enough - just exclude the supposedly offending app in Win 10 Defender...

@jurgentreep
Copy link

I've excluded the file in Windows Defender but when I try to install it it leads to this: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3aWin32%2fTilevn.A&threatid=2147760578

@xavier2k6
Copy link
Member

Although I didn't get a trojan, have encountered the PUA windows defender intervention for the 1st time with 4.3.4

@dpetroff
Copy link

dpetroff commented Aug 5, 2021

Exlusion/whitelisting is not the answer. It's a workaround, and a bad one at that. I'm hoping dearly that some effort is put into solving this long term.

Abandon all hope. The contributors to this project have made it abundantly clear for over a year now on similar tickets that in their view:

  1. signing binaries is just not a thing that is at all necessary or beneficial for FOSS projects and distributing hashes that may be verified manually by the paranoid is a sufficient level of provenance;
  2. this is all Microsoft's fault anyway so they don't need to address it.

And who could blame them? The latest v4.3.7 has installed on my machine today without any Windows Defender complaints, so their stubborn stance has been partially validated. Will this stick? Maybe. Was anything solved? Nah, other people are still getting the warnings. But did they have to follow best practices? Hell naw - if it works for linux power users, it surely works for all.

@curryking3
Copy link

4.3.7 just trying to update the program and melted down again because of windows defender. Tried to let it through defender and it wouldn't even let me access the downloads folder anymore and had to delete it through command prompt.

Really needs to be fixed otherwise it's just too much hassle to even update.

1 similar comment
@curryking3
Copy link

4.3.7 just trying to update the program and melted down again because of windows defender. Tried to let it through defender and it wouldn't even let me access the downloads folder anymore and had to delete it through command prompt.

Really needs to be fixed otherwise it's just too much hassle to even update.

@rover-debug
Copy link

Same issue occurred to me on latest 4.3.8. Even have windows defender app protection disabled

@paz
Copy link

paz commented Nov 2, 2021

Haven't had this issue before but 4.3.9 was blocked when I downloaded the update. Using MS edge and win 10 21h1 19043.1288
ApplicationFrameHost_2021-11-02_18-51-53

@AnthonyBe
Copy link

Yeah, I saw same with v4.3.9
It was detected as "PUA:Win32/QBitTorrent!torrent"
PUA stands for "Potentially Unwanted App"

@munrobasher
Copy link

Yeah, I saw same with v4.3.9 It was detected as "PUA:Win32/QBitTorrent!torrent" PUA stands for "Potentially Unwanted App"

Same here on two Windows 10 systems.

@rafi-d
Copy link

rafi-d commented Nov 4, 2021

Because M$ decided what torrent applications are potentially unwanted applications (PUA). They were blocking PUA in enterprise OS versions, currently they enabled it for everyone. https://www.windowslatest.com/2021/08/04/windows-10-will-automatically-block-potentially-unwanted-apps/

@duckimann
Copy link

Yeah, I saw same with v4.3.9 It was detected as "PUA:Win32/QBitTorrent!torrent" PUA stands for "Potentially Unwanted App"

Same here. Windows def has a lot of false positive :(

@yontekh
Copy link

yontekh commented Nov 6, 2021

This just happened to me aswell, I am on Windows 10 HOME edition
I used to always completely disable Windows Defender using registry edits and such, but was too lazy to do it this time around, but now I am sure I will never allow it to run again.

And I blame Microsoft. Because you cannot argue that this app is PUA more than any other program is "Potentially" unwanted.

@paz
Copy link

paz commented Nov 7, 2021

is there anything that matches up with how good win defender is for a free antivirus? or should I just disable the PUP thing and move on.. i heard eset or kaspersky are decent ..

@rafi-d
Copy link

rafi-d commented Nov 7, 2021

is there anything that matches up with how good win defender is for a free antivirus? or should I just disable the PUP thing and move on.. i heard eset or kaspersky are decent ..

The correct way is to exclude the false positives, not disable all PUP detections.
I am happy with Avast (+ Defender)

@icedterminal
Copy link

It's gotten worse with 4.3.9. Once launching the installer, Defender takes it away from you and puts it in quarantine.

PUP Detection Trojan on launch
pup trojan

@jamiew0w
Copy link

jamiew0w commented Jan 1, 2022

hello qbittorrent team,

i understand your guys stance, but I must ask has there been any pro-active communication with microsoft?

https://www.microsoft.com/en-us/wdsi/filesubmission

from what i can gleam, signing the releases should help substantially too. is this something you guys and girls are planning on doing?

i think it's important we get a yes/no answer. right now, this issue is left in limbo and swept under the rug (why is it closed?)

thanks in advance, and love qbittorrent!

@rafi-d
Copy link

rafi-d commented Jan 1, 2022

has there been any pro-active communication with microsoft?

Why don't you [re]submitted it? Anyone can.
I am guessing it is closed since there is nothing that can be done, code-wise...

@jamiew0w
Copy link

jamiew0w commented Jan 1, 2022

has there been any pro-active communication with microsoft?

Why don't you [re]submitted it? Anyone can. I am guessing it is closed since there is nothing that can be done, code-wise...

It needs to be submitted as a developer and impersonating qbittorrent maintainers isn't going to help.

@rafi-d
Copy link

rafi-d commented Jan 1, 2022

has there been any pro-active communication with microsoft?

Why don't you [re]submitted it? Anyone can. I am guessing it is closed since there is nothing that can be done, code-wise...

It needs to be submitted as a developer and impersonating qbittorrent maintainers isn't going to help.

Not if you enter under "Home Customer"

@jamiew0w
Copy link

jamiew0w commented Jan 1, 2022

has there been any pro-active communication with microsoft?

Why don't you [re]submitted it? Anyone can. I am guessing it is closed since there is nothing that can be done, code-wise...

It needs to be submitted as a developer and impersonating qbittorrent maintainers isn't going to help.

Not if you enter under "Home Customer"

@rafi-d , please stop trying to derail this issue, this isn't a forum. It needs maintainer clarification.

@duckimann
Copy link

Correct me if i'm wrong: I remembered they said somewhere that they will not deal with this PUA thing anymore, that's MS problem.

@rinick
Copy link

rinick commented Aug 17, 2022

install avira or any other anti virus software should solve the problem.

@jpegxguy
Copy link

jpegxguy commented Nov 6, 2022

You can disable Potentially Unwanted Apps protection in Defender Settings. You guys could try that if and only if the explicit exclusion of the .exe doesn't work

@jpeg115
Copy link

jpeg115 commented Nov 14, 2022

Kaspersky is also blocking it now....

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Not an issue User error, problem unrelated to qBittorrent, feature already implemented, etc OS: Windows Issues specific to Windows
Projects
None yet
Development

No branches or pull requests