[GH-ISSUE #781] netboot.xyz-efi.iso triggers windows defender [Trojan:Script/Conteban.A!ml] malware detection. #214

Closed
opened 2026-02-27 14:50:52 +03:00 by kerem · 4 comments
Owner

Originally created by @gtxaspec on GitHub (Nov 30, 2020).
Original GitHub issue: https://github.com/netbootxyz/netboot.xyz/issues/781

https://boot.netboot.xyz/ipxe/netboot.xyz-efi.iso

downloading this iso on windows 10, with windows defender enabled, triggers deletion due to Defender flagging it containing a trojan: Trojan:Script/Conteban.A!ml [Threat Blocked]

Originally created by @gtxaspec on GitHub (Nov 30, 2020). Original GitHub issue: https://github.com/netbootxyz/netboot.xyz/issues/781 https://boot.netboot.xyz/ipxe/netboot.xyz-efi.iso downloading this iso on windows 10, with windows defender enabled, triggers deletion due to Defender flagging it containing a trojan: Trojan:Script/Conteban.A!ml [Threat Blocked]
kerem closed this issue 2026-02-27 14:50:53 +03:00
Author
Owner

@antonym commented on GitHub (Nov 30, 2020):

Was unable to reproduce on Windows 10, Defender's latest build did not identify any issues with the ISO.

<!-- gh-comment-id:735534384 --> @antonym commented on GitHub (Nov 30, 2020): Was unable to reproduce on Windows 10, Defender's latest build did not identify any issues with the ISO.
Author
Owner

@dadatuputi commented on GitHub (Jun 13, 2021):

I just experienced this same issue, latest Windows 10 and latest ISO from git README.

<!-- gh-comment-id:860277312 --> @dadatuputi commented on GitHub (Jun 13, 2021): I just experienced this same issue, latest Windows 10 and latest ISO from git README.
Author
Owner

@gtxaspec commented on GitHub (Jun 13, 2021):

@antonym Just tried this again, like @dadatuputi did, and yes, it failed again, the same virus "detected"

Windows Defender Info:
Version: 1.341.677.0 Engine Version: 1.1.18200.4 Platform Version: 4.18.2105.5 Released: 6/13/2021 8:39:16 PM

<!-- gh-comment-id:860279548 --> @gtxaspec commented on GitHub (Jun 13, 2021): @antonym Just tried this again, like @dadatuputi did, and yes, it failed again, the same virus "detected" Windows Defender Info: `Version: 1.341.677.0 Engine Version: 1.1.18200.4 Platform Version: 4.18.2105.5 Released: 6/13/2021 8:39:16 PM`
Author
Owner

@antonym commented on GitHub (Jun 14, 2021):

I ran across this too this time when trying to download it as well. The last modified date was April 25th when it was uploaded from the CI for the 2.0.37 build, these images actually aren't used anymore since I switched to a combined hybrid legacy and efi ISO which is also using a different build method to generate the ISO. Downloading the hybrid ISO didn't trigger anything with defender (https://boot.netboot.xyz/ipxe/netboot.xyz.iso).

I'll clean out those old images since they aren't used or built anymore, more than likely it's just a false positive.

<!-- gh-comment-id:860293219 --> @antonym commented on GitHub (Jun 14, 2021): I ran across this too this time when trying to download it as well. The last modified date was April 25th when it was uploaded from the CI for the 2.0.37 build, these images actually aren't used anymore since I switched to a combined hybrid legacy and efi ISO which is also using a different build method to generate the ISO. Downloading the hybrid ISO didn't trigger anything with defender (https://boot.netboot.xyz/ipxe/netboot.xyz.iso). I'll clean out those old images since they aren't used or built anymore, more than likely it's just a false positive.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/netboot.xyz#214
No description provided.