#Running official install command triggers Windows Defender - malicious batch file and registry keys

1 messages Β· Page 1 of 1 (latest)

delicate trailBOT
#

Thanks for the detailed report β€” this is serious, and you did the right thing by posting it.

What you saw (C:\ProgramData\system.bat + HKCU\...\Run\MicrosoftUpdate) is not expected OpenClaw installer behavior.

I checked the current https://openclaw.ai/install.ps1 flow, and the β€œ2nd run skipped disclaimer and ran doctor” part is actually consistent with upgrade logic (existing install β†’ run openclaw doctor --non-interactive), documented here:

But those malware IOCs are still concerning. To investigate properly, can you share:

  1. Exact URL you clicked from Google (copy link target, not just visible text)
  2. Exact command line you pasted into cmd.exe
  3. Output of openclaw --version
  4. Defender Protection History screenshot/export for that detection event

Recommended safety steps on that machine (now):

  • Keep Defender quarantine in place