in my case, I was running ClamAV from Linux,
and Avast was running from Windows in the system, and once after reboot in Windows booting phase.
So I think it's not a problem, because they don't exist in the same systems.
Scanning results from ClamAV.
First are from Windows main partition.
/run/media/user/0CD216BFD216ACC8/Program Files/Google/Chrome/Application/102.0.5005.63/elevation_service.exe: Win.Dropper.Sykipot-9950507-0 FOUND
/run/media/user/0CD216BFD216ACC8/Program Files/Google/Chrome/Application/102.0.5005.63/Installer/chrmstp.exe: Win.Dropper.Sykipot-9950505-0 FOUND
/run/media/user/0CD216BFD216ACC8/Program Files/Google/Chrome/Application/102.0.5005.63/Installer/setup.exe: Win.Dropper.Sykipot-9950505-0 FOUND
/run/media/user/0CD216BFD216ACC8/Program Files/Google/Chrome/Application/chrome.exe: Win.Dropper.Sykipot-9950506-0 FOUND
I've created for test purpose 32bit Wine Prefix on Linux, and I've installed the same browser, but I've downloaded installer again, separately.
Here are results from closed Wine environment.
/home/user/wine-prefixes/test-browser/drive_c/Program Files/Google/Chrome/Application/102.0.5005.63/elevation_service.exe: Win.Dropper.Sykipot-9950507-0 FOUND
/home/user/wine-prefixes/test-browser/drive_c/Program Files/Google/Chrome/Application/102.0.5005.63/Installer/chrmstp.exe: Win.Dropper.Sykipot-9950505-0 FOUND
/home/user/wine-prefixes/test-browser/drive_c/Program Files/Google/Chrome/Application/102.0.5005.63/Installer/setup.exe: Win.Dropper.Sykipot-9950505-0 FOUND
/home/user/wine-prefixes/test-browser/drive_c/Program Files/Google/Chrome/Application/chrome.exe: Win.Dropper.Sykipot-9950506-0 FOUND
/home/user/wine-prefixes/test-browser/drive_c/Program Files/Google/Update/Download/{8A69D345-D564-463C-AFF1-A69D9E530F96}/102.0.5005.63/102.0.5005.63_chrome_installer.exe: Win.Dropper.Sykipot-9950505-0 FOUND
/home/user/wine-prefixes/test-browser/drive_c/Program Files/Google/Update/Install/{7D6240B5-B336-45CA-91D9-8DA878DF6897}/102.0.5005.63_chrome_installer.exe: Win.Dropper.Sykipot-9950505-0 FOUND
That's weird, anyway. The same results. I can agree that they can be false positive.