-
-
Notifications
You must be signed in to change notification settings - Fork 385
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Windows Security flags v3.6.1-3 as a threat #619
Comments
Thank you for opening your first issue in this project! Engagement like this is essential for open source projects! 🤗 |
me too! on Windows 10 |
Installer was created by GitHub Actions and I had tested in Windows 10. this is very surprising. Could it be a false alarm? I will rollback the release to investigate it further. |
I tried on Windows 11 and initially I got the same error. Then I updated Windows and security flag cleared. Can you retry after updating your Windows? |
Thanks for looking into it @mbektas , I'd be happy to try again, but could you please just confirm what version of Windows you have now, so I could verify that I'm up-to-date before I do so? (the one I had the issue on was |
I get the same on windows 10 KB5023696 with 1.385.471.0 definitions which is the most up to date it will offer me Edit: got the definition number wrong |
Sorry to say that I'm still getting the same "Threat blocked" with the latest update I have access to, which is Here are the full threat details from this run (almost identical to those from last time): Windows Security outputDetected: Trojan:Win32/Casdet!rfn Status: Removed A threat or app was removed from this device. Please let me know if I can help in any other way. Thanks |
I tried again in Win 11 with |
@MaxPelly are you getting this error for |
3.6.1-3, cant check with an earlier version now as IT is still "checking" its a fasle positive |
VirusTotal has zero detections (including Microsoft) for it https://www.virustotal.com/gui/file/1926fbe2c288f940b35cce4e42424f1e9066feeecdcbe25812ee085ff8d1dcb3 but additionally to the definition based detections they also use behavioral, heuristic and cloud methods, I am suspecting this detection is coming from their cloud engine. There is this site to submit suspicious files and report false-positives https://www.microsoft.com/en-us/wdsi/filesubmission but the file is too big to upload... |
@yoniLavi @MaxPelly @masozzo could you test the newer version release candidate (v3.6.2-1) to see if it raises any security flags. |
No more problem, i have installed last version [release candidate] without virus detection. |
Hi @mbektas, Thank you very much, I installed Just curious - did you identify any specific issue there? Thanks, |
Thanks for testing. Main change is to upgrade to newer version of Electron. However, I am not sure if that upgrade has anything to do with the fix. It was just a false positive and the new binary is not causing an alert. @yoniLavi auto updating is only available for macOS at the moment. to get it working for Windows, we need to code-sign the binary. It is something waiting to be prioritized. By the way, code signing Windows installer might also fix these Defender alerts. |
I will release the new version after further testing. Let's keep this issue open until the release. |
This false positive problem is fixed with v3.6.2-1 release. |
Description
The installation of v3.6.1-3 on my Windows11 PC is being blocked by Windows Security, saying that it identified
Trojan:Wint32/Casdet!rfn
. I've pasted the full details below.Reproduce
I reproduced it twice by re-downloading from the same url.
Expected behavior
After seeing the issue, I've re-downloaded v3.6.1-2 and had no issue with that.
Context
Windows Security output
The text was updated successfully, but these errors were encountered: