[GH-ISSUE #422] Virus detected (maybe false positive) #351

Closed
opened 2026-02-26 11:57:53 +03:00 by kerem · 6 comments
Owner

Originally created by @Wikiphil on GitHub (May 24, 2023).
Original GitHub issue: https://github.com/1Remote/1Remote/issues/422

Originally assigned to: @VShawn on GitHub.

Describe the bug
1Remote.exe is catched by Trend Micro EDR or Microsoft Defender

To Reproduce
Unzip the nightly build and start from the folder.

Expected behavior
Just starting the

Screenshots
N/A

Desktop (please complete the following information):

  • OS: Windows 11 Pro
  • 1Remote-1.0.0.0-beta.03-net6-x64-nightly-20230523-fe2b87
Originally created by @Wikiphil on GitHub (May 24, 2023). Original GitHub issue: https://github.com/1Remote/1Remote/issues/422 Originally assigned to: @VShawn on GitHub. **Describe the bug** 1Remote.exe is catched by Trend Micro EDR or Microsoft Defender **To Reproduce** Unzip the nightly build and start from the folder. **Expected behavior** Just starting the **Screenshots** N/A **Desktop (please complete the following information):** - OS: Windows 11 Pro - 1Remote-1.0.0.0-beta.03-net6-x64-nightly-20230523-fe2b87
kerem 2026-02-26 11:57:53 +03:00
Author
Owner

@Wikiphil commented on GitHub (May 24, 2023):

Just to let you know, PRemoteM vers 0.7.2.8 doesn't have the same issue.

<!-- gh-comment-id:1562050652 --> @Wikiphil commented on GitHub (May 24, 2023): Just to let you know, PRemoteM vers 0.7.2.8 doesn't have the same issue.
Author
Owner

@majkinetor commented on GitHub (May 25, 2023):

Its not maybe false positive, it is false positive. Exe is created by the GitHub CI/CD and it never touches our machines.

<!-- gh-comment-id:1562318228 --> @majkinetor commented on GitHub (May 25, 2023): Its not maybe false positive, it is false positive. Exe is created by the GitHub CI/CD and it never touches our machines.
Author
Owner

@Wikiphil commented on GitHub (May 25, 2023):

When I start the EXE, it tries to access Explorer, may be that where the is catched.

<!-- gh-comment-id:1562722881 --> @Wikiphil commented on GitHub (May 25, 2023): When I start the EXE, it tries to access Explorer, may be that where the is catched.
Author
Owner

@VShawn commented on GitHub (May 26, 2023):

It does not make sense that accessing explorer will be treated as a virus.

How should the program read configuration files from explorer in this case?

Note: 1Remote accesses explorer.exe directly only when the user needs to open Explorer. When the program starts, it only reads configuration and data from the file system.

image

<!-- gh-comment-id:1563665971 --> @VShawn commented on GitHub (May 26, 2023): It does not make sense that accessing explorer will be treated as a virus. How should the program read configuration files from explorer in this case? Note: 1Remote accesses explorer.exe directly only when the user needs to open Explorer. When the program starts, it only reads configuration and data from the file system. ![image](https://github.com/1Remote/1Remote/assets/10143738/f3f09f9f-06eb-4588-a4de-a17a558e7650)
Author
Owner

@Wikiphil commented on GitHub (May 26, 2023):

Sorry, not a Virus, it's reported by EDR. And then DCS erased the 1Remote.exe file.

image

<!-- gh-comment-id:1565081443 --> @Wikiphil commented on GitHub (May 26, 2023): Sorry, not a Virus, it's reported by EDR. And then DCS erased the 1Remote.exe file. ![image](https://github.com/1Remote/1Remote/assets/84292480/3069afeb-45ca-4cc3-973f-d4cbee2f2327)
Author
Owner

@majkinetor commented on GitHub (Jun 4, 2023):

Closing this since there is nothing we can do

<!-- gh-comment-id:1575466947 --> @majkinetor commented on GitHub (Jun 4, 2023): Closing this since there is nothing we can do
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/1Remote#351
No description provided.