mirror of
https://github.com/1Remote/1Remote.git
synced 2026-04-25 13:36:03 +03:00
[GH-ISSUE #422] Virus detected (maybe false positive) #351
Labels
No labels
area-configuration
area-ct-app
area-ct-rdp
area-ct-remoteapp
area-ct-ssh
area-ct-vnc
area-launcher
area-list
area-tags
area-teamwork
bug
chore
dependencies
general-build/ci
general-performance
general-refactor
general-security
general-supportive
general-ux
meta-documentation
meta-enhancement
meta-enhancement
meta-feature
meta-help-wanted
meta-unknown-error
priority-hi
priority-low
pull-request
question
resolution-duplicate
resolution-invalid
resolution-wontfix
stale
task-put-off
task-still-considering
task-working-in-progress
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/1Remote#351
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Wikiphil on GitHub (May 24, 2023).
Original GitHub issue: https://github.com/1Remote/1Remote/issues/422
Originally assigned to: @VShawn on GitHub.
Describe the bug
1Remote.exe is catched by Trend Micro EDR or Microsoft Defender
To Reproduce
Unzip the nightly build and start from the folder.
Expected behavior
Just starting the
Screenshots
N/A
Desktop (please complete the following information):
@Wikiphil commented on GitHub (May 24, 2023):
Just to let you know, PRemoteM vers 0.7.2.8 doesn't have the same issue.
@majkinetor commented on GitHub (May 25, 2023):
Its not maybe false positive, it is false positive. Exe is created by the GitHub CI/CD and it never touches our machines.
@Wikiphil commented on GitHub (May 25, 2023):
When I start the EXE, it tries to access Explorer, may be that where the is catched.
@VShawn commented on GitHub (May 26, 2023):
It does not make sense that accessing explorer will be treated as a virus.
How should the program read configuration files from explorer in this case?
Note: 1Remote accesses explorer.exe directly only when the user needs to open Explorer. When the program starts, it only reads configuration and data from the file system.
@Wikiphil commented on GitHub (May 26, 2023):
Sorry, not a Virus, it's reported by EDR. And then DCS erased the 1Remote.exe file.
@majkinetor commented on GitHub (Jun 4, 2023):
Closing this since there is nothing we can do