PerfectlyCromulentLtd / PowerBuddy

A Windows tray icon/menu which allows you to switch between ALL your power plans.
52 stars 4 forks source link

Installer: NSIS installer "Start with Windows" functionality is detected as a Trojan by Windows Defender #12

Closed MetaFight closed 7 years ago

MetaFight commented 7 years ago

See comments:

The NSIS functionality probably writes to the registry "Run" key. I'm assuming this is frowned upon nowadays leading to Windows Defender reporting it as a Trojan.

I'll find a more modern/sensible way of doing this.

MetaFight commented 7 years ago

I can't seem to reproduce this. I'm hoping the person who raised the problem will come back and provide some more details.

ujell commented 7 years ago

Not sure if this helps, but Windows Defender identifies the trojan as this. I just downloaded latest release directly from Releases page, wasn't even able to run the .exe

MetaFight commented 7 years ago

@ujell thanks, that does help. I'm going to pull the last release until I can figure this out.

Cheers.

MetaFight commented 7 years ago

@ujell out of curiosity, could you share your OS version and Windows Defender "threat definition version"? I still can't seem to reproduce this issue.

ujell commented 7 years ago

@MetaFight Windows 10 Pro, Version 1703, Build 15063.138 If thread definition version is the same with Antivirus/Antispyware version then 1.241.890.0

MetaFight commented 7 years ago

@ujell Thanks.

I'm on a slightly more recent build of Windows 10 than your, however we have the same Windows Defender version.

I've scanned the 1.2.0.0 and 1.3.0.0 builds and they report as clean. I'm confused :|

Anyway, I just built 1.3.0.1 removing the "Start automatically with Windows" thing from the installer. Hopefully that will help.

Could you give it a try?

https://github.com/PerfectlyCromulentLtd/PowerBuddy/releases/tag/1.3.0.1

ujell commented 7 years ago

@MetaFight Seems like it works! Windows Defender didn't automatically warned me so I also manually scanned the file, no threads found.

MetaFight commented 7 years ago

@ujell thanks!

MetaFight commented 7 years ago

Resolved by 941a843