henrypp / simplewall

Simple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.
GNU General Public License v3.0
6.27k stars 487 forks source link

[Bug] Microsoft Defender quarantining autoinstaller and installer from website #1563

Closed treydun closed 1 year ago

treydun commented 1 year ago

Checklist

App version

3.7.2

Windows version

Windows 10

Steps to reproduce

On startup, receive notice about update from 3.7.1 to 3.7.2 Click install When downloaded click OK Microsoft Defender Quarantines

Go to henrypp.org/product/simplewall Click simplewall-3.7.2-setup.exe When finished downloading Microsoft Defender Quarantines

The portable package does not have the same issue. Scans fine with Defender

Expected behavior

No response

Actual behavior

Application is prevented from installing Autoupdate

Installer from site

Logs

Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Phonzy.B!ml&threatid=2147772967&enterprise=0 Name: Trojan:Script/Phonzy.B!ml Severity: Severe Category: Trojan Path: file:_C:\Program Files\simplewall\cache\update-simplewall-tefpuvv.exe Detection Origin: Local machine Detection Type: FastPath Detection Source: Real-Time Protection User: MyPC\Trey Process Name: C:\Program Files\simplewall\simplewall.exe Security intelligence Version: AV: 1.397.1450.0, AS: 1.397.1450.0, NIS: 1.397.1450.0 Engine Version: AM: 1.1.23080.2005, NIS: 1.1.23080.2005

henrypp commented 1 year ago

u blind or what?

treydun commented 1 year ago

I am very sorry Henry.

I really appreciate your software. It is excellent.

I now realize when I click search on bug reports it automatically adds the "is open" filter to my search box. So searching does not show the 15 reports filed before me. I did look.

I understand why you are frustrated with the situation.

Perhaps leaving just one "false positive" report open in your github "issues" would help with the wasting your time. You could open one yourself just letting people know the current situation.

Thank you for your time and effort. Again, best firewall program of all time.