Why is WindowsTerminal.exe and conhost.exe triggering Trend Micro Antivirus? #1597

Closed
opened 2026-01-30 22:31:30 +00:00 by claunia · 2 comments
Owner

Originally created by @tdelany on GitHub (Jun 11, 2019).

What would WindowsTerminal.exe and conhost.exe be doing that would make our Trend Micro WFB antivirus think that they are trojans?

I cannot test the Windows Terminal because the program will launch for a few seconds and then disappear with Trend Micro reporting that WindowsTerminal.exe and conhost.exe are infected with troj.win32.gen.xxbm100ff005r0001 and the files are quarantined.

Since this is on a corporate network, I have no control over what the A/V software does. I have asked IT to whitelist both WindowsTerminal.exe and conhost.exe in the reported path (D:\Projects\terminal\src\cascadia\CascadiaPackage\bin\x64\Release\AppX) but Trend still jumps all over them when I try to run them.

I realize this is probably a little out-of-scope for this venue, but it would be great if someone could shed some light on why the A/V is getting so upset. I may just be out of luck for testing here.

2019-06-11 13_49_19-Window

Originally created by @tdelany on GitHub (Jun 11, 2019). What would WindowsTerminal.exe and conhost.exe be doing that would make our Trend Micro WFB antivirus think that they are trojans? I cannot test the Windows Terminal because the program will launch for a few seconds and then disappear with Trend Micro reporting that WindowsTerminal.exe and conhost.exe are infected with troj.win32.gen.xxbm100ff005r0001 and the files are quarantined. Since this is on a corporate network, I have no control over what the A/V software does. I have asked IT to whitelist both WindowsTerminal.exe and conhost.exe in the reported path (D:\Projects\terminal\src\cascadia\CascadiaPackage\bin\x64\Release\AppX) but Trend still jumps all over them when I try to run them. I realize this is probably a little out-of-scope for this venue, but it would be great if someone could shed some light on why the A/V is getting so upset. I may just be out of luck for testing here. ![2019-06-11 13_49_19-Window](https://user-images.githubusercontent.com/22082102/59294635-e42d7480-8c4f-11e9-98cd-620e3dc1320a.png)
claunia added the Needs-TriageNeeds-Tag-Fix labels 2026-01-30 22:31:30 +00:00
Author
Owner

@zadjii-msft commented on GitHub (Jun 11, 2019):

I don't think we're doing anything that should be triggering your antivirus. Hopefully your corporate network will push updated definitions to you soon, but I think this is totally out of our control.

This would probably be an issue to bring up with the issue tracker for your A/V provider - I doubt any of us on the Windows team have any experience with that A/V in particular.

@zadjii-msft commented on GitHub (Jun 11, 2019): I don't think we're doing anything that should be triggering your antivirus. Hopefully your corporate network will push updated definitions to you soon, but I think this is totally out of our control. This would probably be an issue to bring up with the issue tracker for your A/V provider - I doubt any of us on the Windows team have any experience with that A/V in particular.
Author
Owner

@tdelany commented on GitHub (Jun 11, 2019):

Kind of what I expected. I was hoping maybe you would say something like, "Well, it's probably because of [blah blah blah]" but I was not overly hopeful. I've not seen anyone else complaining about anything like this. Oh well. Unfortunately, I can't do anything about the $#@! A/V software (can't change settings or anything). I was just hoping you all knew about something that I didn't. Didn't really expect you all to be experts on our A/V and didn't really think it was your fault.

It would be nice if there was a place to just ask questions and discuss things like this without having to open an "issue". Thanks, and keep up the good work.

@tdelany commented on GitHub (Jun 11, 2019): Kind of what I expected. I was hoping maybe you would say something like, "Well, it's probably because of [blah blah blah]" but I was not overly hopeful. I've not seen anyone else complaining about anything like this. Oh well. Unfortunately, I can't do anything about the $#@! A/V software (can't change settings or anything). I was just hoping you all knew about something that I didn't. Didn't really expect you all to be experts on our A/V and didn't really think it was your fault. It would be nice if there was a place to just ask questions and discuss things like this without having to open an "issue". Thanks, and keep up the good work.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/terminal#1597