The execution file seems not signed, it keeps being marked as virus by my antivirus. #1901

Closed
opened 2026-01-30 22:41:35 +00:00 by claunia · 2 comments
Owner

Originally created by @jimchen5209 on GitHub (Jun 22, 2019).

Environment

Windows build number: 18917
Windows Terminal version (if applicable): 0.2.1715.0

AntiVirus: Trend Micro PC-Cillin 2019 15.0.1231

Steps to reproduce

Open up Windows Terminal

Expected behavior

Nothing happened, just as normal terminal.

Actual behavior

conhost.exe was marked as HEU_FALCONTroj.Win32.Gen.XXBM100FF005R0001 and got removed by antivirus.
WindowsTerminal.exe and conhost.exe were stopped becase of unauthorized change.

Originally created by @jimchen5209 on GitHub (Jun 22, 2019). <!-- This bug tracker is monitored by Windows Terminal development team and other technical folks. **Important: When reporting BSODs or security issues, DO NOT attach memory dumps, logs, or traces to Github issues**. Instead, send dumps/traces to secure@microsoft.com, referencing this GitHub issue. Please use this form and describe your issue, concisely but precisely, with as much detail as possible. --> # Environment ```none Windows build number: 18917 Windows Terminal version (if applicable): 0.2.1715.0 AntiVirus: Trend Micro PC-Cillin 2019 15.0.1231 ``` # Steps to reproduce Open up Windows Terminal <!-- A description of how to trigger this bug. --> # Expected behavior Nothing happened, just as normal terminal. <!-- A description of what you're expecting, possibly containing screenshots or reference material. --> # Actual behavior conhost.exe was marked as `HEU_FALCONTroj.Win32.Gen.XXBM100FF005R0001` and got removed by antivirus. WindowsTerminal.exe and conhost.exe were stopped becase of unauthorized change. <!-- What's actually happening? -->
claunia added the Needs-TriageNeeds-Tag-Fix labels 2026-01-30 22:41:35 +00:00
Author
Owner

@DHowett-MSFT commented on GitHub (Jun 22, 2019):

Get a better AV. Our application bundle is code-signed

@DHowett-MSFT commented on GitHub (Jun 22, 2019): Get a better AV. Our application bundle is code-signed
Author
Owner

@DHowett-MSFT commented on GitHub (Jun 22, 2019):

I think #1204 is a duplicate of this!

@DHowett-MSFT commented on GitHub (Jun 22, 2019): I think #1204 is a duplicate of this!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/terminal#1901