Bug Report - Trojan in conhost.exe compiled from SOURCE #2464

Closed
opened 2026-01-30 22:55:44 +00:00 by claunia · 4 comments
Owner

Originally created by @xpwn3rx on GitHub (Jul 1, 2019).

Environment

Windows build number: [run "ver" at a command prompt] Microsoft Windows [Version 10.0.18922.1000]
Windows Terminal version (if applicable): Thursday 6/27 build from SOURCE

Any other software?

Steps to reproduce

Compiled Thursday build from source.

Expected behavior

Working terminal.

Actual behavior

Get a popup about severe trojan from conhost.exe which was compiled from source.

image

Originally created by @xpwn3rx on GitHub (Jul 1, 2019). # Environment ```none Windows build number: [run "ver" at a command prompt] Microsoft Windows [Version 10.0.18922.1000] Windows Terminal version (if applicable): Thursday 6/27 build from SOURCE Any other software? ``` # Steps to reproduce Compiled Thursday build from source. # Expected behavior Working terminal. # Actual behavior Get a popup about severe trojan from conhost.exe which was compiled from source. ![image](https://user-images.githubusercontent.com/19785522/60451388-c749e880-9be0-11e9-8bd1-2b3417a06774.png)
claunia added the Needs-TriageNeeds-Tag-Fix labels 2026-01-30 22:55:44 +00:00
Author
Owner

@JushBJJ commented on GitHub (Jul 1, 2019):

Possible false positive.

On Tue, 2 Jul. 2019, 2:18 am xpwn3rx, notifications@github.com wrote:

Environment

Windows build number: [run "ver" at a command prompt] Microsoft Windows [Version 10.0.18922.1000]
Windows Terminal version (if applicable): Thursday 6/27 build from SOURCE

Any other software?

Steps to reproduce

Compiled Thursday build from source.
Expected behavior

Working terminal.
Actual behavior

Get a popup about severe trojan from conhost.exe which was compiled from
source.

[image: image]
https://user-images.githubusercontent.com/19785522/60451388-c749e880-9be0-11e9-8bd1-2b3417a06774.png


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
https://github.com/microsoft/terminal/issues/1760?email_source=notifications&email_token=AIZ5IGAMXWQMNKQJEHQNZZDP5IU4PA5CNFSM4H4T6ZH2YY3PNVWWK3TUL52HS4DFUVEXG43VMWVGG33NNVSW45C7NFSM4G4VZHKA,
or mute the thread
https://github.com/notifications/unsubscribe-auth/AIZ5IGBOFI5ZZWVO5C6UQM3P5IU4PANCNFSM4H4T6ZHQ
.

@JushBJJ commented on GitHub (Jul 1, 2019): Possible false positive. On Tue, 2 Jul. 2019, 2:18 am xpwn3rx, <notifications@github.com> wrote: > Environment > > Windows build number: [run "ver" at a command prompt] Microsoft Windows [Version 10.0.18922.1000] > Windows Terminal version (if applicable): Thursday 6/27 build from SOURCE > > Any other software? > > Steps to reproduce > > Compiled Thursday build from source. > Expected behavior > > Working terminal. > Actual behavior > > Get a popup about severe trojan from conhost.exe which was compiled from > source. > > [image: image] > <https://user-images.githubusercontent.com/19785522/60451388-c749e880-9be0-11e9-8bd1-2b3417a06774.png> > > — > You are receiving this because you are subscribed to this thread. > Reply to this email directly, view it on GitHub > <https://github.com/microsoft/terminal/issues/1760?email_source=notifications&email_token=AIZ5IGAMXWQMNKQJEHQNZZDP5IU4PA5CNFSM4H4T6ZH2YY3PNVWWK3TUL52HS4DFUVEXG43VMWVGG33NNVSW45C7NFSM4G4VZHKA>, > or mute the thread > <https://github.com/notifications/unsubscribe-auth/AIZ5IGBOFI5ZZWVO5C6UQM3P5IU4PANCNFSM4H4T6ZHQ> > . >
Author
Owner

@xpwn3rx commented on GitHub (Jul 1, 2019):

Likely, but it's either a bug or something that really needs to be addressed.

Edit: Just rebuilt from source, with the updates from today. No anti-virus rage this time.

@xpwn3rx commented on GitHub (Jul 1, 2019): Likely, but it's either a bug or something that really needs to be addressed. Edit: Just rebuilt from source, with the updates from today. No anti-virus rage this time.
Author
Owner

@DHowett-MSFT commented on GitHub (Jul 1, 2019):

This is literally the code for the console host executable that ships inside Windows. If your antivirus solution is tripping up on it, it is very likely that the bug is in your antivirus solution. If that happens to be Windows Defender, we can at least work with them to figure out why there’s a false positive.

@DHowett-MSFT commented on GitHub (Jul 1, 2019): This is literally the code for the console host executable that ships inside Windows. If your antivirus solution is tripping up on it, it is very likely that the bug is in your antivirus solution. If that happens to be Windows Defender, we can at least work with them to figure out why there’s a false positive.
Author
Owner

@xpwn3rx commented on GitHub (Jul 1, 2019):

This is literally the code for the console host executable that ships inside Windows. If your antivirus solution is tripping up on it, it is very likely that the bug is in your antivirus solution. If that happens to be Windows Defender, we can at least work with them to figure out why there’s a false positive.

That was from Windows Defender. The Defender trip also caused a follow up ticket from our Crowdstrike AV system.

@xpwn3rx commented on GitHub (Jul 1, 2019): > This is literally the code for the console host executable that ships inside Windows. If your antivirus solution is tripping up on it, it is very likely that the bug is in your antivirus solution. If that happens to be Windows Defender, we can at least work with them to figure out why there’s a false positive. That was from Windows Defender. The Defender trip also caused a follow up ticket from our Crowdstrike AV system.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/terminal#2464