Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Portable v1.3.6 is getting flagged as Trojan:Win32/Zpevdo.B by Windows Defender #510

Closed
d-rez opened this issue Sep 10, 2020 · 4 comments
Closed

Comments

@d-rez
Copy link

d-rez commented Sep 10, 2020

Describe the problem
Portable v1.3.6 is getting flagged as Trojan:Win32/Zpevdo.B by Windows Defender right after downloading it through a browser

To Reproduce
Steps to reproduce the behavior:

  1. Go to https://electrumsv.io/download.html on Windows in any browser
  2. Download 1.3.6-portable.exe from the official page
  3. See file flagged and quarantined by Defender as https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3aWin32%2fZpevdo.B&threatid=2147729093

Expected behavior
Not being detected as malware

Screenshots
obraz

Desktop (please complete the following information):

  • OS: [e.g. iOS] Win10 v2004
  • Defender DB: v1.323.850.0
  • Browser [e.g. chrome, safari] Firefox
  • Version [e.g. 22] 80.0.1

Additional context
Downloaded the file in Windows Sandbox and checked its md5, it matches the expected hash (0977860035060E42CD73607E85D271035B904744CABEC394483CAE792A9BF8EA)

@rt121212121
Copy link
Contributor

Thank you for reporting this and for providing all the information, the malware name and defender db information are required for reporting so it's much appreciated. I've filed a false alarm report with Microsoft. The builds are generated on Azure CI automatically as are the hashes, so if the hashes match then these are the files that came from Amazon.

@rt121212121
Copy link
Contributor

I just checked Azure and redownloaded the hashes to make sure.

image

It matches. Also Microsoft seem to confirm the match you got, we'll see how it goes.

image

@rt121212121
Copy link
Contributor

image

@d-rez
Copy link
Author

d-rez commented Sep 11, 2020

Thanks! Works fine now :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants