Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Defender detects C:\Program Files\WezTerm\strip-ansi-escapes.exe as malware #5198

Closed
carterols opened this issue Mar 20, 2024 · 7 comments
Labels
bug Something isn't working

Comments

@carterols
Copy link

What Operating System(s) are you seeing this problem on?

Windows

Which Wayland compositor or X11 Window manager(s) are you using?

No response

WezTerm version

20240203-110809-5046fc22

Did you try the latest nightly build to see if the issue is better (or worse!) than your current version?

No, and I'll explain why below

Describe the bug

This is on a work computer and it is safer to just uninstall wezterm, so I did not update Wezterm.

Windows detects C:\Program Files\WezTerm\strip-ansi-escapes.exe as containing a Trojan virus.
image

To Reproduce

Download the executable and run windows defender on it... My company's Windows Defender might be configured differently, so you may or may not find a threat. This could be a false positive.

Configuration

no config

Expected Behavior

I didn't expect WezTerm to contain a Trojan Virus. This could be a false positive though

Logs

No response

Anything else?

No response

@carterols carterols added the bug Something isn't working label Mar 20, 2024
@valerian
Copy link

I have the same issue, on a regular default windows defender

@dbs
Copy link

dbs commented Apr 9, 2024

SentinelOne also considers strip-ansi-escapes a threat (using the Windows stable installer build as of five minutes ago):
image

What are you trying to do to us, Wez? :)

@NotYourAlejandro
Copy link

A check on VirusTotal shows a very concerning result: https://www.virustotal.com/gui/file/ac6b05ae682c120778791eb942895db8fe1e513787c718df6996a3895d82c1c3

@carterols
Copy link
Author

Is @wez the only contributor to this project? Can someone figure out if this was malicious or an accident? Kinda concerning...

@NotYourAlejandro
Copy link

Apparently this issue is a duplicate of #5074. The tag on that issue states it's fixed in the nightly build.

@wez
Copy link
Owner

wez commented Apr 11, 2024

Duplicate of #5074

@wez wez marked this as a duplicate of #5074 Apr 11, 2024
@wez wez closed this as completed Apr 11, 2024
Copy link
Contributor

I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. If you have found a problem that seems similar to this, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators May 12, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

5 participants