H
HASS.Agent4mo ago
stormy-gold

Windows Security flagging as trojan

Going to assume this is a false positive?
No description
35 Replies
unwilling-turquoise
unwilling-turquoise3mo ago
I got the same today
No description
DrR0x
DrR0x3mo ago
This is fixed in the latest beta, see #🚀・releases
sensitive-blue
sensitive-blue3mo ago
Installed latest beta and Windows Defender is still showing vulnerability.
No description
DrR0x
DrR0x3mo ago
@Amadeo
Amadeo
Amadeo3mo ago
How in the world Can you please see if you have "LibreHardwareMonitor.dll" in the same path as the .sys file mentioned by defender? LHM is not included starting with 2.2.0-beta1 and the installer explicitly removes those 2 files if they exist There should be no way it's still there and used by HASS.Agent/Satellite + could you please check version of satellite service? (Open the Satellite config UI and it's on the first page) I did tests on 2 vms and they were in fact removed...
DrR0x
DrR0x3mo ago
Hmm, maybe dangling old version?
ambitious-aqua
ambitious-aqua3mo ago
When I did the upgrade, LibreHardwareMomitor.dll didn't get removed automatically. I had to go and remove it myself. What's interesting is that to start the upgrade, I had to start HassAgent, which created the .sys file. This would have resulted in a detection for me when this issue first occurred but during the upgrade, no notification popped up. (I didn't add any exceptions in Defender.)
Amadeo
Amadeo3mo ago
to start the upgrade you had to start HASS.Agent? the installer should complain that you need to close it before installation
Amadeo
Amadeo3mo ago
@angelo_aaa & @Gvolten would you be so kind please to screenshot me the basic details of HASS.Agent.Satellite.Service.exe? something like this from explorer:https://b.chihi.ro/60QBin.png
ambitious-aqua
ambitious-aqua3mo ago
If you need help with the Czech translation, let me know.
No description
ambitious-aqua
ambitious-aqua3mo ago
Yes but I first used the program to switch the installation channel and initiate the upgrade. I didn't download the installer externally. Btw I am running on 2.2.0-beta2 according to the app
Amadeo
Amadeo3mo ago
kurwa language is compatible with chech 😄 BUT thank you very much for the screenshot as it tells me what the fault might be it says 02.03.2024 - I'll confirm it 100% but that looks like 2.1.1 timestamp which would mean the satellite upgrade went wrong somehow and wasn't fully upgraded
ambitious-aqua
ambitious-aqua3mo ago
And it says 2.1.0 in the properties
Amadeo
Amadeo3mo ago
i.e that would explain why Windows Defender is still (rightfully) complaining ffs I'll just add logic that installer stright of kills satellite before upgrade - this is not the first time that this kind of issue created other problems (issue of files not being updated because satellite service is still running or something) tank you for swift response ❤️
ambitious-aqua
ambitious-aqua3mo ago
No, thank you for working this out for us 😄 Just to be absolutely clear, Defender was detecting the .sys file as Trojan:Win32/Vigorf.A instead of VulnerableDriver:WinNT/Winring0.G. Now after the update (even though it may not have gone through completely), no detections are present.
sensitive-blue
sensitive-blue3mo ago
Sorry about the delay in responding. The only place the LibreHardwareMonitor.dll exists is the $RPG6A6I.zip file in my recycle bin. I am running 2.2.0-beta2. I can't see the Satellite version because of Windows Defender quarantining files. Here are the quarantine items.
No description
No description
No description
sensitive-blue
sensitive-blue3mo ago
No description
sensitive-blue
sensitive-blue3mo ago
I tried to reinstall 2.2.0-beta2. I checked the box to migrate settings. As soon as the Satellite Service was being installed, Widows Defender said that I was installing a virus.
Amadeo
Amadeo3mo ago
please tell Windows Defender to remove them (the .sys files) and then see if the Satellite Service is running migrate settings from the original hass.agent by LAB02 Research? note: from my testing, even when installing "clean" version of HASS.Agent without LHM, during the installation Windows Defender scans with what folder the installer is interacting with, finds .sys files of previous HASS.Agent version and complains about it this is confirmed by running the installer again after all LHM files have been removed by previous install Defender will not complain again (I just tested it on one of the VMs)
Amadeo
Amadeo3mo ago
mind you, if you'll do any tests, please use beta3 (some changes to the satellite installer to "double check" if the files are removed during first install) https://github.com/hass-agent/HASS.Agent/releases/tag/2.2.0-beta3
GitHub
Release 2.2.0-beta3 · hass-agent/HASS.Agent
BREAKING CHANGES STARTING WITH 2.2.0-beta1 As with all beta versions, please remember to backup your configuration. Automatic configuration backup is coming, at least I'm working on it :) Break...
ambitious-aqua
ambitious-aqua3mo ago
The upgrade seems to have worked now
No description
ambitious-aqua
ambitious-aqua3mo ago
What is still strange to me is that during the upgrade to beta-1, Defender did not report any malware. Though Defender is working. I also have the official LibreHardwareMonitor installed and that still detects. But it changed the malware type to VulnerableDriver:WinNT/Winring0.G
Amadeo
Amadeo3mo ago
the .sys files are created on the fly by the LibrehardwareMonitor.dll from what I understood (the .sys files were never "installed by the installer") I can only speculate that the service&agent were stopped so the .sys files were not there (they are removed by the exiting process) or Defender just didnt catch that - I did so much testing with this that it's starting to be a blur xd
ambitious-aqua
ambitious-aqua3mo ago
Yes, the .sys file only gets created when you run the service, that is the same with the original LibreHardwareMonitor. And yes, it is possible that I have disabled the satelite service after the first detection but it should have still detected the .sys file in the Client. Well. Whatever. It has worked for me without any detections since. But on a little different topic, I have to say that having the option to migrate from LAB02 Workstation Service in the installer could be confusing for new users. Maybe the installer could detect if the Workstation Service had been installed and only show the prompt once in that case. After a migration has been done, store a flag somewhere in the appdata and never even prompt for it again.
Amadeo
Amadeo3mo ago
hmm the detection might be a bit tricky still doable but tricky but storing the fact that user already migrated configuration and then skiping it could be a nice and quick win
sensitive-blue
sensitive-blue3mo ago
I was running version 2.1.1
Amadeo
Amadeo3mo ago
got ya (☞゚ヮ゚)☞ https://b.chihi.ro/ulmIA6.png
sensitive-blue
sensitive-blue3mo ago
I pulled down beta3 version, installed, and this time did not ask to migrate settings. No Windows Defender issues and everything is working correctly. Big thank you!!
quickest-silver
quickest-silver3mo ago
So, I got the same today, installing from Latest, not Beta. Should I go for reinstalling from Beta3 version as above, or manually remove the dll mentioned as the culprit, or, allow the "trojan" that Defender detects? 🤯
Amadeo
Amadeo3mo ago
Either way works If defender put it's m$ hands on it the installer might not be able to remove it since file will be locked
quickest-silver
quickest-silver3mo ago
Ahh, thanks! Sounds to me like beta is the best way to go then. I'll try that I think. Any recommendations whether to go for beta3 or 4? I went with beta3, as that was listed under "additional releases" and 4 was not (yet) 🙂 Thank you all above for figuring this out!
ambitious-aqua
ambitious-aqua2mo ago
@Amadeo So I'm bringing this up again because I have only just know noticed that according to the control panel program list, beta1 is still present on my PC even though I am using beta3. Could it be that the upgrade to beta2 failed to remove it from the list?
No description
Amadeo
Amadeo2mo ago
I'll take a look at it and try to replicate it Might take some time tho, looks like I've cought covid 🥲
ambitious-aqua
ambitious-aqua2mo ago
No worries, take as much time as you need and get well soon!

Did you find this page helpful?