Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Service Wrapper WinSW.exe is reported in Microsoft Defender as Thread #1083

Open
seedwa opened this issue Apr 18, 2024 · 1 comment
Labels

Comments

@seedwa
Copy link

seedwa commented Apr 18, 2024

Summary
When Windows Defender scans the WinSW.exe it reports an security issue "PUABundler:Win32/CandyOpen".

Steps to reproduce

  1. Download WinSW.exe (any version report issues)
  2. Scan with Defender by right-click on executable and selecting Defender

Environment

  • WinSW version: any will report
  • WinSW package type: any will cause this issue
  • Windows version: 10 and 11
  • Wrapped executable and version: WinSW in Jenkinx Version 2.440.3 LTS also reports. Even the jenkins.msi reports the same issue due to the tagged WinSW binary

Possible Solution

Unkown

@seedwa seedwa added the bug label Apr 18, 2024
@daniel-beck
Copy link
Contributor

daniel-beck commented Apr 18, 2024

@seedwa Do you have any reason to believe this is a true positive finding?

https://en.wikipedia.org/wiki/OpenCandy

OpenCandy was an adware module and a potentially unwanted program classified as malware by many anti-virus vendors. … After massive criticism of the software occurred, it was eventually discontinued in August of 2016.

This looks very wrong and should be reported as such to Microsoft.

From them, it doesn't appear to be a different, recent finding either.

Microsoft doesn't have any details on PUABundler:Win32/CandyOpen unfortunately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants