i2pd icon indicating copy to clipboard operation
i2pd copied to clipboard

Windows Defender keeps uninstalling I2Pd saying it is Trojan

Open absolutep opened this issue 7 months ago • 5 comments

Windows 10 Defender keeps uninstalling I2Pd saying it is a Trojan.

After every restart of the computer this happens.

I have paid antivirus software and it does not mention anything like this ever, even after I forcefully scanned whole I2Pd.

Why does this happen? Any workaround or solution to this?

absolutep avatar May 05 '25 12:05 absolutep

Any workaround or solution to this?

Yes, here: https://www.microsoft.com/en-us/wdsi/filesubmission/?persona=HomeUser

Vort avatar May 05 '25 12:05 Vort

Any workaround or solution to this?

Yes, here: https://www.microsoft.com/en-us/wdsi/filesubmission/?persona=HomeUser

will try this and check

absolutep avatar May 06 '25 07:05 absolutep

nothing happened windows defender continues to mark it severe security threat and I keep on allowing it on the device.

absolutep avatar May 29 '25 07:05 absolutep

Сегодня Windows Defender (Windows 10) ругается на 2.57, Trojan:Script/Ulthar.A!ml. На предыдущие 2 релиза сегодняшний Defender не ругается, зато Firefox необоснованно подозревает наличие зловреда в i2pd_2.56.0_win64_mingw.zip и i2pd_2.55.0_win64_mingw.zip.

LLE8 avatar Jun 06 '25 08:06 LLE8

А у меня 11 ый ругается на собранный на месте из исходников.

orignal avatar Jun 13 '25 19:06 orignal

back to v2.55

zoqiao avatar Jun 24 '25 03:06 zoqiao

This error still persists as of August 2025. I have to keep installing I2Pd repeatedly every week, that is the only solution that works.

absolutep avatar Aug 06 '25 04:08 absolutep

Add to exceptions

orignal avatar Aug 06 '25 11:08 orignal

Windows 10 Defender keeps uninstalling I2Pd saying it is a Trojan.

After every restart of the computer this happens.

I have paid antivirus software and it does not mention anything like this ever, even after I forcefully scanned whole I2Pd.

Why does this happen? Any workaround or solution to this?

spyware?

s-b-repo avatar Aug 11 '25 14:08 s-b-repo

spyware?

No, it's Microsoft's false positive. React this way even to a binary built locally from source. You can try yourself.

orignal avatar Aug 11 '25 17:08 orignal

Add to exceptions

AT THE MOMENT, THIS SEEMS TO WORK SO CLOSING IT.

absolutep avatar Aug 12 '25 05:08 absolutep