If Windows says Tendvane is a trojan: it is a false alarm, and here is what we are doing about it
Update, 4 September 2026. Three days on, here is where things stand. On VirusTotal the 0.7.001 installer is now flagged by 3 of roughly 70 engines, down from 16 when this started, and Microsoft's own engine there reports it clean. On real PCs, however, Windows Defender is still removing the download, now usually under a new name, Trojan:Win32/Ulthar.A!ml, alongside the earlier Trojan:Win32/Wacatac. Defender on your PC also asks Microsoft's cloud service for a machine-learning verdict, and that service has not yet cleared the file. Our false-positive report is with Microsoft's analysts, and we will update this post the moment it clears. Everything below still applies.
If you downloaded Tendvane recently and Windows told you it had found a trojan - typically Trojan:Win32/Wacatac or Trojan:Win32/Ulthar - and then removed the file, we owe you an explanation. The short version: it is a false alarm. Tendvane does not contain malware. But "trust us" is not a good enough answer to a security warning, so this post sets out what is happening, how you can check it yourself, and what we are doing to fix it.
What is happening
Microsoft Defender, and a handful of other scanners, are flagging the Tendvane download. Look closely at the detection name and you will see it ends in !ml. That suffix means the verdict came from a machine-learning model judging that the file looks suspicious - not from a match against a known piece of malware. On VirusTotal, which runs a file past roughly 70 antivirus engines, every engine that flags Tendvane is of this "looks suspicious" kind, and none of them names an actual malware family. The engines that work from signatures of real malware - Kaspersky, Bitdefender, ESET, Avast, Malwarebytes and others - report it clean.
Why a legitimate program gets caught
Tendvane is a small, new, free program that asks for administrator rights and then does exactly what a system utility does: it copies itself to Program Files, creates its shortcuts, schedules a maintenance task, reads Windows settings, checks whether remote-access software is installed, and can show you your own saved Wi-Fi password as a QR code. Each of those is a normal thing for a PC tool or its installer to do. Put them all in one program that is brand new, has almost no download history yet and is not code-signed, and a machine-learning model sees the same shape it has learned from malware. That is the whole story: it is a reputation problem, not a behaviour problem.
How to check for yourself
Please do not take our word for it. The current release is Tendvane 0.7.001, and its installer has this SHA-256 fingerprint:
04920ff5e308df96b1739242eb2f675fb49de86409e017d3ee429274d2a0add9
The full engine-by-engine report for that exact file is on VirusTotal (link below). If you want to check your own copy, open PowerShell in your Downloads folder and run Get-FileHash .\Tendvane-Setup.exe - the result should match the fingerprint above. Only ever download Tendvane from tendvane.com, never from a third-party download site, and if a fingerprint does not match, delete the file.
What we are doing about it
- Proper publisher details inside the program. Earlier builds shipped with no company or product name embedded in the file, which is itself a red flag to scanners. Version 0.7.001 fixes that, and that change alone took the VirusTotal count from 16 flagging engines down to 4, and to 3 as of 4 September.
- Reporting the false positive to Microsoft. The file has been submitted to Microsoft's analysts as a false positive. Once they confirm it, Defender stops flagging that release, usually within a few days.
- Scanning every release before it goes out. Each new version is now run past Windows Defender and VirusTotal automatically before it is published, so we see a problem like this before you do.
- Code-signing the app. This is the permanent fix. A signed program carries a verified publisher identity that scanners can trust, instead of having to guess from its behaviour. We are working towards it.
What you can do in the meantime
If Defender has already removed Tendvane, you have two honest options. The first is simply to wait a few days and download again once Microsoft has processed the report. If you are not comfortable overriding a security warning, that is the right choice, and we would rather you wait than second-guess your antivirus. The second, if your copy came from tendvane.com and you want to run it now, is to open Windows Security > Virus & threat protection > Protection history, find the Tendvane entry and choose Restore, then Allow on device. Please only do that for a file downloaded from this site.
We are sorry for the confusion and the wasted time. Tendvane exists to make PCs less stressful for people who are not technical, and a frightening warning on first launch is the opposite of that. We will update this post as Microsoft processes the report and as code signing lands.