OpenLogi.exe blocked but shouldn't be flagged as a dangerous file

Hi,

I'm using OpenLogi, an open-source software allowing personnalisation of Logitech products without the hassle of their official app.
The full project is stored in GitHub:

AprilNEA/OpenLogi: ⚡️A native, local-first alternative to Logitech Options+, written in Rust 🦀 — remap buttons, DPI, and SmartShift over HID++. No account, no telemetry.

The official app from Logitech uses more RAM than needed, is unnecessarily big, and requests an account to personnalise products, hence why OpenLogi exists and become more and more popular.

While updating the software today, I noticed FS Protection (version 26.9 beta 3) flagged the executable file as a dangerous file and did move it to quarantine.
I want to report this as I believe this is a false positive and could be tweaked.

Best regards,

Melvin

Answers

  • Ukko
    Ukko Posts: 4,100 Superuser

    Hello,

    They usually recommend using this webpage for submission: https://www.f-secure.com/en/support/submit-a-sample

    There used to be a feature for sending files directly from quarantine (or so), but it was likely dropped at some point and never brought back (as for yet).

    What is detection name, by the way? Is it something like: TR/W32.Malware or TR/W64.Evo;

    Or a more specific detection name?

    I mean, since it is recently updated (or even while updating itself) - it may be just too "fresh" and "unknown" for F-Secure Security Cloud or any engine in use. Therefore, detection can be even simply temporary, based on certain indicators and an insufficient reputation score. In other words, the detection might disappear on its own following a "re-analysis" in the backend.

    Thanks!