Back to home
Download safety

Why did my antivirus flag Subnetlens?

The short answer: it is a false positive, and it affects most network scanning tools. This page explains exactly what happened, what Subnetlens really does, how to verify your copy yourself, and where our fix stands with each antivirus vendor.

What happened, in plain terms

Some antivirus products include a behaviour based shield that watches what running programs do, on top of the classic file signature scan. Network scanning tools exercise exactly the behaviours those shields are tuned to notice, because mapping a network on purpose looks similar, at the traffic level, to malware probing a network without permission. As a result, tools in this category get flagged from time to time. Well known scanners such as Advanced IP Scanner, Nmap, and Angry IP Scanner are affected in the same way, and it can happen even when the file itself is clean and digitally signed.

In July 2026 we observed the Avast and AVG behaviour shield ("Behavior Shield") quarantine Subnetlens on some machines, under these detection names:

IDP.Generic (installer) IDP.HELU.PSE81 (installed app)

These are false positives. Subnetlens is a legitimate, digitally signed network administration tool for IT professionals. Your scan data never leaves your machine. We reported both detections to the vendor straight away, and the current status of every vendor we track is listed below.

What Subnetlens does that heuristics react to

Subnetlens maps your own local network. During a scan it does what any network scanner must do:

  • Address table sweeps: it reads the network address table (ARP) that Windows already keeps, and sends short discovery pings across the subnet you asked it to scan.
  • Connection checks to your own devices: it briefly connects to common ports on the devices it finds, to tell you what services they run.
  • Listening for device announcements: it passively receives the mDNS and SSDP broadcasts that devices such as printers, TVs, and phones send out anyway.
  • Browsing shared folders and querying devices you point it at: SMB share browsing and optional SNMP queries, only when you use those features.

Every one of these is an intended, documented function of the product, and each overlaps with the behaviours that heuristic shields use to spot network reconnaissance. That overlap, not anything hidden in the app, is what triggers the flag. For contrast, here is what Subnetlens does not do:

  • It does not send your scan results, device inventory, credentials, or reports anywhere. Everything stays on your machine.
  • It has zero telemetry, by design. Its only outbound connections are the license check to license.subnetlens.com and a version check against our public GitHub releases page for updates.
  • It does not self replicate, inject into other processes, encrypt files, or install anything beyond a normal user application.

Verify your copy yourself

You do not have to take our word for any of this. Here is how to prove for yourself that a Subnetlens download is authentic and untampered:

  1. Check the digital signature. Right click the installer, choose Properties, open the Digital Signatures tab. It must show HELIOSOFT LTD with a valid signature and timestamp. Every Subnetlens release is signed through Microsoft Azure Trusted Signing, which requires verified company identity. An unsigned copy, or one signed by anyone else, is not from us: delete it.
  2. Check the SHA-256 checksum. In PowerShell, run: Get-FileHash .\Subnetlens-Setup-<version>.exe Compare the result with the checksum published on the download page (also shown under "Verify your download" on the home page). A match means your copy is byte for byte the file we built and signed.
  3. Download only from us. The official sources are subnetlens.com and dl.subnetlens.com/latest. If a copy from anywhere else fails either check above, do not run it.

For a wider second opinion: on 24 August 2026 VirusTotal reported 0 out of 53 on the 1.0.1 installer, with no security vendor flagging it. Behaviour shields judge programs while they run, which is why one can still object on a specific machine even when every file scanner passes the same file.

Where things stand with each vendor

We resolve false positives at the source, with each vendor, so the fix reaches every user of that product rather than one machine at a time. Current status:

VendorObservedStatus
Avast Behaviour shield flag on some machines (IDP.Generic, IDP.HELU.PSE81)
Developer file whitelisting submitted; whitelisting of our code signing certificate (covering all current and future signed builds) also requested.
AVG Same engine family as Avast
Covered by the same developer whitelisting program.
Avira Scanned the 1.0.1 installer on VirusTotal (24 August 2026): no detection. No flag reported to us so far.
Covered by the same developer whitelisting program.
Norton No flag reported to us so far
Covered by the same developer whitelisting program.
Bitdefender No detection. We repeated the exact workflow that triggered the Avast flag: it passed. No flag observed
Microsoft No Defender detection observed, on our own testing and on VirusTotal (24 August 2026) No prompt observed
SmartScreen earns reputation over time for the certificate a program is signed with, and ours has been building since our first signed release. Tested on 25 August 2026: the signed 1.0.1 installer downloaded and installed on a clean Windows 11 machine with SmartScreen switched on, and no warning appeared. Even so, SmartScreen can still show a caution prompt on a given machine when a build is new to it, because reputation is judged per file as well as per certificate. The prompt names the verified publisher, HELIOSOFT LTD, and choosing More info then Run anyway continues the install. We submit each signed release to Microsoft's developer file submission portal as part of our release checklist.

We will keep this table current as vendors process the submissions. If your antivirus product flags Subnetlens and it is not listed here, please tell us: a concrete report is exactly what a vendor's false positive team needs.

Our approach: fix it upstream, never weaken your protection

Your antivirus is doing its job, and we want it to keep doing its job. So our policy is simple: we take every false positive to the vendor and get it cleared at the source. We will not ask you to disable your antivirus, lower its sensitivity, or exclude whole folders from scanning to run our software. Subnetlens also never detects or behaves differently around antivirus products: what you see is what every machine gets.

If your antivirus has already quarantined Subnetlens and you need it back before the vendor processes our report, a narrowly scoped exception is a reasonable temporary measure: restore the file from quarantine, verify its digital signature (step 1 above), and if your product keeps re flagging it, add an exception for the single signed executable only, at %LOCALAPPDATA%\Programs\Subnetlens\Subnetlens.exe. Never exclude a whole folder, and remove the exception once your antivirus stops flagging the app: it is a bridge until the vendor's fix lands, not a permanent setting.

Independent context on false positives

False positives are a routine, industry wide phenomenon, not something unique to us or to any one antivirus vendor. AV-Comparatives, an independent testing organisation, runs regular false alarm tests across the industry and maintains a practical guide on how false positives happen and where each vendor accepts reports: Dealing with False Positives: Reporting Issues to Antivirus Vendors. It is the same directory we use for our own submissions.

Seen a flag we should know about?

Email support@subnetlens.com with the name of your antivirus product, the detection name it shows, and which file it flagged (the installer or Subnetlens.exe). We take every report to the vendor, and we will reply to you with what we did about it.

Signed installer, published checksums, zero telemetry. Verify everything yourself.

Download Free