Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

potential security problem, virus found. #699

Closed
ccchan234 opened this issue Mar 19, 2024 · 10 comments
Closed

potential security problem, virus found. #699

ccchan234 opened this issue Mar 19, 2024 · 10 comments

Comments

@ccchan234
Copy link

no joke, virus found!

image

from the version 0.9.0, windows.

i did submit that to virustotal before i run,
but virustotal report nothing.

not sure if a new update in windows caught it.

@ccchan234
Copy link
Author

ps: i sent the install.exe to virustotal, yet it's the buzz.exe that windows caught.

@ashepp
Copy link

ashepp commented Mar 19, 2024

I'm also seeing this and was about to report. Is this a real issue or a false positive?

@ccchan234
Copy link
Author

I'm also seeing this and was about to report. Is this a real issue or a false positive?

i wish i can upload the buzz.exe to virustotal for better analysis.
however, my windows didn't allow me to touch the file anymore.

even i am on a chromebook, the installer is a .exe and i cant decompress it.

would be nice if someone could decompress the installer/install in sandboxie and send to virustotal for 50 scanners. thx

@chidiwilliams
Copy link
Owner

I believe this is a false positive from the installer not being code-signed. I'll leave this issue open for a few more days in case you find anything else, but I'll sign the 0.9.0 installer and give updates on #700.

@ccchan234
Copy link
Author

hi, today i just extracted the buzz.exe and submitted to virustotal again (last time i submitted the install.exe),

it doesn't look good...
image

thank you.

however, one could use buzz inside vm/sandbox instead.

@ashepp
Copy link

ashepp commented Mar 21, 2024

This morning I had an ~$8K paypal transactions fraudulently charged to my account. I have no idea if it's related to the virus that was identified in the executable but I'm flagging so that this is investigated properly. It's unclear from this thread whether there's an issue or not.

@chidiwilliams
Copy link
Owner

This morning I had an ~$8K paypal transactions fraudulently charged to my account. I have no idea if it's related to the virus that was identified in the executable but I'm flagging so that this is investigated properly. It's unclear from this thread whether there's an issue or not.

Oh, no. I'm sorry to hear that. I took down the 0.9.0 exe file from the Releases page yesterday just to be safe. I haven't found anything substantial yet but I'll continue to investigate. Please let me know if there's anything else I can do to help.

@chidiwilliams
Copy link
Owner

Created at discussion at #702

@ccchan234
Copy link
Author

This morning I had an ~$8K paypal transactions fraudulently charged to my account. I have no idea if it's related to the virus that was identified in the executable but I'm flagging so that this is investigated properly. It's unclear from this thread whether there's an issue or not.

are you sure?

would be nice if i could get a screen shot /w the private info cropped out.

thanks

@chidiwilliams
Copy link
Owner

The 0.9.0 signed exe has been updated on the Releases page. Pls let me know if you see the Windows warning again. Will close this issue for now since there was no follow-up from @ashepp.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants