Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows AV blocking opening zen.exe due to virus/trojan found in the executable. #37

Open
TrueHerobrine opened this issue Jul 6, 2024 · 66 comments
Assignees

Comments

@TrueHerobrine
Copy link

zen

@mauro-balades mauro-balades self-assigned this Jul 6, 2024
@mauro-balades
Copy link
Member

Screenshot_20240706_225017

virus detection websites dont detect anything so I dont know why is windows AV complaining...

@TrueHerobrine
Copy link
Author

I might try to whitelist the exe. I'll get back with an update.

@TrueHerobrine
Copy link
Author

Update: Just tried again without adding an exception and it works flawlessly. TLDR: Windows is weird.

@mauro-balades
Copy link
Member

mauro-balades commented Jul 6, 2024

Windows is weird. Thanks a lot for trying it out!

image

@TrueHerobrine
Copy link
Author

No worries! Found it on Reddit and was actually very impressed. I have my own browser but I'm not forking it off of anything, so it's cool to see an indie browser thriving like this!

@mauro-balades mauro-balades pinned this issue Jul 11, 2024
@DavidGreen63
Copy link

In the last 30 minutes, while I was accessing a site, using version 1.0.0-a.29 (64-bit), Windows Defender terminated the App and deleted the core executable.

@clembu
Copy link

clembu commented Aug 26, 2024

Same happened to me. Admittedly my Defender is very weird and Windows Security crashes when I try to open it, so I can't open the UI to add exclusions or inspect things that way, but a.28 works

@danmaxis
Copy link

It happened to me too, mine Zen was flagged by Kaspersky when I tried to import data from another browser.

@Meathelix1
Copy link

Windows 11
Version 10.0.22631 Build 22631

Zen was installed directly from the website. https://www.zen-browser.app/

Windows Defender Picked it up as soon as I opened Zen.exe

Trojan Name = "Wacatac.B!ml"

I dont want to be excluding something with that name, a quick google search will show you this is a popular one.

@Xavi-X333
Copy link

I have the same problem, first the core executable was deleted and then a can't download the installer :/

@DavidGreen63
Copy link

Maybe it is an issue that will fade once Zen gets a signature, but as it stands, its normal operations are being flagged as Malware/Trojan like. I think I'll look into Zen again once it gets a little less alpha or beta-ish.

@Meathelix1
Copy link

The Generic Version does not pick up as a Trojan. It's just the Optimized Version.

@HamzaConcepts
Copy link

Screenshot 2024-08-26 094935

Virustotal is also showing it as some trojan script. Are all of these just false positives?

@extropyst
Copy link

Check this information:
https://virustotal.readme.io/docs/false-positive

and try also analyzing the file in other places like:

https://internxt.com/virus-scanner

https://opentip.kaspersky.com/

image

@jakehower
Copy link

Getting blocked for me too.

@soulhax
Copy link

soulhax commented Aug 26, 2024

Exactly the same problem as others are having. Also the installer is detected as PUA:Win32/Packunwan.
Idk but I'm not satisfied with the answer "Windows is weird". I guess we're going to wait until this exe and thing are going to be signed and stuff. Peace.

ApplicationFrameHost_EKwNHXAcrb

@MatfenV1
Copy link

afbeelding
Same issue here, it worked just fine when I installed it on my desktop but my laptop refuses installing it.

@Abelkrijgtalles
Copy link

Abelkrijgtalles commented Aug 26, 2024

Same here (Windows 11 Pro 23h2)
image

@J-Cake
Copy link

J-Cake commented Aug 26, 2024

Just wanted to report that this is still happening. System: Windows 11 Pro 22H2 Build: 22621.3880

@MikeyA-yo
Copy link

I also get this same trojan script, this made me uninstall zen immediately

@Abelkrijgtalles
Copy link

Abelkrijgtalles commented Aug 26, 2024

Could this maybe have a connection to the new windows defender update? 1.0.0-a.29 was released 2 days ago, but this problem only started about 9 hours ago.

EDIT: The latest update I've installed (defender version 1.417.317.0), doesn't include anything about Trojan:Script/Wacatac.B!ml.

@alexmro
Copy link

alexmro commented Aug 26, 2024

Just tried to install the Zen browser on a Windows 10 and it blocks it claiming that there's a "PUA:Win32/Packunwan" virus

@DavidGreen63
Copy link

I am on Win 10 Pro, and after the core executable was annexed, I attempted to uninstall. The uninstall would not function, which did surprise me. Maybe the missing file was causing the uninstaller to fail.
I just deleted the folder where the application had been stored.
Judging from the previous posts on this thread, I will definitely consider carefully before any re-install before a signed binary is available.

@J-Cake
Copy link

J-Cake commented Aug 26, 2024

False positives can also be reported at https://www.microsoft.com/en-us/wdsi/filesubmission/ and maybe they will take care of it

Knowing Microsoft they'll probably keep letting Windows Defender bitch about it because their pride and joy Edge is being actually challenged

@wakeuphaku
Copy link

In the end, everyone decided that the defender deceives everyone

@Iziram
Copy link

Iziram commented Aug 26, 2024

1.0.0-a.30 seems fine for now. I hope Windows Defender is not gonna go off again.

image

@FelipeGlauber
Copy link

Here just to give @mauro-balades a huge THANK YOU and share my great admiration by his professionalism and humble talk with people here, assuming his limitations. For me as a development student you gave me some inspiration.

@sitiom
Copy link

sitiom commented Aug 27, 2024

This is preventing the winget package from being merged:

@nsde
Copy link

nsde commented Aug 27, 2024

I love this browser, but unfortunately it suddenly got deleted by Kaspersky.
In hope of helping devs, I will provide as much info about this as possible:

  • AV: Kaspersky Free
Event: Object deleted
Application: Zen Browser
User: FIERY\Lynx
User type: Initiator
Component: System Watcher
Result description: Deleted
Type: Trojan
Name: PDM:Trojan.Win32.Generic
Threat level: High
Object type: Process
Object path: C:\Program Files\Zen Browser
Object name: zen.exe
MD5: F65A002208E471404726B4142AEC8550

@szpatrik5
Copy link

a30 with eset av:

Screenshot 2024-08-27 200526
Screenshot 2024-08-27 200534

@mauro-balades
Copy link
Member

Arghhhh the windows key didnt arive yet

@BearDad
Copy link

BearDad commented Aug 27, 2024

in version
image

with zen version:
1.0.0-a.30 (64-bit)

it does not get picked up by windows defender. Though the untrusted souce persists and should be fixed once it's signed

@rollingmoai
Copy link

In a couple of days, I'll receive a mail with a physical key and I'll need to figure out how to use it

@mauro-balades How can you automate signing builds with a physical key?

@mauro-balades
Copy link
Member

I can't, I'll have to sign it and reupload

@StefanKoell
Copy link

When you order a code signing certificate, you can either order one on a physical key (USB device) or you can order a cert which integrates with a Key Vault service (such as Azure Key Vault). In the latter case, you can setup scripts to automate the signing process. Unfortunately there's no way to extract the certificate with the private key information from the physical device. Last time I checked, you can actually extract the certificate with the private key from Azure Key Vault and use the cert in a CI pipeline using the sign tool and the extracted cert file.

@CptnFizzbin
Copy link

I can't, I'll have to sign it and reupload

Might be good to look into setting up a cert in Azure Vault so that trusted pipelines can do automatic signing. I can see having to manually perform the signing will get old real quick.

@nevotheless
Copy link

nevotheless commented Aug 31, 2024

I was able to install it but after 2 days windows security says the zen.installer.exe is a potential PUA:Win32/Packunwan.

Current VT

@mauro-balades
Copy link
Member

Update:

IMG_20240902_120725

@rengare
Copy link

rengare commented Sep 2, 2024

image

@mauro-balades
Copy link
Member

I dont think these vulnerabilities have to do with zen, I tried updating them but it just breaks surfer

@jgcabotd
Copy link

jgcabotd commented Sep 3, 2024

Hi guys, just yesterday I tried the browser and when I start it, in a few seconds Kaspersky killed the process and detected as a Trojan zen.exe.

There is a screenshot so you can see what happened.

image

@soulhax
Copy link

soulhax commented Sep 5, 2024

Any update on the signing of the exe?

@oslohes123
Copy link

Any update on the signing of the exe?

@mauro-balades any updates of the above?

@mauro-balades
Copy link
Member

The license is getting approved by certum

@jgonzales20
Copy link

This would be a great browser to use for work but there are currently false positives that won't let it get approved by IT. Glad to hear a license is getting acquired. Here are some of my scanner results

http://www.hybrid-analysis.com/sample/d67a453b2505863b830530e87ff455fc1a95084273dd83c74d4ab409e4f5300e/66df1a31f85fc2840b00d2f0

mitre_d67a453b2505863b830530e87ff455fc1a95084273dd83c74d4ab409e4f5300e_160.csv

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests