Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows AV blocking opening zen.exe due to virus/trojan found in the executable. #37

Open
TrueHerobrine opened this issue Jul 6, 2024 · 128 comments
Assignees

Comments

@TrueHerobrine
Copy link

zen

@mr-cheff mr-cheff self-assigned this Jul 6, 2024
@mr-cheff mr-cheff added the bug label Jul 6, 2024
@mr-cheff
Copy link
Member

mr-cheff commented Jul 6, 2024

Screenshot_20240706_225017

virus detection websites dont detect anything so I dont know why is windows AV complaining...

@TrueHerobrine
Copy link
Author

I might try to whitelist the exe. I'll get back with an update.

@TrueHerobrine
Copy link
Author

Update: Just tried again without adding an exception and it works flawlessly. TLDR: Windows is weird.

@mr-cheff
Copy link
Member

mr-cheff commented Jul 6, 2024

Windows is weird. Thanks a lot for trying it out!

image

@TrueHerobrine
Copy link
Author

No worries! Found it on Reddit and was actually very impressed. I have my own browser but I'm not forking it off of anything, so it's cool to see an indie browser thriving like this!

@mr-cheff mr-cheff pinned this issue Jul 11, 2024
@DavidGreen63
Copy link

In the last 30 minutes, while I was accessing a site, using version 1.0.0-a.29 (64-bit), Windows Defender terminated the App and deleted the core executable.

@clembu
Copy link

clembu commented Aug 26, 2024

Same happened to me. Admittedly my Defender is very weird and Windows Security crashes when I try to open it, so I can't open the UI to add exclusions or inspect things that way, but a.28 works

@danmaxis
Copy link

It happened to me too, mine Zen was flagged by Kaspersky when I tried to import data from another browser.

@Meathelix1
Copy link

Windows 11
Version 10.0.22631 Build 22631

Zen was installed directly from the website. https://www.zen-browser.app/

Windows Defender Picked it up as soon as I opened Zen.exe

Trojan Name = "Wacatac.B!ml"

I dont want to be excluding something with that name, a quick google search will show you this is a popular one.

@Xavi-X333
Copy link

I have the same problem, first the core executable was deleted and then a can't download the installer :/

@DavidGreen63
Copy link

Maybe it is an issue that will fade once Zen gets a signature, but as it stands, its normal operations are being flagged as Malware/Trojan like. I think I'll look into Zen again once it gets a little less alpha or beta-ish.

@Meathelix1
Copy link

The Generic Version does not pick up as a Trojan. It's just the Optimized Version.

@HamzaConcepts
Copy link

Screenshot 2024-08-26 094935

Virustotal is also showing it as some trojan script. Are all of these just false positives?

@extropyst
Copy link

Check this information:
https://virustotal.readme.io/docs/false-positive

and try also analyzing the file in other places like:

https://internxt.com/virus-scanner

https://opentip.kaspersky.com/

image

@jakehower
Copy link

Getting blocked for me too.

@soulhax
Copy link

soulhax commented Aug 26, 2024

Exactly the same problem as others are having. Also the installer is detected as PUA:Win32/Packunwan.
Idk but I'm not satisfied with the answer "Windows is weird". I guess we're going to wait until this exe and thing are going to be signed and stuff. Peace.

ApplicationFrameHost_EKwNHXAcrb

@MatfenV1
Copy link

afbeelding
Same issue here, it worked just fine when I installed it on my desktop but my laptop refuses installing it.

@Abelkrijgtalles
Copy link

Abelkrijgtalles commented Aug 26, 2024

Same here (Windows 11 Pro 23h2)
image

@J-Cake
Copy link

J-Cake commented Aug 26, 2024

Just wanted to report that this is still happening. System: Windows 11 Pro 22H2 Build: 22621.3880

@MikeyA-yo
Copy link

I also get this same trojan script, this made me uninstall zen immediately

@Abelkrijgtalles
Copy link

Abelkrijgtalles commented Aug 26, 2024

Could this maybe have a connection to the new windows defender update? 1.0.0-a.29 was released 2 days ago, but this problem only started about 9 hours ago.

EDIT: The latest update I've installed (defender version 1.417.317.0), doesn't include anything about Trojan:Script/Wacatac.B!ml.

@alexugthub
Copy link

Just tried to install the Zen browser on a Windows 10 and it blocks it claiming that there's a "PUA:Win32/Packunwan" virus

@DavidGreen63
Copy link

I am on Win 10 Pro, and after the core executable was annexed, I attempted to uninstall. The uninstall would not function, which did surprise me. Maybe the missing file was causing the uninstaller to fail.
I just deleted the folder where the application had been stored.
Judging from the previous posts on this thread, I will definitely consider carefully before any re-install before a signed binary is available.

@FeraltCode
Copy link

Did you get it from the zip file or installer?

Installer

For me this looks ok

imagem
That's weird, for me shows as not signed

@markox92
Copy link

@FeraltCode just updated to 1.0.1-a.6 and here is

Screenshot 2024-09-30 151414

@jgonzales20
Copy link

@FeraltCode just updated to 1.0.1-a.6 and here is

Screenshot 2024-09-30 151414

still getting unsigned DLL's
image

@markox92
Copy link

Which dll ? If is AccessibleMarshal.dll looks fine for me.
Screenshot 2024-09-30 165532

@jgonzales20
Copy link

Which dll ? If is AccessibleMarshal.dll looks fine for me. Screenshot 2024-09-30 165532

Link: https://www.virustotal.com/gui/file/068347961d00e4c0842c7eb5764a1338b869b62ac4a855feca703be6728da3d3?nocache=1
image

All three of these files are unsigned.
Link: https://www.virustotal.com/gui/file/30073077a83770dc3c13110d2499067343bc882fab51aef074479be492a40c3c/relations
image

@meguroyama
Copy link

Did you get it from the zip file or installer?

Used the installer and the installer on it's own is fine but the bundled / extracted files are the issue here.

@markox92
Copy link

@jgonzales20 how is it possible that the same file AccessibleMarshal.dll has a different size on my and your PC? For me, VT reports that file is signed for you, unsigned wtf?? :(

@mr-cheff
Copy link
Member

mr-cheff commented Oct 5, 2024

I see non of the files are signed on the installer... Hmmm

@mr-cheff mr-cheff reopened this Oct 5, 2024
@jgonzales20
Copy link

@jgonzales20 how is it possible that the same file AccessibleMarshal.dll has a different size on my and your PC? For me, VT reports that file is signed for you, unsigned wtf?? :(

It's coming from the installer.

@jgonzales20
Copy link

Latest Update:
image
image

@szpatrik5
Copy link

Had to reinstall 1.0.1-a.8 from setup. None of the files are signed. And the blocking started again...

@mrmind77
Copy link

Same by Kaspersky

Hoy, 15/10/2024 21:55:12;Se detectó un objeto malicioso;Zen Browser;zen.exe;C:\Program Files\Zen Browser;26164;MENTE\josue;Iniciador;Detectado: PDM:Trojan.Win32.Generic;Detectado;PDM:Trojan.Win32.Generic;Troyano;Alta;Exacta;zen.exe;zen.exe;C:\Program Files\Zen Browser;Proceso;Análisis de comportamiento

@jgonzales20
Copy link

a. 10 is receiving the following detections.
image

@jgonzales20
Copy link

jgonzales20 commented Oct 21, 2024

@mauro-balades a.12 still has two unsigned files in the installer.
image

Virus total: https://www.virustotal.com/gui/file/90cb7c445fd7a99c05f8aae60fb49ea4e7a84f69449b5a4a9b10c4af3d441cb5/relations

@FeraltCode
Copy link

imagem

AV flagged Zen once more, I ran the Installer (Executable, Optimized, downloaded through website) through VirusTotal and there are 5 unsigned files

@daviddelven
Copy link

image
and what about this?

@TiboGabriels
Copy link

Pallo Alto XDR has been flagging it too on occasion, today was this alert:
image

@jgonzales20
Copy link

I believe these false positives will occur until this goes to stable as you can't get a signing cert until you are in production / out of alpha

@leic4u
Copy link

leic4u commented Nov 28, 2024

I got this problem with v1.0.1-a.21 in my PC just now, while intalled in my laptop correctly.

PC information:

OS: 24H2 
Windows Security Application Version: 1000.27703.0.1006
Windows Security Platform Version: 10.0.27703.1006-0
Microsoft Defender Antivirus Platform version: 4.18.24090.11
Engine Version: 1.1.24090.11
security intelligence update: 1.421.516.0

@siddhant-dev
Copy link

its because the windows exe file needs to singed as per microsoft's protocol. I guess only the production version will have it

@mr-cheff
Copy link
Member

Im still investigating into how I can properly fix this issue for once and for all. I think there's a slight issue when signing the executables inside the installer

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: No status
Development

No branches or pull requests