Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Important #2357

Closed
ghost opened this issue Aug 31, 2020 · 5 comments
Closed

Important #2357

ghost opened this issue Aug 31, 2020 · 5 comments
Labels
Meta Relating to code organisation or to things that aren't code

Comments

@ghost
Copy link

ghost commented Aug 31, 2020

The file at this link got compromised guys download it and check this is my last post

https://github.com/TASVideos/BizHawk/releases/download/2.5/BizHawk-2.5.0.zip

Its not the same file u guys have. Please download it frsh just tried with my iphone on lte and its also infected

Dont scan the url

Doenload the file and upload to virus total

Please try

@Sonia-7
Copy link

Sonia-7 commented Aug 31, 2020

Ok. I just wanted to say that OP isn't the only one who got this Windows Defender report. I also got it, and had to put the .exe under "allowed threats" to keep it around.

So yeah, seems like something went wrong with the 2.5 release. Saying it now while I still can before this thread also gets locked.

@ghost
Copy link
Author

ghost commented Aug 31, 2020

They need to trust me and test how im saying

@NarryG
Copy link
Contributor

NarryG commented Aug 31, 2020

He is right that if you directly upload the file, and don't do a URL scan, Virustotal throws two hits.
https://www.virustotal.com/gui/file/44b290d8332d0c64307c8f602aedfe683c5739238db219fdcb72e4f361de5187/details

But this is nothing new. If you go through Bizhawk history you'll find plenty of versions flagged as malware. It's usually pissy about the Waterbox binaries because they use weird memory manipulation shenanigans.

This is just failing heuristics, not an actual infection. There's nothing to be worried about OP.

As an additional note, the file getting flagged by Defender is the main binary.
I'd bet that it's the MOTW whacking code in program.cs setting it off again. I actually modified my fork because that code was making AVs upset. https://www.virustotal.com/gui/file/b16aaa38d66cb93a188aa4a1fe6702df9678431c0c5d2ca365989bd021ca5681/

@TiKevin83
Copy link
Contributor

TiKevin83 commented Aug 31, 2020

Seconding NarryG's comment, I had the same findings that the URL scan gives different results from uploading the zip, and 2.4.2 gets hit by one of the same heuristics as 2.5.

Edit: to be clear I also agree with zeromus' assessment here, there's no possible way this is actually malware

@zeromus
Copy link
Contributor

zeromus commented Aug 31, 2020

One hit from microsoft on virustotal doesn't count, and microsoft's quality is not spectacular if it can find malware in the exe but not in the exe in the zip so it doubly doesn't count

@TASEmulators TASEmulators locked and limited conversation to collaborators Aug 31, 2020
@YoshiRulz YoshiRulz added the Meta Relating to code organisation or to things that aren't code label Aug 31, 2020
@TASEmulators TASEmulators unlocked this conversation Oct 11, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Meta Relating to code organisation or to things that aren't code
Projects
None yet
Development

No branches or pull requests

5 participants