Re: PostgreSQL\12\bin\pg_ctl.exe - Trojan detected

From: Andres Freund <andres(at)anarazel(dot)de>
To: Magnus Hagander <magnus(at)hagander(dot)net>,Manoj Agrawal <manoj(dot)agrawal(at)hotmail(dot)com>
Cc: "security(at)postgresql(dot)org" <security(at)postgresql(dot)org>,"pgsql-bugs(at)lists(dot)postgresql(dot)org" <pgsql-bugs(at)lists(dot)postgresql(dot)org>
Subject: Re: PostgreSQL\12\bin\pg_ctl.exe - Trojan detected
Date: 2019-12-22 15:48:45
Message-ID: 2B803319-D7B2-4B78-8345-3928CB9494C8@anarazel.de
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

Hi,

On December 22, 2019 10:38:57 AM EST, Magnus Hagander <magnus(at)hagander(dot)net> wrote:
>On Sun, Dec 22, 2019 at 4:26 PM Manoj Agrawal
><manoj(dot)agrawal(at)hotmail(dot)com>
>wrote:
>
>> Dear PostgreSQL Team,
>>
>> I am a regular ordinary user of your application.
>> I apologies for not following your bug and security template. I
>suppose
>> this will be OK with you.
>>
>> Kindly look at this screen from Windows 10 machine.
>>
>> I have downloaded "postgresql-12.1-3-windows-x64.exe" from your
>website
>> and during installation it is reporting Malware in one of your
>executable.
>>
>
>
>Exactly which URL did you download it from? And please provide a
>checksum
>(md5, sha1 or similar) of the file downloaded to your system.
>
>
>
>>
>> *PostgreSQL\12\bin\pg_ctl.exe*
>>
>> *Threat detected: Trojan:Win32/Detplock *
>>
>> *Alert level: Severe *
>>
>> *Date: 22-12-2019 07:32 PM *
>>
>> *Category: Trojan *
>>
>> *Details: This program is dangerous and executes commands from an
>> attacker. *
>>
>> I need you to look into this on priority basis. As I am stuck-up
>>
>
>Hi!
>
>Can you please take the file from your system and upload it to
>https://www.virustotal.com/gui/home/upload, and let us know what the
>detection there says? It also gives you a link to the finished
>analysis,
>so please post the link to that one as well.

Fwiw, there's a note on MS's page about recent false positives for this"virus":
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Detplock
--
Sent from my Android device with K-9 Mail. Please excuse my brevity.

In response to

Browse pgsql-bugs by date

  From Date Subject
Next Message Manoj Agrawal 2019-12-22 16:03:14 Re: PostgreSQL\12\bin\pg_ctl.exe - Trojan detected
Previous Message Magnus Hagander 2019-12-22 15:38:57 Re: PostgreSQL\12\bin\pg_ctl.exe - Trojan detected