Showing results for 
Search instead for 
Do you mean 
Reply
Bit Torrent
Posts: 1,796
Registered: ‎11-28-2007
Location: CZ
Message 1 of 12 (3,913 Views)

Yoga Book software update downloads possible infection

[ Edited ]

It is already discussed here. I downloaded both files yetiwdmm1671.exe and yetiwdds1669.exe from Lenovo Support and checked online via VirtusTotal. Both yeilds positive infection detected by multiple AV software.

 

https://www.virustotal.com/cs/file/a93b8be8f070b182e893b77afce71a5c2b5296313b94963de2b4276b06aa9f48/...

https://www.virustotal.com/cs/file/808ed674bb4276290a05f1c54bb1cbe4ca36f981dc72fe564ecd06add432181c/...

 

Moreover both executable files are not digitally signed by Lenovo !

 

It is also worth to note that these installation batch files inside the package are terrible scripts that can not work reliably. It looks like written by a non-professional person who is almost clueless in software industry.

__________________________________
ThinkPad (1992 - 2012): R51, X31, X220, Tablet 8.
Do you care about privacy and security ? Leave Google behind
802.11n
Posts: 164
Registered: ‎01-21-2016
Location: DE
Message 2 of 12 (3,855 Views)

Betreff: Yoga Book software update downloads possible infection

Hey, don't worry. The detection ratio is 4 / 56. Almost all reputable antivirus programs say it's okay.

  
Posts: 1,602
Registered: ‎05-01-2010
Location: US
Message 3 of 12 (3,829 Views)

Betreff: Yoga Book software update downloads possible infection

[ Edited ]

Yes, exactly. I'm seeing 2/56 though.


Blotha wrote:

Hey, don't worry. The detection ratio is 4 / 56. Almost all reputable antivirus programs say it's okay.

   

 










English    Deutsche     Español     Português     Русскоязычное

If you find a post helpful and it answers your question, please click the "Accept As Solution" button.

I am not employed by Lenovo or Microsoft. I am a volunteer.

SpywareHammer





Bit Torrent
Posts: 1,796
Registered: ‎11-28-2007
Location: CZ
Message 4 of 12 (3,806 Views)

Betreff: Yoga Book software update downloads possible infection

[ Edited ]

Blotha wrote:

Hey, don't worry. The detection ratio is 4 / 56. Almost all reputable antivirus programs say it's okay.

  

No digital signature = no trust. It is also detected by Symantec. These files looks like a WinRar self-extractors, why ? Lenovo isn't capable to create standard MSI package and sign it ? Tools for this are free (Wix).

__________________________________
ThinkPad (1992 - 2012): R51, X31, X220, Tablet 8.
Do you care about privacy and security ? Leave Google behind
Bit Torrent
Posts: 1,796
Registered: ‎11-28-2007
Location: CZ
Message 5 of 12 (3,753 Views)

Betreff: Yoga Book software update downloads possible infection

[ Edited ]

Do you realize that default Windows Defender also detects these executable files as infected ? It is embarrassing and completely unnecessary if proper tools were used to create the software package.

__________________________________
ThinkPad (1992 - 2012): R51, X31, X220, Tablet 8.
Do you care about privacy and security ? Leave Google behind
802.11n
Posts: 164
Registered: ‎01-21-2016
Location: DE
Message 6 of 12 (3,663 Views)

Betreff: Yoga Book software update downloads possible infection

[ Edited ]

Today I downloaded the above linked files (exe). Afterwards I scanned both with Windows Defender (default, right click). Result: Nothing was detected as malware on my device.

Posts: 1,602
Registered: ‎05-01-2010
Location: US
Message 7 of 12 (3,465 Views)

Betreff: Yoga Book software update downloads possible infection

Blotha, thank you for following up on this. Apparently, there has been an update in the virus detections.










English    Deutsche     Español     Português     Русскоязычное

If you find a post helpful and it answers your question, please click the "Accept As Solution" button.

I am not employed by Lenovo or Microsoft. I am a volunteer.

SpywareHammer





Bit Torrent
Posts: 1,796
Registered: ‎11-28-2007
Location: CZ
Message 8 of 12 (3,374 Views)

Betreff: Yoga Book software update downloads possible infection

[ Edited ]

Lenovo has removed all Yoga Book Windows 10 updates from support page downloads. A good "solution" after all, that confirms there were issues.

__________________________________
ThinkPad (1992 - 2012): R51, X31, X220, Tablet 8.
Do you care about privacy and security ? Leave Google behind
Administrator
Posts: 64,320
Registered: ‎09-03-2014
Location: SK
Message 9 of 12 (3,329 Views)

Betreff: Yoga Book software update downloads possible infection

Hello Puppy,

 

I can see how you arrived at that conclusion and how it would appear to be a logical one, however, that is definitely not the case. The drivers disappearing was first noted, to my knowledge, on 26th October and on questioning it turned out that, due to how Windows now handles updates, it was felt there was no need to have them on the web.  That said, I know that not seeing available downloads for their system may make some customers feel their system is not supported by Lenovo and, for that reason, I would also like to see their return.

Andy


English Community Leader


Please remember to come back and mark the post that you feel solved your question as the solution, it earns the member + points


Did you find a post helpfull? You can thank the member by clicking on the star to the left awarding them Kudos


T430 2347-G7U W8 x64, Yoga 10 HD+, Tablet 1838-2BG, T61p 6460-67G W7 x64, T43p 2668-G2G XP, T23 2647-9LG XP, plus a few more.


Please don't ask me questions by Personal Message; questions belong in the forums.


Deutsche Community Comunidad en Español English Community Русскоязычное Сообщество Communidade Portugues

Bit Torrent
Posts: 1,796
Registered: ‎11-28-2007
Location: CZ
Message 10 of 12 (3,310 Views)

Betreff: Yoga Book software update downloads possible infection


Andy_Lenovo wrote:

it turned out that, due to how Windows now handles updates, it was felt there was no need to have them on the web..


Sorry, I don't get it. What is the connection between installation of a custom software and Windows updates ? The only issue was these primitive update batch scripts were poorly written and that's why it had never worked.

__________________________________
ThinkPad (1992 - 2012): R51, X31, X220, Tablet 8.
Do you care about privacy and security ? Leave Google behind
Top kudoed Authors
User Kudos Count
1