You are here

Recent downloads with Trojans and Broken Executables with worms

14 posts / 0 new
Last post
email4jack2read...
Offline
Last seen: 16 years 10 months ago
Joined: 2008-06-25 17:47
Recent downloads with Trojans and Broken Executables with worms

I recently downloaded the packages open office 3 beta and peazip to find trojan.hupignon in open office 3 and a broken executable with worm in peazip ?

Not very good security boys.

Jack

PS Found virus inside clam portable 0.93 using a clam antivirus scanner... not the 0.93 version. Also found broken link insdie.

And...., the boys that scanned the files that have been blue pilled will get false results.

LOGAN-Portable
LOGAN-Portable's picture
Offline
Last seen: 12 years 3 months ago
Developer
Joined: 2007-09-11 12:24
Probably a false positive due

Probably a false positive due to compressing files. You might check with other virus scanners.

Nowadays virus scanners 'guess' about changed files being viruses. Some scanners falsely pick up compressed files as 'virus'.

This really should be a FAQ!

OliverK
OliverK's picture
Offline
Last seen: 3 years 10 months ago
Developer
Joined: 2007-03-27 15:21
IT IS! In reply to the

IT IS!

In reply to the original post-https://portableapps.com/support

Too many lonely hearts in the real world
Too many bridges you can burn
Too many tables you can't turn
Don't wanna live my life in the real world

powerjuce
powerjuce's picture
Offline
Last seen: 14 years 2 months ago
Developer
Joined: 2007-09-20 21:34
here is a list of scanners and results
Antivirus	Version	Last Update	Result
AhnLab-V3	2008.6.19.0	2008.06.20	-
AntiVir	7.8.0.59	2008.06.20	-
Authentium	5.1.0.4	2008.06.20	-
Avast	4.8.1195.0	2008.06.20	-
AVG	7.5.0.516	2008.06.20	-
BitDefender	7.2	2008.06.21	-
CAT-QuickHeal	9.50	2008.06.20	-
ClamAV	0.93.1	2008.06.21	-
DrWeb	4.44.0.09170	2008.06.21	-
eSafe	7.0.15.0	2008.06.19	-
eTrust-Vet	31.6.5892	2008.06.21	-
Ewido	4.0	2008.06.21	-
F-Prot	4.4.4.56	2008.06.20	-
F-Secure	7.60.13501.0	2008.06.20	-
Fortinet	3.14.0.0	2008.06.21	-
GData	2.0.7306.1023	2008.06.21	-
Ikarus	T3.1.1.26.0	2008.06.21	-
Kaspersky	7.0.0.125	2008.06.21	-
McAfee	5322	2008.06.20	-
Microsoft	1.3604	2008.06.21	-
NOD32v2	3204	2008.06.20	-
Norman	5.80.02	2008.06.20	-
Panda	9.0.0.4	2008.06.20	-
Prevx1	V2	2008.06.21	-
Rising	20.49.51.00	2008.06.21	-
Sophos	4.30.0	2008.06.21	-
Sunbelt	3.0.1153.1	2008.06.15	-
Symantec	10	2008.06.21	-
TheHacker	6.2.92.356	2008.06.20	-
TrendMicro	8.700.0.1004	2008.06.20	PAK_Generic.001
VBA32	3.12.6.7	2008.06.19	-
VirusBuster	4.3.26:9	2008.06.12	-
Webwasher-Gateway	6.6.2	2008.06.21	-

33 virus scans and only one that said that it was anything. That result is a false positive.

Did you check the md5

Please search before posting. ~Thanks

email4jack2read...
Offline
Last seen: 16 years 10 months ago
Joined: 2008-06-25 17:47
Checked with several of the best virus scanners...

Check the files with avg, kaspersky, clam, bitdefender, and nortons. They all said the files contained a worm and trojan.

powerjuce
powerjuce's picture
Offline
Last seen: 14 years 2 months ago
Developer
Joined: 2007-09-20 21:34
check my list...

those scanners are there and show nothing

only trendmicro

Please search before posting. ~Thanks

powerjuce
powerjuce's picture
Offline
Last seen: 14 years 2 months ago
Developer
Joined: 2007-09-20 21:34
also...

here is the test of the actual launcher (that works btw)

Antivirus	Version	Last Update	Result
AhnLab-V3	2008.6.26.0	2008.06.25	-
AntiVir	7.8.0.59	2008.06.25	-
Authentium	5.1.0.4	2008.06.25	-
Avast	4.8.1195.0	2008.06.25	-
AVG	7.5.0.516	2008.06.25	-
BitDefender	7.2	2008.06.25	-
CAT-QuickHeal	9.50	2008.06.25	-
ClamAV	0.93.1	2008.06.25	-
DrWeb	4.44.0.09170	2008.06.25	-
eSafe	7.0.17.0	2008.06.25	-
eTrust-Vet	31.6.5904	2008.06.25	-
Ewido	4.0	2008.06.25	-
F-Prot	4.4.4.56	2008.06.25	-
F-Secure	7.60.13501.0	2008.06.24	-
Fortinet	3.14.0.0	2008.06.25	-
GData	2.0.7306.1023	2008.06.25	-
Ikarus	T3.1.1.26.0	2008.06.25	-
Kaspersky	7.0.0.125	2008.06.25	-
McAfee	5325	2008.06.25	-
Microsoft	1.3604	2008.06.25	-
NOD32v2	3219	2008.06.26	-
Norman	5.80.02	2008.06.25	-
Panda	9.0.0.4	2008.06.26	-
Prevx1	V2	2008.06.26	-
Rising	20.50.22.00	2008.06.25	-
Sophos	4.30.0	2008.06.25	-
Sunbelt	3.0.1153.1	2008.06.15	-
Symantec	10	2008.06.25	-
TheHacker	6.2.92.362	2008.06.26	-
TrendMicro	8.700.0.1004	2008.06.25	-
VBA32	3.12.6.8	2008.06.25	-
VirusBuster	4.5.11.0	2008.06.23	-
Webwasher-Gateway	6.6.2	2008.06.25	-

0/33

Please search before posting. ~Thanks

consul
consul's picture
Offline
Last seen: 3 months 2 weeks ago
Joined: 2007-05-02 13:47
do you have ...

the actual programs or is there some scripted macro that you use?

I believe you that it's probably a false positive, but maybe a full individual program scan generates different results.

Don't be an uberPr∅. They are stinky.

BuddhaChu
BuddhaChu's picture
Offline
Last seen: 10 months 3 weeks ago
Joined: 2006-11-18 10:26
Since you asked that

Since you asked that question, I take it you didn't read the support page linked to above or visit the websites linked to from there.

The two websites mentioned run files through all the virus scanners mentioned in the previous posts.

https://portableapps.com/support
http://www.virustotal.com/
http://virusscan.jotti.org/

Cancer Survivors -- Remember the fight, celebrate the victory!
Help control the rugrat population -- have yourself spayed or neutered!

consul
consul's picture
Offline
Last seen: 3 months 2 weeks ago
Joined: 2007-05-02 13:47
I don't see any ...

website or program name listed previously in your posts. I only see the ones that you put in the response to my post.
I've read the faq way back when it was created, hasn't really changed since then. Smile
I still think that online macros may not get the same results a local scan does. One or the other may not be uptodate.

Don't be an uberPr∅. They are stinky.

MarkoMLM
MarkoMLM's picture
Offline
Last seen: 9 years 6 months ago
DeveloperTranslator
Joined: 2006-01-16 04:08
Please read the posts and the hint to virus scanners...

... the sense of online-scanners is, that they allways use the actual virus databases and signatures, cause they get them direct if they will available.

The local installed programs scans with the local database (which state and source ever). If the local database is outdated it could be that You don't get a direct hint on it, if Your Abonement is canceled. In this case You'll get the message 'no newer files/updates available (this occures eg. in sometimes in McAffee).
So please check the dates (!) of Your databases.

BTW: There are a lot of false positives for this:
http://www.google.de/search?hl=de&client=firefox-a&rls=org.mozilla:de:of...

I have checked the files with a local installed scanner without a warning.

Did You check the md5sums? Please download an check it again.

Paid for Software more or less?
What You need is OSS!

ottosykora
Offline
Last seen: 6 hours 45 min ago
Joined: 2007-10-11 17:48
send the file to antivirus

>Check the files with avg, kaspersky, clam, bitdefender, and nortons. They all said the files contained a worm and trojan.

Otto Sykora
Basel, Switzerland

m-p-3
m-p-3's picture
Offline
Last seen: 1 year 2 weeks ago
Joined: 2006-06-17 21:25
1- Make sure your anti-virus

1- Make sure your anti-virus definition database is up-to-date
2- There is a possibility of false-positive, use an online-scanner to have a second advice
3- Download ONLY from the PortableApps website

RMB Fixed
Offline
Last seen: 15 years 4 months ago
Joined: 2006-10-24 10:30
A third possibility ..

.. is that YOUR security isn't to good and you in fact
DO have a virus on your system that infects everything it can .

Log in or register to post comments