You are here

Virus found

6 posts / 0 new
Last post
saa001
Offline
Last seen: 11 years 7 months ago
Joined: 2007-08-09 18:55
Virus found

Just did an update via the Portable Apps menu and came up with a virus on one of the apps. This happened only after the update and not before. I wasn't downloading anything else either.

The virus is: Cyrano.exe and it was in the Lucas Chess app.

Is there any scan done of apps prior to them being distributed?

John T. Haller
John T. Haller's picture
Online
Last seen: 9 min 48 sec ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
Double Scanned, 100% Clean

Lucas Chess was double-scanned before release, as always. Lucas Chess Portable 7.05 is 100% clean as are all our releases. You can confirm it right here: https://www.virustotal.com/en/file/f6780e35305c72320eddee33505ed33d782a3...

Likely, your antivirus either has a buggy definitions update or has buggy heuristics enabled (heuristics work quite poorly in most commercial antivirus applications). Which antivirus do you have? Also, be sure to update your definitions as they may have already fixed their buggy set.

Sometimes, the impossible can become possible, if you're awesome!

suicidemayhem
suicidemayhem's picture
Offline
Last seen: 11 years 6 months ago
Joined: 2013-07-30 09:41
no, this file is definitely

no, this file is definitely infected. found with symantec endpoint protection at work and on my laptop using kaspersky. only have screen of symantec. http://i.imgur.com/P1UnTOe.jpg

Gord Caswell
Gord Caswell's picture
Offline
Last seen: 19 hours 23 min ago
DeveloperModerator
Joined: 2008-07-24 18:46
Heuristic scanner

As you can see in that screenshot, that is using Symantec's "heuristic scanner", in other words, the antivirus is guessing if something is infected. If you check the analysis report, it shows that symantec's scanner tests the file as clean.

Please report it to Symantec as a false positive.

The current virustotal analysis report is here: https://www.virustotal.com/en/file/f6780e35305c72320eddee33505ed33d782a3...

SakiTC
SakiTC's picture
Offline
Last seen: 3 years 5 months ago
Joined: 2008-06-13 02:05
A little bit different

It's a little bit different if you scan the file in question, cyrano.exe. Positive result is currently returned 5 times out of 46:

https://www.virustotal.com/en/file/354e4ccb70c93eb84e44aca3f169cbaa84302...

It's still heuristic detection in all these cases and most probably a false positive.

No typin th las lette ca sav yo plent o spac

John T. Haller
John T. Haller's picture
Online
Last seen: 9 min 48 sec ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
Generic

It's still just a generic/heuristic warning by some flawed engines. The PAK.Generic one can always be ignored (it just means the file is compressed with UPX and isn't a cause for it to be blocked). TrendMicro usually takes a few days to get it right and whitelist it so even that will disappear. Symantec's flawed heuristic engine will whitelist it soon enough.

Basically, none of them are claiming it's a virus. One (with two listings) is saying it's compressed. One is saying it's compressed with a possibly malicious tool (PCTools is pretty useless in that respect). Symantec's flawed heuristic engine will complain for a couple more days before they get around to fixing it. TheHacker, I'm unfamiliar with but it looks like another flawed heuristic engine.

Again, the file is the standard one from LibreOffice's base package (which was already scanned by two leading antivirus engines before we pack it) which is then UPX compressed to save space (LibreOffice is a huge app). It's then re-scanned by two engines, packaged into an installer that has automatic tamper detection (so if the installer is altered in any way it will fail to run) and then digitally signed.

Unfortunately, users of lesser antivirus products/poor default settings will have to wait a couple days for their publisher to fix their issues. Considering that Symantec has been wrong every single time they've alerted on one of our files for the past 9 years (and they've been wrong A LOT... especially their buggy heuristic scanner), you have nothing to be worried about.

Sometimes, the impossible can become possible, if you're awesome!

Log in or register to post comments