Page 1 of 1

dunno where to post this

Posted: 02 May 2005, 11:42
by rain
hey, i downloaded the latest version/client what so ever "tmw-0.0.12-win32.exe" and my antivirus says that it is a trojan horse virus what so ever, i downloaded the previous version before and my anti-virus didnt alert me anything.

thank you

Posted: 02 May 2005, 12:15
by Bjørn
Which anti-virus is that and which trojan horse or virus does it report to be contained in the executable?

Thanks for reporting, I hope it's nothing serious...

Posted: 02 May 2005, 12:55
by ElvenProgrammer
I checked the executable with ClamWin and McAfee, nothing was reported, but I know some nsis installers are considered as trojan some time, just let us know ok ?

Posted: 02 May 2005, 13:09
by ElvenProgrammer
Just scanned with Pc-cillin and nothing found

Posted: 02 May 2005, 13:39
by Pajarico
Tried with f-prot and latest virii definitions. Nothing found.

Must be a false positive.

Posted: 02 May 2005, 23:48
by Rotonen
What level of heuristics was involved?

Posted: 03 May 2005, 11:13
by rain
im using AVG anti-virus from grisoft, i just downloaded the file and when im about to install it my anti-virus warns me and says it was a trojan horse virus, prevents me from executing the file

Posted: 03 May 2005, 12:24
by rain
well.. i downloaded it again cauz i deleted it before when my anti-virus warned me, well it really wasnt a virus, it was some sort of "trojan horse downloader.lstbr.8.K"

heres a screenshot i took.

and i cant install it at all.

thnks n_n

http://img.photobucket.com/albums/v510/ ... titled.bmp

Posted: 03 May 2005, 13:30
by Pajarico
Rotonen wrote:What level of heuristics was involved?
On the first test I don't know, it was just the default options.
I've read the man and there is no heuristic, the thing closest to it is this:

Code: Select all

 
-ai
Enable neural-network virus detection. The -ai option should not
be used with the -noheur option.
This makes me think that it's activated by default:

Code: Select all

 -noheur
Disable heuristic scanning. The -noheur  option  should  not  be
used with the -ai option.

Code: Select all

lxuser@localhost lxuser $ f-prot -ai -server -packed /home/lxuser/.nicotine/share/tmw-0.0.12-win32.exe
Virus scanning report  -  4 May 2005 @ 15:36

F-PROT ANTIVIRUS
Program version: 4.5.4
Engine version: 3.16.6

VIRUS SIGNATURE FILES
SIGN.DEF created 2 May 2005
SIGN2.DEF created 2 May 2005
MACRO.DEF created 20 April 2005

Search: /home/lxuser/.nicotine/share/tmw-0.0.12-win32.exe
Action: Report only
Files: "Dumb" scan of all files
Switches: -ARCHIVE -PACKED -SERVER -AI


Results of virus scanning:

Files: 1
MBRs: 0
Boot sectors: 0
Objects scanned: 1

Time: 0:00

No viruses or suspicious files/boot sectors were found.
:wink: