PDA

View Full Version : ISPconfig install archive virus


martien
26th October 2008, 15:27
Hello. This happened and more than half year ago and it makes me not to see what it's ISPconfig like. When I try to download the ISPconfig installation archive my anti-virus program (nod32) terminates the download because of virus fle. I continue downloading ispconfig and then search it for viruses and here is the log:
Date: 26.10.2008 Time: 15:09:49
Scanned disks, folders and files: C:\Users\root\Downloads\ISPConfig-svn-stable.tar.gz
C:\Users\root\Downloads\ISPConfig-svn-stable.tar.gz »GZ »ISPConfig-svn-stable.tar »TAR »install_ispconfig/compile_aps/clamav-0.94.tar.gz »GZ »clamav-0.94.tar »TAR »clamav-0.94/test/.split/split.clam-upack.exeaa - a variant of Win32/Kryptik.AE trojan
C:\Users\root\Downloads\ISPConfig-svn-stable.tar.gz »GZ »ISPConfig-svn-stable.tar »TAR »install_ispconfig/compile_aps/clamav-0.94.tar.gz »GZ »clamav-0.94.tar »TAR »clamav-0.94/test/.split/split.clam.arjaa »ARJ »clam.exe - incorrect CRC checksum, the file may be damaged
C:\Users\root\Downloads\ISPConfig-svn-stable.tar.gz »GZ »ISPConfig-svn-stable.tar »TAR »install_ispconfig/compile_aps/clamav-0.94.tar.gz »GZ »clamav-0.94.tar »TAR »clamav-0.94/test/.split/split.clam.arjaa »ARJ - archive damaged
C:\Users\root\Downloads\ISPConfig-svn-stable.tar.gz »GZ »ISPConfig-svn-stable.tar »TAR »install_ispconfig/compile_aps/clamav-0.94.tar.gz »GZ »clamav-0.94.tar »TAR »clamav-0.94/test/.split/split.clam.chmaa »CHM »/#SYSTEM - error occurred while reading archive
...(few other errors like "error while reading archive", "unpack error", "archive damaged"..)
Number of scanned files: 15520
Number of threats found: 1
Time of completion: 15:10:50 Total scanning time: 61 sec (00:01:01)
It happened before and it happens now. I try it on two machines and the result is the same. I think its something that should not happens. Sorry if im wrong.

Ben
26th October 2008, 21:30
As the mentioned files belong to clamav, a free virus scanner itself, I guess this is a false positive.

till
27th October 2008, 09:14
This is a false positive, you might report it to your antivirus vendor that the nod32 version you use reports clamav (which is a antivirus program too) as virus.

martien
27th October 2008, 12:49
This is a false positive, you might report it to your antivirus vendor that the nod32 version you use reports clamav (which is a antivirus program too) as virus.
It reports only this file:
split.clam-upack.exeaa, not the whole clamav. I guess its because of its .exeaa extenstion.
However i wanted just to make sure that the nod is lying.