aMule Forum
September 02, 2010, 03:54:38 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: We're back! (IN POG FORM)
 
   Home   Search | Web BugTracker Wiki Download Help Login Register  
Pages: [1] 2
  Print  
Author Topic: amule download giving virus?  (Read 9087 times)
0 Members and 1 Guest are viewing this topic.
Jake
Newbie
*

Karma: 0
Posts: 2


View Profile
« on: September 27, 2008, 12:27:02 PM »

Well I'm trying to download aMule for Windows but both links files gives a virus after completion, the Virus is NewHeur PE.
Logged
iz0bbz
Hero Member
*****

Karma: 26
Posts: 581



View Profile WWW
« Reply #1 on: September 27, 2008, 02:38:30 PM »

I tried both Symantec Antivirus & Clamav on the official links and I haven't found any virus.

Please try a different scan engine , perhaps it is a false positive.
Logged

The answer lies within your soul, but it's the wrong one.
aMule  unofficial Fedora packages - stable and SVN
wuischke
Administrator
Hero Member
*****

Karma: 183
Posts: 4376



View Profile
« Reply #2 on: September 27, 2008, 06:13:12 PM »

Thank you for this report, we are interested in resolving this:

1. Which files did you download? Could you calculate a checksum (Use i.e. http://www.md5summer.org) of the files?

2. Which virus scanner does report this result?
Logged

Efficient and fast open source file compression - http://freearc.org
Kry
Main Developer / Elder Admin / Lazy bastard
Administrator
Hero Member
*****

Karma: -661
Posts: 5484



View Profile
« Reply #3 on: September 27, 2008, 07:03:22 PM »

Where are oyu trying to download it from?
Logged
Jake
Newbie
*

Karma: 0
Posts: 2


View Profile
« Reply #4 on: September 28, 2008, 12:20:15 AM »

I downloaded the amule-2.2.2-install.exe from Sourceforge and BerliOS.  I'm using Eset Nod32 3.0.650. It put the file in quaratin the moment I get it home.
Logged
SmopuiM
Newbie
*

Karma: 0
Posts: 1


View Profile
« Reply #5 on: September 29, 2008, 09:24:22 PM »

Also NOD32  3.0.642.0



No matter the source of the file (Sourceforge or Berlin)
Logged
Supersnail
Full Member
***

Karma: 3
Posts: 183



View Profile
« Reply #6 on: September 29, 2008, 11:15:39 PM »

I scanned the file at virusscan.jotti.org and only NOD32 detected it as a "probably unknown NewHeur_PE (probable variant)"
Logged
cv01
Newbie
*

Karma: 0
Posts: 3


View Profile
« Reply #7 on: September 30, 2008, 11:00:35 AM »

This morning I got a virus warning too. I'm using AVG (http://www.avg.com/).





It moved amule.exe to the virus vault.
What's up with that?

Edit: I used latest build from sourceforge, always used the official amule.org page to get to the download link...

I do get the same error on a different PC after downloading from sf:

« Last Edit: September 30, 2008, 11:06:41 AM by cv01 » Logged
phoenix
Evil respawning bird from aMule Dev Team
Administrator
Hero Member
*****

Karma: 38
Posts: 2495


The last shadow you'll ever see


View Profile
« Reply #8 on: September 30, 2008, 11:45:14 AM »

That is the problem with binaries. It may be a false alarm, but it may not be. Anyone knows how this program has been generated (environment)? MSVC, minGW? Maybe someone can try using something different or regenerate to make sure it is ok?

My suggestion is to remove the file ASAP until things are made clear.
Logged
wuischke
Administrator
Hero Member
*****

Karma: 183
Posts: 4376



View Profile
« Reply #9 on: September 30, 2008, 11:59:01 AM »

Is the AVG warning only about the installer or about the amule.exe, amulegui.exe,... , too?

Both warnings are most probably false positives (the first one "heuristic", the second one "generic" - you won't find information about these viruses on the vendor's web page, because there is no such specific virus), but I'll upload a zip file to source forge while trying to contact the affected vendors.
Logged

Efficient and fast open source file compression - http://freearc.org
cv01
Newbie
*

Karma: 0
Posts: 3


View Profile
« Reply #10 on: September 30, 2008, 12:22:54 PM »

It is both files. You can see that in the first picture I posted it is amule.exe and then the installer download from sf is the second picture. Probably both false positives, I didn't find anything about the Generic Trojan Horse too.
Logged
wuischke
Administrator
Hero Member
*****

Karma: 183
Posts: 4376



View Profile
« Reply #11 on: September 30, 2008, 01:02:23 PM »

I contacted nod32 about this.

cv01: According to the AVG FAQ, one should report these files using the program. Unfortunately I don't own AVG, would you be so kind to send the files for analysis?

I've also upload compressed files to the sourceforge download page
Logged

Efficient and fast open source file compression - http://freearc.org
cv01
Newbie
*

Karma: 0
Posts: 3


View Profile
« Reply #12 on: September 30, 2008, 01:17:58 PM »

I'm sending the files to AVG. In the .zip-file I get a Generic Trojan Horse for amulegui.exe. I keep you posted.
Logged
eyerobot
Newbie
*

Karma: 0
Posts: 1


View Profile
« Reply #13 on: October 19, 2008, 10:03:15 PM »

Was there no answer for this problem?

I use avaste antivirus and im getting the same Win32:Trojan-gen(other) warning with the downloaded exe, and the internal amule.exe file.

Ive downloaded every installer hosted here, and they all give the same warning.

Is it safe now?
Logged
wuischke
Administrator
Hero Member
*****

Karma: 183
Posts: 4376



View Profile
« Reply #14 on: October 19, 2008, 10:25:07 PM »

I have received no further information from the nod32 developers and no anti-virus vendor has made a statement about their warnings. I would appreciate if you could contact the developers of avaste antivirus and ask them to check the concerning files.

These virus reports are very damaging to our reputation.  I believe these are wrong warnings and I trust the package creators. If you are worried about the safety of the files, please do not install them and either use eMule or compile aMule yourself.
Logged

Efficient and fast open source file compression - http://freearc.org
Pages: [1] 2
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!