aMule Forum

Please login or register.

Login with username, password and session length
Advanced search  

News:

We're back! (IN POG FORM)

Pages: [1] 2

Author Topic: amule download giving virus?  (Read 20127 times)

Jake

  • Newbie
  • Karma: 0
  • Offline Offline
  • Posts: 2
amule download giving virus?
« on: September 27, 2008, 01:27:02 PM »

Well I'm trying to download aMule for Windows but both links files gives a virus after completion, the Virus is NewHeur PE.
Logged

wuischke

  • Developer
  • Hero Member
  • *****
  • Karma: 183
  • Offline Offline
  • Posts: 4292
Re: amule download giving virus?
« Reply #1 on: September 27, 2008, 07:13:12 PM »

Thank you for this report, we are interested in resolving this:

1. Which files did you download? Could you calculate a checksum (Use i.e. http://www.md5summer.org) of the files?

2. Which virus scanner does report this result?
Logged

Kry

  • Ex-developer
  • Retired admin
  • Hero Member
  • *****
  • Karma: -665
  • Offline Offline
  • Posts: 5795
Re: amule download giving virus?
« Reply #2 on: September 27, 2008, 08:03:22 PM »

Where are oyu trying to download it from?
Logged

Jake

  • Newbie
  • Karma: 0
  • Offline Offline
  • Posts: 2
Re: amule download giving virus?
« Reply #3 on: September 28, 2008, 01:20:15 AM »

I downloaded the amule-2.2.2-install.exe from Sourceforge and BerliOS.  I'm using Eset Nod32 3.0.650. It put the file in quaratin the moment I get it home.
Logged

SmopuiM

  • Newbie
  • Karma: 0
  • Offline Offline
  • Posts: 1
Re: amule download giving virus?
« Reply #4 on: September 29, 2008, 10:24:22 PM »

Also NOD32  3.0.642.0



No matter the source of the file (Sourceforge or Berlin)
Logged

Supersnail

  • Full Member
  • ***
  • Karma: 4
  • Offline Offline
  • Posts: 186
Re: amule download giving virus?
« Reply #5 on: September 30, 2008, 12:15:39 AM »

I scanned the file at virusscan.jotti.org and only NOD32 detected it as a "probably unknown NewHeur_PE (probable variant)"
Logged

cv01

  • Newbie
  • Karma: 0
  • Offline Offline
  • Posts: 3
Re: amule download giving virus?
« Reply #6 on: September 30, 2008, 12:00:35 PM »

This morning I got a virus warning too. I'm using AVG (http://www.avg.com/).





It moved amule.exe to the virus vault.
What's up with that?

Edit: I used latest build from sourceforge, always used the official amule.org page to get to the download link...

I do get the same error on a different PC after downloading from sf:

« Last Edit: September 30, 2008, 12:06:41 PM by cv01 »
Logged

phoenix

  • Evil respawning bird from aMule Dev Team
  • Developer
  • Hero Member
  • *****
  • Karma: 44
  • Offline Offline
  • Posts: 2503
  • The last shadow you'll ever see
Re: amule download giving virus?
« Reply #7 on: September 30, 2008, 12:45:14 PM »

That is the problem with binaries. It may be a false alarm, but it may not be. Anyone knows how this program has been generated (environment)? MSVC, minGW? Maybe someone can try using something different or regenerate to make sure it is ok?

My suggestion is to remove the file ASAP until things are made clear.
Logged

wuischke

  • Developer
  • Hero Member
  • *****
  • Karma: 183
  • Offline Offline
  • Posts: 4292
Re: amule download giving virus?
« Reply #8 on: September 30, 2008, 12:59:01 PM »

Is the AVG warning only about the installer or about the amule.exe, amulegui.exe,... , too?

Both warnings are most probably false positives (the first one "heuristic", the second one "generic" - you won't find information about these viruses on the vendor's web page, because there is no such specific virus), but I'll upload a zip file to source forge while trying to contact the affected vendors.
Logged

cv01

  • Newbie
  • Karma: 0
  • Offline Offline
  • Posts: 3
Re: amule download giving virus?
« Reply #9 on: September 30, 2008, 01:22:54 PM »

It is both files. You can see that in the first picture I posted it is amule.exe and then the installer download from sf is the second picture. Probably both false positives, I didn't find anything about the Generic Trojan Horse too.
Logged

wuischke

  • Developer
  • Hero Member
  • *****
  • Karma: 183
  • Offline Offline
  • Posts: 4292
Re: amule download giving virus?
« Reply #10 on: September 30, 2008, 02:02:23 PM »

I contacted nod32 about this.

cv01: According to the AVG FAQ, one should report these files using the program. Unfortunately I don't own AVG, would you be so kind to send the files for analysis?

I've also upload compressed files to the sourceforge download page
Logged

cv01

  • Newbie
  • Karma: 0
  • Offline Offline
  • Posts: 3
Re: amule download giving virus?
« Reply #11 on: September 30, 2008, 02:17:58 PM »

I'm sending the files to AVG. In the .zip-file I get a Generic Trojan Horse for amulegui.exe. I keep you posted.
Logged

eyerobot

  • Newbie
  • Karma: 0
  • Offline Offline
  • Posts: 1
Re: amule download giving virus?
« Reply #12 on: October 19, 2008, 11:03:15 PM »

Was there no answer for this problem?

I use avaste antivirus and im getting the same Win32:Trojan-gen(other) warning with the downloaded exe, and the internal amule.exe file.

Ive downloaded every installer hosted here, and they all give the same warning.

Is it safe now?
Logged

wuischke

  • Developer
  • Hero Member
  • *****
  • Karma: 183
  • Offline Offline
  • Posts: 4292
Re: amule download giving virus?
« Reply #13 on: October 19, 2008, 11:25:07 PM »

I have received no further information from the nod32 developers and no anti-virus vendor has made a statement about their warnings. I would appreciate if you could contact the developers of avaste antivirus and ask them to check the concerning files.

These virus reports are very damaging to our reputation.  I believe these are wrong warnings and I trust the package creators. If you are worried about the safety of the files, please do not install them and either use eMule or compile aMule yourself.
Logged

wuischke

  • Developer
  • Hero Member
  • *****
  • Karma: 183
  • Offline Offline
  • Posts: 4292
Re: amule download giving virus?
« Reply #14 on: October 21, 2008, 02:26:45 PM »

OK, I believe we know now about the origin of the warnings (I'll write a news item about it later).

Furthermore I did a scan on jotti.org today and got no virus warnings, can anyone confirm that nod32 does not recognize the file anymore? (I tested the installer and the amule.exe file.)

Nonetheless, there's now a aMule-2.2.2-mingw32.zip on sourceforge. I cross-compiled it yesterday on Linux and tested it on wine.
Logged
Pages: [1] 2