delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2009/07/08/22:37:07

X-Recipient: archive-cygwin AT delorie DOT com
X-SWARE-Spam-Status: No, hits=-2.4 required=5.0 tests=AWL,BAYES_00,SPF_PASS
X-Spam-Check-By: sourceware.org
Message-ID: <4A555ABC.6020401@gmail.com>
Date: Thu, 09 Jul 2009 03:49:32 +0100
From: Dave Korn <dave DOT korn DOT cygwin AT googlemail DOT com>
User-Agent: Thunderbird 2.0.0.17 (Windows/20080914)
MIME-Version: 1.0
To: cygwin AT cygwin DOT com
Subject: Re: Virus on sed.exe
References: <4A554E61 DOT 3040302 AT ebrady DOT net>
In-Reply-To: <4A554E61.3040302@ebrady.net>
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

Ed Brady wrote:
> I just ran a virus scan, and got a hit for sed.exe.  
> Win32/AMalum.ZZQIA.   Anyone else seen anything similar to this?

  Seen a few false positives with AVG in my personal experience.  Most AVs run
into the odd one now and again.  Some of them seem to have a fondness for
Cygwin, probably because it's not part of any of their standard testing
environments, so they wouldn't notice false positives in it before releasing a
new .dat file.

> I run scans frequently and have never had this show up before I want to
> believe that this is a false positive, but want to be sure...

  Here's md5sums of my versions:

1.5:
~ $ cygcheck -c sed
Cygwin Package Information
Package              Version        Status
sed                  4.1.5-2        OK
~ $ md5sum /bin/sed.exe
dd5f2d46b572b534d22f65a43916351c */bin/sed.exe

1.7:
$ cygcheck -c sed
Cygwin Package Information
Package              Version        Status
sed                  4.1.5-2        OK

$ md5sum /bin/sed.exe
dd5f2d46b572b534d22f65a43916351c */bin/sed.exe

  If yours match (assuming same versions of course), you're clean.  For a
second opinion, try uploading your sed.exe at http://virusscan.jotti.org/

    cheers,
      DaveK

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019