delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2009/07/09/09:15:15

X-Recipient: archive-cygwin AT delorie DOT com
X-SWARE-Spam-Status: No, hits=-0.4 required=5.0 tests=AWL,BAYES_00
X-Spam-Check-By: sourceware.org
Message-ID: <4A55ED43.9030407@ebrady.net>
Date: Thu, 09 Jul 2009 09:14:43 -0400
From: Ed Brady <mailinglist AT ebrady DOT net>
User-Agent: Thunderbird 2.0.0.22 (Windows/20090605)
MIME-Version: 1.0
To: Dave Korn <dave DOT korn DOT cygwin AT googlemail DOT com>
CC: cygwin AT cygwin DOT com
Subject: Re: Re: Virus on sed.exe
References: <4A555ABC DOT 6020401 AT gmail DOT com>
In-Reply-To: <4A555ABC.6020401@gmail.com>
X-Antivirus-Scanner: Clean mail though you should still use an Antivirus
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

Thanks, 
All file look good,  I submitted to a couple of online file scanner 
sites and they confirmed no problem.  This appears to be a false 
positive with CA Antivirus...

BTW: After posting this message to the board I found 6 additional exe 
files that also caused false positives.  I posted these new files in a 
message to the board also, however they all checked out good also..

Ed


Dave Korn wrote:
> Ed Brady wrote:
>   
>> I just ran a virus scan, and got a hit for sed.exe.  
>> Win32/AMalum.ZZQIA.   Anyone else seen anything similar to this?
>>     
>
>   Seen a few false positives with AVG in my personal experience.  Most AVs run
> into the odd one now and again.  Some of them seem to have a fondness for
> Cygwin, probably because it's not part of any of their standard testing
> environments, so they wouldn't notice false positives in it before releasing a
> new .dat file.
>
>   
>> I run scans frequently and have never had this show up before I want to
>> believe that this is a false positive, but want to be sure...
>>     
>
>   Here's md5sums of my versions:
>
> 1.5:
> ~ $ cygcheck -c sed
> Cygwin Package Information
> Package              Version        Status
> sed                  4.1.5-2        OK
> ~ $ md5sum /bin/sed.exe
> dd5f2d46b572b534d22f65a43916351c */bin/sed.exe
>
> 1.7:
> $ cygcheck -c sed
> Cygwin Package Information
> Package              Version        Status
> sed                  4.1.5-2        OK
>
> $ md5sum /bin/sed.exe
> dd5f2d46b572b534d22f65a43916351c */bin/sed.exe
>
>   If yours match (assuming same versions of course), you're clean.  For a
> second opinion, try uploading your sed.exe at http://virusscan.jotti.org/
>
>     cheers,
>       DaveK
>   


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019