X-Recipient: archive-cygwin AT delorie DOT com X-SWARE-Spam-Status: No, hits=-0.4 required=5.0 tests=AWL,BAYES_00 X-Spam-Check-By: sourceware.org Message-ID: <4A55ED43.9030407@ebrady.net> Date: Thu, 09 Jul 2009 09:14:43 -0400 From: Ed Brady User-Agent: Thunderbird 2.0.0.22 (Windows/20090605) MIME-Version: 1.0 To: Dave Korn CC: cygwin AT cygwin DOT com Subject: Re: Re: Virus on sed.exe References: <4A555ABC DOT 6020401 AT gmail DOT com> In-Reply-To: <4A555ABC.6020401@gmail.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Antivirus-Scanner: Clean mail though you should still use an Antivirus Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com Thanks, All file look good, I submitted to a couple of online file scanner sites and they confirmed no problem. This appears to be a false positive with CA Antivirus... BTW: After posting this message to the board I found 6 additional exe files that also caused false positives. I posted these new files in a message to the board also, however they all checked out good also.. Ed Dave Korn wrote: > Ed Brady wrote: > >> I just ran a virus scan, and got a hit for sed.exe. >> Win32/AMalum.ZZQIA. Anyone else seen anything similar to this? >> > > Seen a few false positives with AVG in my personal experience. Most AVs run > into the odd one now and again. Some of them seem to have a fondness for > Cygwin, probably because it's not part of any of their standard testing > environments, so they wouldn't notice false positives in it before releasing a > new .dat file. > > >> I run scans frequently and have never had this show up before I want to >> believe that this is a false positive, but want to be sure... >> > > Here's md5sums of my versions: > > 1.5: > ~ $ cygcheck -c sed > Cygwin Package Information > Package Version Status > sed 4.1.5-2 OK > ~ $ md5sum /bin/sed.exe > dd5f2d46b572b534d22f65a43916351c */bin/sed.exe > > 1.7: > $ cygcheck -c sed > Cygwin Package Information > Package Version Status > sed 4.1.5-2 OK > > $ md5sum /bin/sed.exe > dd5f2d46b572b534d22f65a43916351c */bin/sed.exe > > If yours match (assuming same versions of course), you're clean. For a > second opinion, try uploading your sed.exe at http://virusscan.jotti.org/ > > cheers, > DaveK > -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple