X-Recipient: archive-cygwin AT delorie DOT com DomainKey-Signature: a=rsa-sha1; c=nofws; d=sourceware.org; h=list-id :list-unsubscribe:list-subscribe:list-archive:list-post :list-help:sender:date:from:reply-to:to:message-id:subject :mime-version:content-type:content-transfer-encoding:references; q=dns; s=default; b=V9Nhe3Q0yEnpcsYWqyrakf1QMNT2rLFzy+06Y8UNT6U 54KC+T2wMgwJlZlwL2F5hwmzZ5K0oORloLOavNZnYzog6Ud/4GL53FNK5SkyYQ7H GuT8bllZADxHzyS/lTR4x/PSOaEamXnunmC1QE8/Td2JQ4tyq3XsXgIwL1MikPo0 = DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sourceware.org; h=list-id :list-unsubscribe:list-subscribe:list-archive:list-post :list-help:sender:date:from:reply-to:to:message-id:subject :mime-version:content-type:content-transfer-encoding:references; s=default; bh=qS8dWtaytT8zl4CfSVuhOp1o9FI=; b=aUoqDlKnRu4WujelS Zxck5ns8I38dbnXT/pnnp4Uw6+Wa//G0JxPUPBIVOyvDPanXFm387mA3oA+pk5q5 +oNMVY6k2x3tCXPjh3kQd/49gKMOM4gc9/SL74ER5T89HZfdtG8YmCwLgtMBQr3C Xked49PmQi3GTI5YCos1ondEqM= Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com Authentication-Results: sourceware.org; auth=none X-Virus-Found: No X-Spam-SWARE-Status: No, score=4.4 required=5.0 tests=AWL,BAYES_80,FREEMAIL_FROM,RCVD_IN_DNSWL_LOW,REPTO_QUOTE_YAHOO,RP_MATCHES_RCVD,SPF_PASS autolearn=no version=3.3.2 spammy=UD:au, Desktop, 2fcygwin, avg X-HELO: nm27-vm5.bullet.mail.gq1.yahoo.com Date: Wed, 16 Mar 2016 23:44:33 +0000 (UTC) From: "Justin S." Reply-To: "Justin S." To: "cygwin AT cygwin DOT com" Message-ID: <412824260.1534094.1458171873522.JavaMail.yahoo@mail.yahoo.com> Subject: AVG scan found WIN-HEUR virus in cygwin install from aarnet ftp MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit References: <412824260 DOT 1534094 DOT 1458171873522 DOT JavaMail DOT yahoo DOT ref AT mail DOT yahoo DOT com> AVG anti-virus reported it found a virus in a Cygwin install pulled from aarnet on 8 Jan 2014. "";"Virus found Win32/Heur, C:\Users\justin\Desktop\ftp%3a%2f%2fmirror.aarnet.edu.au%2fpub%2fsourceware%2fcygwin%2f\x86\release\cygwin\cygwin-debuginfo\cygwin-debuginfo-1.7.27-2.tar.xz";"Secured" The AVG info on the reported virus is as follows: http://www.avgthreatlabs.com/au-en/virus-and-malware-information/info/win-heur/?name=Win32/Heur&utm_source=TDPU&utm_medium=SCAN&PRTYPE=AVF I think it has been lurking there for some time. You might want to check into it to make sure nothing has sneaked in. Justin -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple