| Author |
Message |
tubby
Joined: 24 Jan 2009 Posts: 317
|
Posted: Wed 24 Feb 2010, 07:34 Post subject:
virus check says it found a virus in a .pet |
|
I have run a virus check on this system and i received the following alert on a pet in my download folder.
[Found possible virus] <Heuristic-90 (not disinfectable)>
Do you think it is dangerous or a bad report from xfprot?.
|
|
Back to top
|
|
 |
cthisbear
Joined: 29 Jan 2006 Posts: 2942 Location: Sydney Australia
|
Posted: Wed 24 Feb 2010, 08:03 Post subject:
|
|
Probably F-Prot.
Chris.
|
|
Back to top
|
|
 |
Lobster
Official Crustacean

Joined: 04 May 2005 Posts: 15109 Location: Paradox Realm
|
Posted: Wed 24 Feb 2010, 09:18 Post subject:
|
|
assuming it is a false positive . . what is the file?
https://forum.f-prot.com/index.php?topic=1251.0
. . . report here
http://www.f-prot.com/virusinfo/submission_form.html
_________________ Puppy WIKI
|
|
Back to top
|
|
 |
DMcCunney
Joined: 02 Feb 2009 Posts: 894
|
Posted: Wed 24 Feb 2010, 10:49 Post subject:
Re: virus or not |
|
| tubby wrote: | I have run a virus check on this system and i received the following alert on a pet in my download folder.
[Found possible virus] <Heuristic-90 (not disinfectable)>
Do you think it is dangerous or a bad report from xfprot?. |
Most likely, false positive.
Was this scan run from Puppy on a Puppy folder?
Viruses don't really exist for Linux. The extant ones all want to infect Windows, and can't run on/infect anything else. Folks running A/V in Puppy are usually concerned with protecting a Windows partition/machine, using Puppy as a secure platform from which to scan/disinfect/repair.
I don't use Puppy for that, hence don't install/run A/V in it.
______
Dennis
|
|
Back to top
|
|
 |
tubby
Joined: 24 Jan 2009 Posts: 317
|
Posted: Wed 24 Feb 2010, 12:11 Post subject:
|
|
Lobster the pet is to large for me to send as i only have a slow upload sorry, i tried to pm you but there appears to be a problem.
|
|
Back to top
|
|
 |
Dingo

Joined: 11 Dec 2007 Posts: 1397 Location: somewhere at the end of rainbow...
|
Posted: Wed 24 Feb 2010, 12:31 Post subject:
|
|
often, false positives are caused by upx compression, so, executables compressed with upx are (falsely) identified as virus
_________________ replace .co.cc with .info to get access to stuff I posted in forum
dropbox 2GB free
OpenOffice for Puppy Linux
Last edited by Dingo on Wed 24 Feb 2010, 14:32; edited 1 time in total
|
|
Back to top
|
|
 |
dejan555

Joined: 30 Nov 2008 Posts: 2407 Location: Montenegro
|
Posted: Wed 24 Feb 2010, 12:53 Post subject:
|
|
Give us link from where you downloaded pet or give us name of pet only, someone will check it.
_________________

|
|
Back to top
|
|
 |
tubby
Joined: 24 Jan 2009 Posts: 317
|
Posted: Wed 24 Feb 2010, 13:07 Post subject:
|
|
As the report is most probably a false positive i thought about posting the name of the pet but decided against it as i did not want to cast any doubt on the work of the originator, one shadow and a lot of good work could be undone.
I was hoping a moderator would allow me to pm them with the info,tried Lobster but it did not get through for some reason.
|
|
Back to top
|
|
 |
Lobster
Official Crustacean

Joined: 04 May 2005 Posts: 15109 Location: Paradox Realm
|
Posted: Thu 25 Feb 2010, 04:26 Post subject:
|
|
| Quote: | Hi Lobster, re the infection reported, it is in the Quirky Linux Kernel 2.6.31.5-tickless_smp-q1.pet that i downloaded from the Quirky repository.
As i only have a very slow upload 20meg would take an awful long time, Maybe you can do it for me or ask someone else to check it out.
As the file came direct from Barry`s site you can understand why i did post what the pet was on the forum.
regards
|
You got through OK
If anyone would like to find that file and check it please do.
Barry is on holiday at the moment
By making public any concerns you may have they can be investigated by our special team
of detective blood hounds
- anyone up for it?
I understand and appreciate your concern not to 'cast aspersions'
but no one believes there is anything other than a false positive
- which has already been documented.
If a mistake has been made, then we would rather know
Something can be done
Puppy Linux
Open Source at its best
_________________ Puppy WIKI
|
|
Back to top
|
|
 |
tubby
Joined: 24 Jan 2009 Posts: 317
|
Posted: Thu 25 Feb 2010, 16:10 Post subject:
|
|
Thanks for following it up Lobster, i am hoping it is a false positive.
|
|
Back to top
|
|
 |
|