Virus in PB4.20 UpdateTool?

For everything that's not in any way related to PureBasic. General chat etc...
pebo
New User
New User
Posts: 2
Joined: Sat Apr 28, 2007 8:18 pm
Location: Germany

Virus in PB4.20 UpdateTool?

Post by pebo »

Hello all,

i have downloadet PB4.2 Beta and when i unpack the File my Kaspersky show me the follow Message:
Image
In the Kaspersky Forum Users say this is a dangerous file. What does the PB-Creators say?

PS. Sorry for my english :wink:

Peter
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

Post by Inf0Byt3 »

Most probably a false alarm. The files cannot be infected. I have both Dr.Web CureIT and PCTools antivirus and the files are clean. This should be reported to Kaspersky Labs for a fix.

[Edit]
Take a look at this:
Scan taken on 04 May 2008 12:19:01 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothingAVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found Packed.Win32.Monder.gen
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found Packed.Win32.Monder.gen
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
Last edited by Inf0Byt3 on Sun May 04, 2008 1:21 pm, edited 1 time in total.
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
UserOfPure
Enthusiast
Enthusiast
Posts: 469
Joined: Sun Mar 16, 2008 9:18 am

Post by UserOfPure »

The good people here have been using that version for months and you're the only one to find a virus? ;)
Dave651
User
User
Posts: 10
Joined: Thu Jun 14, 2007 11:27 pm

Post by Dave651 »

UserOfPure wrote:The good people here have been using that version for months and you're the only one to find a virus? ;)
I had the same warning from Kaspersky but I did a search on the forum and found a number of false positives.
rsts
Addict
Addict
Posts: 2736
Joined: Wed Aug 24, 2005 8:39 am
Location: Southwest OH - USA

Post by rsts »

We (the PureBasic community) can basically assure you that, if you downloaded from the PureBasic site, it's 'clean'.

cheers (and Welcom to PB) :)
User avatar
Rook Zimbabwe
Addict
Addict
Posts: 4322
Joined: Tue Jan 02, 2007 8:16 pm
Location: Cypress TX
Contact:

Post by Rook Zimbabwe »

We (the PureBasic community) can basically assure you that, if you downloaded from the PureBasic site, it's 'clean'.
And if you didn't, you got what you deserved! 8)

I stilll find several "discount software" sites around the net... Selling pirated actual versions of software! How can this continue?
Binarily speaking... it takes 10 to Tango!!!

Image
http://www.bluemesapc.com/
User avatar
DoubleDutch
Addict
Addict
Posts: 3220
Joined: Thu Aug 07, 2003 7:01 pm
Location: United Kingdom
Contact:

Post by DoubleDutch »

How can this continue?
You just have to live with it.
https://deluxepixel.com <- My Business website
https://reportcomplete.com <- School end of term reports system
Tranquil
Addict
Addict
Posts: 952
Joined: Mon Apr 28, 2003 2:22 pm
Location: Europe

Post by Tranquil »

I have the same problem at work. Couse I'm not admin on this host I can not send an email with the file to kaspersky so that they can change their signature files. Kaspersky deletes the file asap. :-(
Tranquil
User avatar
pdwyer
Addict
Addict
Posts: 2813
Joined: Tue May 08, 2007 1:27 pm
Location: Chiba, Japan

Post by pdwyer »

I remember when I was testing some AV products (not the Adult video type, the Anti Virus type ;) ) I had to put an exception on my source code directories bacause of things like this. Particularly Kapersky wanted to quarantine all the compiled version of some of my apps.

Mainly:

My Sniffer (shareware, not home made), my home made port scanners and network wide PC registry updators etc that I'd use in my last company (some in powerbasic back then)

But then, I suppose, virus's don't need to be hidden in the PE header of an exe anymore, Some are more like, a zip file in the mail with a note saying "run me" and a batch file that uses the del command. :roll:

Some people need that situation to be handled by their AV software, many people would prefer if AV software just let it lie
Paul Dwyer

“In nature, it’s not the strongest nor the most intelligent who survives. It’s the most adaptable to change” - Charles Darwin
“If you can't explain it to a six-year old you really don't understand it yourself.” - Albert Einstein
User avatar
DoubleDutch
Addict
Addict
Posts: 3220
Joined: Thu Aug 07, 2003 7:01 pm
Location: United Kingdom
Contact:

Post by DoubleDutch »

The situation can only improve if AntiVirus software houses could be held more accountable to what they delete by accident or be sued for lible if they falsely accuse legitimate software of being a virus.

The way things stand, I could write the worlds best antivirus program by going thru a pc and deleting every file and blocking all other writes to disk or memory!
https://deluxepixel.com <- My Business website
https://reportcomplete.com <- School end of term reports system
User avatar
Fluid Byte
Addict
Addict
Posts: 2336
Joined: Fri Jul 21, 2006 4:41 am
Location: Berlin, Germany

Post by Fluid Byte »

Kaspersky sux?
Windows 10 Pro, 64-Bit / Whose Hoff is it anyway?
User avatar
Rook Zimbabwe
Addict
Addict
Posts: 4322
Joined: Tue Jan 02, 2007 8:16 pm
Location: Cypress TX
Contact:

Post by Rook Zimbabwe »

The way things stand, I could write the worlds best antivirus program by going thru a pc and deleting every file and blocking all other writes to disk or memory!
I had a virus that did that once... You forgot to block all internet connectiosn as well!!! 8)
Binarily speaking... it takes 10 to Tango!!!

Image
http://www.bluemesapc.com/
UserOfPure
Enthusiast
Enthusiast
Posts: 469
Joined: Sun Mar 16, 2008 9:18 am

Re: Virus in PB4.20 UpdateTool?

Post by UserOfPure »

Hmm, I just updated Avira AntiVir right now and it showed me this! :shock: So: Kaspersky, F-Secure and Avira all say UpdateTool.exe has a virus. Remember, Avira didn't say anything before, but now it does, so perhaps the other apps will catch up too and see the virus in due course...

[Edit] ClamWin doesn't report anything, so I don't know. Why would 3 apps detect something though? I don't have heuristics turned on.

The reason I'm reporting this, is that I did just have a virus on my PC, which I've since cleaned (it replaced Explorer.exe). So I was wondering where I got it, and the UpdateTool.exe would seem to be it.

Image
Last edited by UserOfPure on Mon May 19, 2008 2:19 am, edited 2 times in total.
User avatar
Kaeru Gaman
Addict
Addict
Posts: 4826
Joined: Sun Mar 19, 2006 1:57 pm
Location: Germany

Post by Kaeru Gaman »

I used Kaspersky for only a few days, its nervous Heuristics drove me mad, I kicked it.
about Avira I heard similar problems.
also the Norton Bloodhound is a Pain in the Ass.

use an Antivir that is not too trigger happy. I'm happy with Avast.

if you are unhappy,
that expensive Antivirus software does not care about Non-Mainstream or Free Development programs,
complain to the companies who produce them.

yo, go ahead, write an email to Kaspersky and Avira.
but tell us later, how much them Nabobs care about us...
oh... and have a nice day.
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

Post by Inf0Byt3 »

Indeed. As I see it, the bigger the company is, the less they care about people. And AV companies definitely prove this. I understand that they have to analyze tons of new programs every day, but losing contact and not caring about the individual don't make a good impression. Speaking about false positive reporting, the ones that gave me quick responses in the past were Alwil (Avast) and Avira. The others didn't even bother to reply. This is sad...
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
Post Reply