Bug 12187 – VisualD-v0.3.37.exe on DSource falsely reports as virus
Status
RESOLVED
Resolution
FIXED
Severity
normal
Priority
P2
Component
visuald
Product
D
Version
D2
Platform
All
OS
Windows
Creation time
2014-02-16T19:09:31Z
Last change time
2017-12-02T16:48:02Z
Assigned to
No Owner
Creator
Neil
Comments
Comment #0 by neil.bryant — 2014-02-16T19:09:31Z
Didn't know where to put this, but I thought I'd let you know.
Report is below. Note that I do *not* get a report on github.../D-Programming-Language/../VisualD-v0.3.37.exe (although apparently the files are the same according to hash)
Also, scanning the exe with 36 scanners at VirScan.org shows nothing.
--------------------
WARNING: ProxyAV has detected a virus/PUS in this
file!
File has been dropped.
ProxyAV Administrator: unknown
2014-02-17 01:11:38+00:00UTC
Hardware serial number: 2609081007
ProxyAV (Version 3.5.1.1(111017)) - http://www.BlueCoat.com/
Antivirus Vendor: Sophos, Plc.
Scan Engine Version: 3.50.1
Pattern File Version: 4.97.6308063.959295994 (Timestamp: 2014/02/16 19:24:00)
Machine name: bv08aztmpe
Machine IP address: 151.151.108.136
Server: 208.78.103.206
Client: 113.1.19.123
Protocol: ICAP
Virus/PUS: "Mal/EncPk-XF" found!
URL: hxxp://www.dsource.org/projects/visuald/browser/downloads/VisualD-v0.3.37.exe?format=raw&FixForIE=.exe
Comment #1 by r.sagitario — 2014-02-26T23:23:30Z
The false alarms were raised after I added file monitoring to find linker dependencies. This uses DLL injection, a technique probably also used by viruses.
I have tried to disuise this functionality a bit and the installer now passes most checkers. Try it with beta4: https://github.com/D-Programming-Language/visuald/releases/tag/v0.3.38beta4