EMULAB Forum

Please login or register.

Login with username, password and session length
Advanced search  

News:

The new forum is online, hope you enjoy it!

Pages: [1]   Go Down

Author Topic: malware on your download site  (Read 4759 times)

andylofgren

  • Member
  • *
  • Karma: 0
  • Offline Offline
  • Posts: 3
  • Operating System:
  • Windows NT 10.0 Windows NT 10.0
  • Browser:
  • Firefox 47.0 Firefox 47.0
    • View Profile
malware on your download site
« on: 23 August 2016, 00:38 »

I'm very sorry, but your link entitled 'clrmamepro 64bit 4.030a    (exe) (3063kb)' [http://mamedev.emulab.it/clrmamepro/binaries/cmp4030a_64.exe] on your website http://mamedev.emulab.it/clrmamepro/#downloads, is affording a malware download, Threat name: SAPE.Heur.BE5C0.
Logged


Roman

  • Global Moderator
  • Member
  • ***
  • Karma: 113
  • Offline Offline
  • Posts: 3292
  • Operating System:
  • Mac OS X Mac OS X
  • Browser:
  • Safari 9.0 Safari 9.0
    • View Profile
Re: malware on your download site
« Reply #1 on: 23 August 2016, 04:55 »

The files have been scanned with various up2date virusscanners on different machines. None reported a problem. Also the file is hosted on several networks which do scan the files before they mirror them....and last but not least...all the other users who downloaded the file before you didn't report a problem.

I'm very sorry but your virusscanner or whatever is wrong. You got a false positive alert.
Let me guess...Zonealarm?
You should update your virus definitions or switch to something more reliable.
« Last Edit: 23 August 2016, 08:22 by Roman »
Logged

andylofgren

  • Member
  • *
  • Karma: 0
  • Offline Offline
  • Posts: 3
  • Operating System:
  • Windows NT 10.0 Windows NT 10.0
  • Browser:
  • Mozilla compatible Mozilla compatible
    • View Profile
Re: malware on your download site
« Reply #2 on: 24 August 2016, 11:19 »

It was Norton.
Logged

andylofgren

  • Member
  • *
  • Karma: 0
  • Offline Offline
  • Posts: 3
  • Operating System:
  • Windows NT 10.0 Windows NT 10.0
  • Browser:
  • Mozilla compatible Mozilla compatible
    • View Profile
Re: malware on your download site
« Reply #3 on: 24 August 2016, 11:23 »

I haven't heard that Norton was all that great in the past, however I only use it because we get it for free with our Comcast internet subscription.
Logged

Roman

  • Global Moderator
  • Member
  • ***
  • Karma: 113
  • Offline Offline
  • Posts: 3292
  • Operating System:
  • Windows NT 10.0 Windows NT 10.0
  • Browser:
  • Chrome 52.0.2743.116 Chrome 52.0.2743.116
    • View Profile
Re: malware on your download site
« Reply #4 on: 24 August 2016, 11:49 »

Well...as I said....false positives are common things. If you're unsure with a result, double check with a different scanner...or use the zip package version.
Logged

Chad

  • Member
  • *
  • Karma: 0
  • Offline Offline
  • Posts: 19
  • Operating System:
  • Windows NT 10.0 Windows NT 10.0
  • Browser:
  • Chrome 66.0.3359.139 Chrome 66.0.3359.139
    • View Profile
Re: malware on your download site
« Reply #5 on: 30 July 2018, 16:46 »

Roman, I am not sure if you ever heard of Virus Total https://www.virustotal.com. It's a handy site that allows you to upload fairly large executables (I believe it's up to 128MB now) and scans them with roughly 60 virus scan engines with current signatures from different vendors and gives you the results. It's interesting to see how some vendors report false positives and others clean. It's very easy to use with a drag-and-drop interface, URL or search. Actually you can use it to scan any file type.

All the main vendors are covered and the ones you never heard of too. :) The details tab has some good logistics information. I use it all the time if I have a "questionable" file. Once a file is uploaded and "finger printed" (SHA-256 hash calculated) you can link the results or if it's a file that's been uploaded prior it will just calculate the hash locally and link the last analysis so you know if a rescan with current signatures might detect something that wasn't prior. Anyway this thread came up while looking for something else and I thought it might be helpful if people have questions or if you haven't heard of it because I find it a very handy tool.

Logged

Roman

  • Global Moderator
  • Member
  • ***
  • Karma: 113
  • Offline Offline
  • Posts: 3292
  • Operating System:
  • Windows NT 10.0 Windows NT 10.0
  • Browser:
  • Chrome 68.0.3440.75 Chrome 68.0.3440.75
    • View Profile
Re: malware on your download site
« Reply #6 on: 31 July 2018, 16:29 »

Thanks for the idea but it wouldn't solve the problem of users reporting false positives ;-) Usually they claim their used tool is right and everyone else is wrong and if it reports a problem, it got a problem....but usually they don't know what false positives are....
So as long as you grab it from the official page you'll be on the safe side....and the official url is https://mamedev.emulab.it/clrmamepro/  and not others which might sound more official and have hack tools and/or trojans ready for you
Logged

Chad

  • Member
  • *
  • Karma: 0
  • Offline Offline
  • Posts: 19
  • Operating System:
  • Windows NT 10.0 Windows NT 10.0
  • Browser:
  • Chrome 66.0.3359.139 Chrome 66.0.3359.139
    • View Profile
Re: malware on your download site
« Reply #7 on: 31 July 2018, 16:57 »

I understand what you're saying completely. I deal with them daily and new threats on edge devices with public facing services through government alerting and other channels watching for threats. No serious virus, trojan, malware or what not has gotten loose on my watch, knock on wood. ;) I always send people their as a "neutral" place to get a second opinion with questionable files. I spent last 22 years working for the state mainly doing firewalls, routers, switches, VMWare and of course virus scan is mine too (uugh! :) and prior to that a whole lot of years at UPS doing the same. We use enterprise deployment tools pushing to 100's of PCs. I have a fairly complex hierarchy of policy inheritance in place for exceptions and other challenging requests. Unfortunately we aren't a large enough organization to have dedicated IT roles like a bank or something that employees 10's of thousands so we wear many hats on a daily basis.
Logged
Pages: [1]   Go Up
 

Page created in 0.193 seconds with 20 queries.