Re: Trojan Horse detected by eSafe (Anti-Virus)
| From: | Richard Quadling | Date: | Mon, 15 Nov 2010 11:14:49 +0000 |
| Subject: | Re: Trojan Horse detected by eSafe (Anti-Virus) | ||
| References: | 1 2 3 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-9426@lists.php.net to get a copy of this message | ||
2010/11/15 Richard Quadling <rquadling@gmail.com>:
> 2010/11/14 Ángel González <keisial@gmail.com>:
>> Lionel Eppe wrote:
>>> I found some mirror of php.net where th e file "php-4.4.7-Win32.zip" are
>>> ready for download but when i scan this file with eSafe ans the Site Virus total, they found a
>>> "Win32.TrojanHorse"? Link of the scan here :
>>> http://www.virustotal.com/file-scan/report.html?id=13328ce9842b05aa8840f9a04364ff7147aa3ae87a8bf86a63f0531d851334e6-1289760335
>>>
>>> Where can i get good version of the file "php-4.4.7-Win32.zip" without
>>> Virus, trojan, ...
>>> Thanks
>>>
>> Note that the last from PHP 4 series is php 4.4.9 not php 4.4.7
>>
>> From http://museum.php.net/php4/ I do NOT get the same file
>> as you.
>>
>> VirusTotal reported file has the following attributes:
>>> MD5 : 3b09977e3beae52f5cac372f375128f9
>>> SHA1 : 7dc7c0dbd13f6b3260557b546ed95b3d4a1431d5
>>> SHA256: 13328ce9842b05aa8840f9a04364ff7147aa3ae87a8bf86a63f0531d851334e6
>>> File size : 8628399 bytes
>>
>> whereas if I download
>> http://museum.php.net/php4/php-4.4.7-Win32.zip it has
>>> MD5 : 065e867fa3cfa75cba8271dde9b10cee
>>> SHA1 : f6457b0d63f28c95ca9581f8ddfd6c42720bcc8b
>>> SHA256: a5849125a40a77bbc5c36a7bdb87310e0d87b3f0e826fd15588e39375d7df0eb
>>> File size : 8627994 bytes
>>
>> It is still detected as a trojan horse by eSafe, though.
>> It looks like a false positive. I tried to bisect which of the zip items
>> was being detected as trojan,
>> but it didn't detect the pieces as infected.
>
>
> http://www.virustotal.com/file-scan/report.html?id=a5849125a40a77bbc5c36a7bdb87310e0d87b3f0e826fd15588e39375d7df0eb-1289819457
>
> Shows only eSafe. High probability of a false positive.
>
>
> --
> Richard Quadling
> Twitter : EE : Zend
> @RQuadling : e-e.com/M_248814.html : bit.ly/9O8vFY
>
http://www.virustotal.com/url-scan/report.html?id=72433999114773122d7f6d2e8b0e5d2b-1289815815
--
Richard Quadling
Twitter : EE : Zend
@RQuadling : e-e.com/M_248814.html : bit.ly/9O8vFY