You are not logged in.
Pages: 1
My viruscanner reported the following when I attempted to install the latest Rolling version in VirtualBox:
Virus or unwanted program 'TR/Crypt.ULPM.Gen [trojan]'
detected in file 'C:\Users\leo\Downloads\slitaz-rolling.iso.
Action performed: Deny access
No panic here, the malware was detected but this is bad for Slitaz' reputation.
Please fix.
/emgi
Offline
Why would a WINDOWS trojan be part of a LINUX LiveCD? It wouldn't have any effect on the Linux system if you boot with it and wouldn't even run. So what could it be? Probably a false positive created by an overzealous AV algorithm that seems aimed at lzma compressed images.
So I have to ask: Which AV scanner is saying this? We can report it as a false positive. Hopefully they aren't as bad as the one Open Proxy Blacklist my IP was listed on. They said I had a Windows Root Kit on my Linux (without Wine or SAMBA) system. Yeah, you get people like that.
Offline
I'll just leave it here: https://www.virustotal.com/en/file/2b0245f970ba4b760d9776be39138d8cdd1aa09a8f764db9d0e0daa719e81dde/analysis/1367207063/
emgi, if you not trust SliTaz developers and suspect that SliTaz is an evil virus,
maybe you trust other antiviruses? Result is 2/46, I think is very good ;-B
And, man, ehm… you can easy cure your system from TR/Crypt.ULPM.Gen: http://yoosupport.com/malware-virus-spyware-removal/831-remove-tr-crypt-ulpm-gen.html ;-D
PS. Tested SliTaz rolling ISO file from April, 26 @ 15:40:06. And for some reasons I can't check URL http://mirror.slitaz.org/iso/rolling/slitaz-rolling.iso
Other online antivirus tool: http://online.drweb.com/
Offline
The iso2exe command is run during the rolling generation, see http://hg.slitaz.org/wok/file/tip/syslinux/stuff/iso2exe/README and http://hg.slitaz.org/tazlito/rev/4a6aaec03e94
The idea : the SliTaz distribution is an ISO 9660 file. It should be burned on a CD-ROM. Now most PC are sold without CD-ROM but with bootable USB ports instead. The iso2exe'd ISO image can be renamed to an EXE file to create an USB boot stick (or boot SliTaz directly in some cases).
You can create iso2exe'd images with any SliTaz iso file version :
- for Linux : with http://cook.slitaz.org/cooker.cgi?download=../wok/syslinux-extra/taz/syslinux-extra-4.06/fs/usr/bin/iso2exe
- for Windows or DOS : with http://mirror.slitaz.org/boot/isohybrid.exe
The 'virus' source files are in http://hg.slitaz.org/wok/file/tip/syslinux/stuff/iso2exe
To 'remove the virus' : dd if=/dev/zero bs=32k count=1 of=slitaz-rolling.iso conv=notrunc
* False positive *
Offline
Probably I should have included some additional info in my first post.
My virusscanner is Avira Free Antivirus, up to date and one of the better ones, especially among the free versions.
I got the message while installing Slitaz Rolling via VirtualBox. The .iso file was mounted as a virtual CD. After that I repeated the download and scanned the file before doing anything else with it. The result was the same: detected TR/Crypt.ULPM.Gen.
Now to answer the replies so far:
@Trixar_Za: Yes, it could be a false positive, that's always possible. The VBox method I used is one of the ways to expose Windows to this kind of malware.
@Aleksej: I have a lot of confidence in Slitaz Developers! However, that doesn't mean nothing can go wrong. It is always possible that a file is somehow infected, even when one is not working under Windows. Shit happens but I've been around here long enough to know this will never be done by you guys on purpose.
@Bellard: Do you mean to say you found where the detection comes from? That would be great. If you want I can try to download these files and verify that's where the report comes from.
@all: I don't think this is a particularly mean Trojan. First of all it is very old and then it is merely classified as malware. Reason for me to report it is simply that anyone who wants to give Slitaz a try will not be inclined to continue with it after receiving such a message from the virusscanner. That would be a real shame.
/emgi
Offline
In my experience Avari is worse than most malware. It spreads itself to systems that even don't have it via usb devices and it's near impossible to stop this behaviour - even if you disable and remove avari.
This 'Malware' allows you to run the iso like it's an exe file so you can create a LiveUSB. It's for convience and removing it will be about as useful as banning guns. Malicious people will STILL abuse it, while the innocent suffer.
Offline
The last Rolling.iso I downloaded dated from 09-03-2012. That one did not give me this message but I had some other problems with it. So I decided to get the latest version, on 28-04-2013, before trying anything else.
The culprit definitely is this one: http://mirror.slitaz.org/boot/isohybrid.exe
Clicking it in Ballard's post immediately gets me the same Vscan message.
As much as I would like to believe this is a false positive, the different behavior between the versions doesn't add up unless there has been a change to this iso2exe between yesterday and ~two months earlier? Isn't this piece of code in there for much longer than that?
/emgi
Offline
It's a false positive because only 2 out of 42 anti-virus scanners lists it (which is only 4.7% mathematically), with only Avari being the one to call it TR/Crypt.ULPM.Gen while eSafe calls it a Suspicious file according to the link Aleksej provided.
Me, Bellard and Aleksej agree that this is a false positive and that it only has to do with Avari. Using something like AVG, Kaspersky or ClamAV wouldn't bring up this result.
We aren't going to fix something that isn't broke because 1 out of 42 AVs has a false positive. It's Avari's problem and not ours.
Offline
Pages: 1
[ Generated in 0.017 seconds, 7 queries executed - Memory usage: 1.55 MiB (Peak: 1.77 MiB) ]