Menu

VirusAlert downloading 4.1.2. Installer.exe -

2007-07-11
2012-11-13
  • Nobody/Anonymous

    Hi,

    I get a messages from my Firewall appliance, blocking the download.

    Content blocked
    The item you have requested is infected by a virus. It will not be downloaded. 
    URL http://heanet.dl.sourceforge.net/sourceforge/notepad-plus/npp.4.1.2.Installer.exe
    Virus name W32/Downloader2.AKGY(click here for more info)

      Details

     
    url http://heanet.dl.sourceforge.net/sourceforge/notepad-plus/npp.4.1.2.Installer.exe
    method GET
    protocol http
    user-profile Default (Response)
    last-scanner /usr/lib/libweedcss.so
    virus-infected yes
    virus-name W32/Downloader2.AKGY
    Reject-Subject Blocked by Surf Protection
    reason Virus 'W32/Downloader2.AKGY' found
    Date Wed, 11 Jul 2007 13:36:19 GMT
    Server Apache/2.2.4 (Unix)
    Last-Modified Sun, 20 May 2007 23:37:30 GMT
    ETag "61101615-1889bf-430ef4cc2e280"
    Content-Length 1608127
    Content-Type application/octet-stream
    X-Cache MISS from fw01.systrion.de
    Connection close
    Proxy-Connection close
    action reject

     
    • steakhacher

      steakhacher - 2007-07-11

      It seems strange, I use notpad++ with norton antivirus and there is no problem. Moreover it is an open source application so it seems so strange that a virus were included.

       
      • DooGie

        DooGie - 2007-07-11

        I'd suggest that all NP++ users who get this submit the file to their respective AV companies for analasys. Either it's a false positive or the download file has been infected from a 3rd party.
        I've been using NP++ for over 12 months and have had no probs like this but just to check I'll download a fresh copy and see what nod32 makes of it.

         
        • Nobody/Anonymous

          I've submitted a ticket/inquiry to AVG. It's not a fresh download, it's the copy we have been using since 4.1.2 was released. This only started with todays definition updates.

           
          • DooGie

            DooGie - 2007-07-11

            Showed clean with my nod32 so submitted it online to http://www.virustotal.com/en/indexf.html.

            Result there was fine

            Antivirus      Versión      Last Update      Result

            AhnLab-V3    2007.7.11.1    20070711    no virus found
            AntiVir     7.4.0.39    20070711    no virus found
            Authentium    4.93.8    20070711    no virus found
            Avast    4.7.997.0    20070711    no virus found
            AVG    7.5.0.476    20070711    no virus found
            BitDefender    7.2    20070711    no virus found
            CAT-QuickHeal    9.00    20070711    no virus found
            ClamAV    devel-20070416    20070711    no virus found
            DrWeb    4.33    20070711    no virus found
            eSafe    7.0.15.0    20070710    no virus found
            eTrust-Vet    30.8.3779    20070711    no virus found
            Ewido    4.0    20070711    no virus found
            FileAdvisor    1    20070711    no virus found
            Fortinet    2.91.0.0    20070711    PossibleThreat
            F-Prot    4.3.2.48    20070710    no virus found
            Ikarus    T3.1.1.8    20070711    no virus found
            Kaspersky    4.0.2.24    20070711    no virus found
            McAfee    5072    20070711    no virus found
            Microsoft    1.2704    20070711    no virus found
            NOD32v2    2394    20070711    no virus found
            Norman    5.80.02    20070711    no virus found
            Panda    9.0.0.4    20070711    no virus found
            Sophos    4.19.0    20070706    no virus found
            Sunbelt    2.2.907.0    20070711    no virus found
            Symantec    10    20070711    no virus found
            TheHacker    6.1.6.144    20070709    no virus found
            VBA32    3.12.0.2    20070710    no virus found
            VirusBuster    4.3.23:9    20070711    no virus found
            Webwasher-Gateway    6.0.1    20070711    no virus found
            Aditional information
            File size: 1608127 bytes
            MD5: 1e52ac113f3713dfd500ff29755102d0
            SHA1: 0de65765da0d7da3de0aebe6402ebb489168f3fd
            packers: BINARYRES, BINARYRES

             
            • DooGie

              DooGie - 2007-07-11

              My earlier post showed the scan of the NP++ installation exe.
              I submitted the NP++ executable to the same sit and all seems well apart from AVG which is throwing a hissy fit.

              Antivirus      Versión      Last Update      Result
              AhnLab-V3    2007.7.11.1    20070711    no virus found
              AntiVir    7.4.0.39    20070711    no virus found
              Authentium    4.93.8    20070711    no virus found
              Avast    4.7.997.0    20070711    no virus found
              AVG    7.5.0.476    20070711    Generic5.HLS
              BitDefender    7.2    20070711    no virus found
              CAT-QuickHeal    9.00    20070711    no virus found
              ClamAV    devel-20070416    20070711    no virus found
              DrWeb    4.33    20070711    no virus found
              eSafe    7.0.15.0    20070710    no virus found
              eTrust-Vet    30.8.3779    20070711    no virus found
              Ewido    4.0    20070711    no virus found
              FileAdvisor    1    20070711    no virus found
              Fortinet    2.91.0.0    20070711    no virus found
              F-Prot    4.3.2.48    20070710    no virus found
              Ikarus    T3.1.1.8    20070711    no virus found
              Kaspersky    4.0.2.24    20070711    no virus found
              McAfee    5072    20070711    no virus found
              Microsoft    1.2704    20070711    no virus found
              NOD32v2    2394    20070711    no virus found
              Norman    5.80.02    20070711    no virus found
              Panda    9.0.0.4    20070711    no virus found
              Sophos    4.19.0    20070706    no virus found
              Sunbelt    2.2.907.0    20070711    no virus found
              Symantec    10    20070711    no virus found
              TheHacker    6.1.6.144    20070709    no virus found
              VBA32    3.12.0.2    20070710    no virus found
              VirusBuster    4.3.23:9    20070711    no virus found
              Webwasher-Gateway    6.0.1    20070711    no virus found
              Aditional information
              File size: 786432 bytes
              MD5: 7121adef6f206e3ebbbf38a4c36d8b24
              SHA1: 29fc254de6ee5f23c4381711001b2ff3cba50e3b

              I strongly feel that AVG is throwing up a false positive. So as far as I'm concerned no threat at all. Not that I thought there would be.

               
              • Nobody/Anonymous

                AVG appears to have resolved the issue with todays updated definitions. Nothing noted in their changelog though.

                 
    • Nobody/Anonymous

      hi

      same problem here
      when i updated my antivirus(AVG7.5 PRO) definition today (11.07.2007), i immediately got a msg that notepad++.exe is infected by "Trojan horse Generic5.HLS"

      i thought that just my copy of notepad++ was infected, but it seams that even the copy from SourceForge is infected.

      it may be that the code of these new threads of viruses resambles the code found in notepad++.exe

      waiting for a patch of some sort :)

      BETng4U
      Romania

       
    • Nobody/Anonymous

      Same thing happening here. Suddenly it's a virus installed on all of our computers.

       
    • Ryan Liebenberg

      Ryan Liebenberg - 2007-07-11

      It certainly seems to be in the 4.1.2 version, uninstalling it and installing 4.1.1 scanned cleaned by AVG7.5Pro. But have submitted a note to AVG, so perhaps they'll check it out.

      -Ryan

       
      • DooGie

        DooGie - 2007-07-11

        Sorry. URL in previous post should read http://www.virustotal.com/ my bad.

         
    • Nobody/Anonymous

      This workaround http://sourceforge.net/forum/message.php?msg_id=4408362 will bring the NP++ back...thx to lurk

       
    • Nobody/Anonymous

      Thats right, latest AVG found the virus. I think its false alert.
      Just use v4.1.1

       
    • Nobody/Anonymous

      Update AVG, the latest one fixes this.

       
    • Nobody/Anonymous

      AVG it has resolved the problem