Jump to content
SubSpace Forum Network

Recommended Posts

Posted (edited)

There appears to be a worm in some of the .svn directories and some other files. I downloaded a fresh copy from the SVN server and scanned it. The complete log is attached, the infected files are here:

./disc_client/zones/.svn/text-base/test.svn-base: Worm.Stration.WR FOUND
./disc_client/zones/test: Worm.Stration.WR FOUND
./disc_client/bin/zones/.svn/text-base/test.svn-base: Worm.Stration.WR FOUND
./disc_client/bin/zones/test: Worm.Stration.WR FOUND
./disc_client/old/Unit Tests/Modules/.svn/text-base/ModuleManager.dll.svn-base: Worm.Stration.WR FOUND
./disc_client/old/Unit Tests/Modules/ModuleManager.dll: Worm.Stration.WR FOUND

 

A couple days after downloading, a worm appeared on my system that messed with my Windows Explorer settings and copied itself onto my USB drive. Still trying to get it off of my system. I don't know if discretion is the cause, but the only other virus my scanner detected was CSEdit.exe, which I know is safe.

EDIT2: One of the computers in my class had a worm on it, which transferred itself onto my thumbdrive. This worm isn't affiliated with the discretion virus.

 

Scanned with ClamAV

 

EDIT: http://www.viruslist.com/en/viruses/encycl...?virusid=140652

scan.log

Edited by Gannon8
Posted
that's not good, my virus scanner doesn't pick it up even if I manually scan the file :/. Is the binary release on sourceforge okay?

 

Nope, It's affected.

 

-CRe>

Posted
I have confirmed the virus.

Did you confirm it using ClamAV or another virus scanner?

 

Like Sass, I checked for the malicious executable in my system directory as well as the registry keys and don't see it. It may be a false positive, but I took off the binary from sourceforge as a precaution while we figure things out.

Posted (edited)
I've heard of at least one program which uses auto-update functionality being caught as false-positives on certain virus scanners (since some viruses include capability to download new programs.) Might want to keep that in mind. Edited by Kilo
Posted
I've heard of at least one program which uses auto-update functionality being caught as false-positives on certain virus scanners (since some viruses include capability to download new programs.) Might want to keep that in mind.

I do not believe the auto-update program would be in a file called "zone/test" not the module manager, so I do not believe that is the problem.

  • 2 weeks later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...