{"id":109,"date":"2008-11-08T08:52:00","date_gmt":"2008-11-08T12:52:00","guid":{"rendered":"http:\/\/www.contrapositivediary.com\/?p=109"},"modified":"2008-12-13T22:46:01","modified_gmt":"2008-12-14T02:46:01","slug":"malware-from-sourceforge","status":"publish","type":"post","link":"http:\/\/www.contrapositivediary.com\/?p=109","title":{"rendered":"Malware from SourceForge?"},"content":{"rendered":"<p>I&apos;ve been chasing something very odd here recently. For about a                year nowI have used a FOSS utility called MozBackup to both archive                and move my 1.7 GB mailbase around. It has always worked beautifully,                but when I used it to restore my mailbase onto my new quad-core                machine last week, the mailbase did not come back intact. I was                getting weird error messages about the inbox not truncating when                messages were moved into the junk folder, etc. which made me wonder                what was going on.<\/p>\n<p>Ok. This is a quad-core machine running XP SP3. I deliberately                set it up so that AVG 8 runs during the day and not at 2 ayem, because                I want to observe what effect multiple tasks in multiple cores has                on overall system response. So every day at 1 PM, AVG 8 runs a full                scan. It ran a full scan on all drives yesterday, and came up with                nothing except warnings about a couple of revenant tracking cookies.<\/p>\n<p>Late yesterday afternoon, I copied the current MozBackup installer                file from my installers archive on D: to my &#8220;installed installers&#8221;                folder (where I put installers for software installed on the machine)                on C:. Instantly, AVG 8 set up a howl that it had found a trojan                in MozBackup-1.4.8-EN.exe, the installer for the instance of MozBackup                that I have had installed on the quad-core since June. The trojan                was called Generic12.HTC.<\/p>\n<p>That&apos;s odd in itself: On all the bazillion-squared pages that Google                indexes, there was not a single mention of &#8220;Generic12.HTC&#8221;                yesterday . Nor is there any entry by that name in AVG&apos;s virus encyclopedia.                This morning, however, I suddenly see five or six mentions indexed                during the night. It looks like a false positive, but I&apos;m still                a little nervous. <\/p>\n<p> As a test, I went back to SourceForge and downloaded another copy                of the file. As soon as it was complete in a temp folder, wham!                AVG&apos;s &#8220;resident shield&#8221; utility called it out as Generic12.HTC.                Now, I&apos;m not used to thinking that SourceForge downloads can be                malware sources, though there&apos;s no reason that it&apos;s impossible.                However, the MozBackup-1.4.8-EN.exe file has been on my hard drive                since June, and has passed muster every afternoon that the machine                has been powered up. The file&apos;s time stamp has not changed. I can                only assume that during yesterday&apos;s daily update, AVG brought down                a signature that matched something inside the file\u2014and that                would be a mighty freaky coincidence if true.<\/p>\n<p>The other freaky thing is that after I deleted MozBackup 1.4.8                and installed the previous version 1.4.7 (which is in use on three                of my other machines, including my X41 tablet) the mailbase restore                worked perfectly. So are there two problems here or one?<\/p>\n<p>The handul of reports surfacing this morning seem to indicate that                it&apos;s a false positive, which would make sense, given that it&apos;s been                on this system since June without AVG making noise. So maybe I don&apos;t                need to warn you against the 1.4.8 version. However, it does look                like 1.4.8 doesn&apos;t necessarily import an archive created with 1.4.7.                Yes, a coincidence, and a weird one.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&apos;ve been chasing something very odd here recently. For about a year nowI have used a FOSS utility called MozBackup to both archive and move my 1.7 GB mailbase around. It has always worked beautifully, but when I used it to restore my mailbase onto my new quad-core machine last week, the mailbase did not [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23],"tags":[36,14],"class_list":["post-109","post","type-post","status-publish","format-standard","hentry","category-ideasandanalysis","tag-malware","tag-software"],"_links":{"self":[{"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/posts\/109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=109"}],"version-history":[{"count":1,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/posts\/109\/revisions"}],"predecessor-version":[{"id":140,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/posts\/109\/revisions\/140"}],"wp:attachment":[{"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=109"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}