Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

virus? #11

Closed
hymie0 opened this issue Aug 17, 2017 · 7 comments
Closed

virus? #11

hymie0 opened this issue Aug 17, 2017 · 7 comments

Comments

@hymie0
Copy link

hymie0 commented Aug 17, 2017

Greetings.

I've been trying to download https://github.com/NoMoreFood/putty-cac/blob/master/binaries/x64/pageant.exe which I believe is version 0.70.2 .

My Symantec Endpoint Protection is marking it "Infected" with "WS.Reputation.1"

I found version 0.70.1 and it appears that Symantec is happy with this version.

Can you please look into this?

(Side note -- I know this is a github thing and not a you thing, but the "tags" are sorted in a weird way, so 0.70 is above 0.70.u2 and 0.70.u1 even though 0.70.u1/2 are newer.)

@NoMoreFood
Copy link
Owner

NoMoreFood commented Aug 17, 2017 via email

@hymie0
Copy link
Author

hymie0 commented Aug 17, 2017

Thanks.

@hymie0 hymie0 closed this as completed Aug 17, 2017
@bluikko
Copy link

bluikko commented Aug 17, 2017

Kaspersky is also detecting infections, only on 0.70u2:

  • PuTTY: "Shelma.ah" and "Shelma.ao"
  • PSCP: "Shelma.bb"

Those are signature-based false positives and not due to reputation or heuristics.

@NoMoreFood
Copy link
Owner

NoMoreFood commented Aug 17, 2017 via email

@NoMoreFood
Copy link
Owner

@bluikko, @hymie0 Before I take action on this, can you confirm you're scanners are still finding an issue after their latest virus update? I fed the file through https://virusdesk.kaspersky.com/?_ga=2.173162666.84273751.1503098125-1435948688.1503098125 and it does not report an issue so maybe they fixed it.

@bluikko
Copy link

bluikko commented Aug 19, 2017

@NoMoreFood The false positive was present on database from 2017-08-14 (at least) until 2017-08-16 (did not test databases after this). On the latest database from today 2017-08-19 there is no more false positive.

So indeed Kaspersky seems to have fixed this issue.

@hymie0
Copy link
Author

hymie0 commented Aug 23, 2017

Sorry for the delay. I am now able to download, install, and run pagent 0.70.2 without virus warnings.

Thank you for your help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants