View Single Post
Old 07-06-2017, 04:39 AM   #1
stretch
Junior Member
stretch began at the beginning.
 
Posts: 1
Karma: 10
Join Date: Jul 2017
Location: Hertfordshire, UK
Device: Sony PRS350
Trojan detected in 3.2.1

Hi

My first post as a heads up in case important. First let me say Calibre is superb and one of my go to apps, always installed on any machine I have. Great work Kovid!

I just installed the 3.2.1 update (win7/64) and then last night (coincidentally) did a full virus scan - machine has the MS security essentials. It's a company machine.

Output from essentials:

Category: Trojan

Description: This program is dangerous and executes commands from an attacker.

Recommended action: Remove this software immediately.

Items:
containerfile:C:\Users\jeff ellis\Downloads\calibre-3.2.1.msi
containerfile:C:\Windows\Installer\3fb8a2.msi
file:C:\Program Files (x86)\Calibre2\app\DLLs\psutil._psutil_windows.pyd
file:C:\Program Files (x86)\Calibre2\app\DLLs\win32evtlog.pyd
file:C:\Program Files (x86)\Calibre2\app\DLLs\_ctypes_test.pyd
file:C:\Program Files (x86)\Calibre2\app\DLLs\_sqlite3.pyd
file:C:\Program Files (x86)\Calibre2\app\DLLs\_testcapi.pyd
file:C:\Users\jeff ellis\Downloads\calibre-3.2.1.msi->calibre.cab->file_124
file:C:\Users\jeff ellis\Downloads\calibre-3.2.1.msi->calibre.cab->file_181
file:C:\Users\jeff ellis\Downloads\calibre-3.2.1.msi->calibre.cab->file_209
file:C:\Users\jeff ellis\Downloads\calibre-3.2.1.msi->calibre.cab->file_217
file:C:\Users\jeff ellis\Downloads\calibre-3.2.1.msi->calibre.cab->file_219
file:C:\Windows\Installer\3fb8a2.msi->calibre.cab->file_124
file:C:\Windows\Installer\3fb8a2.msi->calibre.cab->file_181
file:C:\Windows\Installer\3fb8a2.msi->calibre.cab->file_209
file:C:\Windows\Installer\3fb8a2.msi->calibre.cab->file_217
file:C:\Windows\Installer\3fb8a2.msi->calibre.cab->file_219

I cleaned as suggested by essentials and Calibre still works as expected. No harm done.
I completely understand this may have been a false positive but post in case it is important.
Keep up the great work!
Cheers
Jeff
stretch is offline   Reply With Quote