Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Software > Calibre

Notices

Reply
 
Thread Tools Search this Thread
Old 03-24-2017, 05:11 PM   #1
Radar1968
Junior Member
Radar1968 began at the beginning.
 
Posts: 2
Karma: 10
Join Date: Mar 2017
Device: Kindle Paperwhite
Calibre v2.82.0 - Virus Scanner Alert

I've just had an alert from ClamXav saying that there is an issue with the latest v2.82.0 of Calibre. I am using macOS Sierra and the latest version and refs of ClamXav.

Exact alert is:
/Applications/calibre.app/Contents/Resources/resources/compiled_coffeescript.zip: Heuristics.Filetype.ZipWithJS-6136370-0 FOUND

Anyone have any idea why this has happened? Is it a false positive?

I have contacted ClamX re the issue but wondered if anyone was seeing similar with other scanners? I can't scan online as Calibre s 202mb.

Any help greatly appreciated.
Radar

UPDATE
I have heard back from ClamX and have they have following to add:
******************
Downloaded Calibre 2.82.0 and can confirm the detection.

The signature was just added by ClamAV yesterday in Daily - 23230 which would have shown up as a ClamXav update today and looks like this:

VIRUS NAME: Heuristics.Filetype.ZipWithJS-6136370-0
CONTAINER TYPE: CL_TYPE_ZIP
CONTAINER SIZE: ANY
FILENAME REGEX: \.[A-Za-z]{3}\.js$
COMPRESSED FILESIZE: ANY
UNCOMPRESSED FILESIZE: ANY
ENCRYPTION: IGNORED
FILE POSITION: 1
CRC SUM: ANY

So I would have to guess that it's not a false positive in that it is a zip file that contains javascript files, which is what it's designed to find. That doesn't mean there is anything wrong with doing that, just that it's suspicious to do so.
******************

This means that its possible that Calibre had this file before but the signatures weren't picking it up.
Be nice to know what the file is and that it is harmless and was there before

Last edited by Radar1968; 03-24-2017 at 05:16 PM.
Radar1968 is offline   Reply With Quote
Old 03-24-2017, 05:52 PM   #2
DiapDealer
Grand Sorcerer
DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.
 
DiapDealer's Avatar
 
Posts: 28,534
Karma: 204127028
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
Flagging any zipfile that contains a javascript file in it seems over-the-top aggressive. That would flag pretty-much any Kobo kepub book.

I can't speak as to what that file actually is, but regardless ... that particular heuristic test wasn't thought out very well.

And in my personal opinion/experience: between calibre and antivirus software ... the antivirus software loses (at least when calibre is downloaded from official locations).

Last edited by DiapDealer; 03-24-2017 at 05:55 PM.
DiapDealer is offline   Reply With Quote
Advert
Old 03-24-2017, 05:52 PM   #3
Divingduck
Wizard
Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.
 
Posts: 1,166
Karma: 1410083
Join Date: Nov 2010
Location: Germany
Device: Sony PRS-650
This version is public since a week now without complains. So no, I don't think there is a general problem. I don't know where you download your installation set. I always download from the official source (https://calibre-ebook.com/download) and hat never a virus problem. But I know there are all the time some external AV with regular false alarms.
Divingduck is offline   Reply With Quote
Old 03-24-2017, 06:33 PM   #4
Radar1968
Junior Member
Radar1968 began at the beginning.
 
Posts: 2
Karma: 10
Join Date: Mar 2017
Device: Kindle Paperwhite
Quote:
Originally Posted by Divingduck View Post
This version is public since a week now without complains. So no, I don't think there is a general problem. I don't know where you download your installation set. I always download from the official source (https://calibre-ebook.com/download) and hat never a virus problem. But I know there are all the time some external AV with regular false alarms.
Downloaded from the official site so I'm not doubting its integrity, just why its caused an alert this time.

Like I said I believe its probably always been there and the update to def has suddenly picked it up and is being, as DiapDealer suggested, overly aggressive.

Whilst on the subject of downloading Calibre, I can't seem to find any SHA1 sigs for the downloads. Am I missing something? I always like to check these where I can for anything I download.
Radar1968 is offline   Reply With Quote
Old 03-24-2017, 06:47 PM   #5
JSWolf
Resident Curmudgeon
JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.
 
JSWolf's Avatar
 
Posts: 79,612
Karma: 145864263
Join Date: Nov 2006
Location: Roslindale, Massachusetts
Device: Kobo Libra 2, Kobo Aura H2O, PRS-650, PRS-T1, nook STR, PW3
False positive. Calibre does not have a virus or trojan. If this false positive is not fixed, it will be time to find a different AV.

Last edited by JSWolf; 03-24-2017 at 06:49 PM.
JSWolf is offline   Reply With Quote
Advert
Old 03-24-2017, 11:24 PM   #6
BetterRed
null operator (he/him)
BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.BetterRed ought to be getting tired of karma fortunes by now.
 
Posts: 21,693
Karma: 29711016
Join Date: Mar 2012
Location: Sydney Australia
Device: none
I wouldn't be at all surprised if the content server didn't contain a line or three of javascript.

I think the new one uses Rapydscript for which Kovid has written a transpiler, ==>> A transpiler for a Python like language to JavaScript.

Yeah, I'd never hear of a transpiler either, sounds like it would be handy if you were building a dock

BR

Last edited by BetterRed; 03-25-2017 at 01:55 AM.
BetterRed is online now   Reply With Quote
Old 03-25-2017, 05:31 AM   #7
Divingduck
Wizard
Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.Divingduck ought to be getting tired of karma fortunes by now.
 
Posts: 1,166
Karma: 1410083
Join Date: Nov 2010
Location: Germany
Device: Sony PRS-650
Quote:
Originally Posted by Radar1968 View Post
Whilst on the subject of downloading Calibre, I can't seem to find any SHA1 sigs for the downloads. Am I missing something? I always like to check these where I can for anything I download.
No, I was looking for it too but it seems Kovid had not attach it.

They are available on the alternate download location for calibre https://www.fosshub.com/Calibre.html
Divingduck is offline   Reply With Quote
Old 03-26-2017, 10:30 PM   #8
kovidgoyal
creator of calibre
kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.kovidgoyal ought to be getting tired of karma fortunes by now.
 
kovidgoyal's Avatar
 
Posts: 45,299
Karma: 27111240
Join Date: Oct 2006
Location: Mumbai, India
Device: Various
All calibre isntaller files are signed, for windwos and os x the signatures are in the installer and verified by the OS when installed, for linux you need to verify them manually and there is a link to them on the main download page.

And yes, this is a false positive: https://manual.calibre-ebook.com/faq...a-virus-trojan
kovidgoyal is offline   Reply With Quote
Old 03-26-2017, 11:35 PM   #9
alvarnell
Junior Member
alvarnell began at the beginning.
 
Posts: 1
Karma: 10
Join Date: Mar 2017
Device: iPhone
Heuristics.Filetype.ZipWithJS-6162396-0

Actually, it cannot be a false positive since Heuristic signatures only detect suspicious files, not necessarily infected ones. In this case it is looking for any zip file that contains one or more javascript files, which is what compiled_coffeescript.zip is. Users should simply verify that the detection is a valid file and ignore any future reports.
alvarnell is offline   Reply With Quote
Old 03-27-2017, 06:01 AM   #10
JSWolf
Resident Curmudgeon
JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.
 
JSWolf's Avatar
 
Posts: 79,612
Karma: 145864263
Join Date: Nov 2006
Location: Roslindale, Massachusetts
Device: Kobo Libra 2, Kobo Aura H2O, PRS-650, PRS-T1, nook STR, PW3
Quote:
Originally Posted by alvarnell View Post
Actually, it cannot be a false positive since Heuristic signatures only detect suspicious files, not necessarily infected ones. In this case it is looking for any zip file that contains one or more javascript files, which is what compiled_coffeescript.zip is. Users should simply verify that the detection is a valid file and ignore any future reports.
When an anti-virus program flags something as possibly infected and it's not, that is a false positive.
JSWolf is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Suspected virus detected in calibre-2.58.0.msi Contemplator Calibre 3 06-03-2016 06:12 AM
Virus alert visiting Onyx International homepage Philju Onyx Boox 5 10-03-2013 07:09 AM
Calibre virus? huffy49 Calibre 8 10-29-2012 10:33 PM
New user - Kindle, Calibre, maybe book scanner anoved Introduce Yourself 3 02-06-2012 12:04 AM
Virus Scanner found something Gustav Gans Sony Reader Dev Corner 1 01-06-2012 12:48 PM


All times are GMT -4. The time now is 03:54 AM.


MobileRead.com is a privately owned, operated and funded community.