![]() |
#1 |
Junior Member
![]() Posts: 2
Karma: 10
Join Date: Mar 2017
Device: Kindle Paperwhite
|
Calibre v2.82.0 - Virus Scanner Alert
I've just had an alert from ClamXav saying that there is an issue with the latest v2.82.0 of Calibre. I am using macOS Sierra and the latest version and refs of ClamXav.
Exact alert is: /Applications/calibre.app/Contents/Resources/resources/compiled_coffeescript.zip: Heuristics.Filetype.ZipWithJS-6136370-0 FOUND Anyone have any idea why this has happened? Is it a false positive? I have contacted ClamX re the issue but wondered if anyone was seeing similar with other scanners? I can't scan online as Calibre s 202mb. Any help greatly appreciated. Radar UPDATE I have heard back from ClamX and have they have following to add: ****************** Downloaded Calibre 2.82.0 and can confirm the detection. The signature was just added by ClamAV yesterday in Daily - 23230 which would have shown up as a ClamXav update today and looks like this: VIRUS NAME: Heuristics.Filetype.ZipWithJS-6136370-0 CONTAINER TYPE: CL_TYPE_ZIP CONTAINER SIZE: ANY FILENAME REGEX: \.[A-Za-z]{3}\.js$ COMPRESSED FILESIZE: ANY UNCOMPRESSED FILESIZE: ANY ENCRYPTION: IGNORED FILE POSITION: 1 CRC SUM: ANY So I would have to guess that it's not a false positive in that it is a zip file that contains javascript files, which is what it's designed to find. That doesn't mean there is anything wrong with doing that, just that it's suspicious to do so. ****************** This means that its possible that Calibre had this file before but the signatures weren't picking it up. Be nice to know what the file is and that it is harmless and was there before Last edited by Radar1968; 03-24-2017 at 05:16 PM. |
![]() |
![]() |
![]() |
#2 |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 28,534
Karma: 204127028
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
|
Flagging any zipfile that contains a javascript file in it seems over-the-top aggressive. That would flag pretty-much any Kobo kepub book.
I can't speak as to what that file actually is, but regardless ... that particular heuristic test wasn't thought out very well. ![]() And in my personal opinion/experience: between calibre and antivirus software ... the antivirus software loses (at least when calibre is downloaded from official locations). Last edited by DiapDealer; 03-24-2017 at 05:55 PM. |
![]() |
![]() |
Advert | |
|
![]() |
#3 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,166
Karma: 1410083
Join Date: Nov 2010
Location: Germany
Device: Sony PRS-650
|
This version is public since a week now without complains. So no, I don't think there is a general problem. I don't know where you download your installation set. I always download from the official source (https://calibre-ebook.com/download) and hat never a virus problem. But I know there are all the time some external AV with regular false alarms.
|
![]() |
![]() |
![]() |
#4 | |
Junior Member
![]() Posts: 2
Karma: 10
Join Date: Mar 2017
Device: Kindle Paperwhite
|
Quote:
Like I said I believe its probably always been there and the update to def has suddenly picked it up and is being, as DiapDealer suggested, overly aggressive. Whilst on the subject of downloading Calibre, I can't seem to find any SHA1 sigs for the downloads. Am I missing something? I always like to check these where I can for anything I download. |
|
![]() |
![]() |
![]() |
#5 |
Resident Curmudgeon
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 79,612
Karma: 145864263
Join Date: Nov 2006
Location: Roslindale, Massachusetts
Device: Kobo Libra 2, Kobo Aura H2O, PRS-650, PRS-T1, nook STR, PW3
|
False positive. Calibre does not have a virus or trojan. If this false positive is not fixed, it will be time to find a different AV.
Last edited by JSWolf; 03-24-2017 at 06:49 PM. |
![]() |
![]() |
Advert | |
|
![]() |
#6 |
null operator (he/him)
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 21,693
Karma: 29711016
Join Date: Mar 2012
Location: Sydney Australia
Device: none
|
I wouldn't be at all surprised if the content server didn't contain a line or three of javascript.
I think the new one uses Rapydscript for which Kovid has written a transpiler, ==>> A transpiler for a Python like language to JavaScript. Yeah, I'd never hear of a transpiler either, sounds like it would be handy if you were building a dock ![]() BR Last edited by BetterRed; 03-25-2017 at 01:55 AM. |
![]() |
![]() |
![]() |
#7 | |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,166
Karma: 1410083
Join Date: Nov 2010
Location: Germany
Device: Sony PRS-650
|
Quote:
They are available on the alternate download location for calibre https://www.fosshub.com/Calibre.html |
|
![]() |
![]() |
![]() |
#8 |
creator of calibre
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,299
Karma: 27111240
Join Date: Oct 2006
Location: Mumbai, India
Device: Various
|
All calibre isntaller files are signed, for windwos and os x the signatures are in the installer and verified by the OS when installed, for linux you need to verify them manually and there is a link to them on the main download page.
And yes, this is a false positive: https://manual.calibre-ebook.com/faq...a-virus-trojan |
![]() |
![]() |
![]() |
#9 |
Junior Member
![]() Posts: 1
Karma: 10
Join Date: Mar 2017
Device: iPhone
|
Heuristics.Filetype.ZipWithJS-6162396-0
Actually, it cannot be a false positive since Heuristic signatures only detect suspicious files, not necessarily infected ones. In this case it is looking for any zip file that contains one or more javascript files, which is what compiled_coffeescript.zip is. Users should simply verify that the detection is a valid file and ignore any future reports.
|
![]() |
![]() |
![]() |
#10 | |
Resident Curmudgeon
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 79,612
Karma: 145864263
Join Date: Nov 2006
Location: Roslindale, Massachusetts
Device: Kobo Libra 2, Kobo Aura H2O, PRS-650, PRS-T1, nook STR, PW3
|
Quote:
|
|
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Suspected virus detected in calibre-2.58.0.msi | Contemplator | Calibre | 3 | 06-03-2016 06:12 AM |
Virus alert visiting Onyx International homepage | Philju | Onyx Boox | 5 | 10-03-2013 07:09 AM |
Calibre virus? | huffy49 | Calibre | 8 | 10-29-2012 10:33 PM |
New user - Kindle, Calibre, maybe book scanner | anoved | Introduce Yourself | 3 | 02-06-2012 12:04 AM |
Virus Scanner found something | Gustav Gans | Sony Reader Dev Corner | 1 | 01-06-2012 12:48 PM |