This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

False positive with Symantec AV - trojan.zlob (?)

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1460
Last Updated: 2006-07-04 23:20:58 UTC
"We have received several emails regarding Wireshark (the new version of Ethereal) being detected as infected with trojan.zlob. After investigation it appears that this is a false positive with Symantec AV def's that are currently in use and that it is actually the NSIS (Nullsoft Installer*) that is triggering the alert. Nullsoft Installer (NSIS) is an open source program that is used by many companies including WINAMP, WireShark and probably others to create low cost installers. Apparently this is not the first time that Symantec has had a false positive on the NSIS installer."

* http://nsis.sourceforge.net/Main_Page

WinAmp Advisory
- http://forums.winamp.com/showthread.php?s=&threadid;=250160

:(
FYI…

- http://isc.sans.org/diary.php?storyid=1462
Last Updated: 2006-07-05 20:14:23 UTC
"We received an email from Brian at Symantec confirming that the trojan.zlob was indeed a false positive.
His email states:
"We have confirmed that this false positive was corrected in virus definitions released on July 3, 2006."
So for those that have been getting this virus warning when trying to download apps using the NSIS installer, update your def's and try it again."

:(