zx_p2wav.exe

General Chit Chat about Sinclair Computers and their Clones
Post Reply
RWAP
Posts: 1348
Joined: Thu May 08, 2008 8:42 am
Location: Stoke-on-Trent, UK
Contact:

zx_p2wav.exe

Post by RWAP »

Those who noticed that the website was not working yesterday (22nd January), might be interested to know that it was because the zx_p2wav.exe file was picked up as containing a Trojan.

It can still be downloaded from http://forum.tlienhard.com/phpBB3/downl ... php?id=238
but can anyone re-compile it to ensure it doesn't get identified as a trojan again by virustotal.com (it showed only 4 minor virus engines out of 53 identified an issue with the file).
XorA
Posts: 98
Joined: Thu May 10, 2012 9:14 am
Location: Glasgow, Scotland, UK
Contact:

Re: zx_p2wav.exe

Post by XorA »

Now we know what RWAP has been up to, trojaning our .p files to make a zeddy botnet!
RWAP
Posts: 1348
Joined: Thu May 08, 2008 8:42 am
Location: Stoke-on-Trent, UK
Contact:

Re: zx_p2wav.exe

Post by RWAP »

Well now I have a mass of data as to what you all get up to on your ZX81s.... :D
User avatar
RetroTechie
Posts: 379
Joined: Tue Nov 01, 2011 12:16 am
Location: Hengelo, NL
Contact:

Re: zx_p2wav.exe

Post by RetroTechie »

Well I've had the exact same (bit-for-bit) .zip on my harddrive as is downloaded from above link - for years. I'm surely not the only one who's tried it, so you can be pretty sure that the .exe in it has been through different virus scanners, at various points in time. So if there were a trojan in there, that same .exe would be flagged as trojan by pretty much all scanners today, I think.

In other words: the .exe in above .zip is perfectly safe to run, this is clearly a false positive. Just a thought: would it be useful to report it as such, to maintainers of those few scanners that threw up a false positive? :?:
RWAP
Posts: 1348
Joined: Thu May 08, 2008 8:42 am
Location: Stoke-on-Trent, UK
Contact:

Re: zx_p2wav.exe

Post by RWAP »

I have sent it to the various companies who reported malware in the file.

Not sure what you do about ClamAV which is probably what my hosting company use - its heuristics checker warns about the characteristics of the program (probably the file conversion!)
XorA
Posts: 98
Joined: Thu May 10, 2012 9:14 am
Location: Glasgow, Scotland, UK
Contact:

Re: zx_p2wav.exe

Post by XorA »

How about report it to clamav :-)

http://www.clamav.net/report/report-fp.html
User avatar
PokeMon
Posts: 2264
Joined: Sat Sep 17, 2011 6:48 pm

Re: zx_p2wav.exe

Post by PokeMon »

RWAP wrote:Those who noticed that the website was not working yesterday (22nd January), might be interested to know that it was because the zx_p2wav.exe file was picked up as containing a Trojan.
By the way - I thought the site was longer dead as it did not automatically update the temporarily webcontent (security issue from your provider). Today I tried (after several days with the same message) to press CTRL-F5 for a reload and the forum appeared again. So could loose some more people who think you forum is dead. This is also a wrong handling from your provider which maybe set a too long cache-time for the temporary site. I am using the latest Firefox with default settings. ;)
User avatar
RetroTechie
Posts: 379
Joined: Tue Nov 01, 2011 12:16 am
Location: Hengelo, NL
Contact:

Re: zx_p2wav.exe

Post by RetroTechie »

PokeMon wrote:This is also a wrong handling from your provider (..)
More so: I don't understand why an entire site would be pulled offline, when a trojan is detected. If a provider's anti-virus is so sure it's spotted a trojan lurking in a site, wouldn't it make more sense to stop serving that particular file? (and inform site owner, etc). After all, false positives are pretty much a fact when using a virus-scanner.

Re-compiling the .exe to avoid this issue, is counter-productive imho: Then you'd have 2 .exe's, with zero functional difference between them. One 'clean', and one flagged as 'trojan' by some virus-scanners. Worse: whatever caused virus-scanners to trip on the original .exe, might also cause (other?!?) virus-scanners to trip on the re-compiled .exe. That would just create confusion, and thus doesn't help things at all.
RWAP
Posts: 1348
Joined: Thu May 08, 2008 8:42 am
Location: Stoke-on-Trent, UK
Contact:

Re: zx_p2wav.exe

Post by RWAP »

PokeMon wrote:
RWAP wrote:Those who noticed that the website was not working yesterday (22nd January), might be interested to know that it was because the zx_p2wav.exe file was picked up as containing a Trojan.
By the way - I thought the site was longer dead as it did not automatically update the temporarily webcontent (security issue from your provider). Today I tried (after several days with the same message) to press CTRL-F5 for a reload and the forum appeared again. So could loose some more people who think you forum is dead. This is also a wrong handling from your provider which maybe set a too long cache-time for the temporary site. I am using the latest Firefox with default settings. ;)
That's odd - I did get the same temporary page the next day but as soon as I did SHIFT F5 in Firefox, it updated - maybe CTRL F5 does not clear the cache?
User avatar
PokeMon
Posts: 2264
Joined: Sat Sep 17, 2011 6:48 pm

Re: zx_p2wav.exe

Post by PokeMon »

I think CTRL-F5 does pretty the same as SHIFT-F5 while SHIFT-F5 calls the HTML inspector window in my browser. ;)
Post Reply