win32 installer download from chrome report 'appears malicious' (false positive)

Bug #1333533 reported by Antoine
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
HomeBank
Invalid
Undecided
Maxime DOYEN

Bug Description

When I download the 4.6 windows installer, Google Chrome block the file informing that it contains a bad software. I tried with Firefox (because it could be a positive false), but my antivirus (Panda cloud antivirus) block the setup file. The detected virus is w32/exploit.gen.

Is this issue specific to my computer (Win 7) or is the setup file really infected ?

Tags: os-windows
Revision history for this message
Maxime DOYEN (mdoyen) wrote :

Apart if my PC is infected and I don't know, which seems not to be the case.
I use Win7 Pro 64 and MSE which report nothing both on my PC and the setup file.
To generate the install I uses Ino Setup Script

Could you download the setup file, and just scan it to learn more if possible ?

Revision history for this message
Antoine (tawane) wrote :

I can download the file on another computer and test the setup with MSE and online antivirus scanner. I only need the link to download the file, since it is not available anymore on the website ;)

Revision history for this message
Antoine (tawane) wrote :

Apparently other people have similar issues https://www.facebook.com/homebank/posts/713852041985891

Panda antivirus scan told me that the file is infected by w32/exploit.gen trojan, I don't have more information.
I am not anymore in my home so I can't scan again the file, and I still can't download the file from homebank website. Maybe you can put it on another server or on free.fr server in private, and share the link here.

Revision history for this message
Maxime DOYEN (mdoyen) wrote :
Maxime DOYEN (mdoyen)
Changed in homebank:
status: New → In Progress
assignee: nobody → Maxime Doyen (mdoyen)
Revision history for this message
Maxime DOYEN (mdoyen) wrote :

Just scan the installer and direct url link with https://www.virustotal.com
no virus detected on most AV

information type: Private Security → Public
summary: - Virus in Homebank 4.6 Win32 installer
+ 4.6 Win32 installer sometime report a virus (false positive)
Revision history for this message
Antoine (tawane) wrote : Re: 4.6 Win32 installer sometime report a virus (false positive)

Ok, with the link, I performed some tests.

On my home computer (Win 7 Pro 64), I still can't donwload the file with Google Chrome. At the end of the download, Chrome warn about malware program, and provide a link to https://support.google.com/chrome/answer/4412392?p=ib_download_blocked&rd=1
If I download with Firefox, everything is ok, and analyzing file with my antivirus (Panda cloud) or the online scanner you provided doesn't report anything.

On my work computer (Ubuntu) I have a virtualbox with Windows XP 32, used only for tests from time to time. There is almost nothing installed on the system, I am pretty sure this environment is secured. It use Microsoft security essentials. Downloading the setup with Chrome blocks with the exactly same issue message (program reported as malware). After moving the setup to the system with another method: MSE doesn't detect anything.

Other information: downloading the file with Chromium 34 on Ubuntu doesn't produce any error.

Summary: There is apparently no Virus on the setup located at http://homebank.free.fr/public/HomeBank-4.6-win32.exe BUT Google Chrome flag this file as malware, and forbid its download.

After installation, the software doesn't run on windows 7 64 bit only. On windows xp 32, it runs perfectly. This is related to another issue, so I will comment or create a new one for this

Revision history for this message
TonyIT (nc8430) wrote :

I've download the source file from
http://homebank.free.fr/public/HomeBank-4.6-win32.exe
and I've tested it with SOPHOS, regularly updated.

No viruses at all and the software works fine with no problem.

XP Pro SP3 32bit - HomeBank 4.6 - Sophos Antivirus - Firefox 30

TonyIT
Ciao

Revision history for this message
Maxime DOYEN (mdoyen) wrote :

Thank for your help guys.

Maybe I have found the trouble after reading part of Chrome documentation.
I have set (into robots.txt) not to explore the folder where I store the installer, as it is an exe and during Google index the file cannot be trusted, it is displayed as a potential malware.

I have just removed that, so let wait for the next indexation and see if I'm right (or not ^^)

Changed in homebank:
status: In Progress → Fix Committed
Maxime DOYEN (mdoyen)
summary: - 4.6 Win32 installer sometime report a virus (false positive)
+ win32 installer download from google chrome report a malware (false
+ positive)
Maxime DOYEN (mdoyen)
tags: added: os-windows
Revision history for this message
Maxime DOYEN (mdoyen) wrote : Re: win32 installer download from google chrome report a malware (false positive)

the problems remains

Changed in homebank:
status: Fix Committed → In Progress
Revision history for this message
Maxime DOYEN (mdoyen) wrote :

iinteresting discussion here, with some silly test tending to say that Chrome dont like self extracting file
https://productforums.google.com/forum/#!topic/chrome/r-9JQIboUmc

summary: - win32 installer download from google chrome report a malware (false
+ win32 installer download from chrome report 'appears malicious' (false
positive)
Maxime DOYEN (mdoyen)
Changed in homebank:
status: In Progress → Triaged
Maxime DOYEN (mdoyen)
Changed in homebank:
status: Triaged → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Related questions

Remote bug watches

Bug watches keep track of this bug in other bug trackers.