realbasic-nug
[Top] [All Lists]

Re: ClamXav & REALbasic - trojans?

To: REALbasic NUG <realbasic-nug@lists.realsoftware.com>
Subject: Re: ClamXav & REALbasic - trojans?
From: Bart Silverstrim <bsilver@chrononomicon.com>
Date: Mon, 29 Dec 2008 13:15:13 -0500
Authentication-results: mx.google.com; spf=neutral (google.com: 74.124.194.228 is neither permitted nor denied by best guess record for domain of realbasic-nug-bounces@lists.realsoftware.com) smtp.mail=realbasic-nug-bounces@lists.realsoftware.com
Delivered-to: listarchive@realsoftware.com
In-reply-to: <C4AC60B2-15C2-40FE-B68F-015477F0FC3A@mac.com>
References: <C57EB496.52399%markus_winter@online.de> <C4AC60B2-15C2-40FE-B68F-015477F0FC3A@mac.com>
Reply-to: REALbasic NUG <realbasic-nug@lists.realsoftware.com>
Sender: realbasic-nug-bounces@lists.realsoftware.com
User-agent: Thunderbird 2.0.0.18 (X11/20081125)


Arnaud Nicolet wrote:
Le 29 déc. 08 à 17:08 (soir), Markus Winter a écrit:

Hi all,

as I exchange quite a few files with PC users I thought I give ClamXav a try on ma Mac. Unsurprisingly it flagged a few PC files that were send to me as
infected, however it also flagged two files in the REALbasic framework:

/Applications/REALbasic 2007 Release 3/REALbasic 2007 Release
3.app/Contents/Resources/Frameworks/X86RunHoudini.exe: Trojan.Dropper-12634
FOUND
/Applications/REALbasic 2008 Release 1/REALbasic 2008 Release
1.app/Contents/Resources/Frameworks/X86HoudiniConsole.exe:
Trojan.Agent-40367 FOUND

Are these false positives or real? I use Parallels Desktop from time to time but I find it hard to believe that that could lead to an infection of my Mac
files ...

Well, if you share your Mac hard disk with the host OS, why would you expect an eventual virus to not infect it?
I'd warn you against sharing anything but a small folder with Parallels.

I admit I don't know what are these X86RunHoudini files (a name that does not seem reliable to me, by the way).

Because if you run Windows on a Mac, the Mac filesystem isn't the same one used by Windows, so malware should only be able to infect files that can be seen by the guest software?

SiteAdvisor seems to not list this file as a problem.
http://www.siteadvisor.com/sites/realsoftware.com/downloads/12244716/

_______________________________________________
Unsubscribe or switch delivery mode:
<http://www.realsoftware.com/support/listmanager/>

Search the archives:
<http://support.realsoftware.com/listarchives/lists.html>


<Prev in Thread] Current Thread [Next in Thread>