Bug 78573 - Trojan in download
Summary: Trojan in download
Status: RESOLVED NOTOURBUG
Alias: None
Product: LibreOffice
Classification: Unclassified
Component: LibreOffice (show other bugs)
Version:
(earliest affected)
unspecified
Hardware: x86 (IA32) Windows (All)
: medium blocker
Assignee: Not Assigned
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-05-12 04:01 UTC by realleslie
Modified: 2014-05-14 06:53 UTC (History)
0 users

See Also:
Crash report or crash signature:
Regression By:


Attachments
log of trojan detection (3.52 KB, text/html)
2014-05-12 04:01 UTC, realleslie
Details

Note You need to log in before you can comment on or make changes to this bug.
Description realleslie 2014-05-12 04:01:45 UTC
Created attachment 98877 [details]
log of trojan detection

Just downloaded for the first time. Comodo detected Cloudscanner.Trojan.Gen@2@1 on installation, in soffice.bin. Obviously uninstalling.
Comment 1 Mike Kaganski 2014-05-13 11:30:13 UTC
What have you downloaded and from which address& Have you used download page from official LO website www.libreoffice.org?
Comment 2 realleslie 2014-05-14 01:49:10 UTC
Yes, I used the official website.  Version 4.2.4.2 for Windows.

--Leslie




On Tue, May 13, 2014 at 4:30 AM, <bugzilla-daemon@freedesktop.org> wrote:

>   *Comment # 1 <https://bugs.freedesktop.org/show_bug.cgi?id=78573#c1> on
> bug 78573 <https://bugs.freedesktop.org/show_bug.cgi?id=78573> from Mike
> Kaganski <mikekaganski@hotmail.com> *
>
> What have you downloaded and from which address& Have you used download page
> from official LO website www.libreoffice.org?
>
>  ------------------------------
> You are receiving this mail because:
>
>    - You reported the bug.
>
>
Comment 3 Mike Kaganski 2014-05-14 06:53:15 UTC
Well, then, this must be a false positive.

You may check this using, e.g., VirusTotal.
The soffice.bin from 4.2.4.2 for Windows check result is here: https://www.virustotal.com/en/file/ec430fa2fa2be06b12fac546c2f5428e662037dfee6af1f2aec5a824dc82a9c2/analysis/1400049976/ - you may see it's clean.

As this issue describes a problem in outside software (false-positive in an AV package), I close it as NOTOURBUG.
You may report this to your AV software vendor. But I believe that this is already fixed, as VirusTotal scan includes results from Comodo.

Next time, please don't answer to messages from Bugzilla using your email client program; instead, use the Bugzilla WEB interface. This helps keeping issues clean and understandable.

Thank you for reporting.