Virus in Easy Gif Animator?

Post your questions and problem reports here

Virus in Easy Gif Animator?

Postby knouse » Thu Jan 25, 2007 5:26 pm

Sophos Anti-Virus is reporting, "Virus Mal/HcPk-A has been detected in 'c:\program files\Easy Gif Animatory\gifan.exe'"

I downloaded a current version and reinstalled and Sophos immediately threw up the same dialog.
knouse
 
Posts: 7
Joined: Thu Jan 25, 2007 5:22 pm

Postby chrisjlocke » Thu Jan 25, 2007 6:26 pm

Any chance you could rename that file "gifan.txt" and email it to me? bluementals [at] chrisjlocke.co.uk
I've Sophos here too, as well as NOD32. What version of Sophos are you using?

I doubt it is a virus, but a false positive, but it would rule that out.
I can also forward the file onto Sophos to check.
User avatar
chrisjlocke
Top Contributor
 
Posts: 995
Joined: Mon Aug 01, 2005 4:12 pm
Location: Essex, UK

Postby knouse » Thu Jan 25, 2007 9:51 pm

I too suspect it is a false positive. I've not used Easy GIF Animator in some weeks so nothing's changed about it. But Sophos is updated multiple times a day.

Sophos version 6.5.2 with Threat detection engine = 2.42.3

I sent you an email with a link to the executable (renamed to gifan.txt) and two attachments: a screen shot of the Sophos warning and a dump of my Sophos configuration.
knouse
 
Posts: 7
Joined: Thu Jan 25, 2007 5:22 pm

Postby chrisjlocke » Fri Jan 26, 2007 12:39 am

Yup, downloading your file kicked off my Sophos too. Interestingly, the IDE has been updated today (25th) and yesterday.

It does mention, "Mal/HckPk-A is a program that has been packed with a protection system typically used by malware authors." so could just be the way Karlis has protected it.
User avatar
chrisjlocke
Top Contributor
 
Posts: 995
Joined: Mon Aug 01, 2005 4:12 pm
Location: Essex, UK

Postby davidp » Sat Jan 27, 2007 3:52 am

This problem seems to occur with HTMLPad too - htmlpad.exe was deleted after Sophos updated its definitions yesterday. I've submitted the file to Sophos for analysis - I think its probably more Sophos' fault than yours. Will now await response from them.

Meanwhile, I've just excluded HTMLpad from scanning, and reinstalled so I can continue to use this excellent software!

(I probably should have posted this under HTMLPad, but this topic seemed more relevant)
davidp
 
Posts: 4
Joined: Sat Jan 27, 2007 3:29 am
Location: Nottingham, UK

Postby chrisjlocke » Sat Jan 27, 2007 4:03 am

Thanks for the confirmation.
User avatar
chrisjlocke
Top Contributor
 
Posts: 995
Joined: Mon Aug 01, 2005 4:12 pm
Location: Essex, UK

Postby knouse » Sat Jan 27, 2007 4:01 pm

chrisjlocke wrote:I can also forward the file onto Sophos to check.

Did you forward the file to Sophos?
knouse
 
Posts: 7
Joined: Thu Jan 25, 2007 5:22 pm

Postby chrisjlocke » Sun Jan 28, 2007 11:26 am

Yes, I sent it to them.
User avatar
chrisjlocke
Top Contributor
 
Posts: 995
Joined: Mon Aug 01, 2005 4:12 pm
Location: Essex, UK

Postby davidp » Mon Jan 29, 2007 7:21 pm

I've just heard back from Sophos - they apologise for the problem and will release an update to correct it shortly:
The file that you sent to us for analysis was indeed producing a false-positive report. An IDE file to correct this will be released on the Databank and our web site shortly.

Hopefully this will also resolve the problem with Easy GIF animator.
davidp
 
Posts: 4
Joined: Sat Jan 27, 2007 3:29 am
Location: Nottingham, UK

Postby chrisjlocke » Tue Jan 30, 2007 1:48 pm

Thanks for posting back. I've yet to hear from my submission, but guess they'll ignore it now, now that its been fixed!
User avatar
chrisjlocke
Top Contributor
 
Posts: 995
Joined: Mon Aug 01, 2005 4:12 pm
Location: Essex, UK

Postby knouse » Thu Feb 01, 2007 6:53 pm

davidp wrote:I've just heard back from Sophos - they apologise for the problem and will release an update to correct it shortly:

They haven't released it yet. Sophos is still flagging it as soon as the installation completes.
knouse
 
Posts: 7
Joined: Thu Jan 25, 2007 5:22 pm

Postby Karlis » Fri Feb 02, 2007 10:22 pm

I guess there is nothing we can do. Please let me know how this resolves.
Karlis Blumentals
Blumentals Software
www.blumentals.net
User avatar
Karlis
Site Admin
 
Posts: 3600
Joined: Mon Jul 15, 2002 5:24 pm
Location: Riga, Latvia, Europe

Postby davidp » Sun Feb 04, 2007 3:24 am

Sophos have corrected the problem with HTMLPad in the latest round of updates. :)

However, the problem with EasyGIF Animator doesn't seem to have been corrected. I downloaded the trial to test it, and the file gifan.exe is still automatically deleted. I guess I could try submitting this file to Sophos as well, but that might be pointless, as Chris has already done it.
davidp
 
Posts: 4
Joined: Sat Jan 27, 2007 3:29 am
Location: Nottingham, UK

Postby Karlis » Fri Feb 09, 2007 2:31 pm

davidp wrote:I guess I could try submitting this file to Sophos as well, but that might be pointless, as Chris has already done it.


I think it does make sense. More bugging they receive, more seriously they will take this issue.
Karlis Blumentals
Blumentals Software
www.blumentals.net
User avatar
Karlis
Site Admin
 
Posts: 3600
Joined: Mon Jul 15, 2002 5:24 pm
Location: Riga, Latvia, Europe

Postby Karlis » Mon Mar 12, 2007 8:08 pm

Please, if you can, BUG SOPHOS as many times as you can! They are slow on fixing this issue and this is harming our business.
Karlis Blumentals
Blumentals Software
www.blumentals.net
User avatar
Karlis
Site Admin
 
Posts: 3600
Joined: Mon Jul 15, 2002 5:24 pm
Location: Riga, Latvia, Europe

Next

Return to Easy GIF Animator Support

Who is online

Users browsing this forum: No registered users and 14 guests

cron