ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 982] New: Norton AV reporting a trojan in the 0.99.1pre1 W

Date: Mon, 3 Jul 2006 17:41:48 +0000 (GMT)
http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=982

           Summary: Norton AV reporting a trojan in the 0.99.1pre1 Windows
                    installer
           Product: Wireshark
           Version: unspecified
          Platform: PC
        OS/Version: Windows XP
            Status: NEW
          Severity: Major
          Priority: Medium
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: gerald@xxxxxxxxxxxxx


Yesterday Norton Antivirus started reporting that the 0.99.1pre1 Windows
installer (wireshark-setup-0.99.1pre1.exe) contained Trojan.Zlob.  The trojan
is described here:

http://securityresponse.symantec.com/avcenter/venc/data/trojan.zlob.html

The machine used to build the installer doesn't have any of the executables or
registry keys listed in Symantec's description.  So far it looks like a false
positive.

I've contacted Symatec's tech support twice so far.  Both times they
recommended that I run a full system scan to remove the trojan.  ?!

Relevant mailing list messages:

http://www.wireshark.org/lists/wireshark-users/200607/msg00001.html
http://www.wireshark.org/lists/wireshark-users/200607/msg00003.html


-- 
Configure bugmail: http://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.