Forum Discussion

donmunyak_10415's avatar
donmunyak_10415
Icon for Nimbostratus rankNimbostratus
Aug 02, 2008

Trojan Virus

I downloaded and tried to install iRuleEditor

 

The downloaded file was iRulerSetup.exe

 

When I launched the setup exe, AV barked at me. "Trojan Horse"

 

 

http://securityresponse.symantec.com/security_response/writeup.jsp?docid=2004-021914-2822-99

 

 

Additionally, Windows XP say it can't verify the publisher ??

 

 

Can someone confirm this

 

1 Reply

  • We have had several reports of this and the only thing I can think that it could be would be a false positive. I've personally compiled this distributable and it has been on the server for some time now. I did scan on the file on the server to make sure it didn't somehow get infected after I uploaded it and it was binary comparible to the build from my server.

     

     

    The installer is a .Net 2.0 ClickOnce deployment which is basically a wrapper around .Net applications that enables the runtime to "phone home" to devcentral to look for updates.

     

     

    I have yet to find the exact writeup on how this categorizes as a trojan horse so that I can determine why it was triggered as one so I can fix it.

     

     

    If you are not comforable using this install, then I have an alternate standalone installer available with the same contents that seems to not trigger this false-positive.

     

     

    http://devcentral.f5.com/LinkClick.aspx?link=http%3a%2f%2fdevcentral.f5.com%2flabs%2fiRuleEditor%2fiRulerSetupStandalone.msi&tabid=73&mid=433

     

    Click here

     

     

     

    I'm in the process of rewriting the installer for the editor and I'll be doing away with ClickOnce due to the many problems I've had with it. I apologize for any inconvenience you've encountered and hopefully the alternate installer will get you up and running.

     

     

    As for why it can't find the publisher, it's an open source package and we release the full source and the installer has not been signed with a certificate. That's likely something I should get around to fixing as well.

     

     

    Please let me know of the other install doesn't work and any other feedback you may have.

     

     

    -Joe