Edelmiro Moman schrieb:
> Hi,
> 
> Today, AVG Free edition has reported the following six virus-infected 
> files, all in Cygwin DLLs:
> 
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\B\C\C.dll","09/08/2007 
> 13:42:20"," C.dll","7.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Cwd\Cwd.dll","09/08/2007
>  
> 13:42:27","Cwd.dll","9 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\Byte\Byte.dll","09/08/2007
>  
> 13:42:46","Byte.dll","112.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\KR\KR.dll","09/08/2007
>  
> 13:43:48"," KR.dll","793 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\vendor_perl\5.8\cygwin\auto\Win32\File\File.dll","09/08/2007
>  
> 13:45:03","File.dll ","9.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\vendor_perl\5.8\cygwin\auto\Win32\Semaphore\Semaphore.dll","09/08/2007
>  
> 13:46:24"," Semaphore.dll","11.5 KB"
> 
> AVG version is 7.5.476 and the virus base is 269.11.10/943
> 
> I allowed it to quarantine the files and then uptaded Cygwin. During the 
> uptade, AVG detected the following infected files :
> 
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\B\C\C.dll","09/08/2007 
> 13:42:20","C.dll","7.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Cwd\Cwd.dll","09/08/2007
>  
> 13:42:27"," Cwd.dll","9 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\Byte\Byte.dll","09/08/2007
>  
> 13:42:46","Byte.dll"," 112.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\KR\KR.dll","09/08/2007
>  
> 13:43:48","KR.dll","793 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\vendor_perl\5.8\cygwin\auto\Win32\File\File.dll","09/08/2007
>  
> 13:45:03","File.dll","9.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\vendor_perl\5.8\cygwin\auto\Win32\Semaphore\Semaphore.dll","09/08/2007
>  
> 13:46:24","Semaphore.dll","11.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\Byte\Byte.dll","09/08/2007
>  
> 13:58:37","Byte.dll","112.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\CN\CN.dll","09/08/2007
>  
> 13:58:48","CN.dll","724 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\JP\JP.dll","09/08/2007
>  
> 13:58:52"," JP.dll","837.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\KR\KR.dll","09/08/2007
>  
> 13:58:58","KR.dll","793 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\Symbol\Symbol.dll","09/08/2007
>  
> 13:59:02","Symbol.dll","20.5 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\perl5\5.8\cygwin\auto\Encode\TW\TW.dll","09/08/2007
>  
> 13:59:06","TW.dll","740 KB"
> "","","Virus found 
> Win32/PolyCrypt","C:\cygwin\lib\python2.5\lib-dynload\_multibytecodec.dll","09/08/2007
>  
> 13:59:10","_multibytecodec.dll","23 KB"
> 
> I guess these are not infected files at all. I will send a copy of this 
> e-mail to AVG.

Thanks. Most of these are mine and it's a false positive.
Only AVG reports these, see  Jotti (http://virusscan.jotti.org/).

See the cygwin thread "PERL's Encode::Byte is being flagged by AVGfree 
as WIN32/PolyCrypt anyonelse" from yesterday.

-- 
Reini Urban
http://phpwiki.org/  http://murbreak.at/
http://helsinki.at/  http://spacemovie.mur.at/

-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >>  http://get.splunk.com/
_______________________________________________
Cygwin-ports-general mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/cygwin-ports-general

Reply via email to