Page 1 of 1

backdoor in xampp-win32-devel-1.6

PostPosted: 17. February 2007 16:21
by kiang
My anti-virus program told me the following message when extracting the package:

Virus or unwanted program 'BDS/Padodor.IL'
detected in file 'C:\Documents and Settings\kiang\Desktop\xampp-win32-devel\openssl\out32dll\sha256t.exe' [BDS/Padodor.IL].

backdoor in xampp-win32-devel-1.6

PostPosted: 09. April 2007 16:32
by jta
Does anyone have any more information regarding the trojan finding in xampp-win32-devel-1.6?

I downloaded the most recent xampp for windows (1.6.0a) on 3-April-2007 and Symantec AntiVirus believes there is a Backdoor.Trojan in xampp-win32-devel/openssl/out32dll/sha256t.exe.

I found the trojan faq for pv.exe, but it doesn't match the current case:
http://www.apachefriends.org/en/faq-xam ... .html#kill

PostPosted: 09. April 2007 22:08
by kenmcd
Other AV vendors fixed this false positive months ago.

PostPosted: 10. April 2007 20:26
by Codesmith
Solution, uninstall Norton. :)

Install free version of Avast or AVG. They work, they are free and they don't install a dozen performance stealing processes.

Or pay for NOD32, its the only one worth paying for your home computer.

backdoor in xampp-win32-devel-1.6

PostPosted: 11. April 2007 04:20
by jta
Codesmith wrote:
Solution, uninstall Norton :)

Better yet, uninstall Windows. oops, that's right -- I'm the one who asked for an update for information about Windows. :P

Seriously, thanks for the confirmation that this is a false positive. That's what was really needed in this case using a Windows machine whose owner requires Norton.