wubi\initrd gets false-positive by antivir-heuristics

Bug #229548 reported by Maximilian Lucius Fischer
8
Affects Status Importance Assigned to Milestone
Wubi
Invalid
Undecided
Unassigned
Ubuntu
Invalid
Undecided
Unassigned

Bug Description

Scanning with an updated antivir under vista64-business marks wubi\boot\initrd as possible "malformed"
The problem is reproducible on my laptop. It seems to be an false-positive

C:\wubi\boot\initrd
  [0] Archivtyp: GZ
    --> unkwn
      [1] Archivtyp: CPIO SVR4
      --> bin/minips
          [FUND] Enthält verdächtigen Code: HEUR/ELF.Malformed
      [WARNUNG] Die Datei wurde ignoriert.

Antivir offers to isolate the suspect. Isolation itself does not affect ubuntus ability to start.

From my point of view it isn't dangerous, but a nasty habit new users shouldn't be faced with.

Revision history for this message
Maximilian Lucius Fischer (luciusfischer) wrote :

Enthält verdächtigen Code <-> Contains suspicious code

Revision history for this message
Agostino Russo (ago) wrote :

Wubi uses the very same initrd as Ubuntu (to be more precise, the initrd is extracted from the LiveCD at runtime), and if anyone thinks there is any malaware there they can doublecheck the source code directly. If there is a bug here it is with the antivirus heuristics and I doubt there is much to fix on the Ubuntu side.

Changed in wubi:
status: New → Invalid
Revision history for this message
Maximilian Lucius Fischer (luciusfischer) wrote :

I already tried to make contact with antivir.

Revision history for this message
Agostino Russo (ago) wrote :

Max, please post here any follow-up.

Revision history for this message
Maximilian Lucius Fischer (luciusfischer) wrote :

I sent them the file, they confirmed the false-positive and updated their heuristic engine.

How do i close a bug?

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.