Page MenuHome GnuPG

Trojan in Windows Install Version?
Closed, ResolvedPublic

Description

Release: 1.4.2

Environment

Windows XP SP2, Bitdefender

Description

Bitdefender 8 tells me, that the Windows installer version "gnupg-w32cli-1.4.2.exe" is infected with "Backdor.Win32.Bifrose.D":

Here is an exerpt of the report:

C:\Daten\Mathias Habel\Eigene Dateien\Eigene Downloads\Internet\gnupg-w32cli-1.4.2.exe OK
C:\Daten\Mathias Habel\Eigene Dateien\Eigene Downloads\Internet\gnupg-w32cli-1.4.2.exe=>(NSIS o) OK
C:\Daten\Mathias Habel\Eigene Dateien\Eigene Downloads\Internet\gnupg-w32cli-1.4.2.exe=>(NSIS o)=>%INSTALLSCRIPT% OK
[....]
C:\Daten\Mathias Habel\Eigene Dateien\Eigene Downloads\Internet\gnupg-w32cli-1.4.2.exe=>(NSIS o)=>lzma_nsis0009 Infiziert mit: Backdoor.Win32.Bifrose.D
[...]

Maybe a false alarm?

How To Repeat

Please email me.

Fix

Unknown

Event Timeline

werner added a subscriber: werner.

Whatever Bitdefender is. There is no malware in GnuPG.

We are fighting using primes and not with faked horses. However is is possible
that the Turkey translation has not been properly protected against the Greek
one. Translators need to check ;-)

A more serious note:

Please check that the sha1sum given in the announcement of the software matches.
This is a clear indication of an unmodified copy.