LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 05-10-2015, 08:13 PM   #1
Wolverine1997
LQ Newbie
 
Registered: May 2015
Posts: 2

Rep: Reputation: Disabled
Slackware 13.1 DVD ISO image - Malware detected by avast?


Hi everyone.

I just downloaded he Slackware 13.1 32-bit DVD ISO from http://mirrors.slackware.com.

ZI scan everything just to make sure there are no potential malware. When I scanned this, it found 4 file right away detected as malware.

I also had the same issue with a Slackware 13.37 image I downloaded from https://archive.org yesterday and just thought maybe that was an infected image from an unknown site although Norton website check said archive.org was safe. But now after downloading from the official Slackware website and finding malware, I wonder if this is a false positive with Slackware DVD ISO images and avast or if I need to be worried.

I verified that the MD5 matched what was on the site for the ISO image using WinMD5Free.

Below is a link to my avast scan screenshot

http://postimg.org/image/ppgux913t/
 
Old 05-11-2015, 12:01 PM   #2
bassmadrigal
LQ Guru
 
Registered: Nov 2003
Location: West Jordan, UT, USA
Distribution: Slackware
Posts: 8,792

Rep: Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656
Well, if you downloaded it from a valid mirror and the MD5 matched, there is certainly no malware and the issue should be sent to Avast so they can get their engine updated so others don't get a false positive.

Just as an FYI, Slackware 13.1 has its EOL (end of life) scheduled for 25 MAY 2015. After this date (2 weeks from today), there may no longer be any provided security updates. Pat and team plan support based on a five year schedule and in two weeks, it marks the 5 year anniversary of when Slackware 13.1 was released.

Just as an FYI, Slackware 13.1 will be 5 years old in 2 weeks from today. We don't know how long they will provide security updates for releases, but with 5 year old Linux software, you start quite behind the times and it can cause compatibilty issues if you're trying to run software that is more current. It is highly recommended to use a more modern release (14.1 being the latest).

Last edited by bassmadrigal; 05-11-2015 at 01:49 PM. Reason: Edited after drmozes pointed out my error on EOL
 
Old 05-11-2015, 12:49 PM   #3
kikinovak
MLED Founder
 
Registered: Jun 2011
Location: Montpezat (South France)
Distribution: CentOS, OpenSUSE
Posts: 3,453

Rep: Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154
Back in 2001, I ran a double-boot Slackware 7.1 and Windows 2000. The antivirus on the Windows partition detected a "malware" in the MBR and... decided to wipe LILO. That day precisely was the last day I actually used Windows for work. I've been 100 GNU/Linux since that time. Never looked back.

PS: you want Slackware 14.1

Last edited by kikinovak; 05-11-2015 at 12:51 PM.
 
1 members found this post helpful.
Old 05-11-2015, 01:34 PM   #4
drmozes
Slackware Contributor
 
Registered: Apr 2008
Distribution: Slackware
Posts: 1,543

Rep: Reputation: 1313Reputation: 1313Reputation: 1313Reputation: 1313Reputation: 1313Reputation: 1313Reputation: 1313Reputation: 1313Reputation: 1313Reputation: 1313
Quote:
Originally Posted by bassmadrigal View Post
Well, if you downloaded it from a valid mirror and the MD5 matched, there is certainly no malware and the issue should be sent to Avast so they can get their engine updated so others don't get a false positive.
Indeed - I'd see exactly what pieces Avast identifies as malware and provide it as feedback. It's not the first time Windows virus scanners have identified Linux tools as viruses.

Quote:
Originally Posted by bassmadrigal View Post
Just as an FYI, Slackware 13.1 has its EOL (end of life) scheduled for 25 MAY 2015. After this date (2 weeks from today), there may no longer be any provided security updates. Pat and team plan support based on a five year schedule and in two weeks, it marks the 5 year anniversary of when Slackware 13.1 was released. It is highly recommended to use a more modern release (14.1 being the latest -- which will be supported until Nov 2018).
There is no EOL announced for 13.1, and I'm not aware of any specific lengths of time being announced or committed to for which a Slackware release will be supported. Did you imply this from the note in the 12.2 ChangeLog?
 
1 members found this post helpful.
Old 05-11-2015, 01:46 PM   #5
bassmadrigal
LQ Guru
 
Registered: Nov 2003
Location: West Jordan, UT, USA
Distribution: Slackware
Posts: 8,792

Rep: Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656
Quote:
Originally Posted by drmozes View Post
There is no EOL announced for 13.1, and I'm not aware of any specific lengths of time being announced or committed to for which a Slackware release will be supported. Did you imply this from the note in the 12.2 ChangeLog?
It was listed on wikipedia's site and I just assumed I'd missed the memo of a 5-year support timeframe.

Haha... oops, I just realized that they had the "~" in front of the EOL date to signify that it is speculation. I'll adjust my initial post to reflect that. Thanks!

Either way, unless there is a solid reason, it doesn't make sense to install a 5 year old Slackware.

EDIT: I have changed wikipedia's entries to show "No EOL Announced" to prevent others from coming to the same conclusion as me.

Last edited by bassmadrigal; 05-11-2015 at 02:05 PM. Reason: Added edit
 
Old 05-11-2015, 03:59 PM   #6
onebuck
Moderator
 
Registered: Jan 2005
Location: Central Florida 20 minutes from Disney World
Distribution: SlackwareŽ
Posts: 13,925
Blog Entries: 44

Rep: Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159
Member response

Hi,

From http://slackware.mirrors.tds.net/pub...ChangeLog.txt;
Code:
+--------------------------+
Thu Jun 14 05:02:39 UTC 2012
####################################################################
# NOTICE OF INPENDING EOL (END OF LIFE) FOR OLD SLACKWARE VERSIONS #
#                                                                  #
# Effective August 1, 2012, security patches will no longer be     #
# provided for the following versions of Slackware (which will all #
# be more than 5 years old at that time):                          #
# Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0.           #
# If you are still running these versions you should consider      #
# migrating to a newer version (preferably as recent as possible). #
# Alternately, you may make arrangements to handle your own        #
# security patches.  If for some reason you are unable to upgrade  #
# or handle your own security patches, limited security support    #
# may be available for a fee.  Inquire at security@slackware.com.  #
####################################################################
Hope this helps.
Have fun & enjoy!
 
Old 05-11-2015, 04:45 PM   #7
bassmadrigal
LQ Guru
 
Registered: Nov 2003
Location: West Jordan, UT, USA
Distribution: Slackware
Posts: 8,792

Rep: Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656
Quote:
Originally Posted by onebuck View Post
Hi,

From http://slackware.mirrors.tds.net/pub...ChangeLog.txt;
Code:
+--------------------------+
Thu Jun 14 05:02:39 UTC 2012
####################################################################
# NOTICE OF INPENDING EOL (END OF LIFE) FOR OLD SLACKWARE VERSIONS #
#                                                                  #
# Effective August 1, 2012, security patches will no longer be     #
# provided for the following versions of Slackware (which will all #
# be more than 5 years old at that time):                          #
# Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0.           #
# If you are still running these versions you should consider      #
# migrating to a newer version (preferably as recent as possible). #
# Alternately, you may make arrangements to handle your own        #
# security patches.  If for some reason you are unable to upgrade  #
# or handle your own security patches, limited security support    #
# may be available for a fee.  Inquire at security@slackware.com.  #
####################################################################
Hope this helps.
Have fun & enjoy!
That does not apply here since none of these versions is the one OP is attempting to download. Also, as drmozes mentioned, Pat has made no mention of any planned EOL for 13.0 and up (12.1 and 12.2 were EOLed on 9 DEC 2013).

All that is mentioned is that the versions would be at least 5 years old before they were EOLed, but 13.0 is coming up on 6 years in August, so using 5 years doesn't work.
 
Old 05-11-2015, 04:49 PM   #8
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,226

Rep: Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320
Avast thinks dip is a rootkit?

Yeah, it's a false positive.
 
Old 05-11-2015, 04:59 PM   #9
onebuck
Moderator
 
Registered: Jan 2005
Location: Central Florida 20 minutes from Disney World
Distribution: SlackwareŽ
Posts: 13,925
Blog Entries: 44

Rep: Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159
Member response

Hi,
Quote:
Originally Posted by bassmadrigal View Post
That does not apply here since none of these versions is the one OP is attempting to download. Also, as drmozes mentioned, Pat has made no mention of any planned EOL for 13.0 and up (12.1 and 12.2 were EOLed on 9 DEC 2013).

All that is mentioned is that the versions would be at least 5 years old before they were EOLed, but 13.0 is coming up on 6 years in August, so using 5 years doesn't work.
I believe the 'five years' comes from this portion of that changelog;
Quote:
# NOTICE OF INPENDING EOL (END OF LIFE) FOR OLD SLACKWARE VERSIONS #
# #
# Effective August 1, 2012, security patches will no longer be #
# provided for the following versions of Slackware (which will all #
# be more than 5 years old at that time):
PV will be the one who decides when to EOL a version.
 
Old 05-11-2015, 05:58 PM   #10
55020
Senior Member
 
Registered: Sep 2009
Location: Yorks. W.R. 167397
Distribution: Slackware
Posts: 1,307
Blog Entries: 4

Rep: Reputation: Disabled
Avast was in the news four days ago for wrecking e.g. "TeamViewer rendering it useless, Corel, and MS XNA framework" last Wednesday because of false positive errors.
F*cking DLL! Avast false positive trashes Windows code libraries, The Register, 7 May 2015
 
Old 05-11-2015, 07:00 PM   #11
volkerdi
Slackware Maintainer
 
Registered: Dec 2002
Location: Minnesota
Distribution: Slackware! :-)
Posts: 2,504

Rep: Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461
We had a lot of problems back in the day from false virus positives. Seems a lot of them consider anything including words in Russian to be malware.
 
3 members found this post helpful.
Old 05-11-2015, 08:23 PM   #12
ReaperX7
LQ Guru
 
Registered: Jul 2011
Location: California
Distribution: Slackware64-15.0 Multilib
Posts: 6,558
Blog Entries: 15

Rep: Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097
Avast! is not a great antivirus solution for Windows like it used to be. It scans for a lot but has too many false positives nowadays. For my Windows machines, I only use Microsoft Security Essential and MalwareBytes Pro any more due to this. I haven't had too many false-positives with these, and usually these try to play fair now with other software.

Another try would be Comodo Internet Security also.
 
Old 05-11-2015, 08:41 PM   #13
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,326
Blog Entries: 28

Rep: Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142
Odds are Avast doesn't understand something about the Slackware *.iso.

when I'm booted into Windows and run Malwarebytes, it finds a suspicious file on one of my external USB drives. The suspicious file is a HOWTO for something in Mac format. It's not malware, but Malwarebytes doesn't know what it is, so it flags the file.
 
Old 05-11-2015, 09:42 PM   #14
Wolverine1997
LQ Newbie
 
Registered: May 2015
Posts: 2

Original Poster
Rep: Reputation: Disabled
Thanks for the help everyone.

As for downloading 13.1 instead of 14.1, I have an old Dell Inspiron 1501 Laptop with the integrated Radeon XPress X1150 graphics chip that ZI am trying to revive and that video chipset is a pain with new Linux releases so I have been trying lots of releases with the 2.6.33 or later kernel so I get TRIM support as per this website here: http://wiki.cchtml.com/index.php/Hardware.

The older Radeon drivers only work with Linux Kernel 2.6.28 or older, so was trying to find a kernel closest to that that supports TRIM which is why I have been messing around with older releases.
 
Old 05-12-2015, 01:32 AM   #15
kikinovak
MLED Founder
 
Registered: Jun 2011
Location: Montpezat (South France)
Distribution: CentOS, OpenSUSE
Posts: 3,453

Rep: Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154
LILO should be patched to identify a Windows partition as malware and delete it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Can I compile slackware-install-dvd.iso out of slackware-source-code-dvd.iso mshlinux Slackware 11 05-25-2013 01:40 PM
How to make boot.iso image from rhel6 installation dvd iso ? Rohit_4739 Linux - Newbie 4 05-25-2012 07:45 AM
How to burn Slackware 13.37 DVD iso image sanjayagayan Linux - Newbie 1 05-12-2011 09:32 AM
Where to Download an i386 DVD installer -.iso image- for Slackware -Current Jags_FL Slackware 7 02-21-2008 10:59 AM
How do you merge 4 CD ISO images into one DVD ISO image? nsydenham Linux - Software 6 01-15-2007 09:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 10:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration