VirtualBox 4.3.20 virus alert with Avira

Discussions related to using VirtualBox on Windows hosts.
Post Reply
zecagalo
Posts: 5
Joined: 25. Nov 2014, 21:53

VirtualBox 4.3.20 virus alert with Avira

Post by zecagalo »

Hi, I just updated VirtualBox to version 4.3.20 and Avira blocked it due to virus warning:

Virus or unwanted program 'TR/Crypt.XPACK.Gen2 [trojan]'
detected in file 'C:\Program Files\Oracle\VirtualBox\VirtualBox.exe.
Action performed: Transfer to Scanner

Virus or unwanted program 'TR/Crypt.XPACK.Gen [trojan]'
detected in file 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.dll.
Action performed: Transfer to Scanner

Virus or unwanted program 'TR/Crypt.XPACK.Gen2 [trojan]'
detected in file 'C:\Program Files\Oracle\VirtualBox\VBoxNetDHCP.exe.
Action performed: Transfer to Scanner

Virus or unwanted program 'TR/Crypt.XPACK.Gen2 [trojan]'
detected in file 'C:\Program Files\Oracle\VirtualBox\VBoxNetNAT.exe.
Action performed: Transfer to Scanner

Any hints in this? Will it be soved soon?
Thanks.
loukingjr
Volunteer
Posts: 8851
Joined: 30. Apr 2009, 09:45
Primary OS: Mac OS X other
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: just about all that run

Re: VirtualBox 4.3.20 virus alert with Avira

Post by loukingjr »

See Windows 4.3.20 specifically for errors due to security
You could try the 4.3.21 test build.
OSX, Linux and Windows Hosts & Guests
There are three groups of people. Those that can count and those that can't.
mpack
Site Moderator
Posts: 39134
Joined: 4. Sep 2008, 17:09
Primary OS: MS Windows 10
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: Mostly XP

Re: VirtualBox 4.3.20 virus alert with Avira

Post by mpack »

Personally, I think you should be asking Avira to explain the false positives from their software, not asking us about it. It really doesn't matter whether it produces the same incorrect result with VBox 4.3.12 and 4.3.21.

VirtualBox is open source. You really don't need indirect tests to see what's in the code.
loukingjr
Volunteer
Posts: 8851
Joined: 30. Apr 2009, 09:45
Primary OS: Mac OS X other
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: just about all that run

Re: VirtualBox 4.3.20 virus alert with Avira

Post by loukingjr »

mpack is correct and originally I was just going to respond that they were false positives which is common with anti-viral programs. I have to admit I suggested trying the 4.3.21 test build just to see if Avira would flag the same sections of code. But it is always up to any anti-viral program to fix false positives and not the code that triggers them as mpack said.
OSX, Linux and Windows Hosts & Guests
There are three groups of people. Those that can count and those that can't.
zecagalo
Posts: 5
Joined: 25. Nov 2014, 21:53

Re: VirtualBox 4.3.20 virus alert with Avira

Post by zecagalo »

Hi, thanks for the replies. I'll ask Avira on this, but anyway, it's allways a good idea to trust you AV software, specially when you're not sure about a particular software. Anyone and anything is vulnerable to malware so it's never too much to play it safe. I wouldn't think VirtualBox had some malware inside it but, neither the less, we hear reports from great renowned companies around the world being hacked and poisoned from time to time, so it's always good to know the opinion from both sides, which was what I was trying to get here.
frank
Oracle Corporation
Posts: 3362
Joined: 7. Jun 2007, 09:11
Primary OS: Debian Sid
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: Linux, Windows
Location: Dresden, Germany
Contact:

Re: VirtualBox 4.3.20 virus alert with Avira

Post by frank »

We have asked Avira in the past. Unfortunately they have only a web interface where one can ask them to test a specific package. Unfortunately there is no feedback.
c7rolek
Posts: 5
Joined: 25. Nov 2014, 13:04

Re: VirtualBox 4.3.20 virus alert with Avira

Post by c7rolek »

Avira is rather fast in support stuff, but sometimes their responses are unreliable. For example, I have send my password rar protected archive which Avira classified as an Trojan (the file inside archive was clean) and the support has claimed that archive content is clean but rar file is dangerous (what was just ridiculous).
If You installed VBOX from official installer just add exception to Avira and forget about the case. Though, You could check and compare md5 sum of VBOX exe.
Post Reply