Keep Server Online
If you find the Apache Lounge, the downloads and overall help useful, please express your satisfaction with a donation.
or
A donation makes a contribution towards the costs, the time and effort that's going in this site and building.
Thank You! Steffen
Your donations will help to keep this site alive and well, and continuing building binaries. Apache Lounge is not sponsored.
| |
|
Topic: Virus on 2.4.2? Johab.so Suspicious.Cloud.7.F |
|
Author |
|
paulalbinson
Joined: 12 Apr 2012 Posts: 3 Location: Poole, England
|
Posted: Thu 12 Apr '12 23:29 Post subject: Virus on 2.4.2? Johab.so Suspicious.Cloud.7.F |
|
|
Hi,
I downloaded Apache httpd 2.4.2 for 32 bit windows and Norton 360 says it has a virus in file Johab.so and it is Suspicious.Cloud.7.F and removed the file. Is this a virus and if so when will a fix be available?
I have been sceptical in the past of using Apache Lounge as it isn't official and this makes me worry if it is safe to use.
Any advice would be greatly received.
Thanks
Paul |
|
Back to top |
|
glsmith Moderator
Joined: 16 Oct 2007 Posts: 2268 Location: Sun Diego, USA
|
Posted: Fri 13 Apr '12 2:01 Post subject: |
|
|
Hard to know where you picked it up from as there is no johab.so file in the zip files here to download. I just downloaded and looked at all four 2.4.2 downloads available here. Just cause it is .so doesn't mean it has anything to do with Apache either. Looking at what is below, looks like it is from some fake anti-malware program.
johab.so description and related error
By default, the johab.so is located in directory of C:\Progam Files\Common Files. The most common size of the johab.so on Windows system is 108,648 bytes. You may also find it in 14,336 bytes (86% of all occurrence), 12,800 bytes, 13,312 bytes, 13,437 bytes, 18,589 bytes and 19,364 bytes sizes.
johab.so is also known to create the following error messages when the system is shutting down:
The instruction at "0x059a2df" referenced memory at 0x059a2df" the memory could not be written. Click OK to terminate the Program.
%UserProfile%\Application Data\<affiliate id>\
%UserProfile%\Start Menu\Malware Destructor.lnk
%UserProfile%\Start Menu\Programs\Startup\Malware Destructor.lnk
%UserProfile%\Application Data\PAV\
%UserProfile%\Application Data\antispy.exe
%UserProfile%\Local Settings\Temp\kjkkklklj.bat
%Documents and Settings%\All Users\Application Data\Microsoft\Network\Downloader\smmservice.exe
%Documents and Settings%\All Users\Application Data\mswd\ |
|
Back to top |
|
paulalbinson
Joined: 12 Apr 2012 Posts: 3 Location: Poole, England
|
Posted: Sat 14 Apr '12 12:37 Post subject: |
|
|
Hi,
Thanks for taking a look at it.
I downloaded both 32 bit versions and johab.so in both it is in bin/iconv. It identified it as a virus on the httpd-2.4.2-win32-ssl_0.9.8u.zip version but it didn't alert me to a virus for that file in the httpd-2.4.2-win32.zip version but this is probably because it has already blocked it for suspicious activity. When I tried it before it was a virus in both versions.
Thanks
Paul |
|
Back to top |
|
Steffen Moderator
Joined: 15 Oct 2005 Posts: 3092 Location: Hilversum, NL, EU
|
Posted: Sat 14 Apr '12 12:57 Post subject: |
|
|
It is a false heuristic positive, way back I had one more report on johab.so and norton. With other downloads it is seen more with the Norton malware-heuristic scanning.
To take your worry away, I removed johab.so from all the downloads. If someone need it, contact me.
Before downloads made available, it is scanned with Eset and MS Essentials, they are not complaining about johab.so.
Thanks for reporting.
Steffen |
|
Back to top |
|
paulalbinson
Joined: 12 Apr 2012 Posts: 3 Location: Poole, England
|
Posted: Sat 14 Apr '12 13:04 Post subject: |
|
|
Hi Steffen,
Many thanks for sorting it.
Regards
Paul |
|
Back to top |
|
James Blond Moderator
Joined: 19 Jan 2006 Posts: 7371 Location: Germany, Next to Hamburg
|
Posted: Mon 16 Apr '12 11:44 Post subject: |
|
|
Steffen wrote: |
To take your worry away, I removed johab.so from all the downloads. If someone need it, contact me.
|
I've never heard of that before. What is it for and from which build? Just curious. |
|
Back to top |
|
Steffen Moderator
Joined: 15 Oct 2005 Posts: 3092 Location: Hilversum, NL, EU
|
Posted: Mon 16 Apr '12 13:12 Post subject: |
|
|
It is in the iconv(Charset Conversion Library) folder. Is was there always. |
|
Back to top |
|
|
|
|
|
|