Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Talk about code development, features, specific bugs, enhancements, patches, and similar things.
Forum rules
Please keep everything here strictly on-topic.
This board is meant for Pale Moon source code development related subjects only like code snippets, patches, specific bugs, git, the repositories, etc.

This is not for tech support! Please do not post tech support questions in the "Development" board!
Please make sure not to use this board for support questions. Please post issues with specific websites, extensions, etc. in the relevant boards for those topics.

Please keep things on-topic as this forum will be used for reference for Pale Moon development. Expect topics that aren't relevant as such to be moved or deleted.
bobber575
Apollo supporter
Apollo supporter
Posts: 30
Joined: 2015-10-14, 15:52
Location: New Mexico, USA

Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by bobber575 » 2018-08-28, 15:28

Kaspersky Total Security 18-0-0-405(j) will not allow installation of Palemoon 28.0.0.1 x64 downloaded from the U. S. mirror site.
See 18-08-27-Speccy-KOSH.7z for System Specs
See 18-08-28-0900-Palemoon-Trojan-Virus-Report.7z for A/V Report
Attachments
18-08-27-Speccy-KOSH.7z
(19.59 KiB) Downloaded 12 times
18-08-28-0900-Palemoon-Trojan-Virus-Report.7z
(1 KiB) Downloaded 8 times

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35634
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by Moonchild » 2018-08-28, 15:34

"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
therube
Board Warrior
Board Warrior
Posts: 1651
Joined: 2018-06-08, 17:02

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by therube » 2018-08-28, 15:38

Did you check the hash of the downloaded file against that posted on the PM download page?

bobber575
Apollo supporter
Apollo supporter
Posts: 30
Joined: 2015-10-14, 15:52
Location: New Mexico, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by bobber575 » 2018-08-28, 15:48

Yup! Hash checks on downloaded file, problem happens when I run the installer.

User avatar
Night Wing
Knows the dark side
Knows the dark side
Posts: 5173
Joined: 2011-10-03, 10:19
Location: Piney Woods of Southeast Texas, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by Night Wing » 2018-08-28, 16:02

bobber575 wrote:Yup! Hash checks on downloaded file, problem happens when I run the installer.
Turn off Kapspersky, then install Pale Moon since it is a false positive. Then tell Kaspersky about the false positive. Free Avast does the same thing to me so I turn off Avast to install windows Pale Moon. Once Pale Moon is installed, I turn Avast back on by rebooting all of my four computers with a windows hard drive installed in them.
Linux Mint 21.3 (Virginia) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
MX Linux 23.2 (Libretto) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
Linux Debian 12.5 (Bookworm) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox

bobber575
Apollo supporter
Apollo supporter
Posts: 30
Joined: 2015-10-14, 15:52
Location: New Mexico, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by bobber575 » 2018-08-28, 16:20

Ok. I get the idea of some A/V products throwing false positives. However, Kaspersky is *normally* quite tolerant of Palemoon. This positive for Palemoon is an outlyer, and therefore the reason for my reporting the problem.
As the checksum and scan of the downloaded file appear to be safe, why does the installation routine trigger the alert from Kaspersky??

User avatar
Night Wing
Knows the dark side
Knows the dark side
Posts: 5173
Joined: 2011-10-03, 10:19
Location: Piney Woods of Southeast Texas, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by Night Wing » 2018-08-28, 16:27

@ bobber575

There have been quite a few changes in Pale Moon from 27.9.4 to (28.0.1). Kaspersky probably hasn't picked up on those changes yet and it is remembering things in the 27.9.4 installer. In other words, something inside the installer for 28.0.1 is "too new" for Kaspersky.
Linux Mint 21.3 (Virginia) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
MX Linux 23.2 (Libretto) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
Linux Debian 12.5 (Bookworm) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox

bobber575
Apollo supporter
Apollo supporter
Posts: 30
Joined: 2015-10-14, 15:52
Location: New Mexico, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by bobber575 » 2018-08-28, 16:34

I agree that the changes from 27.x to 28.0.0 were substantial, but Kaspersky passed the installation of 28.0.0 with no problems. I'll wait a couple of days and see if I can install Palemoon 28.0.0.1. Kaspersky is reporting that this latest installer is only 5 hours old.
Thanks for your time.
Last edited by bobber575 on 2018-08-28, 16:34, edited 1 time in total.

User avatar
therube
Board Warrior
Board Warrior
Posts: 1651
Joined: 2018-06-08, 17:02

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by therube » 2018-08-28, 16:34

Are you using a VPN?
(rubyw.exe is listed & wondering if that is expected?)

bobber575
Apollo supporter
Apollo supporter
Posts: 30
Joined: 2015-10-14, 15:52
Location: New Mexico, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by bobber575 » 2018-08-28, 16:37

I have Private Internet Access installed, but not active.

User avatar
Night Wing
Knows the dark side
Knows the dark side
Posts: 5173
Joined: 2011-10-03, 10:19
Location: Piney Woods of Southeast Texas, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by Night Wing » 2018-08-28, 16:42

bobber575 wrote:I agree that the changes from 27.x to 28.0.0 were substantial, but Kaspersky passed the installation of 28.0.0 with no problems. I'll wait a couple of days and see if I can install Palemoon 28.0.0.1. Kaspersky is reporting that this latest installer is only 5 hours old.
Like I said previously, 28.0.1 is too new so Kaspersky is going to "play it safe". Since Kaspersky is a paid AV (as far as I know), Kaspersky is "covering it's own a$$".
Linux Mint 21.3 (Virginia) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
MX Linux 23.2 (Libretto) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
Linux Debian 12.5 (Bookworm) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35634
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by Moonchild » 2018-08-28, 16:44

bobber575 wrote:As the checksum and scan of the downloaded file appear to be safe, why does the installation routine trigger the alert from Kaspersky??
Only Kaspersky can answer that, but my guess is it does a dumb pattern scan whenever new files are written to disk or loaded into memory, and if it happens to hit something in Pale Moon that is a "match" at that stage, it will raise an alarm. Since the installer itself is a compressed 7z SFX archive, it will likely NOT scan inside of it when you scan the installer, and the compressed data will of course not match whatever pattern is tripped up.

AV vendors should really stop using static binary patterns because it will create more and more false positives as both their database grows and applications are getting more optimized resulting in very similar patterns to viruses as a normal part of their compiled state.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

bobber575
Apollo supporter
Apollo supporter
Posts: 30
Joined: 2015-10-14, 15:52
Location: New Mexico, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by bobber575 » 2018-08-28, 16:46

You are probably quite correct about Kaspersky having a severe dose of "CYA". And, Yes, this is a "Paid" version of Kaspersky.
Cheers

tenseys

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by tenseys » 2018-08-28, 17:27

Windows defender (Windows 10) gives an unknown publisher warning after double clicking installer for 28.0.0.1 (Americas, 64bit) stopping the installation.

Capture1.PNG
new.PNG
Last edited by tenseys on 2018-08-28, 18:27, edited 23 times in total.

bobber575
Apollo supporter
Apollo supporter
Posts: 30
Joined: 2015-10-14, 15:52
Location: New Mexico, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by bobber575 » 2018-08-28, 17:33

I have "Smartscreen" disabled.

User avatar
therube
Board Warrior
Board Warrior
Posts: 1651
Joined: 2018-06-08, 17:02

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by therube » 2018-08-28, 17:52

Last edited by therube on 2018-08-28, 17:53, edited 2 times in total.

tenseys

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by tenseys » 2018-08-28, 17:54

Oh ok, this is the first time I've seen this warning. Doesn't happen with earlier (27.9.4, 28.0.0 etc) installers for me.
I'll probably shut the smartscreen off.
Last edited by tenseys on 2018-08-28, 18:28, edited 8 times in total.

bobber575
Apollo supporter
Apollo supporter
Posts: 30
Joined: 2015-10-14, 15:52
Location: New Mexico, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by bobber575 » 2018-08-28, 20:11

Well, I have a shiny new definition update for Kaspersky (DtD 2018-08-28 10:23) and by using the internal updater in Palemoon, I successfully installed Palemoon 28.0.0.1 x64. However the Palemoon "Restart Now" button results in an instance of Palemoon running with no GUI. Was necessary to kill the phantom instances and manually restart Palemoon to get the GUI to appear. This is the second time the installer has failed in this manner.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35634
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by Moonchild » 2018-08-28, 20:19

That can only happen if something holds the process hostages and prevents it from shutting down normally. AV suites are notorious for doing that.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

bobber575
Apollo supporter
Apollo supporter
Posts: 30
Joined: 2015-10-14, 15:52
Location: New Mexico, USA

Re: Kaspersky Reporting Trojan in 28.0.0.1 x64 Installer

Unread post by bobber575 » 2018-08-29, 16:34

If anyone is still interested, Kaspersky Total Security (Definition update DtD 2018-08-29 04:30) now loves Palemoon 28.0.0.1.
I downloaded the 28.0.0.1 64Bit installer from the U. S. Mirror, and successfully installed same with no complaints from Kaspersky.
Dealing with Micro$quash Windows, and the necessity to run competent Anti-Virus products can be a huge PITA.
Thanks to everyone for taking the time to respond to my Tempest in a Teapot.
Cheers,
G. R. "Bob" Main

Locked