Vrirus detected in installation file for Windows: Gen:Variant.Cerbu.123329 / cannot install software. #6824

Closed limtileong closed 3 weeks ago

limtileong commented 3 weeks ago

While installing orange for windows, my BIDDEFENDER Anti-virus app detected a virus

The file C:\Users\limti\anaconda3\pkgs\expat-2.6.2-h63175ca_0\Library\bin\expat.dll has been detected as infected with Gen:Variant.Cerbu.123329 and Bitdefender could not clean this item. A device restart is required to finalize the cleaning process.

xorg-libsm-1.2.4-hcd874cb_0.conda Extract: xorg-libx11-1.8.9-hefa74cf_0.conda Extract: xorg-libxau-1.0.11-hcd874cb_0.conda Extract: xorg-libxdmcp-1.1.3-hcd874cb_0.tar.bz2 Extract: xorg-libxext-1.3.4-hcd874cb_2.conda Extract: xorg-libxpm-3.5.17-hcd874cb_0.conda Extract: xorg-libxt-1.3.0-hcd874cb_1.conda Extract: xorg-xextproto-7.3.0-hcd874cb_1003.conda Extract: xorg-xproto-7.0.31-hcd874cb_1007.tar.bz2 Extract: xz-5.2.6-h8d14728_0.tar.bz2 Extract: yaml-0.2.5-h8ffe710_2.tar.bz2 Extract: zeromq-4.3.5-he1f189c_4.conda Extract: zipp-3.17.0-pyhd8ed1ab_0.conda Extract: zlib-1.2.13-h2466b09_6.conda Extract: zstd-1.5.6-h0ea2cb4_0.conda Output folder: C:\Users\limti\AppData\Local\Temp\nsb2B10.tmp\Orange-installer-data\conda-pkgs Installing packages (this might take a while) Executing: cmd.exe /c install.bat "C:\Users\limti\AppData\Local\Programs\Orange" "C:\Users\limti\anaconda3\condabin\conda.bat" Creating a conda env in "C:\Users\limti\AppData\Local\Programs\Orange"

Rolling back transaction: ...working... done

[Errno 13] Permission denied: 'C:\Users\limti\anaconda3\pkgs\libexpat-2.6.2-h63175ca_0\Library\bin\libexpat.dll' () "conda" command exited with 1. Cannot continue.

What's wrong?

How can we reproduce the problem?

What's your environment?

ales-erjavec commented 3 weeks ago

The file C:\Users\limti\anaconda3\pkgs\expat-2.6.2-h63175ca_0\Library\bin\expat.dll has been detected as infected with Gen:Variant.Cerbu.123329 and Bitdefender could not clean this item. A device restart is required to finalize the cleaning process.

The expat-2.6.2-h63175ca_0 (sha256:f5a13d4bc591a4dc210954f492dd59a0ecf9b9d2ab28bf2ece755ca8f69ec1b4) is from conda-forge The Library/bin/expat.dll(sha256:e3c28b818c84b13da7f325f6588a6e9cffe8d25b7e2f9e3fbf75bd42ea058108) itself does not appear to be flagged as malicious (

I am guessing this is a false positive.