logo
Apache Lounge
Webmasters

 

About Forum Index Downloads Search Register Log in RSS X


Keep Server Online

If you find the Apache Lounge, the downloads and overall help useful, please express your satisfaction with a donation.

or

Bitcoin

A donation makes a contribution towards the costs, the time and effort that's going in this site and building.

Thank You! Steffen

Your donations will help to keep this site alive and well, and continuing building binaries. Apache Lounge is not sponsored.
Post new topic   Forum Index -> Apache View previous topic :: View next topic
Reply to topic   Topic: Virus on 2.4.2? Johab.so Suspicious.Cloud.7.F
Author
paulalbinson



Joined: 12 Apr 2012
Posts: 3
Location: Poole, England

PostPosted: Thu 12 Apr '12 23:29    Post subject: Virus on 2.4.2? Johab.so Suspicious.Cloud.7.F Reply with quote

Hi,

I downloaded Apache httpd 2.4.2 for 32 bit windows and Norton 360 says it has a virus in file Johab.so and it is Suspicious.Cloud.7.F and removed the file. Is this a virus and if so when will a fix be available?

I have been sceptical in the past of using Apache Lounge as it isn't official and this makes me worry if it is safe to use.

Any advice would be greatly received.

Thanks
Paul
Back to top
glsmith
Moderator


Joined: 16 Oct 2007
Posts: 2268
Location: Sun Diego, USA

PostPosted: Fri 13 Apr '12 2:01    Post subject: Reply with quote

Hard to know where you picked it up from as there is no johab.so file in the zip files here to download. I just downloaded and looked at all four 2.4.2 downloads available here. Just cause it is .so doesn't mean it has anything to do with Apache either. Looking at what is below, looks like it is from some fake anti-malware program.

johab.so description and related error

By default, the johab.so is located in directory of C:\Progam Files\Common Files. The most common size of the johab.so on Windows system is 108,648 bytes. You may also find it in 14,336 bytes (86% of all occurrence), 12,800 bytes, 13,312 bytes, 13,437 bytes, 18,589 bytes and 19,364 bytes sizes.

johab.so is also known to create the following error messages when the system is shutting down:

The instruction at "0x059a2df" referenced memory at 0x059a2df" the memory could not be written. Click OK to terminate the Program.

%UserProfile%\Application Data\<affiliate id>\

%UserProfile%\Start Menu\Malware Destructor.lnk

%UserProfile%\Start Menu\Programs\Startup\Malware Destructor.lnk

%UserProfile%\Application Data\PAV\

%UserProfile%\Application Data\antispy.exe

%UserProfile%\Local Settings\Temp\kjkkklklj.bat

%Documents and Settings%\All Users\Application Data\Microsoft\Network\Downloader\smmservice.exe

%Documents and Settings%\All Users\Application Data\mswd\
Back to top
paulalbinson



Joined: 12 Apr 2012
Posts: 3
Location: Poole, England

PostPosted: Sat 14 Apr '12 12:37    Post subject: Reply with quote

Hi,

Thanks for taking a look at it.

I downloaded both 32 bit versions and johab.so in both it is in bin/iconv. It identified it as a virus on the httpd-2.4.2-win32-ssl_0.9.8u.zip version but it didn't alert me to a virus for that file in the httpd-2.4.2-win32.zip version but this is probably because it has already blocked it for suspicious activity. When I tried it before it was a virus in both versions.

Thanks
Paul
Back to top
Steffen
Moderator


Joined: 15 Oct 2005
Posts: 3054
Location: Hilversum, NL, EU

PostPosted: Sat 14 Apr '12 12:57    Post subject: Reply with quote

It is a false heuristic positive, way back I had one more report on johab.so and norton. With other downloads it is seen more with the Norton malware-heuristic scanning.

To take your worry away, I removed johab.so from all the downloads. If someone need it, contact me.

Before downloads made available, it is scanned with Eset and MS Essentials, they are not complaining about johab.so.

Thanks for reporting.


Steffen
Back to top
paulalbinson



Joined: 12 Apr 2012
Posts: 3
Location: Poole, England

PostPosted: Sat 14 Apr '12 13:04    Post subject: Reply with quote

Hi Steffen,

Many thanks for sorting it.

Regards
Paul
Back to top
James Blond
Moderator


Joined: 19 Jan 2006
Posts: 7294
Location: Germany, Next to Hamburg

PostPosted: Mon 16 Apr '12 11:44    Post subject: Reply with quote

Steffen wrote:

To take your worry away, I removed johab.so from all the downloads. If someone need it, contact me.


I've never heard of that before. What is it for and from which build? Just curious.
Back to top
Steffen
Moderator


Joined: 15 Oct 2005
Posts: 3054
Location: Hilversum, NL, EU

PostPosted: Mon 16 Apr '12 13:12    Post subject: Reply with quote

It is in the iconv(Charset Conversion Library) folder. Is was there always.
Back to top


Reply to topic   Topic: Virus on 2.4.2? Johab.so Suspicious.Cloud.7.F View previous topic :: View next topic
Post new topic   Forum Index -> Apache