Author Topic: Trojan Malware reported within the installation: inkscape-0.92.1-x64-1.exe  (Read 4772 times)

June 23, 2017, 02:16:39 PM
Read 4772 times

jlborowicz

  • Sr. Newbie

  • Offline
  • **

  • 2
Hi,
I work at Geospan Corp, and I'm developing an OSS 'processing pipeline' for converting and inserting geographic coordinates into SVG files.
A major component in this evolving process and pipeline development project is "inkscape".  It plays a pivotal role and will be deployed to about a dozen stations once passing QA. At this company, the IT folks have installed a set of security software products from Fortinet for our anti-virus, VPN, firewall.
Each client is setup to do a system wide scan every day or week (mine is set to a daily scan). As you might have guessed, yesterday after performing the 'threat scan' of my computer, my Fortinet client reported malware in the 'inkscape.exe'. Given the AV software was set-up to react to this 'potential serious threat' it promptly locked down the application and made it such it could not be run.  I hasten to note that 'the malware signature' appears to have been 'a new addition' to Fortinet's Threats database (see attached screenshot). For the record, inkscape was operational and performing as expected prior to the 'discovery, lockdown and quarantine'.

I uninstalled inkscape and removed all of the files. I then pointed my browser back to inkscape.org and downloaded a 'new' install executable. 
The installation was halted when it came to transferring/loading 'inkscape.exe' which it reported as being 'infected'. The reported malware is identified as W64/Agent.5892!tr

For the record, I've submitted a report to Fortinet to see what they have to say. 

OK, my question is - is this the place to report this issue?,  or should this go to the developers forum? 
My next questions are - are we stuck finding out if this is a false positive or the 'real deal' from Fortinet's AV engine?  is flagged' by any other AV engines?
Any advice or direction would be most welcome.   

I am a humble inkscape newbie and just want to get back to work (with inkscape) and help out the community from getting unnecessary headaches and downtime, if possible.

Thanks, JLB

June 23, 2017, 10:03:44 PM
Reply #1

brynn

  • Administrator

  • Offline
  • ******

  • 3,941
  • Gender
    Female

    Female
    • Inkscape Community
Hi JLB,
As I indicated by email, when you contacted me the other day, you should post on the development mailing list.  This is the kind of thing that the developers will want to investigate immediately.

Except for the false positives which I mentioned that we've seen with a product called 360 Total Security, there have been no other reports to my knowledge.  The reports from 360 came a few months ago.  They were posted in this forum, so I'll search to find out the date for you.  But I think it was with an earlier version of Inkscape (and therefore a different file was downloaded).

Maybe you've posted on the mailing list by now?  I've only just logged on since yesterday, and haven't gotten to my email yet.  But if not please do, asap.

Thanks :)
  • Inkscape version 0.92.3
  • Windows 7 Pro, 64-bit
Inkscape Tutorials (and manuals)                      Inkscape Community Gallery                        Inkscape for Cutting Design                     



"Be ashamed to die until you have won some victory for humanity" - Horace Mann                       

June 28, 2017, 10:40:55 AM
Reply #2

jlborowicz

  • Sr. Newbie

  • Offline
  • **

  • 2
Hi Brynn,

You are correct. I didn't get this posted in the Developer/Bugs section because I couldn't get logged in to UbuntuOne (using  my known and proper credentials, the response I kept getting was: "Bad bot, go away! Request aborted."  I haven't dug in to find that problem...

I sent the same information to Fortinet, the makers of our software prophylactic, to ask if they could determine if this was perhaps a 'false positive' or a 'real infestation' in the inkscape.exe program.  I haven't heard from them. But I soldiered on -

First I  made sure my computer and drives were clean. I ran 24 hours of scans using three different 'nasti-detectors':  Fortinet's product, Windows Defender, and Norton's AV.  Then I downloaded the latest and greatest 32-bit version of inkscape.
I  disabled Fortinet and relied on Windows Defender when I d/l the 32-bit version and it all went well.  I then uninstalled it and d/l it again this time with Defender disabled and Fortinet enabled. And everything went well and I noticed that the database that Foritnet uses was updated.
I quickly uninstalled the 32-bit version of inkscape and ran a system scan with Fortinet using their newest nasties database.  Everything was fine and dandy and clean. Finally, I downloaded the inkscape 64-bit windows installation and it came down without incident and installed without incident.
All  is back to normal in my inkscape world and I am a happy newbie. Ergo, no need to post anything for the developers. 

Thank you.  JLB

June 28, 2017, 11:38:06 AM
Reply #3

brynn

  • Administrator

  • Offline
  • ******

  • 3,941
  • Gender
    Female

    Female
    • Inkscape Community
  • Inkscape version 0.92.3
  • Windows 7 Pro, 64-bit
Inkscape Tutorials (and manuals)                      Inkscape Community Gallery                        Inkscape for Cutting Design                     



"Be ashamed to die until you have won some victory for humanity" - Horace Mann