Virus found on both windows builds V4.0.5

FYI: My firewall ran into the following issues on the latest windows builds:
http://downloads.kicad.org/windows/stable/kicad-4.0.5-x86_64.exe
http://downloads.kicad.org/windows/stable/kicad-4.0.5-i686.exe

Message:
Gateway Anti-Virus Alert

This request is blocked by the SonicWALL Gateway Anti-Virus Service. Name: DigitalPlugin.A_92 (Adware)

Note: 4.0.0 did not have any issues.

You should report this as a bug over at the bug-tracker.
How to report a bug: https://kicad.org/help/report-a-bug/
Reporting a bug: https://bugs.launchpad.net/kicad

I hope that this is a false alarm, but the developers should be informed about it.

1 Like

Ok Thanks Rene, I’ve reported it.

1 Like

Many of us here have installed 4.0.5 64 bit (who uses 32 bit these days?) and not noticed any adware activities, so I think this is almost certainly a false positive. Nothing detected by Avast by the way.

indeed, such error can be related to antivirus. Avast is the most progressive, in my opinion

I am trying the latest nightly build on Windows 7, AVG chose to scan the download, but passed it. Then with the program running in the background I got a Ransomware alert - something about KiCAD trying to delete ‘Documents’ from ‘My Documents’…? Could there be a virus?

I don’t do windows but my first question would be to ask if you had a previous version of Kicad that the new one might be trying to clean up?

I did - but this was over an hour later…

They just started playing with signing the downloads I think but it seems they haven’t signed the nightlies and aren’t vouching for their integrity. :frowning:

As we don’t have a valid code signing certificate at the moment, downloads
are unsigned, and we cannot guarantee their integrity.

Bottom line, if you didn’t have Kicad up that’s suspicious. You might want to open your task manager? and keep an eye on things or just delete that version for now if you feel unsafe. I walked away from Windows a long time ago so I can’t be a lot more help. I know their are plenty of false positives with these malware engines. Some have even flagged themselves in the past.

4 Likes

Also never download KiCad from one of those “free downloads” sites

1 Like

The problem with unsigned versions was just a temporary one and only when downloaded directly from the nightly windows build server while they were working to update the certificate. The ones off the official site are signed, as they cannot upload to that site without a valid certificate.

5 Likes

As I did not know that, this really adds confidence in the developers and support team.

1 Like