<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/20200" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2016-08-13T01:53:32-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/20200</id>

		<entry>
		<author><name><![CDATA[caesar]]></name></author>
		<updated>2016-08-13T01:53:32-04:00</updated>

		<published>2016-08-13T01:53:32-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=105328#p105328</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=105328#p105328"/>
		<title type="html"><![CDATA[Trojan in eggdrop module false positive ?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=105328#p105328"><![CDATA[
Because they haven't marked more files and just the seen module makes me think that the file has some piece of code (for instance like writing something in a file) similar to what malicious botnets used, maybe got some inspiration from the seen module..<br><br>Anyway, I wouldn't be bothered by this if you got the source from Eggheads.org's website.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=187">caesar</a> — Sat Aug 13, 2016 1:53 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2016-08-12T14:03:16-04:00</updated>

		<published>2016-08-12T14:03:16-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=105327#p105327</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=105327#p105327"/>
		<title type="html"><![CDATA[Trojan in eggdrop module false positive ?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=105327#p105327"><![CDATA[
I would assume they (Avast) classify it as a positive trojan, as eggdrops have been used to power malicious botnets in the past. To be honest, I'd almost expect them to classify any irc-client as an intrusion or trojan...<br><br>Sadly, I doubt they'll change their minds about it. Best bet is to get the binaries from a trusted source, or build them yourself, and do whatever you can to whitelist the file on your system.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Fri Aug 12, 2016 2:03 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[caesar]]></name></author>
		<updated>2016-08-11T01:27:14-04:00</updated>

		<published>2016-08-11T01:27:14-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=105318#p105318</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=105318#p105318"/>
		<title type="html"><![CDATA[Trojan in eggdrop module false positive ?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=105318#p105318"><![CDATA[
I got the seen.so file from my own eggdrop that i know for sure i got from the official source and the virus scan has the same <a href="https://www.virustotal.com/en/file/96438a0dc35bc7a68c059f247bc4e2b1088f2aa64576b8660b1b15d160fea1f5/analysis/1470893123/" class="postlink">result</a>.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=187">caesar</a> — Thu Aug 11, 2016 1:27 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[juanamores]]></name></author>
		<updated>2016-08-10T20:39:41-04:00</updated>

		<published>2016-08-10T20:39:41-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=105317#p105317</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=105317#p105317"/>
		<title type="html"><![CDATA[Trojan in eggdrop module false positive ?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=105317#p105317"><![CDATA[
I uploaded the file to <div class="codebox"><p>Code: </p><pre><code>https://mega.nz/#!cYsRhZzY</code></pre></div> so they can scan.<br>encryption key for file: <blockquote class="uncited"><div>!MUKHc7zBoMixKVPaw3VEZ7ra8TBsAZ5LqN80b430L9Y</div></blockquote>I do not remember where I downloaded this eggdrop .<br>I used to download it from the official website, but this was a while ago.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=12499">juanamores</a> — Wed Aug 10, 2016 8:39 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[caesar]]></name></author>
		<updated>2016-08-10T02:30:26-04:00</updated>

		<published>2016-08-10T02:30:26-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=105308#p105308</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=105308#p105308"/>
		<title type="html"><![CDATA[Trojan in eggdrop module false positive ?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=105308#p105308"><![CDATA[
If and only if you got the eggdrop1.6.21.tar.gz (or whatever version you are using) from the official source aka. <a href="ftp://ftp.eggheads.org/pub/eggdrop/source/1.6/eggdrop1.6.21.tar.gz" class="postlink">Eggheads.org</a> site, then grab the non-compiled seen.c from the archive located in <em class="text-italics">eggdrop1.6.21/src/mod/seen.mod</em>, tell them that they are idiots cos it's a false positive result and uninstall the product.<br><br>I just got the seen.c file and <a href="https://www.virustotal.com/en/file/c032e0ae8ed87cdc2700d54dee39bf794bbb16c1d622178a7bab9f201acc2ac1/analysis/1470810441/" class="postlink">here</a> (link) is the virustotal result.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=187">caesar</a> — Wed Aug 10, 2016 2:30 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[juanamores]]></name></author>
		<updated>2016-08-09T19:06:48-04:00</updated>

		<published>2016-08-09T19:06:48-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=105307#p105307</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=105307#p105307"/>
		<title type="html"><![CDATA[Trojan in eggdrop module false positive ?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=105307#p105307"><![CDATA[
I sent the file to AVAST Laboratory.<br>I have confirmed that the virus detection is correct.<br>The truth is I do not think it virus.<br><br>I do not think 52 antivirus mistake .<br>It is a false positive!<br><br>This said AVAST :<blockquote class="uncited"><div>Buenos días<br><br>Gracias por ponerse en contacto con Avast y enviarnos la muestra<br><br>El laboratorio de virus me informa de que es realmente un virus y la detección es correcta.<br><br>Reciba un cordial saludo</div></blockquote><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=12499">juanamores</a> — Tue Aug 09, 2016 7:06 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[caesar]]></name></author>
		<updated>2016-08-09T01:20:41-04:00</updated>

		<published>2016-08-09T01:20:41-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=105300#p105300</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=105300#p105300"/>
		<title type="html"><![CDATA[Trojan in eggdrop module false positive ?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=105300#p105300"><![CDATA[
False positive, nothing to worry about unless you got the file from another source other than the official one that might have tampered with the files.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=187">caesar</a> — Tue Aug 09, 2016 1:20 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[juanamores]]></name></author>
		<updated>2016-08-08T21:04:18-04:00</updated>

		<published>2016-08-08T21:04:18-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=105299#p105299</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=105299#p105299"/>
		<title type="html"><![CDATA[Trojan in eggdrop module false positive ?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=105299#p105299"><![CDATA[
I made a backup of my VPS on my PC and Avast antivirus detect a trojan in a file.<br>The path: \eggdrop\modules-1.6.21\<br>The file: seen.so<br>Detection: ELF:IRCBot-D [Trj]<br><br>Most likely is a false positive.<br>I've scanned the file using web total virus and here are the results:<br><a href="https://www.virustotal.com/es/file/9747d59e90bcc5c56c93bee2e4a35ed45c0317be879c97ded5632e0933370096/analysis/1470704763/" class="postlink">https://www.virustotal.com/es/file/9747 ... 470704763/</a><br><br>Only Avast detect virus of 53 AVs.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=12499">juanamores</a> — Mon Aug 08, 2016 9:04 pm</p><hr />
]]></content>
	</entry>
	</feed>
