When updating two Drupal 6 site menus, the handles used to reorder menus disappeared and a Trend Micro alert popped up. In doing some research, it turns out that a June 30th, 2009 update to Trend Micro added some AJAX patterns which have now begun to flag those handles as a trojan. They then become hidden in all browsers unless Trend is shut down on the local machine and clear the private cache data. I'll post more details if I can find them, but I wanted to make sure someone was aware of the problem. If it's happening with Trend Micro, it's reasonable to assume that it would happen with other corporate AV programs.
| Comment | File | Size | Author |
|---|---|---|---|
| drupal_trend_2.jpg | 25.07 KB | Saoirse1916 | |
| drupal_trend_1.jpg | 20.74 KB | Saoirse1916 |
Comments
Comment #1
Saoirse1916 commentedI checked into our Trend Micro logs and found that it's also catching trojans in the following files:
siteroot\modules\color\color.install - flagged as "BKDR_IRCBOT.BZQ"
siteroot\modules\profile\profile-wrapper.tpl.php - flagged as "TROJ_SWIZZOR.KXV"
siteroot\modules\translation\translation.module - flagged as "TROJ_FRAUDLO.LL"
It's actually removing them from the local copy of my site -- fortunately the files are up on the webserver so it's not really a big issue, but it could be for some.
Comment #2
bigdave commentedComment #3
kaakuu commentedDoes it affect other D 6 versions ?
Comment #4
yt2s commentedYes it does. See this post.
I've since spent several hours with Trend Micro support and the issue has not been resolved. TM issued another update to the software this morning (or last night) and the problem is even worse now than before. In addition to the files snagged by TM a few days ago, last night it also got:
File: modules/book/book.admin.inc
Threat name: TROJ_SWIZZOR.KVR
File: modules/poll/poll-results.tpl.php
Threat name: TROJ_SWIZZOR.KVC
File: modules/upload/upload.module
Threat name: TSPY_MMORPG.NP
This article show's a similar discussion as this one. I am certainly hoping these are all false positives. Either way, this debacle is killing productivity for sure.
I even thought about switching to another AV software brand; but, don't commercial AV's generally follow suite with the same, or similar, pattern releases? If so, wouldn't it make sense to expect similar behaviors in other AV's soon? Is, or can, Drupal get involved with TM to help get this issue resolved?
Comment #5
kaakuu commentedThere are certain things serious with these results even if false positive.
During the recent gumblar and similar attacks several sites were affected and even when cleaned they continued to be shown as unsafe by Google - false positives but firefox, which relies on Google's reports, kept on blocking legit users from visiting purely legit sites. There are several such stories in unmaskparasites.com
Is there a way to run a reliable AV on actual linux servers particularly by shared account holders ? This may perhaps specify if the problem only occurs in local machine.
It is also worth testing if the same problem happens with the download package from Acquia ? Can some one test?
Comment #6
yt2s commentedAgreed, on the serious nature. While my testing has certainly not been scientific, I have yet to find any OS-CMS to get flagged by Trend Micro over the past few days. It is very frustrating. TM is blowing up my machine again this morning, and Drupal files are the only files on my entire system being caught (...and I don't mean just the only cms files, I mean they are literally the only files being flagged on an otherwise seemingly clean machine. I just don't understand it. I'm calling Trend Micro again this afternoon after this scan finishes.
Comment #7
michelleThis is not a bug in Drupal; it is a bug in Trend. It needs to be fixed on their end, so you need to file an issue in their queue.
Michelle
Comment #8
yt2s commentedHi Michelle,
That's exactly what I've done. Hopefully the matter will be resolved soon. In the meantime it is a serious encumbrance to productivity, not to mention a little scary. The sooner this whole thing is behind Drupal/Trend Micro users the better.
Certainly I will update the hopeful/expected "all clear" here soon.
Comment #9
theunraveler commentedSubscribing.
Comment #10
yt2s commentedI have spent every day this week on the phone with varying levels of Trend Micro support. After scanning my drive with the latest pattern release (issued within the past day or so) Trend Micro DOES NOT quarantine, or flag any Drupal Files as having a threat. This most recent scan (again yielding no threat consisted of several vs' of Drupal, including 5.19, 6.5-6.13.
It would appear the alarm was most definitely a False Positive.
Comment #11
swh commentedI can confirm this too: with pattern release 6.287, OfficeScan no longer identifies threats in Drupal 6.12 or 6.13.
Todd, thanks for your efforts pushing that along with Trend Micro.
Comment #12
kaakuu commentedYep! Thanks yt2s. The community needs efforts like you to fix things.
Comment #13
yt2s commentedFinal Update:
I've continued to follow up with Trend Micro on this issue in hopes that TM users don't go through this again. TM collected and tested samples of the files in question (mentioned here and elsewhere recently in similar posts on drupal.org). After tests were concluded, and the drupal files in question proved to NOT contain any threats, TM updated their software to correct the problem. Following is a direct quote from an email I received from the TM support supervisor today:
TM users, just make sure your TM - AV software has been updated to the latest pattern release and you should be All Clear with respect to the drupal files mentioned here.
Comment #14
webchickWow, thanks a lot, yt2s! What a nasty (and totally bizarre) problem. Really appreciate your tireless efforts in following up! This weird bug could've given Drupal a very bad name, indeed.
Nice that Trend Micro reacted quickly to fix the bug, too. Hopefully they've fixed their heuristics so we don't run into this in the future.
Comment #15
Saoirse1916 commentedDitto -- glad this is straightened out. I noticed with the latest TM updates it's not flagging the AJAX handles as trojans anymore so the problem must be resolved.
Comment #17
a.bond commentedUpdate: Trend Micro now lists the "download Drupal 6.13" link as a "malicious website". I'm getting really irritated with them.