Forum archive
LAMP 16.0 detected as virus or malware
Hi,
I wanted to download and test the version 16 of the LAMP stack uisng Firefox and I get this notification from the browser saying that the ISO file may contain a malware or virus. I think it may be that my ESET antivirus is mistaking the file to be malicious?
Just want to make sure this is not the case before proceeding.
Any clarification would be appreciated.
Thanks!
I have never had a report that any of our ISOs have triggered a warning such as that, so it's certainly a surprise to me. I can confirm that our ISOs (and other builds) do not contain any malicious software to the best of my knowledge. They certainly didn't when I uploaded them, and on face value, they appear to be the same images that I uploaded.
Having said that, I can't guarantee that what is going on on your computer is not malicious. It seems unlikely, but perhaps your browser is being hijacked (by some malicious code unconnected to us) to download a file that isn't coming from our mirror?
If you have more information about the warning that you are seeing (e.g. a log file with details of what issue it's hitting), please fee free to share and I'll give you my further thoughts.
In the meantime, so long as you just "download" the ISO file (i.e. don't auto run it with anything) and double check against the hashes (I'll also post the hashes below). The hash file is also signed by our GPG release key, so you can also download it and double check that you have the right/legitimate hash file. You can find our GPG release key (Fingerprint: A8B2 EF42 8781 9B03 D351 6CCA 7623 1C20 425E 9772) for v16.x images either on the SKS keyserver network (e.g. Ubuntu keyserver) under the email release-buster-images@turnkeylinux.org . And/or you can also find it in our GitHub "common" repo.
The hashes for the v16.0 LAMP appliance ISO are: