Dear All,
This file has been hosted by GoogleCode since October 2013. On the download page there is a checksum so you can check the file is not being modified after downloading it.
We have also had a report that Symantec detects this as Trojan.ADH.SMH. The Symantec website has some details about this:
"If one or more files on your computer have been classified as having a Trojan.ADH.SMH threat, this indicates that the files have suspicious characteristics and therefore might contain a new or unknown threat. However, given the sensitive nature of this detection technology, it may occasionally identify non-malicious, legitimate software programs that also share these behavioral characteristics. Therefore, it is recommended that users manually check all files detected as Trojan.ADH.SMH by Symantec antivirus products for potential misidentification, and submit any suspect files to Symantec Security Response for further analysis. For instructions on how to do this, read Submit Virus Samples.”
This would suggest that it isn’t a recognised Trojan but some suspicious behaviour. This may be to do with the Windows Executable wrapper we use to launch BEAST (which is a Java program).
The final thing is that the actual executable was build on a Mac so it couldn’t have been infected at that point (there is the possibility that the wrapper (Launch4J) was infected at source but this is quite widely used and would likely have been noticed.
The other possibility is that something is infecting these files after download. It would be useful if Windows users could run their anti-viral software and report any warnings.
The temporary solution is to download the UNIX/Linux version and run it in a command line.
Andrew