TeX Live and MacTeXBAT.CMDFlood - Possible Spyware

Information and discussion about TeX Live distribution for all platforms (Windows, Linux, Mac OS X) and the related MacTeX: installing, updating, configuring
Post Reply
Posts: 1
Joined: Sat Aug 27, 2011 9:48 pm

BAT.CMDFlood - Possible Spyware

Post by burke »

Has anyone run across this spyware or whatever it is in TeXLive 2011? BAT.CMDFlood

It was found (on two different machines) using ClamXav:
/usr/local/texlive/2011/texmf-dist/context/data/scite/cont-pe-scite.properties: BAT.CMDFlood FOUND
ERROR: Can't unlink '/usr/local/texlive/2011/texmf-dist/context/data/scite/cont-pe-scite.properties': Permission denied
To elaborate: It is also in the 2010 distribution but not 2009.

Recommended reading 2024:

LaTeXguide.org • LaTeX-Cookbook.net • TikZ.org
LaTeX Beginner's Guide LaTeX Cookbook LaTeX TikZ graphics TikZによるLaTeXグラフィックス
Posts: 1
Joined: Thu Sep 15, 2011 6:28 am

BAT.CMDFlood - Possible Spyware

Post by gefion777 »

Found BAT.CMDFlood today on my Mac using ClamXav. Viewed the file in a terminal window using the "More" command. At the beginning the file looks similar to the english version (cont-en-scite.properties). Later strange non-latin characters and several Unicode U+200C characters (zero-width non-joiner) show up.

Seems to be either a corrupted or a hijacked language file.

Decided to delete it using a sudo rm cont-pe-scite.properties command.
User avatar
Posts: 69
Joined: Mon Sep 05, 2011 10:27 am

Re: BAT.CMDFlood - Possible Spyware

Post by justdeath »

This is written in Persian language.
The filename is: cont-pe-scite.properties
Obviously pe is short from Persian.

The language is also known as Farsi, that is why google says fa.

You can translate some strings to see for yourself.

Post Reply