In your case somebody probably just uploaded a bugged file, then when somebody tried downloading it their AV software caught it and then 'phoned home' so everyone would be warned.
Then of course there are the upload forms input fields, ideally these SHOULD be validated by a server side script...