Trojan Horse SHeur
Moderator: Moderators
- alanch
- Very Active Forum Member
- Posts: 4907
- Joined: Mon Feb 27, 2006 6:07 pm
- Location: Leeds, England
- Contact:
Trojan Horse SHeur
I had a scare yesterday with some downloaded files from the US which AVG Free identified as containing this virus. The name of the virus found suggests that this has been discovered through heuristic techniques, rather than by matching to a specific virus. I suspect this might be a false positive introduced by the latest AVG update, as I check all files when I download them and nothing was found by these earlier checks.
I have run a full check of my computer, including all my stored downloads from this site. AVG identified the following files from here as containing the same Trojan - 18002, 18003, 18004, 18056, 18070, 18140, 18148, 18241, 18405, 18406 and 18407. It would be helpful if someone could check one or more of these with another antivirus package to see if there really is a problem - preferably several of you with different antivirus suites if possible.
I have run a full check of my computer, including all my stored downloads from this site. AVG identified the following files from here as containing the same Trojan - 18002, 18003, 18004, 18056, 18070, 18140, 18148, 18241, 18405, 18406 and 18407. It would be helpful if someone could check one or more of these with another antivirus package to see if there really is a problem - preferably several of you with different antivirus suites if possible.
Alan
My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558
Lots of steam and early diesels from 1959 to 1963.
My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558
Lots of steam and early diesels from 1959 to 1963.
Re: Trojan Horse SHeur
18002 is clean - scanned with Norton AV.
I'll go through the others but i expect they will all be ok
Ive now checked all those files with Norton AV, updated today so bang up to date, and all of them have come back clean. I think you have a false positive
I'll go through the others but i expect they will all be ok
Ive now checked all those files with Norton AV, updated today so bang up to date, and all of them have come back clean. I think you have a false positive
Last edited by Lad491 on Mon Mar 03, 2008 4:51 pm, edited 2 times in total.
- alanch
- Very Active Forum Member
- Posts: 4907
- Joined: Mon Feb 27, 2006 6:07 pm
- Location: Leeds, England
- Contact:
Re: Trojan Horse SHeur
Thanks Laurie - as I said, I suspect AVG is producing heuristic false positives. I wonder if they are all using the same installer.
Alan
My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558
Lots of steam and early diesels from 1959 to 1963.
My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558
Lots of steam and early diesels from 1959 to 1963.
- jbilton
- Very Active Forum Member
- Posts: 19267
- Joined: Fri Oct 10, 2003 12:08 pm
- Location: At home ..waiting to go to Work.
- Contact:
Re: Trojan Horse SHeur
Hopefully AVGs next pattern will fix the 'false positives'........... got me yesterday too.alanch wrote:Thanks Laurie - as I said, I suspect AVG is producing heuristic false positives. I wonder if they are all using the same installer.
Cheers
Jon
------------------------Supporting whats good in the British community------------------------


- jbilton
- Very Active Forum Member
- Posts: 19267
- Joined: Fri Oct 10, 2003 12:08 pm
- Location: At home ..waiting to go to Work.
- Contact:
Re: Trojan Horse SHeur
Update released 17.06 03/03/08jbilton wrote:Hopefully AVGs next pattern will fix the 'false positives'........... got me yesterday too.alanch wrote:Thanks Laurie - as I said, I suspect AVG is producing heuristic false positives. I wonder if they are all using the same installer.![]()
Cheers
Jon
Unfortunately still showing as virus.
Cheers
Jon
------------------------Supporting whats good in the British community------------------------


- 6rdfar90
- Very Active Forum Member
- Posts: 1445
- Joined: Wed Oct 13, 2004 8:16 pm
- Location: Leeds
- Contact:
Re: Trojan Horse SHeur
AVG does this quite a lot... Kinda annoying really
- alanch
- Very Active Forum Member
- Posts: 4907
- Joined: Mon Feb 27, 2006 6:07 pm
- Location: Leeds, England
- Contact:
Re: Trojan Horse SHeur
This is only the second time in over 5 years that I've had this happen with AVG, so I don't think it is that bad.
Alan
My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558
Lots of steam and early diesels from 1959 to 1963.
My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558
Lots of steam and early diesels from 1959 to 1963.
- 6rdfar90
- Very Active Forum Member
- Posts: 1445
- Joined: Wed Oct 13, 2004 8:16 pm
- Location: Leeds
- Contact:
Re: Trojan Horse SHeur
Ouch. Its like the same number of times for me - but in the space of less than a year 
- ashgray
- Wafflus Maximus
- Posts: 12235
- Joined: Sun Jan 09, 2005 3:25 pm
- Location: GWR, Nailsea, Somerset
Re: Trojan Horse SHeur
Just scanned the lot with Norton, Alan - all OK.
Ash
Ash
Ashley Gray
Intel Core i7-7700K @ 4.2Ghz Quad Core, Gigabyte Gaming Motherboard, 2 x 512Gb SSDs + 1TB SATA drives,
16 Gb DDR-4 Corsair RAM, Nvidia GeForce GTX1060 6Gb RAM, ASUS Xonar D2X/XDT Soundcard, Windows 10 64 bit
Intel Core i7-7700K @ 4.2Ghz Quad Core, Gigabyte Gaming Motherboard, 2 x 512Gb SSDs + 1TB SATA drives,
16 Gb DDR-4 Corsair RAM, Nvidia GeForce GTX1060 6Gb RAM, ASUS Xonar D2X/XDT Soundcard, Windows 10 64 bit
Re: Trojan Horse SHeur
I'll scan one with McAfee VirusScan later tonight when the download queue is smaller (no Premium Access currently). Alternatively if anyone wants to drop one of those files in my mailbox (I don't care which one so choose the smallest), I'll report back here with the result as soon as I see it. I get over 200 spams per day so I don't worry about posting my address as is any more, it just gives my spam filter more material to learn from- princegaz@lineone.net
Chances are it is just a false positive, as others have mentioned.
Chances are it is just a false positive, as others have mentioned.
-
ronald parkin
- Very Active Forum Member
- Posts: 1741
- Joined: Thu Mar 10, 2005 10:08 pm
- Location: Sheffield Yorkshire
Re: Trojan Horse SHeur
Hi Alan, Hit it with the big one and drop it in here.
http://www.virustotal.com/
This was recommended By Uncle Bill's men.
Regards
Ron P
http://www.virustotal.com/
This was recommended By Uncle Bill's men.
Regards
Ron P
" To err is human,but to really foul things up you need a computer"
Paul Ehrlich
Paul Ehrlich
Re: Trojan Horse SHeur
Alan
Ive scanned them all again tonight on another PC running McAfee Internet Security, and once again all 11 files come back completely clean. Im also using advanced heuristic scanning.
Definitely an AVG false positive
Ive scanned them all again tonight on another PC running McAfee Internet Security, and once again all 11 files come back completely clean. Im also using advanced heuristic scanning.
Definitely an AVG false positive
- richard222
- Very Active Forum Member
- Posts: 1572
- Joined: Tue Oct 10, 2006 2:44 pm
- Location: Surrey
- Contact:
Re: Trojan Horse SHeur
richard222 / Richard Jenkins
- alanch
- Very Active Forum Member
- Posts: 4907
- Joined: Mon Feb 27, 2006 6:07 pm
- Location: Leeds, England
- Contact:
Re: Trojan Horse SHeur
Thanks all - I think we can put this one to bed. I still wonder if it is just one installed that is affected.
Alan
My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558
Lots of steam and early diesels from 1959 to 1963.
My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558
Lots of steam and early diesels from 1959 to 1963.
- Easilyconfused
- Worried about Silent Chickens
- Posts: 13205
- Joined: Tue Dec 31, 2002 9:06 am
- Location: Portsmouth & Bristol
- Contact:
Re: Trojan Horse SHeur
Thanks to Alan for raising this with us.
At this point I think the thread serves little more purpose and I don't want to get into a debate about the virtues / snags of different security products since that gets very subjective. Therefore I will lock the thread. It will be found by the search tools and the internet search engines so is useful reference material.
I would also urge anyone getting a positive report on any file from our library not only to post a thread but most importantly create a helpdesk ticket at http://support.atomic-systems.com so it comes to our attention quicker. The support team may not spot a thread immediately but the helpdesk tickets do get quick visibility. We do get a few reports of this sort from the helpdesk tickets and they are all investigated promptly
At this point I think the thread serves little more purpose and I don't want to get into a debate about the virtues / snags of different security products since that gets very subjective. Therefore I will lock the thread. It will be found by the search tools and the internet search engines so is useful reference material.
I would also urge anyone getting a positive report on any file from our library not only to post a thread but most importantly create a helpdesk ticket at http://support.atomic-systems.com so it comes to our attention quicker. The support team may not spot a thread immediately but the helpdesk tickets do get quick visibility. We do get a few reports of this sort from the helpdesk tickets and they are all investigated promptly
Kindest regards
John Lewis
Member of the forum moderation team
John Lewis
Member of the forum moderation team