Trojan Horse SHeur

General MSTS related discussion that doesn't really fit into any of the other specific forums.

Moderator: Moderators

Locked
User avatar
alanch
Very Active Forum Member
Posts: 4907
Joined: Mon Feb 27, 2006 6:07 pm
Location: Leeds, England
Contact:

Trojan Horse SHeur

Post by alanch »

I had a scare yesterday with some downloaded files from the US which AVG Free identified as containing this virus. The name of the virus found suggests that this has been discovered through heuristic techniques, rather than by matching to a specific virus. I suspect this might be a false positive introduced by the latest AVG update, as I check all files when I download them and nothing was found by these earlier checks.

I have run a full check of my computer, including all my stored downloads from this site. AVG identified the following files from here as containing the same Trojan - 18002, 18003, 18004, 18056, 18070, 18140, 18148, 18241, 18405, 18406 and 18407. It would be helpful if someone could check one or more of these with another antivirus package to see if there really is a problem - preferably several of you with different antivirus suites if possible.
Alan

My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558

Lots of steam and early diesels from 1959 to 1963.
Lad491
Very Active Forum Member
Posts: 10013
Joined: Mon Aug 11, 2003 9:25 pm
Location: West Sussex

Re: Trojan Horse SHeur

Post by Lad491 »

18002 is clean - scanned with Norton AV.
I'll go through the others but i expect they will all be ok

Ive now checked all those files with Norton AV, updated today so bang up to date, and all of them have come back clean. I think you have a false positive :(
Last edited by Lad491 on Mon Mar 03, 2008 4:51 pm, edited 2 times in total.
User avatar
alanch
Very Active Forum Member
Posts: 4907
Joined: Mon Feb 27, 2006 6:07 pm
Location: Leeds, England
Contact:

Re: Trojan Horse SHeur

Post by alanch »

Thanks Laurie - as I said, I suspect AVG is producing heuristic false positives. I wonder if they are all using the same installer.
Alan

My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558

Lots of steam and early diesels from 1959 to 1963.
User avatar
jbilton
Very Active Forum Member
Posts: 19267
Joined: Fri Oct 10, 2003 12:08 pm
Location: At home ..waiting to go to Work.
Contact:

Re: Trojan Horse SHeur

Post by jbilton »

alanch wrote:Thanks Laurie - as I said, I suspect AVG is producing heuristic false positives. I wonder if they are all using the same installer.
Hopefully AVGs next pattern will fix the 'false positives'........... got me yesterday too. :o

Cheers
Jon
------------------------Supporting whats good in the British community------------------------
Image
User avatar
jbilton
Very Active Forum Member
Posts: 19267
Joined: Fri Oct 10, 2003 12:08 pm
Location: At home ..waiting to go to Work.
Contact:

Re: Trojan Horse SHeur

Post by jbilton »

jbilton wrote:
alanch wrote:Thanks Laurie - as I said, I suspect AVG is producing heuristic false positives. I wonder if they are all using the same installer.
Hopefully AVGs next pattern will fix the 'false positives'........... got me yesterday too. :o

Cheers
Jon
Update released 17.06 03/03/08
Unfortunately still showing as virus.

Cheers
Jon
------------------------Supporting whats good in the British community------------------------
Image
User avatar
6rdfar90
Very Active Forum Member
Posts: 1445
Joined: Wed Oct 13, 2004 8:16 pm
Location: Leeds
Contact:

Re: Trojan Horse SHeur

Post by 6rdfar90 »

AVG does this quite a lot... Kinda annoying really
User avatar
alanch
Very Active Forum Member
Posts: 4907
Joined: Mon Feb 27, 2006 6:07 pm
Location: Leeds, England
Contact:

Re: Trojan Horse SHeur

Post by alanch »

This is only the second time in over 5 years that I've had this happen with AVG, so I don't think it is that bad.
Alan

My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558

Lots of steam and early diesels from 1959 to 1963.
User avatar
6rdfar90
Very Active Forum Member
Posts: 1445
Joined: Wed Oct 13, 2004 8:16 pm
Location: Leeds
Contact:

Re: Trojan Horse SHeur

Post by 6rdfar90 »

Ouch. Its like the same number of times for me - but in the space of less than a year :o
User avatar
ashgray
Wafflus Maximus
Posts: 12235
Joined: Sun Jan 09, 2005 3:25 pm
Location: GWR, Nailsea, Somerset

Re: Trojan Horse SHeur

Post by ashgray »

Just scanned the lot with Norton, Alan - all OK.

Ash
Ashley Gray

Intel Core i7-7700K @ 4.2Ghz Quad Core, Gigabyte Gaming Motherboard, 2 x 512Gb SSDs + 1TB SATA drives,
16 Gb DDR-4 Corsair RAM, Nvidia GeForce GTX1060 6Gb RAM, ASUS Xonar D2X/XDT Soundcard, Windows 10 64 bit
PrinceGaz
Established Forum Member
Posts: 376
Joined: Fri May 12, 2006 2:06 am
Location: Newcastle

Re: Trojan Horse SHeur

Post by PrinceGaz »

I'll scan one with McAfee VirusScan later tonight when the download queue is smaller (no Premium Access currently). Alternatively if anyone wants to drop one of those files in my mailbox (I don't care which one so choose the smallest), I'll report back here with the result as soon as I see it. I get over 200 spams per day so I don't worry about posting my address as is any more, it just gives my spam filter more material to learn from- princegaz@lineone.net

Chances are it is just a false positive, as others have mentioned.
ronald parkin
Very Active Forum Member
Posts: 1741
Joined: Thu Mar 10, 2005 10:08 pm
Location: Sheffield Yorkshire

Re: Trojan Horse SHeur

Post by ronald parkin »

Hi Alan, Hit it with the big one and drop it in here.
http://www.virustotal.com/
This was recommended By Uncle Bill's men.
Regards

Ron P :D
" To err is human,but to really foul things up you need a computer"
Paul Ehrlich
Lad491
Very Active Forum Member
Posts: 10013
Joined: Mon Aug 11, 2003 9:25 pm
Location: West Sussex

Re: Trojan Horse SHeur

Post by Lad491 »

Alan

Ive scanned them all again tonight on another PC running McAfee Internet Security, and once again all 11 files come back completely clean. Im also using advanced heuristic scanning.

Definitely an AVG false positive :(
User avatar
richard222
Very Active Forum Member
Posts: 1572
Joined: Tue Oct 10, 2006 2:44 pm
Location: Surrey
Contact:

Re: Trojan Horse SHeur

Post by richard222 »

Again if anyone really cares


http://online.drweb.com/?url=1
richard222 / Richard Jenkins
User avatar
alanch
Very Active Forum Member
Posts: 4907
Joined: Mon Feb 27, 2006 6:07 pm
Location: Leeds, England
Contact:

Re: Trojan Horse SHeur

Post by alanch »

Thanks all - I think we can put this one to bed. I still wonder if it is just one installed that is affected.
Alan

My railway photos are now on Google + - links to the albums are in this thread http://forums.uktrainsim.com/viewtopic. ... 9&t=149558

Lots of steam and early diesels from 1959 to 1963.
User avatar
Easilyconfused
Worried about Silent Chickens
Posts: 13205
Joined: Tue Dec 31, 2002 9:06 am
Location: Portsmouth & Bristol
Contact:

Re: Trojan Horse SHeur

Post by Easilyconfused »

Thanks to Alan for raising this with us.

At this point I think the thread serves little more purpose and I don't want to get into a debate about the virtues / snags of different security products since that gets very subjective. Therefore I will lock the thread. It will be found by the search tools and the internet search engines so is useful reference material.

I would also urge anyone getting a positive report on any file from our library not only to post a thread but most importantly create a helpdesk ticket at http://support.atomic-systems.com so it comes to our attention quicker. The support team may not spot a thread immediately but the helpdesk tickets do get quick visibility. We do get a few reports of this sort from the helpdesk tickets and they are all investigated promptly
Kindest regards

John Lewis

Member of the forum moderation team
Locked

Return to “[MSTS1] General MSTS Discussion”