RSDL Foliage 1.0 - Infected by Trojan Horse
Moderator: Moderators
RSDL Foliage 1.0 - Infected by Trojan Horse
Hi,
I've purchased and downloaded the Foliage package.
I've ESET NOD32 installed under Windows XP Pro SP3.
Unfortunately NOD32 quarantined and deleted some part of the package and informed
me about the potential threat by Win32/Kryptic C Trojan.
Very bad. How can I resolve this problem.
Adam
I've purchased and downloaded the Foliage package.
I've ESET NOD32 installed under Windows XP Pro SP3.
Unfortunately NOD32 quarantined and deleted some part of the package and informed
me about the potential threat by Win32/Kryptic C Trojan.
Very bad. How can I resolve this problem.
Adam
- Easilyconfused
- Worried about Silent Chickens
- Posts: 13205
- Joined: Tue Dec 31, 2002 9:06 am
- Location: Portsmouth & Bristol
- Contact:
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
Well first off I would contact the publisher and ask them.
Secondly I would double check with one of the online checking services that scans the files against multiple anti-virus products. We have seen many reports that turned out to be false positives but people are convinced there is a problem because their anti-virus product says so.
Lastly, before making public announcements about a "problem" or "infection" be very sure that it is a real problem
Secondly I would double check with one of the online checking services that scans the files against multiple anti-virus products. We have seen many reports that turned out to be false positives but people are convinced there is a problem because their anti-virus product says so.
Lastly, before making public announcements about a "problem" or "infection" be very sure that it is a real problem
Kindest regards
John Lewis
Member of the forum moderation team
John Lewis
Member of the forum moderation team
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
I have just purchased this also this very second its downloaded 62%.
I will check on my mcaffee and report back.
I will check on my mcaffee and report back.
A computer that's more than adequate to run TS
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
Well mcafee says its clean.
A computer that's more than adequate to run TS
- iceman2117
- Very Active Forum Member
- Posts: 3287
- Joined: Thu Dec 27, 2007 1:45 pm
- Location: Western Germany
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
hi, ...
My protection say NO VIRUS.
possibly a software license protection?
greets ice
My protection say NO VIRUS.
possibly a software license protection?
greets ice
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
Make a full scan of your computer, it is not only foliage pack, that it is infected.
Your computer was infected before dowloading foliage pack.
Your computer was infected before dowloading foliage pack.
- Acorncomputer
- Very Active Forum Member
- Posts: 10699
- Joined: Wed Oct 17, 2007 5:37 pm
- Location: Horley, Surrey, (in a cupboard under the stairs)
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
Hi
Just to say that my copy has no infection either.
Just to say that my copy has no infection either.
Geoff Potter
Now working on my Bluebell Railway route for TS2022
RISC OS - Now Open Source
Now working on my Bluebell Railway route for TS2022
RISC OS - Now Open Source
-
Basherz
- Very Active Forum Member
- Posts: 1394
- Joined: Tue Jan 08, 2008 7:14 pm
- Location: Cimla, Neath
- Contact:
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
There is no infection in this pack, but some AV's don't like .rpk's. Also as keber implies, check your own machine before lighting the fuse.
Chris
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
Indeed, I don't own the pack but am 99.99999% certain that software from a reputable company would not contain any virus / malware.Basherz wrote:There is no infection in this pack, but some AV's don't like .rpk's. Also as keber implies, check your own machine before lighting the fuse.
I use AVG free on my day to day PC (none on my gaming pc), and sometimes AVG will release a new Virus Signature that marks previously safe .exe files as infected. Once reported to AVG, the next Virus Signature then says that there is nothing wrong with the file even though the previous Signature said that there was.
This is I believe in part due to the way that some .exe files are protected via DRM schemes.
AV software whilst valuable at times isn't ever 100% trustworthy, in fact "I" believe that some AV manufacturers make up false threats on occasion to keep users paranoid and therefore pay for new yearly AV updates when the truth of the matter is that unless you're doing something dodgy then you're not likely to get a virus with a fully patched OS and with a smidge of common sense when opening files / etc...
If in doubt, submit the file to the AV company (if they have a scheme via the software), keep the file in Quarantine until you download a new Virus Signature (usually a daily or weekly update) and then see if the AV software flags it up again. If it does then get worried, if it doesn't then it's simply a false positive.
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
Meantime, I've de-activated my NOD32 and installed the package.
I'll make a full computer scan tonight.
Thanks for your input.
Adam
I'll make a full computer scan tonight.
Thanks for your input.
Adam
-
NeutronIC
- Atomic Systems Team

- Posts: 11085
- Joined: Fri Oct 05, 2001 12:00 am
- Location: E11, London, England
- Contact:
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
It's highly unlikely that it does have a virus, more than likely it's just got exactly the right sequence of bytes to make it look like one of the virii - virus detection is still quite simple.
What I would do however is talk to RSDL about getting a copy of the file off to your AV vendor for them to verify and exclude it.
Matt.
What I would do however is talk to RSDL about getting a copy of the file off to your AV vendor for them to verify and exclude it.
Matt.
Re: RSDL Foliage 1.0 - Infected by Trojan Horse
I'm in contact with the vendor who ask me about exact log of events as by NOD32 (which I sent them) and reply me as follows:NeutronIC wrote:It's highly unlikely that it does have a virus, more than likely it's just got exactly the right sequence of bytes to make it look like one of the virii - virus detection is still quite simple.
What I would do however is talk to RSDL about getting a copy of the file off to your AV vendor for them to verify and exclude it.
Matt.
"Dear Adam Witkowski,
This shows that NOD32 is detecting the entire .exe not just a DLL file.
Have you tried to run your security software after you have installed the product? Does it come up with the same .exe detected?"
Well, I did run the whole computer scan and nothing found connected with RDSL software.
Adam
