RSDL Foliage 1.0 - Infected by Trojan Horse

General discussion about Rail Simulator that doesn't really fit in to any specific category. A good place to start if you're not sure what category it should fit in to as well.

Moderator: Moderators

Locked
User avatar
adam3544
Well Established Forum Member
Posts: 954
Joined: Mon Oct 24, 2005 7:10 pm

RSDL Foliage 1.0 - Infected by Trojan Horse

Post by adam3544 »

Hi,
I've purchased and downloaded the Foliage package.
I've ESET NOD32 installed under Windows XP Pro SP3.
Unfortunately NOD32 quarantined and deleted some part of the package and informed
me about the potential threat by Win32/Kryptic C Trojan.
Very bad. How can I resolve this problem.

Adam
User avatar

Easilyconfused
Worried about Silent Chickens
Posts: 13205
Joined: Tue Dec 31, 2002 9:06 am
Location: Portsmouth & Bristol
Contact:

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by Easilyconfused »

Well first off I would contact the publisher and ask them.

Secondly I would double check with one of the online checking services that scans the files against multiple anti-virus products. We have seen many reports that turned out to be false positives but people are convinced there is a problem because their anti-virus product says so.

Lastly, before making public announcements about a "problem" or "infection" be very sure that it is a real problem
Kindest regards

John Lewis

Member of the forum moderation team
User avatar
TheTazman
Very Active Forum Member
Posts: 4886
Joined: Thu Dec 25, 2003 4:55 pm
Location: Wales

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by TheTazman »

I have just purchased this also this very second its downloaded 62%.

I will check on my mcaffee and report back.
A computer that's more than adequate to run TS
User avatar
TheTazman
Very Active Forum Member
Posts: 4886
Joined: Thu Dec 25, 2003 4:55 pm
Location: Wales

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by TheTazman »

Well mcafee says its clean.
A computer that's more than adequate to run TS
User avatar
iceman2117
Very Active Forum Member
Posts: 3287
Joined: Thu Dec 27, 2007 1:45 pm
Location: Western Germany

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by iceman2117 »

hi, ...

My protection say NO VIRUS.
possibly a software license protection?

greets ice
keber
Established Forum Member
Posts: 347
Joined: Fri Mar 10, 2006 10:58 am

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by keber »

Make a full scan of your computer, it is not only foliage pack, that it is infected.
Your computer was infected before dowloading foliage pack.
User avatar
Acorncomputer
Very Active Forum Member
Posts: 10699
Joined: Wed Oct 17, 2007 5:37 pm
Location: Horley, Surrey, (in a cupboard under the stairs)

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by Acorncomputer »

Hi

Just to say that my copy has no infection either.
Geoff Potter
Now working on my Bluebell Railway route for TS2022
RISC OS - Now Open Source
Basherz
Very Active Forum Member
Posts: 1394
Joined: Tue Jan 08, 2008 7:14 pm
Location: Cimla, Neath
Contact:

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by Basherz »

There is no infection in this pack, but some AV's don't like .rpk's. Also as keber implies, check your own machine before lighting the fuse.
Chris
AndyM77
Very Active Forum Member
Posts: 1983
Joined: Tue May 08, 2007 12:16 am

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by AndyM77 »

Basherz wrote:There is no infection in this pack, but some AV's don't like .rpk's. Also as keber implies, check your own machine before lighting the fuse.
Indeed, I don't own the pack but am 99.99999% certain that software from a reputable company would not contain any virus / malware.

I use AVG free on my day to day PC (none on my gaming pc), and sometimes AVG will release a new Virus Signature that marks previously safe .exe files as infected. Once reported to AVG, the next Virus Signature then says that there is nothing wrong with the file even though the previous Signature said that there was.

This is I believe in part due to the way that some .exe files are protected via DRM schemes.

AV software whilst valuable at times isn't ever 100% trustworthy, in fact "I" believe that some AV manufacturers make up false threats on occasion to keep users paranoid and therefore pay for new yearly AV updates when the truth of the matter is that unless you're doing something dodgy then you're not likely to get a virus with a fully patched OS and with a smidge of common sense when opening files / etc...

If in doubt, submit the file to the AV company (if they have a scheme via the software), keep the file in Quarantine until you download a new Virus Signature (usually a daily or weekly update) and then see if the AV software flags it up again. If it does then get worried, if it doesn't then it's simply a false positive.
User avatar
adam3544
Well Established Forum Member
Posts: 954
Joined: Mon Oct 24, 2005 7:10 pm

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by adam3544 »

Meantime, I've de-activated my NOD32 and installed the package.
I'll make a full computer scan tonight.
Thanks for your input.

Adam
NeutronIC
Atomic Systems Team
Atomic Systems Team
Posts: 11085
Joined: Fri Oct 05, 2001 12:00 am
Location: E11, London, England
Contact:

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by NeutronIC »

It's highly unlikely that it does have a virus, more than likely it's just got exactly the right sequence of bytes to make it look like one of the virii - virus detection is still quite simple.

What I would do however is talk to RSDL about getting a copy of the file off to your AV vendor for them to verify and exclude it.

Matt.
User avatar
adam3544
Well Established Forum Member
Posts: 954
Joined: Mon Oct 24, 2005 7:10 pm

Re: RSDL Foliage 1.0 - Infected by Trojan Horse

Post by adam3544 »

NeutronIC wrote:It's highly unlikely that it does have a virus, more than likely it's just got exactly the right sequence of bytes to make it look like one of the virii - virus detection is still quite simple.

What I would do however is talk to RSDL about getting a copy of the file off to your AV vendor for them to verify and exclude it.

Matt.
I'm in contact with the vendor who ask me about exact log of events as by NOD32 (which I sent them) and reply me as follows:

"Dear Adam Witkowski,

This shows that NOD32 is detecting the entire .exe not just a DLL file.

Have you tried to run your security software after you have installed the product? Does it come up with the same .exe detected?"

Well, I did run the whole computer scan and nothing found connected with RDSL software.

Adam
Locked

Return to “[RS] General RS Discussion”