Trojan Horse in Oolite!
Moderators: winston, another_commander
Trojan Horse in Oolite!
If you haven't already picked this up' my AVG found this yesterday:
Trojan Horse Downloader Zlob.MCQ
It's location was C:\ programme files\Oolite\Uninst.exe
I'm still running version 1.65 which was downloaded when it first came out last year, although I did add Dajt's patch for planet textures a while later.
I prompted AVG to heal it, but apparently it is unhealable though it has dropped it into the virus vault.
It's not just me either, it has been picked up by others on the EBBS here
Has anyone else here had this, and WTF do I do to fix it?
Trojan Horse Downloader Zlob.MCQ
It's location was C:\ programme files\Oolite\Uninst.exe
I'm still running version 1.65 which was downloaded when it first came out last year, although I did add Dajt's patch for planet textures a while later.
I prompted AVG to heal it, but apparently it is unhealable though it has dropped it into the virus vault.
It's not just me either, it has been picked up by others on the EBBS here
Has anyone else here had this, and WTF do I do to fix it?
The Grey Haired Commander has spoken!
OK so I'm a PC user - "you know whats scary? Out of billions of sperm I was the fastest"
OK so I'm a PC user - "you know whats scary? Out of billions of sperm I was the fastest"
- Killer Wolf
- ---- E L I T E ----
- Posts: 2280
- Joined: Tue Jan 02, 2007 12:38 pm
- Captain Hesperus
- Grand High Clock-Tower Poobah
- Posts: 2310
- Joined: Tue Sep 19, 2006 1:10 pm
- Location: Anywhere I can sell Trumbles.....
Could be a false positive. I run bi-weekly virus scans on my PC and it's never flagged that one up, I use Oolite 1.65-tp for Assassins and 1.68 for everything else.
Captain Hesperus
Captain Hesperus
The truth, revealed!!
-
- Dangerous
- Posts: 103
- Joined: Wed Jan 03, 2007 8:20 pm
- Location: Czech Republic
- JensAyton
- Grand Admiral Emeritus
- Posts: 6657
- Joined: Sat Apr 02, 2005 2:43 pm
- Location: Sweden
- Contact:
Either that, or it’s been infected by something else… in which case it isn’t actually a trojan.Helvellyn wrote:If something has been sitting around for a long time unchanged and only gets picked up now it's probably going to be a false positive.
E-mail: [email protected]
- Captain Hesperus
- Grand High Clock-Tower Poobah
- Posts: 2310
- Joined: Tue Sep 19, 2006 1:10 pm
- Location: Anywhere I can sell Trumbles.....
But then where would it have come from. Only you and a select group have the ability to upload to the BerliOS site, and none of you would knowingly upload anything even remotely virusy (is that a word? Probably not, but hey).Ahruman wrote:Either that, or it’s been infected by something else… in which case it isn’t actually a trojan.
I think it's just an over-protective AV program.
Captain Hesperus
The truth, revealed!!
- JensAyton
- Grand Admiral Emeritus
- Posts: 6657
- Joined: Sat Apr 02, 2005 2:43 pm
- Location: Sweden
- Contact:
There was a time, in deepest, darkest history, when viruses primarily spread between programs on the same computer. I know you can’t remember this, since you’re just an ickle kitty. :-)
E-mail: [email protected]
ohh i recall that... that was... yeah...Ahruman wrote:There was a time, in deepest, darkest history, when viruses primarily spread between programs on the same computer. I know you can’t remember this, since you’re just an ickle kitty.
Before The Internet...
Bounty Scanner
Number 935
Number 935
Hence my use of the word "unchanged". I had AVG report a false positive on C&C Generals once, which was rather obviously such when it gave the same result when I scanned the original CD.Ahruman wrote:Either that, or it’s been infected by something else… in which case it isn’t actually a trojan.Helvellyn wrote:If something has been sitting around for a long time unchanged and only gets picked up now it's probably going to be a false positive.
This could be a false positive. Best way to check will be to compare an "infected" file with a fresh download.
If anybody would like to send me an "infected" file I'll gladly investigate.
You can upload the file to ftp://cloud9.dyndns.tv . Login as anonymous and them PM me.
Note: I am risk free in this as I run Linux.
If anybody would like to send me an "infected" file I'll gladly investigate.
You can upload the file to ftp://cloud9.dyndns.tv . Login as anonymous and them PM me.
Note: I am risk free in this as I run Linux.