Trojan ? No Trojan ? please ^^

There are 14 replies in this Thread. The last Post () by Gast.

  • greetings all,


    I have a small question about crossfire mod ...
    my antivirus Kaspersky detects me all the time 4 files (possibility of trojan horses) in the crossfire mod.


    their names are:
    TR / Crypt.ULPM.Gen
    TR / Crypt.FKM.Gen
    HEUR / Crypted


    infected files are:
    freelancer.exe
    sol.dll
    flserver.exe
    namesources.dll



    I just wanted to know if this is normal? reassure me ... :)


    thank you in advance

  • normal but no trojans

    signew.jpg


    cfmoddblogo.png5904.png5904.png
    http://www.moddb.com/scripts/topsite.php?ts=4766


    Only dead fish swim with the stream.
    Don't discuss with idiots. They only drag you down to their level and then beat you with experience there.


    This is ten percent luck,
    Twenty percent skill,
    Fifteen percent concentrated power of will,
    Five percent pleasure,
    Fifty percent pain,
    And a hundred percent reason to remember the name!

  • Yes, there seem to be some codes there that are detected as virus, or trojan, depending the antivirus. But you can be sure the 'Sol' system is not a virus xD or freelancer.exe... or anything in this wonderful game. If not, this wouldn't be filled with people hehe


    The antivirus = fail, the mod = rocks

    Chars: [CFPD]Michael~something (x25), [CFPD]~SQMS~{[(store)]} (x3), [CFPD]xfer, Event~Manager~Michael, StarfIier~EM~Michael, Event_Team_2, [GR]Michael[SP] and a blueprint of [CFPD]Sephirothis

  • it wasnt... it never is

    signew.jpg


    cfmoddblogo.png5904.png5904.png
    http://www.moddb.com/scripts/topsite.php?ts=4766


    Only dead fish swim with the stream.
    Don't discuss with idiots. They only drag you down to their level and then beat you with experience there.


    This is ten percent luck,
    Twenty percent skill,
    Fifteen percent concentrated power of will,
    Five percent pleasure,
    Fifty percent pain,
    And a hundred percent reason to remember the name!

  • My antivirus which is Norton, has taken this trojan problem a stage further. It no longer allows me to play the game. It just started today identifying cfwd.exe, freelancer.exe, ambientec.utf, a0645499.dll and infocards.dll all as high risk Trojans. Restoring the files is no good because it instantly deletes them. Why it has just started I do not know, I can only assume that Norton's world wide reporting system has incorporated these files as potential threats and takes immediate action against. For the time being I can't play until I can find a solution to this problem.

  • cfwd.exe - should not be affected
    freelancer.exe
    ambientec.utf
    a0645499.dll - i dont know that file
    infocards.dll - should not be affected


    i seriously would suggest to let norton clean your directory... i think for some reason a real virus affected your pc

    signew.jpg


    cfmoddblogo.png5904.png5904.png
    http://www.moddb.com/scripts/topsite.php?ts=4766


    Only dead fish swim with the stream.
    Don't discuss with idiots. They only drag you down to their level and then beat you with experience there.


    This is ten percent luck,
    Twenty percent skill,
    Fifteen percent concentrated power of will,
    Five percent pleasure,
    Fifty percent pain,
    And a hundred percent reason to remember the name!

  • well i too got that warning with norton (what the hell is a0645499.dll i am getting c:\system volume information\_restore{f845e3db-f751-4be4-a620-64f2ca1bfb5f}\rp85\a0103816.exe
    ____________________________
    ____________________________
    ____________________________
    a0103816.exe (Trojan Horse)
    Origin: Not Available
    ____________________________
    Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
    ____________________________
    Very Few Users
    Fewer than 10 users in the Norton Community have used this file.
    New
    This file was released more than 7 days ago.
    High
    This file risk is high.
    ____________________________
    File Thumbprint:
    Not Available
    ____________________________

    c:\system volume information\_restore{f845e3db-f751-4be4-a620-64f2ca1bfb5f}\rp85\a0103763.exe
    ____________________________
    ____________________________
    ____________________________
    a0103763.exe (Trojan Horse)
    Origin: Not Available
    ____________________________
    Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
    ____________________________
    Very Few Users
    Fewer than 10 users in the Norton Community have used this file.
    New
    This file was released more than 7 days ago.
    High
    This file risk is high.
    ____________________________
    File Thumbprint:
    Not Available
    ____________________________




    c:\system volume information\_restore{f845e3db-f751-4be4-a620-64f2ca1bfb5f}\rp85\a0103711.exe
    ____________________________
    ____________________________
    ____________________________
    a0103711.exe (Trojan Horse)
    Origin: Not Available
    ____________________________
    Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
    ____________________________
    Very Few Users
    Fewer than 10 users in the Norton Community have used this file.
    New
    This file was released more than 7 days ago.
    High
    This file risk is high.
    ____________________________
    File Thumbprint:
    Not Available
    ____________________________




    c:\system volume information\_restore{f845e3db-f751-4be4-a620-64f2ca1bfb5f}\rp85\a0103575.exe
    ____________________________
    ____________________________
    ____________________________
    a0103575.exe (Trojan Horse)
    Origin: Not Available
    ____________________________
    Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
    ____________________________
    Very Few Users
    Fewer than 10 users in the Norton Community have used this file.
    New
    This file was released more than 7 days ago.
    High
    This file risk is high.
    ____________________________
    File Thumbprint:
    Not Available
    ____________________________


    but as op said these might be viruses
    but they r in quarintine now
    turn on heurustic protection
    exclude CF_181.exe
    the whole FL game
    no need for flmm


    from both auto protect and scan

    meh.

  • recommendation:


    deinstall everything unneccesary from your computer (including all games) -> this is to make the things faster, since there will be less data


    install Avira and SuperAntiSpyware -> update -> scan -> Remove all viruses. this 2 tools will remove 99% of shits you have/had on your computer.


    run CCleaner, and maybe RegistryDefrag => now is your computer completely clean and it should work like never before (unless you picked some heavy virus, like blaster, for which you need better tools)


    After that, create a restore point, and start spamming your computer with all necessary games and other stuff


    if you want, you can try with Avast in the boot scan mode.. perfect thing for some viruses


    and stop surfing on porn sites...that might help in the future :D

  • At that point wouldn't it be faster, easier and safer to reinstall windows?


    SMG_myric, SMG_RDaneel, SMG_MULTIVAC


    Interested in joining SMG? PM me


    Those people who think they know everything
    are a great annoyance to those of us who do.

    - Isaac Asimov

  • I have plenty of this files at my compie and we learn to live together. :)


    Right now suspicious file is "Freelancer.exe2" (in quarantine atm ) and few other files which are under investigation of my provider.


    And yes reinstall all is a way better solution.Ofc this is not 100% solution, but easy and safer 1 for sure.There is a lil percent that some virus can stay at ur HD even after formatting of ur HD, but i hope this is not the case.


    http://technet.microsoft.com/en-us/library/cc977223.aspx


    http://antivirus.about.com/od/…ips/a/bootsectorvirus.htm


    few hours of reading can help to figure out, what are u fighting.


    ps
    there is a link about mbr at the forum which i post b4 few days.

  • yeah man, Bond, if you allow Freelancer.exe2 to be removed it removes alos the original Freelancer.exe file and your game gets screwed up... happened to me a couple of times