I know CF can be detected as Trojan and its all safe, but wanted to inform that since update it detected a new one.

There are 21 replies in this Thread. The last Post () by SWAT_OP-R8R.

  • Today i started the game and the virusscanner detected a new "trojan".


    I know its prob nothing as normal but wanted to give you guys the info about it.
    If somethings wrong ill prob read it here.
    Ill go play anyway, trojan or not...



    Do not go where the path may lead, go instead where there is no path and leave a trail. – Ralph Waldo Emerson .
    Obstacles are those frightful things you see when you take your eyes off your goal. – Henry Ford .
    If you aren’t making any mistakes, it’s a sure sign you’re playing it too safe. - John Maxwell .

  • which file are we actually talking about?

    signew.jpg


    cfmoddblogo.png5904.png5904.png
    http://www.moddb.com/scripts/topsite.php?ts=4766


    Only dead fish swim with the stream.
    Don't discuss with idiots. They only drag you down to their level and then beat you with experience there.


    This is ten percent luck,
    Twenty percent skill,
    Fifteen percent concentrated power of will,
    Five percent pleasure,
    Fifty percent pain,
    And a hundred percent reason to remember the name!

  • We're talking about the freelancer.exe file here. And yes, i have the same problem and told my Avira to put the freelancer.exe into quarantine. The infection warning came after i wanted to start Crossfire a few minutes ago and the launcher downloaded some files.

  • Malware Found
    Date/Time: 12/29/2011, 6:39:44 AM
    Type: Detection
    A virus or unwanted program 'TR/Crypt.XPACK.Gen5' was found in file 'C:\Program Files\Microsoft Games\...\Freelancer.exe'.
    Access to this file was denied.
    Please select a further action:
    ( Remove ) ( Details )


    Presumably automatic updates caused this new detection.


    From the details button you can choose to ignore the file. Except I did that, and it's not ignoring it. Might be time to go back to avast!

  • well, that file was never part of any patch I did
    you still have the file that you got when installing the mod for the first time

    signew.jpg


    cfmoddblogo.png5904.png5904.png
    http://www.moddb.com/scripts/topsite.php?ts=4766


    Only dead fish swim with the stream.
    Don't discuss with idiots. They only drag you down to their level and then beat you with experience there.


    This is ten percent luck,
    Twenty percent skill,
    Fifteen percent concentrated power of will,
    Five percent pleasure,
    Fifty percent pain,
    And a hundred percent reason to remember the name!

  • well what should i tell you... i have not done any changes on that file

    signew.jpg


    cfmoddblogo.png5904.png5904.png
    http://www.moddb.com/scripts/topsite.php?ts=4766


    Only dead fish swim with the stream.
    Don't discuss with idiots. They only drag you down to their level and then beat you with experience there.


    This is ten percent luck,
    Twenty percent skill,
    Fifteen percent concentrated power of will,
    Five percent pleasure,
    Fifty percent pain,
    And a hundred percent reason to remember the name!

  • Well i had the same problems like the others since 1.00 am. I just started the Freelancer exe, let the launcher patch and than my avira say that my Freelancer exe is a malware. Now I said that he have to ignore it and now there is no problem anymore.

  • Same problem, but only since today.


    Keeps on reoccuring every single time I attempt to start FL, no matter how often the problem is ignored, quarantined or deleted (apparently the freelancer.exe cannot be deleted or keeps being restored by something), the "always ignore" option does not seem to change anything either.


    Also keeps on reoccuring after making a completely fresh Freelancer installation (which, on it's own when not having CF installed, does not have this problem), a completely fresh mod manager 1.31 download&installation and a completely fresh Crossfire download&installation (which took forever because 1.9 is huge).
    Thus I doubt there is a problem with my Freelancer version or the mod manager.


    Uninstalling my antivir and then downloading and installing a different one changed nothing, it was still detected every time and neither ignoring, nor quarantining or deleting did anything at all.
    So it cannot be an immediate problem with avira antivir.


    An interesting note: If I hammer the "play singleplayer" button fast enough (before the launcher can start downloading any files), it will display "Problem starting Multiplayer [E7]" (or E6 or E8 or so, it's hard to recreate and look which number, but it does say multiplayer for some reason even though I try to start singleplayer) instead.



    So since it is the only thing that could potentially have changed anything about multiple people's FLCF files from yesterday to today is the launcher, it is The only suspect thing left, but if OP says he did not change anything about the .exe file there is no reason not to believe him.



    Anyway, not that I'm accusing anyone of foul play or something, it's just that the game doesn't work while this problem persists. The usual ways of dealing with problems like this do not work.

    Ist das Leben nicht schön, wenn man besessen ist?

    Edited 7 times, last by Shoat ().

  • well, yeah but ... the launcher... the freelancer.exe was not updated at all
    the version you have is still the version that was installed with the mod which was released 3 months ago
    nothing has changed

    signew.jpg


    cfmoddblogo.png5904.png5904.png
    http://www.moddb.com/scripts/topsite.php?ts=4766


    Only dead fish swim with the stream.
    Don't discuss with idiots. They only drag you down to their level and then beat you with experience there.


    This is ten percent luck,
    Twenty percent skill,
    Fifteen percent concentrated power of will,
    Five percent pleasure,
    Fifty percent pain,
    And a hundred percent reason to remember the name!

  • Same Problem started today with me, too. But i looked a bit and its not the normal freelancer.exe but the one in Microsoft Games/Freelancer/EXE2/freelancer.exe
    Well telling Avira to ignore that file removes the problem ;)

  • Update:


    The "always ignore" option now actually works and I can play again.


    I still have no idea wtf was going on there.
    The only thing that changed since my last post was a tiny windows update.

    Ist das Leben nicht schön, wenn man besessen ist?

    Edited 3 times, last by Shoat ().

  • I got a new warning today, this time for a different file. This time Avira told me that the ambienteA.utf in C:\Program Files (x86)\Microsoft Games\Freelancer\DATA\AUDIO\ is also the Virus TR/Crypt.XPACK.Gen5.


    Update: There were 5 more files with a possible infection detected, all in the same directory as the ambienteA.utf. Those files are: ambienteB.utf, ambienteD.utf, ambienteE.utf, _ambienteA.utf and _ambienteB.utf. The flmm.bak files of those files were also found to be infected. I just deinstalled Freelancer and Crossfire. I hope a reinstall will solve this problem which looks like a false positive report from Avira. But just in case it isn't a false positive report, i'm running a complete system scan right now. And if a reinstall won't solve this problem with the false positive report...oh well. The world isn't perfect, right?


    2nd Update: According to the complete system scan, the TR/Crypt.XPACK.Gen5 was found in the Crossfire19.exe file. So the problem with the false positive reports from earlier Crossfire versions seem to persist. Time to reinstall Crossfire.

  • The reason is the packer, since an update of the virus scanner files that are packed with one packet programm result a virus warning.


    I unpaked them with UPX packer and packed them again with that programm and Antivirus is quiet^^


    I was a highwayman. Along the coach roads I did ride
    With sword and pistol by my side


    I was a sailor. I was born upon the tide
    And with the sea I did abide.


    I fly a starship across the Universe divide
    And when I reach the other side
    I'll find a place to rest my spirit if I can
    Perhaps I may become a highwayman again...


    Or I may simply be a single drop of rain
    But I will remain
    And I'll be back again, and again and again and again and again..


    Chars: Bonanza Chingachcook Comanchero Goyathlay Highwayman Klondike Last.Mohican Tecumseh The.Iron.Horse

  • will take care of it this weekend

    signew.jpg


    cfmoddblogo.png5904.png5904.png
    http://www.moddb.com/scripts/topsite.php?ts=4766


    Only dead fish swim with the stream.
    Don't discuss with idiots. They only drag you down to their level and then beat you with experience there.


    This is ten percent luck,
    Twenty percent skill,
    Fifteen percent concentrated power of will,
    Five percent pleasure,
    Fifty percent pain,
    And a hundred percent reason to remember the name!

  • The problem is perhaps no problem: the antivir-software "think´s" that she has detected a virus. But there is no virus. Conclusion: before you install anything of Freelancer and CF s w i t ch your Virenscanner off!
    After installation you can already switch it on, nothing bad will happen in the meantime.


    This problem ist typical for some v.-scanners, therefore many installation manuals demand to switch any scanner off before installation.


    Hope I could help you
    Blacky

  • its very likely that i can add the CF file to the build in exclude list for that av

    signew.jpg


    cfmoddblogo.png5904.png5904.png
    http://www.moddb.com/scripts/topsite.php?ts=4766


    Only dead fish swim with the stream.
    Don't discuss with idiots. They only drag you down to their level and then beat you with experience there.


    This is ten percent luck,
    Twenty percent skill,
    Fifteen percent concentrated power of will,
    Five percent pleasure,
    Fifty percent pain,
    And a hundred percent reason to remember the name!

  • I did the same (added the Fl install directory and the crosfire 1.9 source directory aswell to the exception list in my AV) and now it is working without problems.


    In the past sometimes AV shot down the install procedure about possible virus warning or deleted some files from my game folder about the same reason.


    Now I can scan my comp without the possible loss of any files from game or the install directory.