Jump to content

Anti-Virus picks up Trojan in ED products installer


Recommended Posts

Posted

I sent the file to Kaspersky labs tech support. They analyzed it and returned this email to me:

 

Hello,

 

This message has been generated by an automatic message response system. The message contains details about verdicts that have been returned by Anti-Virus in response to the files (if any are included in the message) with the latest updates installed.

 

lua-ED_demosceneAPI.dll - Trojan-Downloader.Win64.Agent.bb

 

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

 

Best Regards, Kaspersky Lab

 

"39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700 http://www.kaspersky.com http://www.viruslist.com"

Answers to most important questions ATC can ask that every pilot should memorize:

 

1. No, I do not have a pen. 2. Indicating 250

Posted

Perhaps I should take DCS off of my exempt list.

ASUS ROG Maximus VIII Hero, i7-6700K, Noctua NH-D14 Cooler, Crucial 32GB DDR4 2133, Samsung 950 Pro NVMe 256GB, Samsung EVO 250GB & 500GB SSD, 2TB Caviar Black, Zotac GTX 1080 AMP! Extreme 8GB, Corsair HX1000i, Phillips BDM4065UC 40" 4k monitor, VX2258 TouchScreen, TIR 5 w/ProClip, TM Warthog, VKB Gladiator Pro, Saitek X56, et. al., MFG Crosswind Pedals #1199, VolairSim Pit, Rift CV1 :thumbup:

Posted

Hmmm...

 

I sent the file to Kaspersky labs tech support. They analyzed it and returned this email to me:

 

Hello,

 

This message has been generated by an automatic message response system. The message contains details about verdicts that have been returned by Anti-Virus in response to the files (if any are included in the message) with the latest updates installed.

 

lua-ED_demosceneAPI.dll - Trojan-Downloader.Win64.Agent.bb

 

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

 

Best Regards, Kaspersky Lab

 

"39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700 http://www.kaspersky.com http://www.viruslist.com"

ASUS ROG Maximus VIII Hero, i7-6700K, Noctua NH-D14 Cooler, Crucial 32GB DDR4 2133, Samsung 950 Pro NVMe 256GB, Samsung EVO 250GB & 500GB SSD, 2TB Caviar Black, Zotac GTX 1080 AMP! Extreme 8GB, Corsair HX1000i, Phillips BDM4065UC 40" 4k monitor, VX2258 TouchScreen, TIR 5 w/ProClip, TM Warthog, VKB Gladiator Pro, Saitek X56, et. al., MFG Crosswind Pedals #1199, VolairSim Pit, Rift CV1 :thumbup:

Posted

Guys, for future problems, feel free to ask VirusTotal so we don't have to collect everybody's result over a period of hours or even days.

 

This specific file is currently reported to be problematic by 0 of 55 AV engines at VirusTotal:

 

https://www.virustotal.com/en/file/0e145e8bf40a7edbf94ea50d3fe838289dece8d71c5f570aaeb2920b8d92962e/analysis/

 

(BTW, it was last scanned over an hour before I queried the service, so it seems someone else had the same idea already :)).

 

VirusTotal start page: https://www.virustotal.com/

 

Rule of thumb: if only one or two engines report a virus, it's either brand new, or the engines are simply wrong. :smartass:

Posted
Have been fixed.

 

It appears to be fixed!

 

Ran the update and now it scans fine. :thumbup:

 

Rule of thumb: if only one or two engines report a virus, it's either brand new, or the engines are simply wrong.

 

New viruses....

 

only one or two engines might detect them at all.

 

[ame]http://www.av-comparatives.org/wp-content/uploads/2015/10/avc_fdt_201509_en.pdf[/ame]

 

In fact, Kaspersky Labs had one of the lowest rates of both false positives (only 2 FP) AND a 99.5% detection rate.

 

Compare that with AVG's 93.7% detection rate and 6 FP's.

 

So when it goes off, I listen.

Answers to most important questions ATC can ask that every pilot should memorize:

 

1. No, I do not have a pen. 2. Indicating 250

Posted
New viruses....

 

only one or two engines might detect them at all.

 

http://www.av-comparatives.org/wp-content/uploads/2015/10/avc_fdt_201509_en.pdf

 

In fact, Kaspersky Labs had one of the lowest rates of both false positives (only 2 FP) AND a 99.5% detection rate.

 

Compare that with AVG's 93.7% detection rate and 6 FP's.

 

So when it goes off, I listen.

 

I don't intend to start a discussion about AV products, but would like to point out one aspect of the quoted test:

 

The malware sets were frozen on the 24th August 2015 and consisted of 166522 malware samples. The products had Internet/cloud-access during the test, were last updated on the 1st of September 2015 and tested under Microsoft Windows 10 64-Bit.

 

If I read this correctly, all tested engines were fed one week old samples.

 

I agree that under these circumstances, 93% detection rate doesn't sound too promising, and failure to remove false positives within this time frame doesn't sound too good either. Then again, I never promoted AVG in the first place (well actually, I did, but that was long ago and never on this forum IIRC). :D

 

However, I would not conclude that Kaspersky has a phenomenally low rate of false positives based on this data. I would only conclude that they're able to remove false positives within a one-week period, which seems to be validated by their response to this particular issue. :thumbup:

Posted
However, I would not conclude that Kaspersky has a phenomenally low rate of false positives based on this data.

 

OK, sounds good and whatever....

 

The data I have seen says otherwise and I am happy with it! :thumbup:

Answers to most important questions ATC can ask that every pilot should memorize:

 

1. No, I do not have a pen. 2. Indicating 250

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...