PDA

View Full Version : Antivirus detects Trojan in GW ColorMixer.


Ember
05-10-2005, 08:41
I downloaded the GW ColorMixer from calderstrake's site, and am now glad that I ran my anti-virus on it before running the executable. Below is what I've found:

http://www.picinabox.com/Monday/wtf.JPG

Now I am sincerely hoping that this is some kind of misunderstanding, especially considering calderstrake's position in the community.

On a side note, I scanned the Guild Wars Cape Maker (as downloaded form calderstrake's site) and found the majority of the picture files "password protected". Considering the above situation I am now loathe to run this executable as well.

Oh, and yes, that is BitDefender v7.2 with the latest definitions update.

nightrunner
05-10-2005, 08:42
It's been posted already.

Ember
05-10-2005, 08:45
And what was the response?

Fallen_62
05-10-2005, 08:45
I downloaded the GW ColorMixer from calderstrake's site, and am now glad that I ran my anti-virus on it before running the executable. Below is what I've found:

Now I am sincerely hoping that this is some kind of misunderstanding, especially considering calderstrake's position in the community.

On a side note, I scanned the Guild Wars Cape Maker (as downloaded form calderstrake's site) and found the majority of the picture files "password protected". Considering the above situation I am now loathe to run this executable as well.

Oh, and yes, that is BitDefender v7.2 with the latest definitions update.

Yes, yes, yes, we know, we know. There is an announcement about that file, but it has been bumped down after a few other announcements (such as the GWOL that is up there right now). That file is safe, as is the one we host. Kaspersky and a few other, more "in-depth" scanners see something in that code that makes it think it is a keylogger, but it is not. Turn on your firewall and then run the program and see if anything pops up about letting a connection go through for that program. And there have been other threads on this... Go ahead and search for them :happy34:

edit: We cannot, however, vouch for the safety of any file not downloaded form our site, or any other reputable site (such as a fansite or Calders, in this case)

calderstrake
05-10-2005, 09:22
Yes, yes, yes, we know, we know. There is an announcement about that file, but it has been bumped down after a few other announcements (such as the GWOL that is up there right now). That file is safe, as is the one we host. Kaspersky and a few other, more "in-depth" scanners see something in that code that makes it think it is a keylogger, but it is not. Turn on your firewall and then run the program and see if anything pops up about letting a connection go through for that program. And there have been other threads on this... Go ahead and search for them :happy34:

edit: We cannot, however, vouch for the safety of any file not downloaded form our site, or any other reputable site (such as a fansite or Calders, in this case)
The one on my site was a copy of the one on GWOnline.net; I simply used my site as a mirror for the times when bandwitdh is sluggish on the site here.

In light of the controversy I have removed it from my site and replaced the link with the same link used for the one in the Files section. I don't think anyone ever experienced any problems, but just to be on the safe side...