Jump to content


- - - - -

Igor.exe Home Of A Trojan?


  • Please log in to reply
11 replies to this topic

#1 Alter

Alter

    Jochen Rindt

  • Supporter
  • PipPipPipPipPipPipPipPipPipPip
  • 169 posts
  • Gender:Male
  • Location:Germany
  • Interests:GPL
  • Sim interest:GPL

Posted Oct 12 2017 - 09:22 AM

Hi Racers
New installation of GPL from scratch using the GPLworld installer. KAV moved iGOR.exe to quarantine because of Trojan.Win32.Snojan.bsbm. I doubt KAV is right. Any ideas?
Alter

#2 Yngwie

Yngwie

    Manager of lateral movements

  • Members
  • PipPipPipPipPipPipPipPipPipPip
  • 295 posts
  • Gender:Male
  • Interests:Breathing
  • Sim interest:GPL

Posted Oct 12 2017 - 09:26 AM

It's a false positive. Put the .exe to the exception list of your AV or turn it off when driving.

#3 Alter

Alter

    Jochen Rindt

  • Supporter
  • PipPipPipPipPipPipPipPipPipPip
  • 169 posts
  • Gender:Male
  • Location:Germany
  • Interests:GPL
  • Sim interest:GPL

Posted Oct 12 2017 - 09:39 AM

Thank you. Thought it was a false too.
It' not easy to persuade KAV to leave iGOR.exe alone because it deletes or moves it to quarantine in seconds. You have to shut down KAV before.

Edited by Alter, Oct 12 2017 - 10:09 AM.


#4 Marx

Marx

    Denny Hulme

  • Members
  • PipPipPipPipPipPipPipPipPipPip
  • 236 posts
  • Gender:Male
  • Location:Abidjan, Côte d'Ivoire
  • Interests:Grand Prix Legends, Nascar Racing 2003, Assetto Corsa, Euro Truck Simulator 2, American Truck Simulator
  • Sim interest:GPL and P&G

Posted Oct 12 2017 - 12:31 PM

Interesting. My KAV detected exactly the same on my laptop today but my GPL installation is many years old. And I have been using KAV also for many years on the same laptop.

#5 gliebzeit

gliebzeit

    Targa Fan

  • Supporter
  • PipPipPipPipPipPipPipPipPipPip
  • 3,008 posts
  • Gender:Male
  • Location:Florida - USA
  • Interests:Old guy stuff...
  • Sim interest:GPL

Posted Oct 12 2017 - 01:41 PM

KAV or any virus detection program will update its database regularly.  So, even if you've had KAV and GPL on a particular computer at some point in time a database update then may flag GPL.

#6 max640

max640

    Jackie Ickx

  • Members
  • Pip
  • 1 posts
  • Gender:Male
  • Location:Spain
  • Sim interest:GPL

Posted Oct 12 2017 - 01:55 PM

Hi all,

The same has happened to me with KAV.... but it deleted the two files (iGOR.exe and GEM 2.exe). Now Itry to play GPL again  and if I have problems I'll reinstall the GEM complete. There is no alternative.
Thanks to Danny in any case. I supposed it could be a false positive and now Ihave it confirmed.

#7 Alter

Alter

    Jochen Rindt

  • Supporter
  • PipPipPipPipPipPipPipPipPipPip
  • 169 posts
  • Gender:Male
  • Location:Germany
  • Interests:GPL
  • Sim interest:GPL

Posted Oct 15 2017 - 02:58 AM

Hi max640
In my case KAV didn't really delete the file. Maybe you find them in the quarantine directory to put them back to where they belong.
Alter

#8 Stefan Roess

Stefan Roess

    Denny Hulme

  • GPLLinks Team
  • PipPipPipPipPipPipPipPipPipPip
  • 3,312 posts
  • Gender:Male
  • Location:Bavaria, Germany
  • Interests:racing :)
  • Sim interest:GPL and P&G

Posted Oct 15 2017 - 01:44 PM

Kaspersky Internet Security has also put igor.exe to quarantine on my system.
I have added it to exceptions.

Edited by Stefan Roess, Oct 15 2017 - 01:45 PM.


#9 Saiph

Saiph

    Driving 4 Team BDS #JC4PM

  • Supporter
  • PipPipPipPipPipPipPipPipPipPip
  • 2,406 posts
  • Gender:Male
  • Location:Aylesbury, UK
  • Interests:Computer gaming (esp. simulations, strategy, RPG), real ale, live music, motor sports, boring the NSA/GCHQ to death.
  • Sim interest:GPL

Posted Oct 15 2017 - 02:13 PM

View Postmax640, on Oct 12 2017 - 01:55 PM, said:

...... if I have problems I'll reinstall the GEM complete. There is no alternative. ......

It's always a good idea to keep a backup of your GPL installation so you can restore individual files which may get corrupted or deleted for various reasons.

I used to work for McAfee as a software QA test engineer, testing the VirusScan anti-virus engine, and doing false alarm testing on new AV driver sets. It was fairly common for new anti-virus drivers to false alarm on older files. When you need to write a completely new class of anti-virus driver to cope with a new breed of malware (eg when network-infecting 'worms' appeared) it's easy to forget about the safeguards which prevent your AV from triggering on older files. That's where my testing came in. If a driver set false-alarmed on my test rig, it got passed back to the researchers with the details of the failure, and a smiley message saying "Try again guys!".

#10 SneakiestDuke68

SneakiestDuke68

    Guy Ligier

  • Members
  • Pip
  • 3 posts
  • Gender:Male
  • Location:Poland
  • Interests:Cars, games, history, technology
  • Sim interest:GPL

Posted Dec 12 2019 - 12:37 PM

Hello,
I know that is old topic but i have information for users which use Kaspersky Anti-virus. I contacted with Kaspersky lab and i send them GEM package installer + GEM2.exe + IGOR.exe for check. Today kaspersky lab send me a message that was in a 101% false positive alarm and they fixed it in anti-virus. So, update anti-virus database and after this you can using GEM package installer, GEM2 and IGOR without disabling anti-virus. I tested it and kaspersky AV now no block this applications.
Greetings.

#11 fajanko

fajanko

    Jani Posta

  • GPLLinks Team
  • PipPipPipPipPipPipPipPipPipPip
  • 1,509 posts
  • Gender:Male
  • Location:Budapest, HU
  • Interests:graphic design, games, languages
  • Sim interest:GPL

Posted Dec 12 2019 - 12:49 PM

Thank you Duke!

#12 Brocky05

Brocky05

    King of the Mountain

  • Members
  • PipPipPipPipPipPipPipPipPipPip
  • 432 posts
  • Gender:Male
  • Location:The Long And Winding Road
  • Interests:I'm Way Too Addicted to GPL For Anything Else
  • Sim interest:GPL

Posted Dec 13 2019 - 12:03 AM

good to know thank you




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Sim Racing Links