Jump to content


- - - - -

Gem+ Download Corrupted?

GEM+

  • Please log in to reply
11 replies to this topic

#1 rdinoma

rdinoma

    Guy Ligier

  • Members
  • Pip
  • 3 posts
  • Interests:Grand Prix racing
  • Sim interest:GPL

Posted Dec 14 2017 - 03:27 PM

Just downloaded the GEMPackage_2.5.0.32.exe file from autosimsport.  Tried to install the .exe file and got a message from my Kaspersky anti virus program that the file contains a Trojan program named Backdoor.Win32.IRCBot.agil.  Is the Gem+ file corrupted, or is there an alternate site to download?  Thanks.

#2 Saiph

Saiph

    Driving 4 Team BDS #JC4PM

  • Supporter
  • PipPipPipPipPipPipPipPipPipPip
  • 2,281 posts
  • Gender:Male
  • Location:Aylesbury, UK
  • Interests:Computer gaming (esp. simulations, strategy, RPG), real ale, live music, motor sports, boring the NSA/GCHQ to death.
  • Sim interest:GPL

Posted Dec 14 2017 - 04:00 PM

It's 99.999% certain to be a false alarm. Ignore Kaspersky, turn the anti-virus off temporarily, and try the install again. You should find that it works fine.

Alternatively, if you're not 100% confident, you could download GEM again from the "official" site here:

https://gem.grandprix.../downloads.html

Edited by Saiph, Dec 14 2017 - 04:09 PM.


#3 rdinoma

rdinoma

    Guy Ligier

  • Members
  • Pip
  • 3 posts
  • Interests:Grand Prix racing
  • Sim interest:GPL

Posted Dec 14 2017 - 06:08 PM

Thanks for the advice.  I did download from the alternate site you mentioned and got the same problem.  I finally got it to run under Kaspersky by listing as a "Trusted Application."

#4 John Woods

John Woods

    Be Somebody

  • GPLLinks Team
  • PipPipPipPipPipPipPipPipPipPip
  • 2,778 posts
  • Gender:Male
  • Interests:Too Much Fun
  • Sim interest:GPL

Posted Dec 16 2017 - 11:58 AM

Might want to make sure its not lurking around.
One of many descriptions linked below.

Backdoor Malware



:D

Edited by John Woods, Dec 16 2017 - 12:01 PM.


#5 Bill

Bill

    BRM Freak

  • Administrators
  • PipPipPipPipPipPipPipPipPipPip
  • 979 posts
  • Gender:Male
  • Location:U.S. Wise Va.

Posted Dec 16 2017 - 12:06 PM

let me know, we can always replace the download, I seem to remember this being a false positive because of the way the installer works...

#6 rdinoma

rdinoma

    Guy Ligier

  • Members
  • Pip
  • 3 posts
  • Interests:Grand Prix racing
  • Sim interest:GPL

Posted Dec 18 2017 - 09:31 AM

The malware is in a file named "//data0150" which seems to attach itself to the GEM+ file during the download process.  After installing as a "Trusted Application" in Kaspersky, I ran a full anti virus scan and cleaned out any residual pieces.  Thanks for your help and advice.  P.S.:  I did find an earlier thread on this Trojan in Igor (last comment October 16, 2017).

#7 Michkov

Michkov

    Denny Hulme

  • Members
  • PipPipPipPipPipPipPipPipPipPip
  • 1,128 posts
  • Gender:Male
  • Location:Graz
  • Sim interest:GPL

Posted Dec 19 2017 - 01:46 PM

View Postrdinoma, on Dec 18 2017 - 09:31 AM, said:

The malware is in a file named "//data0150" which seems to attach itself to the GEM+ file during the download process.  After installing as a "Trusted Application" in Kaspersky, I ran a full anti virus scan and cleaned out any residual pieces.  Thanks for your help and advice.  P.S.:  I did find an earlier thread on this Trojan in Igor (last comment October 16, 2017).

Have you got file paths for what your AV found?

#8 Yngwie

Yngwie

    Manager of lateral movements

  • Members
  • PipPipPipPipPipPipPipPipPipPip
  • 251 posts
  • Gender:Male
  • Interests:Breathing
  • Sim interest:GPL

Posted Dec 22 2017 - 04:25 AM

Well, if I take a look at the results of Virustotal.com, I'm pretty sure it's a false positive.

I guess something in the behaviour of the .exe is categorized as beeing malware. Due to the age and beeing developed for previous OSses I guess.

#9 John Woods

John Woods

    Be Somebody

  • GPLLinks Team
  • PipPipPipPipPipPipPipPipPipPip
  • 2,778 posts
  • Gender:Male
  • Interests:Too Much Fun
  • Sim interest:GPL

Posted Dec 23 2017 - 07:19 AM

View PostYngwie, on Dec 22 2017 - 04:25 AM, said:

Well, if I take a look at the results of Virustotal.com, I'm pretty sure it's a false positive.

Quote

Raising the global IT security level through sharing


Appreciate the link.



:D

Edited by John Woods, Dec 23 2017 - 07:23 AM.


#10 SneakiestDuke68

SneakiestDuke68

    Guy Ligier

  • Members
  • Pip
  • 3 posts
  • Gender:Male
  • Location:Poland
  • Interests:Cars, games, history, technology
  • Sim interest:GPL

Posted Dec 12 2019 - 12:37 PM

Hello,
I know that is old topic but i have information for users which use Kaspersky Anti-virus. I contacted with Kaspersky lab and i send them GEM package installer + GEM2.exe + IGOR.exe for check. Today kaspersky lab send me a message that was in a 101% false positive alarm and they fixed it in anti-virus. So, update anti-virus database and after this you can using GEM package installer, GEM2 and IGOR without disabling anti-virus. I tested it and kaspersky AV now no block this applications.
Greetings.

#11 Brocky05

Brocky05

    King of the Mountain

  • Members
  • PipPipPipPipPipPipPipPipPipPip
  • 374 posts
  • Gender:Male
  • Location:The Long And Winding Road
  • Interests:I'm Way Too Addicted to GPL For Anything Else
  • Sim interest:GPL

Posted Dec 12 2019 - 11:59 PM

good to know thank you

#12 ginetto

ginetto

    GPL track editor

  • Administrators
  • PipPipPipPipPipPipPipPipPipPip
  • 3,304 posts
  • Gender:Male
  • Location:Lombardia, Italia
  • Interests:Mountain
  • Sim interest:GPL

Posted Dec 14 2019 - 04:04 AM

Thank you Sneakiest Duke 68, way to go! :thumbup:





Also tagged with one or more of these keywords: GEM+

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Sim Racing Links