PDA

View Full Version : mod 4.0 installer...Trojan -false positive ??



plehmann
Nov-27-2014, 20:46
just passing norton with a full scan and the 4.0 installer.exe identified this file as having a trojan payload....both SEP and Norton confirmed it
13652
now based on the fact that Norton and Symantec endpoint protection (SEP) originate from the same melting pot I am unable to confirm whether this is a false positive or not...
anybody had similar issues ?
thoughts
Piers

ATAG_Colander
Nov-27-2014, 21:28
Yes, is a false positive.

From symantec page:

Trojan.Gen is a generic detection for many individual but varied Trojans for which specific definitions have not been created. A generic detection is used because it protects against many Trojans that share similar characteristics.


Translation:
Since there are a lot of trojans that we don't know about, we detect everything that does certain things (like the installer using extracting files) to be on the safe side.

Wolfskid
Nov-28-2014, 16:00
Hi....

The same problem is with: AVAST Vire Scan...

I ignore it. And it works...:), well

Mar28
Nov-30-2014, 18:50
Hi to All!
Tonight after an AVIRA update it also detecĀ“s the installer end name it TR/Roque.268800.13 as Trojan!
Good flights for everyone!!!

B.Hammer
Dec-05-2014, 15:21
-S-


I had the same problem...on one download of the 4.0 mod the 2 files came separate, I scanned each one separate and the scan came up clean (Norton), when I scanned them

together in the folder..the scan showed the Trojan Gen.


Hammer