Page 1 of 2 12 LastLast
Results 1 to 20 of 21

Thread: Trojan.Gen.X

  1. #1

    Trojan.Gen.X

    This morning I tried to launch Anarchy the launcher attempts to download 2.81 mb of something ...

    Then I get a message that Windows can not find ...\Anarchy Online\patchertmp\AnarchyPatcher.exe.

    Then my Nortons blocks a file Trojan.Gen.X

    I did not have any issues yesterday with Anarchy ... and I don't see any indication of patching today.

    Any suggestions or clues?

    Emma

  2. #2
    Within my Norton's Recent Activity it says the Trojan.Gen.X was contained in the file / attempted 2.81 mb download sourced from: http://update.anarchy-online.com/c/M...chyPatcher.exe

    I assume this Trojan is coming thru Funcom servers?

    Anyone else seeing this? My housemate logged in 2 hours or so ago and did not get this message.

    Emma

  3. #3
    It's extremely unlikely (nearly impossible) that this detection has anything to do with Funcom or AO directly.

    It would look like something else you have on your computer (either something downloaded/ran/installed or just a simple USB Flash Drive or even CD or anything else with an auto run) brought you a little unwanted present.

    I can confirm zero detections on 3 PC's that we have AO installed on over here.

    Try running a full scan of your system with a reliable anti-malware and/or anti-virus software. Not sure Norton is still considered reliable as I haven't used it in many years.
    Michizure is love, Michizure is life.
    --
    Dywas - 220/30/70 Neutral Nanomage Nano-Technician
    Caramela - 220/30/70 Neutral Solitus Doctor
    Desejos - 220/30/?? Neutral Atrox Enforcer
    Gretchenross - 220/30/?? Neutral Opifex Shade
    Bizzle - 220/30/70 Neutral Atrox Soldier

    --<3 Professional love--
    * Aiken pets Lazy on the head. Sure it is, you keep telling self that
    <Aiken> such a cutesy clammer aren't you *cheekpinch*
    <Lazy>
    <Lazy> viva la revolucion
    * Dywas decides to walk away from the soon-to-be sexytime
    <Aiken> lol Dywas, Id make a man of him
    <Lazy> Dywas, i'd go gay for aiken. no lie

  4. #4
    Norton is junk, that's what i think is the problem here given the info you posted.
    Don't you just hate this kind of ppl
    http://redwing.hutman.net/%7Emreed/w...rouscranus.htm

  5. #5
    Do yourself a favour & ditch Norton, it's nothing but bloatware for your system. As suggested before, run a system scan with something reliable & also check with a malware scanner such as Spybot Search & Destroy.
    Chances are high it's just a false-positive on Nortons side & it's nuked something important from the AO files, for reasons I'm sure only Norton will ever know.
    One profession to RoO them all, one profession to proc stun them, one profession to calm them all and in the darkness Exp perk them!

    Crataiken 220/30/70 General - Primal Evolution - 3rd AI 30 'Crat on RK 1 Setup
    Calms 220/30/70 General - Primal Evolution
    Medicaiken 220/30/70 General - Primal Evolution Setup
    Newen 220/30/70 President - The Galactic Milieu
    Mettagirl 220/20/** General - Primal Evolution
    Krataiken 150/18/40 General - Primal Evolution Setup

  6. #6
    My guess is that Norton's heuristic analyzer is just crap and found false positive...
    Ekarona 220/30 Female Solitus Engineer, long term member of Northern Star and proper "poor" gimp.
    Ekaslave 220/low Female Solitus Trader, FLAT(TM) pricing TS, almost all can do!
    Ekaros almost there/almost there too Male Solitus Martial-Artist.
    Ekadv gimp/gimp Female Opifex Adventurer

  7. #7
    If Norton's is so bad then why do many of the ISP's include it in their services? How would I know an anti-virus program I download wouldn't be just as bad as Norton's?

    I have had issues with Norton's before when it didn't recognize a newly named Anarchy program included with an announced patch. I have never had issues when there were no scheduled patches.

    Emma

  8. #8
    AvG free and spybot will help massively, as will running malwarebytes on your system.

    To answer you question, Norton pay those companies the most money to use their bloatware. Norton is trash honestly.
    Caloss2 LVL 220 melee VANGUARD (semi retired).....Llewlyn 220/30/70 meepmeep.....Boooocal 220../30/70 Soldier.......Knack 220/30/70 Keeper.....Hiesenberg 215/xx/xx NT NERFED Neytiri1 220/30/70 Shade Knacker220/30/70Meat shield
    https://www.youtube.com/user/caloss2 for guides/walkthroughs/letsplays and all your other AO needs
    Quote Originally Posted by Mastablasta
    In my special design documents that I feed to the FC devs, who are my willing slaves.

  9. #9
    So anyways, installed a different virus software ... it is scanning now.

    However, Norton's not withstanding ...

    Something tried to download when I opened the launch screen and there are no patches today that I noticed ...

    Emma

  10. #10
    Quote Originally Posted by Emma View Post
    So anyways, installed a different virus software ... it is scanning now.

    However, Norton's not withstanding ...

    Something tried to download when I opened the launch screen and there are no patches today that I noticed ...

    Emma
    It sounds like something was detected when you ran the launcher. It wasn't necessarily an attempt to download anything.

    It may have been a false positive, as mentioned previously. That could be caused by a recent update to Norton's wacky virus definitions/heuristics and something that previously seemed fine to Norton in AO's files (because it was!), now seems not fine. It doesn't actually mean there's a virus involved.

    If it wasn't a false positive, it may have simply been something else you had that calmly ran in the background infecting your stuff until a recent update to Norton's stuff picked up on it.

    Did some reading.. Norton is really not up to par with even 100% free Anti-Virus and Anti-Malware software these days and may cause many issues (mostly major slowdown) in a system. The problem is it's apparently also notoriously hard to uninstall so BE CAREFUL.
    Michizure is love, Michizure is life.
    --
    Dywas - 220/30/70 Neutral Nanomage Nano-Technician
    Caramela - 220/30/70 Neutral Solitus Doctor
    Desejos - 220/30/?? Neutral Atrox Enforcer
    Gretchenross - 220/30/?? Neutral Opifex Shade
    Bizzle - 220/30/70 Neutral Atrox Soldier

    --<3 Professional love--
    * Aiken pets Lazy on the head. Sure it is, you keep telling self that
    <Aiken> such a cutesy clammer aren't you *cheekpinch*
    <Lazy>
    <Lazy> viva la revolucion
    * Dywas decides to walk away from the soon-to-be sexytime
    <Aiken> lol Dywas, Id make a man of him
    <Lazy> Dywas, i'd go gay for aiken. no lie

  11. #11
    I'm glad to see this thread, as I came across this issue yesterday running Symantec, and although I was 99% certain it was a false positive, I am now even more certain. Some additional info:

    Symantec updated the heuristic for Trojan.Gen.X yesterday, which is presumably why it all of a sudden decided that AO, or more specifically AnarchyPatcher.exe is a trojan. Symantec then deleted this file. The next time I went to launch AO, anarchy.exe noticed that the patcher was missing, and attempted to download it (hence the download). Symantec saw this, blocked the download, and then classified anarchy.exe as a SONAR.Dropper because it tried to install what it believed to be a trojan, and therefore Symantec decided to delete anarchy.exe.

    To be fair, I can see how a program designed to patch existing files on your computer could appear to be malware to a heuristic based scan. It would probably be best if Funcom reached out to Symantec to get AnarchyPatcher.exe white listed, as I think this how these sort of things are normally resolved.

    As far as the Norton/Symantec hate goes, don't read into it too much. In my opinion, there was a time where there were some better/more efficient options than Norton out there, but as long as you're running the latest version of Norton it's perfectly reasonable software. However, I don't actively keep up with the Norton side of things, as I use a different product by the same company, so my opinion may not be worth much. If you don't like it for other reasons or if it continues to give you issues with AO updates and patches, there are many great alternatives out there, both free and paid.

  12. #12
    It appears that my issue was similar to yours Fromm ... the file the launcher wanted to download was the patcher.exe that Norton's had blocked/deleted. I did a full scan with new virus software and no issues found ... allowed the launcher to download the missing file ... and now doing another full scan for good measure.

    Emma

  13. #13
    Just as a sidenote to this thread as it's kind've related. I haven't had an antivirus installed permanently on any of my machines in probably 5 or 6 years now. I occasionally scanned with various AV's over this time, just to be sure, and never had a hit. Ever. Ofc this is related to general safe browsing habits and such, but it's definitely worth noting.
    One profession to RoO them all, one profession to proc stun them, one profession to calm them all and in the darkness Exp perk them!

    Crataiken 220/30/70 General - Primal Evolution - 3rd AI 30 'Crat on RK 1 Setup
    Calms 220/30/70 General - Primal Evolution
    Medicaiken 220/30/70 General - Primal Evolution Setup
    Newen 220/30/70 President - The Galactic Milieu
    Mettagirl 220/20/** General - Primal Evolution
    Krataiken 150/18/40 General - Primal Evolution Setup

  14. #14
    Quote Originally Posted by Aiken View Post
    Just as a sidenote to this thread as it's kind've related. I haven't had an antivirus installed permanently on any of my machines in probably 5 or 6 years now. I occasionally scanned with various AV's over this time, just to be sure, and never had a hit. Ever. Ofc this is related to general safe browsing habits and such, but it's definitely worth noting.
    Same here. Adopt safe browsing habits, run a clean system. Run proper checks with trustworthy software when you do your PC's spring cleaning (which you should do anyway).
    Your system will perform better and you'll be safe.. and it's really not hard/time consuming to learn.
    Michizure is love, Michizure is life.
    --
    Dywas - 220/30/70 Neutral Nanomage Nano-Technician
    Caramela - 220/30/70 Neutral Solitus Doctor
    Desejos - 220/30/?? Neutral Atrox Enforcer
    Gretchenross - 220/30/?? Neutral Opifex Shade
    Bizzle - 220/30/70 Neutral Atrox Soldier

    --<3 Professional love--
    * Aiken pets Lazy on the head. Sure it is, you keep telling self that
    <Aiken> such a cutesy clammer aren't you *cheekpinch*
    <Lazy>
    <Lazy> viva la revolucion
    * Dywas decides to walk away from the soon-to-be sexytime
    <Aiken> lol Dywas, Id make a man of him
    <Lazy> Dywas, i'd go gay for aiken. no lie

  15. #15
    Norton is not as bad as it used to be. It has an enormously poor reputation among the IT crowd because of their marketing tactics - they spent a lot of effort to become ubiquitous, but less effort to be good at their job. These days, however, Norton is pretty competitive as an anti-virus suite. That said, I don't agree with their nagware behavior and installation practices - so I don't use them.

    If you're on a genuine copy of windows, the best free AV suite is Microsoft Security Essentials. It's 1) free 2) not nagging 3) comprehensive and 4) lightweight (Doesn't take up much resources). This is the only AV suite I use on any PC. Nod32 is often rated as simply the best AV/Anti-Malware suite - but it is expensive.

    In addition to this, I've found that Malwarebytes and specific tools such as Kaspersky's TDSSKiller can clean 99% of infections in a short amount of time.
    Raise your hand \o if you want to pay lots of attention to Veebz!

  16. #16
    Thanks for all the input and suggestions. I consider myself to be a fairly safe browser. I uninstalled Norton's, installed the Microsoft Security Essentials and did full scan twice and it did not find any issues with Anarchy or otherwise. I feel comfortable that it was what you all called a false positive and the reason the launcher wanted to download something was because Norton's had deleted/quarantined the Anarchy patcher.

    Emma

  17. #17
    Yeah, my Symantec Endpoint Protection pinned it too, but I just reversed the scan and put it under an exception.
    Characters:
    Legendfluff (with many accounts of froobs)

    Froob Level 5 Collar: http://i.imgur.com/I19c92X.jpg
    Froob atrox Lv5 Collar: http://i.imgur.com/2zVqTX9.jpg

    With the onset of awakened beast armor, we can now equip Alpha chest on Atrox Soldiers & Alpha Brain on Atrox Doctors.

  18. #18
    Avast antivirus,comodo firewall,peerblock, any good spyware etc use them.

    http://www.urbandictionary.com/defin...rton+antivirus
    Last edited by doctorgore; Aug 12th, 2015 at 06:05:29.

  19. #19
    Quote Originally Posted by Emma View Post
    So anyways, installed a different virus software ... it is scanning now.

    However, Norton's not withstanding ...

    Something tried to download when I opened the launch screen and there are no patches today that I noticed ...

    Emma
    Nothing tried to download anything. AnarchyPatcher.exe is exactly 2.8 MB in size, and every time you start AO, the game will checksum all of its binary components like .exes and .dlls as a protection against tampering. Real time virus scanners work by hooking themselves to file open actions performed on protected file types, such as these, and scan the file before the requesting process is allowed to open them. Norton likely received a (bad) signature update since the last time you ran AO, and as it seems to often hapen with it, it contained incorrect data that caused a false positive on this file when it was scanned as the game tried to access it.

    "All things point to that they didn't play to win, but for the game itself and to play well. ... Later in their evolution, they forgot all about playing and having fun. When their corrupted minds only cared for what new ways they could gain power, there was no room for the simple things in life."
    - One Who Will Always Listen
    "Hope is the first step on the road to disappointment."
    - Librarian Isador Aikos, W40k: Dawn of War
    "If you want to make enemies... try to change something."
    - Adam Jensen, Deus Ex: Human Revolution

  20. #20
    Quote Originally Posted by Honorbound View Post
    Nothing tried to download anything. AnarchyPatcher.exe is exactly 2.8 MB in size, and every time you start AO, the game will checksum all of its binary components like .exes and .dlls as a protection against tampering. Real time virus scanners work by hooking themselves to file open actions performed on protected file types, such as these, and scan the file before the requesting process is allowed to open them. Norton likely received a (bad) signature update since the last time you ran AO, and as it seems to often hapen with it, it contained incorrect data that caused a false positive on this file when it was scanned as the game tried to access it.
    Actually, the launcher did indeed download AnarchyPatcher.exe, as it noticed that it was missing because the virus scanner had deleted it. The virus scanner then deleted the freshly downloaded patcher as well.

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •