Posted March 02, 2014
I've downloaded a few installation files this evening, and ran into an unexpected issue.
When attempting to install Unepic from setup_unepic_2.2.0.7.exe (just downloaded - file size 200,881,752 bytes, size on disk 200,884,224 bytes, Certification signing date Friday, November 15, 2013 7:39:30 AM) Comodo Antivirus reports
TrojWare.Win32.Injector.sbp@281376821 for file C:\Users\[..]\setup_unepic_2.2.0.7.tmp
The AV is part of "Comodo Internet Security Premium"
Product version 6.3.302093.2976
Database version 17872
I checked other files downloaded during the same session:
setup_dungeon_keeper_gold_2.0.0.4.exe (file size 258,148,408 bytes)
setup_dungeon_keeper2_2.0.0.32.exe (file size 441,410,424 bytes)
setup_darklands_2.0.0.6.exe (file size 85,795,904 bytes)
setup_master_of_magic_2.0.0.20.exe (file size 25,454,840 bytes)
setup_patrician3_2.0.0.5.exe (file size 463,984,520 bytes)
setup_syndicate_plus_2.0.0.12.exe (file size 28,243,368 bytes)
setup_thief_gold_2.0.0.46.exe (file size 752,199,848 bytes)
patch_thief_gold_2.0.3.49.exe (file size 1,740,208 bytes)
setup_thief2_2.0.0.18.exe (file size 801,836,368 bytes)
patch_thief2_2.0.1.19.exe (file size 2,357,352 bytes)
All of them report the same trojan injection attempt when the installation .tmp file is created.
I checked older GOG installation files, none of them results in this message, indicating that this is not a system infection issue.
I downloaded Dwarf Fortress as a sample from another source - no infection. So it's not the connection on my end being hacked, either.
What's going on?
I have the files archived in case you want to analyze them.
When attempting to install Unepic from setup_unepic_2.2.0.7.exe (just downloaded - file size 200,881,752 bytes, size on disk 200,884,224 bytes, Certification signing date Friday, November 15, 2013 7:39:30 AM) Comodo Antivirus reports
TrojWare.Win32.Injector.sbp@281376821 for file C:\Users\[..]\setup_unepic_2.2.0.7.tmp
The AV is part of "Comodo Internet Security Premium"
Product version 6.3.302093.2976
Database version 17872
I checked other files downloaded during the same session:
setup_dungeon_keeper_gold_2.0.0.4.exe (file size 258,148,408 bytes)
setup_dungeon_keeper2_2.0.0.32.exe (file size 441,410,424 bytes)
setup_darklands_2.0.0.6.exe (file size 85,795,904 bytes)
setup_master_of_magic_2.0.0.20.exe (file size 25,454,840 bytes)
setup_patrician3_2.0.0.5.exe (file size 463,984,520 bytes)
setup_syndicate_plus_2.0.0.12.exe (file size 28,243,368 bytes)
setup_thief_gold_2.0.0.46.exe (file size 752,199,848 bytes)
patch_thief_gold_2.0.3.49.exe (file size 1,740,208 bytes)
setup_thief2_2.0.0.18.exe (file size 801,836,368 bytes)
patch_thief2_2.0.1.19.exe (file size 2,357,352 bytes)
All of them report the same trojan injection attempt when the installation .tmp file is created.
I checked older GOG installation files, none of them results in this message, indicating that this is not a system infection issue.
I downloaded Dwarf Fortress as a sample from another source - no infection. So it's not the connection on my end being hacked, either.
What's going on?
I have the files archived in case you want to analyze them.
Post edited March 02, 2014 by Lukaszmik
No posts in this topic were marked as the solution yet. If you can help, add your reply