User avatar
ERISS
AGEod Guard of Honor
Posts: 2219
Joined: Mon Aug 23, 2010 10:25 am
Location: France

Virus in many AGE .exe?

Sat Dec 17, 2011 11:18 pm

With my Avira scan:
Nom: PCK/ExeCryptor
Type: Packer (fr)
En circulation: Oui
Infections signalées Faible
Potentiel de distribution: Faible
Potentiel de destruction: Faible
Fichier statique: Non

Général PCK/ malware class description (fr)

Détails de fichier Logiciel de compression des fichiers exécutables:
Afin d'entraver la détection et de réduire la taille du fichier il est compressé avec un logiciel de compression des exécutables.

User avatar
lodilefty
Posts: 7616
Joined: Sat Aug 11, 2007 3:27 pm
Location: Finger Lakes, NY GMT -5 US Eastern

Sat Dec 17, 2011 11:33 pm

Is this reporting the installer or patch .exe files? They definitely are compacted executables.

We get occasional inquiries, and have yet to encounter anything real...
Some AV software gets a bit "too robust".



(I run Avast, which has kept me virus free for ~6 years now. And it's free!)
Always ask yourself: "Am I part of the Solution?" If you aren't, then you are part of the Problem!
[CENTER][/CENTER]
[CENTER]Visit AGEWiki - your increasingly comprehensive source for information about AGE games[/CENTER]

[CENTER]Rules for new members[/CENTER]
[CENTER]Forum Rules[/CENTER]

[CENTER]Help desk: support@slitherine.co.uk[/CENTER]

User avatar
Hobbes
Posts: 4438
Joined: Sat Mar 11, 2006 12:18 am
Location: UK

Sat Dec 17, 2011 11:39 pm

I have also had false virus detections with AGEOD games in the past.
Like Lodi I have been using Avast for the past few years and have had no problems (and it has also never highlighted AGEOD games as a possible infection).

Cheers, Chris

User avatar
ERISS
AGEod Guard of Honor
Posts: 2219
Joined: Mon Aug 23, 2010 10:25 am
Location: France

Sun Dec 18, 2011 12:58 am

En Angliche c'est plus détaillé:
Virus: PCK/ExeCryptor
Type: Packer
In the wild: Yes
Reported Infections: Low
Distribution Potential: Low
Damage Potential: Low
Static file: No

General PCK/ - Packer

Packer detection is a heuristic detection routine designed to detect common packers used by malware. Even though some packers are commercially available, many executables compressed with them are malware, or have a behaviour that presents a security or privacy risk.

Usually these packers employ encryption mechanisms and often manipulate the original executable code to hide the real functionality.

Please note that legitimate software may employ some of these commercial packers. A packer detection does not necessarily mean that the detected file is malicious. Due to this, enabling packer detection is usually only recommended for corporate users or for users who understand what runtime packers are and how to interpret a packer detection.

A PCK/ detected file is most likely not to be malicious if one or more of the following are true:
- The program is in use for a very long time and is known to the user
- The program was installed by the user himself
- The program comes from a trustworthy source

If you are ever unsure whether a PCK/ detected file is legitimate we highly recommend uploading it to http://www.avira.com/en/support/submit_suspicious_files.html for further analysis.

File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Description inserted by Andrei Ivanes on Friday, March 19, 2010
Description updated by Andrei Ivanes on Friday, March 19, 2010

Ca semblerait un faux-positif, mais par précaution j'enverrai ça chez mon support d'Avira Internet Security 2012 (payant).
J'indiquerai la liste complète des exe incriminés quand mon scan sera enfin terminé.

User avatar
deguerra
Major
Posts: 227
Joined: Sat Sep 18, 2010 2:20 am

Sun Dec 18, 2011 1:24 am

et cela?

Please note that legitimate software may employ some of these commercial packers. A packer detection does not necessarily mean that the detected file is malicious. Due to this, enabling packer detection is usually only recommended for corporate users or for users who understand what runtime packers are and how to interpret a packer detection.

A PCK/ detected file is most likely not to be malicious if one or more of the following are true:
- The program is in use for a very long time and is known to the user
- The program was installed by the user himself
- The program comes from a trustworthy source

User avatar
ERISS
AGEod Guard of Honor
Posts: 2219
Joined: Mon Aug 23, 2010 10:25 am
Location: France

Sun Dec 18, 2011 1:56 am

Exécutables de jeux:
. Wars in America\AGESettings.exe
. Birth of America\BoA.exe

Patch:
. BoA_patch1.13d.exe

J'ai ignoré au lieu de les mettre en quarantaine.

Return to “General discussions”

Who is online

Users browsing this forum: No registered users and 4 guests