Previous Thread
Next Thread
Print Thread
Rate This Thread
Hop To
#1729079 - 03/28/06 12:13 AM LB2 Anthology Virus Infected?  
Joined: Jun 2005
Posts: 2,132
Reticuli Offline
Member
Reticuli  Offline
Member

Joined: Jun 2005
Posts: 2,132
Dayton, OH, USA
I just happened to decide to turn on ezAntivirus, which I've had turned off for a month or so and this is what it came up with just after rebooting the computer:

eTrust ezAntivirus

Filename: lb2cfg.exe
Location: C:\Program Files\Janes\LBA\Longbow2\
Date and Time: 3/27/2006 15:50.50Pm
Infection: Win32/CIH/remnants*2
Type: File
Status: Cleaned
Engine Version: 12.4.1
Signature: 2136
Scanner Type: Real-time

It didn't ask me if I wanted to clean it, but rather simply did it. Is it a virus, or what? Wonder if it has something to do with the multiple keypress and control lockup thing.


The term "necroposting" was invented by a person with no social memory beyond a year. People with a similar hangup are those o.k. with the internet being transient vapor.

http://www.openfuelstandard.org/2011/12/methanol-wins-open-wager.html

Saitek X65 and X52, Glide, Winx3D, and GlovePIE Profiles http://library.avsim.net/search.php?SearchTerm=reticuli&CatID=miscmisc

http://library.avsim.net/register.php

X52 + Silicone Grease = JOY stick
Inline advert (2nd and 3rd post)

#1729080 - 03/28/06 12:36 AM Re: LB2 Anthology Virus Infected?  
Joined: Jun 2005
Posts: 2,132
Reticuli Offline
Member
Reticuli  Offline
Member

Joined: Jun 2005
Posts: 2,132
Dayton, OH, USA
I did a full scan, and the LB2crack209.zip, the resulting no-CD executable, as well as the copy of the original 209 executable it replaced are showing up as infected with CIHremnants (Chernobyl). I wonder if it's the 2.09 patch that everyone's been using, including whoever made the no-CD.exe, or maybe it's in LB2 even unpatched. It's definitely not just Anthology, though.


The term "necroposting" was invented by a person with no social memory beyond a year. People with a similar hangup are those o.k. with the internet being transient vapor.

http://www.openfuelstandard.org/2011/12/methanol-wins-open-wager.html

Saitek X65 and X52, Glide, Winx3D, and GlovePIE Profiles http://library.avsim.net/search.php?SearchTerm=reticuli&CatID=miscmisc

http://library.avsim.net/register.php

X52 + Silicone Grease = JOY stick
#1729081 - 03/28/06 12:56 AM Re: LB2 Anthology Virus Infected?  
Joined: Jul 2002
Posts: 406
Franze Offline
Member
Franze  Offline
Member

Joined: Jul 2002
Posts: 406
Could it have anything to do with the fact that LB2 is a Win32 program?

Isn't there also a possibility that the files were just infected by some other program?

#1729082 - 03/28/06 01:39 AM Re: LB2 Anthology Virus Infected?  
Joined: Jun 2005
Posts: 2,132
Reticuli Offline
Member
Reticuli  Offline
Member

Joined: Jun 2005
Posts: 2,132
Dayton, OH, USA
Like what? I read that CIH can't move around in XP, like it could in 95/98. So it would make more sense that it's already there to begin with. I just reinstalled my entire system like a month ago and no other program is infected. And didn't the 2.09 patch come about at around that time of 1999 when CIH was doing its thing all over the world? The no-CD exe.zip itself is infected, not to mention the original patched exe that it replaced in the LB2 folder. So it's either the 2.09 patch that we've all been using or LB2 even pre-patch. Right? If I download the no-CD exe.zip and scan it I bet the same thing would show up. The ezAntivirus obviously couldn't clean it since it was still zipped on my desktop, but it cleaned everything in the LB2 folder...including the cfg and original 2.09 exe.


The term "necroposting" was invented by a person with no social memory beyond a year. People with a similar hangup are those o.k. with the internet being transient vapor.

http://www.openfuelstandard.org/2011/12/methanol-wins-open-wager.html

Saitek X65 and X52, Glide, Winx3D, and GlovePIE Profiles http://library.avsim.net/search.php?SearchTerm=reticuli&CatID=miscmisc

http://library.avsim.net/register.php

X52 + Silicone Grease = JOY stick
#1729083 - 03/28/06 01:44 AM Re: LB2 Anthology Virus Infected?  
Joined: Jun 2005
Posts: 2,132
Reticuli Offline
Member
Reticuli  Offline
Member

Joined: Jun 2005
Posts: 2,132
Dayton, OH, USA
Yep...

The no-cd zip itself even shows infection.


The term "necroposting" was invented by a person with no social memory beyond a year. People with a similar hangup are those o.k. with the internet being transient vapor.

http://www.openfuelstandard.org/2011/12/methanol-wins-open-wager.html

Saitek X65 and X52, Glide, Winx3D, and GlovePIE Profiles http://library.avsim.net/search.php?SearchTerm=reticuli&CatID=miscmisc

http://library.avsim.net/register.php

X52 + Silicone Grease = JOY stick
#1729084 - 03/28/06 01:53 AM Re: LB2 Anthology Virus Infected?  
Joined: Dec 2000
Posts: 5,600
Recluse Offline
Mediocrity Above All!
Recluse  Offline
Mediocrity Above All!
Hotshot

Joined: Dec 2000
Posts: 5,600
Randolph, NJ
Interesting. I never got a sniff from AVG or F-Prot antivirus on this. Maybe somehow the source you downloaded them from infected them?

I guess we could send you our 'good' copies and see if ezAntivirus still flags it. I suspect false positive, but you can't be too careful.

Recluse


Long system spec sig follows:






PowerSpec G436
Lian Li ATX 205
MSI Z490 Plus Motherboard
Intel Core i7 10700K 3.8 GHz
32 GB RAM DDR4 1600
Nvidia RTX3070

Windows 10 Professional 64 Bit

Flight Gear:

Cougar Hotas S/N 26453
Thrustmaster RCS Rudder Pedals

#1729085 - 03/28/06 01:58 AM Re: LB2 Anthology Virus Infected?  
Joined: Jun 2005
Posts: 2,132
Reticuli Offline
Member
Reticuli  Offline
Member

Joined: Jun 2005
Posts: 2,132
Dayton, OH, USA
http://www.speichts.com/games/lb2/Lb2crack209.zip

Try scanning this one and see what it says. Could be a false positive if there's some Win32 code in the LB2.exe and cfg.exe that resembles Chernobyl.


The term "necroposting" was invented by a person with no social memory beyond a year. People with a similar hangup are those o.k. with the internet being transient vapor.

http://www.openfuelstandard.org/2011/12/methanol-wins-open-wager.html

Saitek X65 and X52, Glide, Winx3D, and GlovePIE Profiles http://library.avsim.net/search.php?SearchTerm=reticuli&CatID=miscmisc

http://library.avsim.net/register.php

X52 + Silicone Grease = JOY stick
#1729086 - 03/28/06 02:14 AM Re: LB2 Anthology Virus Infected?  
Joined: May 2000
Posts: 2,536
AV8R Offline
Senior Member
AV8R  Offline
Senior Member

Joined: May 2000
Posts: 2,536
Southern California USA
I just ran Norton AV on this download and it came out clean. Thats with brand new Norton and updated files.


AV8R
#1729087 - 03/28/06 02:25 PM Re: LB2 Anthology Virus Infected?  
Joined: Sep 2000
Posts: 12,110
PositiveG Offline
Veteran
PositiveG  Offline
Veteran

Joined: Sep 2000
Posts: 12,110
Nothing personal Reticuli.

It's a false positive from an inferior AV product. PERIOD.

My files are Virus free. Email your AV company and tell them to fix their buggy software.

Honestly, this question gets Emailed to me about once a year, the last time it was a weird German AV product that reported it.

Again, these files are Virus FREE!


McAfee reports it's clean.
AVG reports it clean.
AVast reports it clean.
Norton reports it clean.
yadda yadda yadda.

#1729088 - 03/28/06 07:15 PM Re: LB2 Anthology Virus Infected?  
Joined: Nov 2005
Posts: 65
ID42928110 Offline
Junior Member
ID42928110  Offline
Junior Member

Joined: Nov 2005
Posts: 65
Toronto, Canada
I've never used the antivirus program that you're mentioning Reticuli but Norton and AVG are both showing all files as clean. Have you scanned the files with any other antivirus scanners? I'm using the files from +G's site and I haven't had any alerts pop up in the last 5 or 6 scans I've performed.

#1729089 - 04/06/06 11:16 PM Re: LB2 Anthology Virus Infected?  
Joined: Jun 2005
Posts: 28
Ms. Doolittle a.k.a. Vigilante Offline
Junior Member
Ms. Doolittle a.k.a. Vigilante  Offline
Junior Member

Joined: Jun 2005
Posts: 28
Germany
Well the weird german AV Soft... that must have been me ;\) Its AntiVir ... i just disabled checking my Longbowfolder, so everything is easypeasy now. \:D


[quote]"I'm fed up to the ears with old men dreaming up wars for young men to die in." -- George McGovern[/quote]
#1729090 - 04/11/06 05:45 AM Re: LB2 Anthology Virus Infected?  
Joined: Apr 2006
Posts: 10
MJ12 Troop Offline
Junior Member
MJ12 Troop  Offline
Junior Member

Joined: Apr 2006
Posts: 10
USA
I have Avast Anti-Virus but it never seemed to mind Longbow Anthology.


LB2 Handle: Reaver
#1729091 - 12/23/06 03:45 AM Re: LB2 Anthology Virus Infected?  
Joined: Dec 2006
Posts: 5,710
Weird_Crapolla Offline
Hotshot
Weird_Crapolla  Offline
Hotshot

Joined: Dec 2006
Posts: 5,710
St Barth
Hi,

To read...

\:\)

OFF


Flying is the perfect vocation for a man who wants to feel like a boy, but not for one who still is.
Latest upgrades for EAW at Mr Jelly attic
EAW Encyclopedia
https://www.mediafire.com/file/98kfnmmxfyfa0x8/EAW.rar/file
Unrar and use the index file
#2114774 - 01/16/07 02:22 AM Re: LB2 Anthology Virus Infected? [Re: ID42928110]  
Joined: Sep 2004
Posts: 4,564
Eugene Offline
Senior Member
Eugene  Offline
Senior Member

Joined: Sep 2004
Posts: 4,564
Oregon
Guys, I use Avast - changed a while ago to it. Running LB2 recently isolated the same virus in the exe. Had to reinstall with AV turned off. Confirmed by doing it twice. Same report as Reticuli's original.


Eugene
i9-9600K
GeForce 2080ti
Creative Z
Win10
32 gig RAM
Cougar
#2115197 - 01/16/07 01:55 PM Re: LB2 Anthology Virus Infected? [Re: Eugene]  
Joined: Sep 2000
Posts: 12,110
PositiveG Offline
Veteran
PositiveG  Offline
Veteran

Joined: Sep 2000
Posts: 12,110
Avast is detecting it as infected. They've been told, but appear to not care. You can add it to your exceptions list in Avast.

#2115758 - 01/16/07 09:20 PM Re: LB2 Anthology Virus Infected? [Re: PositiveG]  
Joined: Sep 2004
Posts: 4,564
Eugene Offline
Senior Member
Eugene  Offline
Senior Member

Joined: Sep 2004
Posts: 4,564
Oregon
Thanks, +G - will do.

Not that it's incredibly critical, but I wonder why various AV programs are picking up this same signature?


Eugene
i9-9600K
GeForce 2080ti
Creative Z
Win10
32 gig RAM
Cougar

Moderated by  RacerGT 

Quick Search
Recent Articles
Support SimHQ

If you shop on Amazon use this Amazon link to support SimHQ
.
Social


Recent Topics
Headphones
by RossUK. 04/24/24 03:48 PM
Skymaster down.
by Mr_Blastman. 04/24/24 03:28 PM
The Old Breed and the Costs of War
by wormfood. 04/24/24 01:39 PM
Actors portraying British Prime Ministers
by Tarnsman. 04/24/24 01:11 AM
Roy Cross is 100 Years Old
by F4UDash4. 04/23/24 11:22 AM
Actors portraying US Presidents
by PanzerMeyer. 04/19/24 12:19 PM
Dickey Betts was 80
by Rick_Rawlings. 04/19/24 01:11 AM
Exodus
by RedOneAlpha. 04/18/24 05:46 PM
Copyright 1997-2016, SimHQ Inc. All Rights Reserved.

Powered by UBB.threads™ PHP Forum Software 7.6.0