User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

AGESettings.exe / Trojan?

Sat Mar 29, 2008 8:36 pm

My antivirus software suddenly claims that the file "AGESettings.exe" "is" the trojan "TR/Crypt.XPACK.Gen". I have no experience whatsoever with these matters. Normally I would probably just delete the file. However, I believe it is required for AACW to run properly. What should I do? If I delete it, will the game recreate it?

Thanks for any advice anyone can provide. :(
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]
Colonial Campaigns Club (supports BoA and WiA)
[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]
American Civil War Game Club (supports AACW)

User avatar
Rafiki
Posts: 5811
Joined: Thu Aug 24, 2006 9:19 am
Location: Oslo, Norway

Sat Mar 29, 2008 8:55 pm

Striclty speaking, I think it only modifies some values in some of the configuration files and is therefore unused later on (unless you want to have an easy way to change those values later)
[CENTER]Latest patches: AACW :: NCP :: WIA :: ROP :: RUS :: PON :: AJE
Visit AGEWiki - your increasingly comprehensive source for information about AGE games
[SIGPIC][/SIGPIC]
[/CENTER]

User avatar
Clovis
Posts: 3222
Joined: Wed Nov 09, 2005 7:43 pm
Location: in a graveyard
Contact: Website

Sat Mar 29, 2008 9:07 pm

Rafiki wrote:Striclty speaking, I think it only modifies some values in some of the configuration files and is therefore unused later on (unless you want to have an easy way to change those values later)


Moreover, the settings can be edited directly in the general settings file opened with any notepad.
[LEFT]Disabled
[CENTER][LEFT]
[/LEFT]
[LEFT]SVF news: http://struggleformodding.wordpress.com/

[/LEFT]
[/CENTER]



[/LEFT]

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Sat Mar 29, 2008 9:45 pm

Thank you, Gentlemen. So basically you are saying I can delete this file without problem?

Still wonder why of all the 300,000 files on my machine it would have to pick THIS. :bonk:
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
Rafiki
Posts: 5811
Joined: Thu Aug 24, 2006 9:19 am
Location: Oslo, Norway

Sat Mar 29, 2008 9:48 pm

Yup, delete it. Given the likely infestation, you can't use for anything anyway.
[CENTER]Latest patches: AACW :: NCP :: WIA :: ROP :: RUS :: PON :: AJE

Visit AGEWiki - your increasingly comprehensive source for information about AGE games

[SIGPIC][/SIGPIC]

[/CENTER]

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Sat Mar 29, 2008 10:01 pm

Thank you.

Although, it's really funny. I am doing a complete system check right now, and now the AV programme claims that Agesettings.exe in NCP is likewise infected with the same trojan. :tournepas

Does this sound likely? I am beginning to think this is a false positive, caused by some strange similitary of strings or something like that ... :bonk:

I do hate computers. :p leure:
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
Rafiki
Posts: 5811
Joined: Thu Aug 24, 2006 9:19 am
Location: Oslo, Norway

Sat Mar 29, 2008 10:07 pm

Sounds strange and I'm starting to think it may be a false positive too. Which AV program is it? Perhaps others here have experience with it?
[CENTER]Latest patches: AACW :: NCP :: WIA :: ROP :: RUS :: PON :: AJE

Visit AGEWiki - your increasingly comprehensive source for information about AGE games

[SIGPIC][/SIGPIC]

[/CENTER]

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Sat Mar 29, 2008 10:08 pm

It's Avira AntiVir. It's a free one (for private use) ... yes, yes, I know, but it's really good. :innocent:

Or at least I thought so until now. :bonk:
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Sat Mar 29, 2008 10:30 pm

Rather than assume that this virus goes hunting for Ageod game files to infect them ... Rafiki, what do you say, you send me your Agesettings.files for these two games per email and I put them in my games, then check again with the AV software ... if it sounds the alarm again, we know it must be false. :innocent:
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
Rafiki
Posts: 5811
Joined: Thu Aug 24, 2006 9:19 am
Location: Oslo, Norway

Sat Mar 29, 2008 10:42 pm

I'd like to do that, but unfortunately, my Windows installation is "unavailable" (as in "the harddisk it's on is refusing to return my calls). I'd send a mail to support@ageod.com asking for those files, that way you *know* they are clean, and things get done by the book :)
[CENTER]Latest patches: AACW :: NCP :: WIA :: ROP :: RUS :: PON :: AJE

Visit AGEWiki - your increasingly comprehensive source for information about AGE games

[SIGPIC][/SIGPIC]

[/CENTER]

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Sat Mar 29, 2008 11:11 pm

Gotcha. Hope you get your computer problems sorted out ...
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Sun Mar 30, 2008 10:16 pm

Well, I wrote to Ageod support asking for clean copies of the files and got them together with a kind explanation, from which I quote:

"Ageod is using an encryption technology to protect their products from being reverse-engineered. In very rare cases this might cause false positives in connection with certain anti-virus software."

Which is of course fine and I am in fact very relieved that I don't actually have a trojan ...

Only on second thought I am still perplexed, because what is the solution? I can't leave the Agesettings.exe files in the game folders because whenever I go there, my AV software goes crazy over this "trojan". Already once it completely crashed my computer over this. These files, fortunately, are not needed, the games run without them. But what if next time my AV software thinks the main game executable is a trojan? :bonk:

I thought maybe I could just tell my AV programme to leave this file alone, but this doesn't work ... what can I do?

Any advise from a kind soul more experienced with computers than I am would be much appreciated. :innocent:
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
Rafiki
Posts: 5811
Joined: Thu Aug 24, 2006 9:19 am
Location: Oslo, Norway

Sun Mar 30, 2008 10:27 pm

Is "use a different AV program" an option? :)
[CENTER]Latest patches: AACW :: NCP :: WIA :: ROP :: RUS :: PON :: AJE

Visit AGEWiki - your increasingly comprehensive source for information about AGE games

[SIGPIC][/SIGPIC]

[/CENTER]

User avatar
arsan
Posts: 6244
Joined: Tue Nov 28, 2006 6:35 pm
Location: Madrid, Spain

Sun Mar 30, 2008 10:29 pm

I suspect this is not the kind of advice you are looking for, but is the only solution i can think of... :siffle:
Change to another antivirus :innocent:
I can recommend Avast which i use since 3 years ago .
It's free like the one you use, works great... and it has nothing to say about AGEod files :niark:
Regards!

User avatar
Primasprit
Posts: 1614
Joined: Mon Jun 19, 2006 7:44 pm
Location: Germany

Sun Mar 30, 2008 10:52 pm

False positives can occur, with every anti virus software and not only for Ageod software. :p

Your anti virus software is surely updated daily, every update can solve your problem. As a workaround you might simply delete the AGESettings as it is not needed, or you compress it (for example with Winrar or Winzip) and add a password protection to the archive, so the virus scanner can not access the file.

Cheers
Norbert

User avatar
Primasprit
Posts: 1614
Joined: Mon Jun 19, 2006 7:44 pm
Location: Germany

Sun Mar 30, 2008 11:14 pm

BTW: If you like you can also use the free online scanner from Kaspersky to check the AGESettings file.
http://www.kaspersky.com/scanforvirus

User avatar
Gray_Lensman
Posts: 497
Joined: Mon Jun 18, 2007 4:04 am
Location: Who is John Galt?

Mon Mar 31, 2008 4:53 am

deleted

User avatar
boudi
Posts: 654
Joined: Mon Jan 16, 2006 9:21 am

Mon Mar 31, 2008 9:46 am

The best solution, before the next antivir update :

if you feel this is defiantly a false positive then you can add it to your Guard exceptions list

http://forum.avira.com/thread.php?postid=327789#post327789

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Mon Mar 31, 2008 10:20 am

boudi wrote:The best solution, before the next antivir update :

if you feel this is defiantly a false positive then you can add it to your Guard exceptions list

http://forum.avira.com/thread.php?postid=327789#post327789


I believe this is what I've been looking for ... pray, how is it done? Thanks in advance. :)
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Mon Mar 31, 2008 10:39 am

Gray_Lensman wrote:This is an excellent suggestion. By doing so you can still run it by double-clicking the .zip file then double-click the internal AGESettings.exe file. I suppose the password protection prevents the AV scanner from looking inside the .zip file. Very slick idea.


Unfortunately not. The moment you even open the zip archive, the AV kicks in. It's very quick and I have consistently failed to fool it. :(
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Mon Mar 31, 2008 10:41 am

Rafiki wrote:Is "use a different AV program" an option? :)


Only as a last resort. I have a rather good opinion of Antivir. It's lean, fast, accurate, updated every other day or so, and completely free. I have had Norton for some years and had nothing but problems. It slowed down my machine, quarreled with my Firewall, and cost money.
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
boudi
Posts: 654
Joined: Mon Jan 16, 2006 9:21 am

Mon Mar 31, 2008 10:43 am

Regarding exception, you need to click the little + sign next to "guard", and then again next to "scan", in configuration (expert mode) to get to the exception page for the guard.

http://forum.avira.com/thread.php?postid=200174#post200174

I will try this this morning at home, i hope that il will be ok after that.

User avatar
boudi
Posts: 654
Joined: Mon Jan 16, 2006 9:21 am

Mon Mar 31, 2008 10:48 am

Heldenkaiser wrote:Only as a last resort. I have a rather good opinion of Antivir. It's lean, fast, accurate, updated every other day or so, and completely free.


i can't say better. Antivir = :coeurs:

User avatar
boudi
Posts: 654
Joined: Mon Jan 16, 2006 9:21 am

Mon Mar 31, 2008 4:02 pm

Welcome back, Mr boudi!
A listing of files alongside their results can be found below:

File ID Filename Size (Byte) Result
3804226 AGESettings.exe 936 KB FALSE POSITIVE


Please find a detailed report concerning each individual sample below:

Filename Result
AGESettings.exe FALSE POSITIVE

The file 'AGESettings.exe' has been determined to be 'FALSE POSITIVE'. In particular this means that this file is not malicious but a false alarm. Detection will be removed from our virus definition file (VDF) with one of the next updates.

Problème réglé, merci qui ? :nuts:

User avatar
Gray_Lensman
Posts: 497
Joined: Mon Jun 18, 2007 4:04 am
Location: Who is John Galt?

Mon Mar 31, 2008 4:10 pm

deleted

User avatar
Rafiki
Posts: 5811
Joined: Thu Aug 24, 2006 9:19 am
Location: Oslo, Norway

Mon Mar 31, 2008 4:35 pm

I *hope* that it means that whatever they detected within AGESettings.exe has been removed from the virus definition files, not that the file itself won't be checked.
[CENTER]Latest patches: AACW :: NCP :: WIA :: ROP :: RUS :: PON :: AJE

Visit AGEWiki - your increasingly comprehensive source for information about AGE games

[SIGPIC][/SIGPIC]

[/CENTER]

User avatar
Heldenkaiser
AGEod Grognard
Posts: 943
Joined: Wed Mar 07, 2007 12:32 pm
Contact: Website

Mon Mar 31, 2008 10:01 pm

I also hope this will be fixed in a real sense, rather than just worked around. I managed to tell Antivir to ignore the file Agesettings.exe, however, this does nothing about its finding the same "trojan" in the system recovery files every other hour ... files that have some (many figures).exe name that changes every time. :bonk:

Did I mention I hate computers? :p leure:
[color="Gray"]"These Savages may indeed be a formidable Enemy to your raw American Militia, but, upon the King's regular & disciplined Troops, Sir, it is impossible they should make any Impression." -- General Edward Braddock[/color]

Colonial Campaigns Club (supports BoA and WiA)

[color="Gray"]"... and keep moving on." -- General U.S. Grant[/color]

American Civil War Game Club (supports AACW)

User avatar
Primasprit
Posts: 1614
Joined: Mon Jun 19, 2006 7:44 pm
Location: Germany

Mon Mar 31, 2008 10:55 pm

Heldenkaiser wrote:I also hope this will be fixed in a real sense, rather than just worked around. I managed to tell Antivir to ignore the file Agesettings.exe, however, this does nothing about its finding the same "trojan" in the system recovery files every other hour ... files that have some (many figures).exe name that changes every time. :bonk:

Did I mention I hate computers? :p leure:

If it is found in several several files than it is very likely that you really have that trojan. :(
Judging the posts in the Avira forum TR/Crypt.XPACK.Gen seems to be a real threat at the moment.

User avatar
Franciscus
Posts: 4571
Joined: Fri Apr 20, 2007 8:31 pm
Location: Portugal

Mon Mar 31, 2008 11:03 pm

May I suggest AVG antivirus (free or full) ?
No problems until now (well, I did had a virus detected in a Montjoie patch once :siffle: )

User avatar
Jabberwock
Posts: 2204
Joined: Thu May 31, 2007 12:12 am
Location: Weymouth, MA
Contact: ICQ

Tue Apr 01, 2008 12:20 am

AVG free is good, but it's not exactly lean or fast, at least on my system.
[color="DimGray"] You deserve to be spanked[/color]

Image

Return to “AACW Technical support / Aide technique”

Who is online

Users browsing this forum: No registered users and 3 guests