Page 1 of 1

Virus in this week's RAW course

PostPosted: Thu Jan 10, 2019 3:37 am
by cooncat
I downloaded the zip file of the course for this week's RAW tournament. When I opened the Zip file, it contained an EXE file, not a course file. I scanned it with my AV, and it contained a virus and was deleted. I mention this so that others, who may be more trusting, will not get burned.

Re: Virus in this week's RAW course

PostPosted: Thu Jan 10, 2019 10:53 am
by rwoodworkr
Which course was it and where was it downloaded from?

Re: Virus in this week's RAW course

PostPosted: Thu Jan 10, 2019 2:05 pm
by Redskin
I clicked on the down arrow to get the course for this weeks RAW.
There is a note at the top of the page that opens and states --

The ZIP File contains an .exe. It will try to install it automatically to the Courses folder. If installed elsewhere it creates a Courses folder there and puts the .crz into it.

I don't know where you got your course file from, but I didn't see any virus. Just an exe file that would put it in the course's folder.
Jim

Re: Virus in this week's RAW course

PostPosted: Fri Jan 11, 2019 9:55 am
by albatros
i downloaded and played the raw course this week without any problems but always appreciate a heads up about possible suspicious activity.


albatros

a bouncing ball never sleeps

Re: Virus in this week's RAW course

PostPosted: Fri Jan 11, 2019 2:24 pm
by cooncat
I downloaded it from LSPN, from the course description. I didn't notice the msg. about it being an EXE file, which creates is own course file. I am very suspicious whenever downloading an EXE file, so I had my AV program check it, and it showed that it contained a virus. As soon as I saw that, I deleted the file. On the chance that something got corrupted, I downloaded it again, and got the EXE file again. I checked it again with my 'WEBROOT' AV program, and it shows it contains a virus .. so I just deleted it and decided not to risk it.
Thanks for the info.
Bill <cooncat>

Re: Virus in this week's RAW course

PostPosted: Fri Jan 11, 2019 3:06 pm
by cooncat
I just tried again, and once again, my AV (Webroot) said that the EXE file contains a "W32.Malware.Gen" threat. It would be good if the Admin would extract the .CRZ file and post THAT as a download. The EXE file just might have something packed in with it.

Re: Virus in this week's RAW course

PostPosted: Sat Jan 12, 2019 1:49 pm
by Redskin
First - you did not get this file FROM LSPN - the link on the course name (green arrow) sends you to LinksCorner and you then download it from them - not LSPN. If you really believe there is a virus in that download -- I would go to LinksCorner and report to them.
I just downloade the course and ran my virus program (AVAST) and it found no virus. Your virus program might be reporting a false positive. But that is hard to say unless more people with the same virus program get that same response.
Jim

Re: Virus in this week's RAW course

PostPosted: Sat Jan 12, 2019 8:09 pm
by JackRussellTerror
Redskin wrote:Your virus program might be reporting a false positive. But that is hard to say unless more people with the same virus program get that same response.
Jim


FWIW, my up to date AVG a/v reports no malware on the ZIP or *.EXE files
I would has it as an UNeducated guess, that WEBROOT' AV program has reported a false-positive.

8)

EDIT: i ran SuperAntiSpyware on the ZIP and *.EXE files........... negative !

Re: Virus in this week's RAW course

PostPosted: Wed Jan 16, 2019 4:57 am
by cooncat
Well as AVAST & AVG are both free AV programs, I don't have as much confidence in them. I used them both at one time, but figured that the security of my computer and all the data on it was worth a minimal yearly fee to be certain that I was protected. Webroot uses cloud based AV/Malware definitions, so that the very latest threats can be covered and blocked within minutes of their discovery.

I didn't know where the downloads came from, but since I clicked on the 'green download arrow' on LSPN, I thought it was their library. I will try to advise the appropriate party to unpack that particular course and offer it as a CRZ download, rather than an EXE download.

Thanks for your comments. I suppose I could download the file again, then boot my computer into Linux and unpack it there, where it would have a hard time infecting me with malware, if it does have any. I could then save the CRZ file and put that into my COURSES folder and that would work. A bit too late for that now, as that tourney ends tonight.