Normal SW gets "Trojan Horse / Virus: Win32:Klone-RX [Trj]"

Hi,

I`m a softwaredeveoper in Norway, and the users (using Avast) gets a “Trojan Horse / Virus: Win32:Klone-RX [trj]” message when trying to download our software from THIS link.

We have signet the setupscript, and have approx 2-300 downloads a night.

No other software reports this (Norton Antivirus, AVG, NoMoreSpy, Trend, Norman) so clearly there must be somthing wrong(bug) in Avast ???

Has anybody else seen this, when trying to download other products (not containing virus) ??

Cheers
Tor-Bjarne Henriksen
Berghs Metall as
Norway
Developer (Berghs metall as)
Http://www.fakturaprogram.no
Http://www.winvask.no
Http://www.vivi.no

Hi clarion1,

You can send the file in which the virus apparently was found to virustotal for analysis.

If you do not find any of the following on your comp, you have not been infected by Klone-RX[trj]:
Hi Splinterhell,

Here are the manual removal instruction, and the way to evaluate the traces of the malware are gone:

Klone manual removal:
Kill processes:
paradise.raw.exe, symsvcsa.exe, winlogon.exe, .exe
HELP:

Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nvchost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\nvchost

Delete files:
paradise.raw.exe, symsvcsa.exe, winlogon.exe, .exe, winuqw32.dll

polonus

Sorry for the false positive. Hope they correct it soon.

Can you send the file in a password protected zip to virus@avast.com ?
Please, mention in the body of the message why you think it is a false positive and the password used.

As a workaround, you (and any other user) can add these files to the Standard Shield provider (on-access scanning) exclusion list.
Left click the ‘a’ blue icon, click on the provider icon at left and then Customize. Go to Advanced tab and click on Add button…
You can use wildcards like * and ?. But be carefull, you should ‘exclude’ that many files that let your system in danger.
After that, please, periodically check it - scan it into Chest, right clicking the file - there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected as being infected then you can also remove it from the Exclusion list.

Hi,

There must be a language problem, I`m developing the software, and I do know, we don’t put virus, or other spyware into it, for certain ;D

I Don’t use Avast, but Norton (Does not give any problems) for me or my users (That use Norton), I also use SpyNoMore (no errors was reported)

Just had a couple of Avast users reporting this “Trojan Horse / Virus: Win32:Klone-RX [trj]” from our download site, whereby I (myself and Irene) had download it again, running it against the virusscanners I have (Norton, AVG, and SpyNoMore) with (offcourse) No errors.

This led me to believe that my 2 avast users or your antivirusprogram is broken / has a bug.

I have never seen this message as I don use Avast

The download link is in the first post, a compressed installfile created the Lindersofts Setupbuilder, digital signed (By Comodo) to our company name Berghs Metall as , in Norway .

The error was receivied as son as they attemptet to download my software (not installing it).

I was just curious if other had similar reports on their software, If Avast users get a “Trojan Horse” message when trying to download clean software, it is a problem for me, Avast, and offcourse the users that stop installing “My great software”

Cheers
Tor-Bjarne

Can you send the file in a password protected zip to virus@avast.com ?

Does the Zip have to be passord protected ? of can i send a ZIP without password, my zip tools does not have the option too put on pw, I dont want to install WinZip (or others) just for that ?

cheers
Tor-Bjarne

Hi clarion1,

I do not doubt your integrity as a developer nor do others here, because it is always an inconveniance when an av-scanner fires an FP at clean software, but that is always a possibility because “signatures are not clairvoyant.” You reported it and I suppose it will soon be fixed. All security programs have FP’s, it is just a fact of life.
Point the real malware symptoms out to your users, so they can establish themselves they are not infected, and feel reassured. And foremost thank you for reporting this False Positive,

polonus

I reported one this afternoon and a few hours later on the next VPS it was corrected, so the sooner it is sent to avast the sooner it can be corrected.

All security programs have FP's, it is just a fact of life.

All software have bugs!, my software to - I have no problem with that.

That said, I dont have to mutch time to spend, debugging other companies software, have enouh with my own :slight_smile:

What I dont understand is the spesific “Trojan Horse / Virus: Win32:Klone-RX [trj]” message, if there was a message like “This program xxxx behaves like an trojan” or somthing, but avast point out a signature for a spesific trojan?

Problem report is offcourse sendt without a ZIP (They can “try” downloading it, link supplied)

Cheers
Tor-Bjarne