Author Topic: What is --> backdoor.win32.Ceckno.RAA...  (Read 2306 times)

KyVarment

  • Wayfarer
  • *
  • Posts: 3
    • View Profile
What is --> backdoor.win32.Ceckno.RAA...
« on: August 17, 2009, 06:41:02 pm »
Howdy all,

I downloaded installed Planeshift without any problems... Now when I run psclient.exe I get an AntiVirus Alert saying "Virus detected" "backdoor.win32.Ceckno.RAA@18514656"

I was wondering if this s this a false positive or a real threat...  ::|

ThomPhoenix

  • Testers
  • Forum Addict
  • *
  • Posts: 2678
  • A Phoenix, what'd you expect?
    • View Profile
Re: What is --> backdoor.win32.Ceckno.RAA...
« Reply #1 on: August 17, 2009, 08:36:33 pm »
What mirror did you download it from? If it's a trustworthy server there should be no such problems.
Also, what antivirus do you have?
We're not evil. We're simply amazing.

verden

  • Hydlaa Notable
  • *
  • Posts: 716
    • View Profile
Re: What is --> backdoor.win32.Ceckno.RAA...
« Reply #2 on: August 17, 2009, 08:40:44 pm »
Its a worm. It might have modified the download exe after uncompressing but before execution.

KyVarment

  • Wayfarer
  • *
  • Posts: 3
    • View Profile
Re: What is --> backdoor.win32.Ceckno.RAA...
« Reply #3 on: August 17, 2009, 10:30:08 pm »
Thanks for the replys

I use Comodo Antivirus...

I downloaded a copy from Xordan then uninstalled it when I got the virus message... I then downloaded another copy using bittorrent and installed and I still get the same Virus warning

Sen

  • Hydlaa Notable
  • *
  • Posts: 746
    • View Profile
Re: What is --> backdoor.win32.Ceckno.RAA...
« Reply #4 on: August 17, 2009, 10:50:13 pm »
Hello

I personally tend to see it as false positive. To be really sure you can compare md5 checksums or even go to irc to ask other players for the md5 checksum of their clients.


Sen
.....also a saddle that won't pinch the tail. One day!

ThomPhoenix

  • Testers
  • Forum Addict
  • *
  • Posts: 2678
  • A Phoenix, what'd you expect?
    • View Profile
Re: What is --> backdoor.win32.Ceckno.RAA...
« Reply #5 on: August 17, 2009, 11:20:31 pm »
If you downloaded it from both the Xordan server and Bittorrent I think you can be sure that not the downloads themselves are infected but your computer. Verden is probably right that a worm infected the files during/after install.

I recommend using an online virusscanner like http://housecall.trendmicro.com/uk/ so you can scan your pc without having to install another antivirus scanner. If that scanner finds no virusses at all and if Comodo is up-to-date an a full disk scan by it doesn't reveal anything, it's probably a false positive. If it's a false positive you can report it to Comodo or put the PlaneShift folder on an ignore list.
We're not evil. We're simply amazing.

KyVarment

  • Wayfarer
  • *
  • Posts: 3
    • View Profile
Re: What is --> backdoor.win32.Ceckno.RAA...
« Reply #6 on: August 18, 2009, 12:51:34 am »
I recommend using an online virusscanner like http://housecall.trendmicro.com/uk/ so you can scan your pc without having to install another antivirus scanner. If that scanner finds no virusses at all and if Comodo is up-to-date an a full disk scan by it doesn't reveal anything, it's probably a false positive. If it's a false positive you can report it to Comodo or put the PlaneShift folder on an ignore list.

It only shows up when running the psclient.exe, I've tried to scan the psclient.exe and it finds nothing... so running the online scanner really want help...

I think I'll ignore it for now, it's a new laptop so restoring want be a problem if needed...

Thanks y'all

ThomPhoenix

  • Testers
  • Forum Addict
  • *
  • Posts: 2678
  • A Phoenix, what'd you expect?
    • View Profile
Re: What is --> backdoor.win32.Ceckno.RAA...
« Reply #7 on: August 18, 2009, 02:05:31 am »
Only when running eh, might be a false positive then, but still, you can never be sure enough with nasty things like virusses ;)
We're not evil. We're simply amazing.

GiGaBaNE

  • Wayfarer
  • *
  • Posts: 1
    • View Profile
Re: What is --> backdoor.win32.Ceckno.RAA...
« Reply #8 on: August 26, 2009, 10:37:17 pm »
confirming this result only when using comodo, guess its just a fakse positive.

Elvicat

  • Hydlaa Notable
  • *
  • Posts: 831
    • View Profile
    • My site
Re: What is --> backdoor.win32.Ceckno.RAA...
« Reply #9 on: August 28, 2009, 01:00:34 am »
odd i use comodo too but don't get that thing... but then again i have the scanner on low :P