PopTray home
 PopTray Forum Index 
 FAQFAQ   SearchSearch   MemberlistMemberlist   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 Renier Crause Homepage 
Poptray virus?

 
Post new topic   Reply to topic    PopTray Forum Index -> General PopTray
View previous topic :: View next topic  
Author Message
davet
First Timer


Joined: 15 Jun 2006
Posts: 2

PostPosted: Thu Jun 15, 2006 12:51 pm    Post subject: Poptray virus? Reply with quote

Yesterday my fsecure anti virus came up with the following message..
Malicious code found in file C:\ZIPFILES\POPTRAY.EXE.
Infection: Trojan-Spy.Win32.Banker.bkl
Action: The file was renamed.

Do I have a virus I did a scan of my drive and all was clear
So I renamed the file back to poptray.exe and as soon as I run it the message appeared again!
So I decided t get the latest version of poptray and as soon as I ran the downloaded exe to install the latest version, the message appeared again.
Has anybody else had this as currently I can’t run pop tray as my antiviral keeps stopping it?
Back to top
View user's profile Send private message
KY Dave
Moderator
Not the Developer


Joined: 14 Mar 2002
Posts: 1576
Location: Burkesville, KY. U.S.A.

PostPosted: Thu Jun 15, 2006 1:16 pm    Post subject: Reply with quote

From where did you download it?

I suggest you DELETE the file you have and take the actions necessary to protect your system. Search with GOOGLE for that trojan, it seems to be a program to steal financial info and also opens a backdoor. You should scan for a trojan and use a removal program.

Then download a clean version from SOURCE FORGE by starting at the link below...

http://www.poptray.org/beta.php

Scan it and then install.

SourceForge has the original PopTray.exe files and they should contain no virus. They are NOT zip files.
_________________
KY Dave

Family Blog
You can STOP SPAM using this SETUP including FreePOPs, K9 and PopTray.
Back to top
View user's profile Send private message Visit poster's website
Rdsok
PopTray Family


Joined: 19 Mar 2004
Posts: 1105
Location: Norman, Oklahoma USA

PostPosted: Thu Jun 15, 2006 5:42 pm    Post subject: Reply with quote

I would suggest double checking the results that your antivirus is giving you.... Test the file at http://virusscan.jotti.org/ and if see if it is a false positive.

If it is a false, report it to your antivirus company, normally this is done by zipping the file and emailing it to them but each company has different methods so check with them first.

Always get the files you download from the official website or its mirror websites to help avoid getting files that may have been altered by others.
_________________
Help Info
Search the Forum
Writing Regular Expressions
How to clean an infected computer
Back to top
View user's profile Send private message
davet
First Timer


Joined: 15 Jun 2006
Posts: 2

PostPosted: Thu Jun 15, 2006 8:12 pm    Post subject: Reply with quote

I did download the latest file it from SOURCE FORGE but the Poptray that i had was running on my PC for about a year without a problem suddenly the virus error appeared today without even receiving an email. So i thought it may be infected that is why i downloaded a new copy and the install.exe gave the same result, but only whe i tried to run/ install it. But before running the install exe the scan said it was fine? and the installation completed without error and the new version of poptray works fine. So confusing!!
Back to top
View user's profile Send private message
Rdsok
PopTray Family


Joined: 19 Mar 2004
Posts: 1105
Location: Norman, Oklahoma USA

PostPosted: Thu Jun 15, 2006 11:10 pm    Post subject: Reply with quote

It shouldn't be confusing if you had read the info I posted as well... it would just mean that now your AV program is giving a false positive after it recieved an update and you need to report it so they may "fix" it in a later update.
_________________
Help Info
Search the Forum
Writing Regular Expressions
How to clean an infected computer
Back to top
View user's profile Send private message
antoine
Enthusiast


Joined: 12 Sep 2003
Posts: 26
Location: Paris, France

PostPosted: Fri Jun 16, 2006 3:38 pm    Post subject: Reply with quote

A french user just reported me the same infection detected by Kaspersky AV with poptray v3.03

My opinion about that :

- I really doubt Renier would ever put a trojan horse in his software
- Maybe the preview feature of poptray may have corrupted a machine when it is used to preview a malicious mail
- As has already been mentionned maybe just a false positive
- It is wise to check where the suspected version of poptray has been downloaded (non official site, P2P, ...)

--
Antoine, french poptray co-translator
Back to top
View user's profile Send private message Visit poster's website
Renier
Site Admin


Joined: 15 Oct 2001
Posts: 1950
Location: Cape Town, South-Africa

PostPosted: Sat Jun 17, 2006 1:09 pm    Post subject: Reply with quote

Sounds like a false positive to me. Maybe PopTray contains the same bytes that they are using as a signature for the virus.
_________________
Renier Crause
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    PopTray Forum Index -> General PopTray All times are GMT + 2 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group