Paradox Newsletter Crusader Kings Download contained a Trojan!!!

  • We have updated our Community Code of Conduct. Please read through the new rules for the forum that are an integral part of Paradox Interactive’s User Agreement.

grahamh

Corporal
69 Badges
Jan 21, 2005
33
0
  • Warlock: Master of the Arcane
  • March of the Eagles
  • Europa Universalis III Complete
  • Europa Universalis IV: Res Publica
  • Victoria: Revolutions
  • Rome Gold
  • Semper Fi
  • Sengoku
  • Supreme Ruler: Cold War
  • Victoria 2
  • Victoria 2: A House Divided
  • Victoria 2: Heart of Darkness
  • Rome: Vae Victis
  • Europa Universalis III Complete
  • Warlock 2: The Exiled
  • War of the Roses
  • 500k Club
  • Cities: Skylines
  • Pride of Nations
  • Pillars of Eternity
  • Cities: Skylines - After Dark
  • Stellaris
  • Hearts of Iron IV Sign-up
  • Hearts of Iron IV: Cadet
  • Stellaris: Digital Anniversary Edition
  • Imperator: Rome - Magna Graecia
  • Europa Universalis III
  • Cities in Motion 2
  • Crusader Kings II
  • Crusader Kings II: Charlemagne
  • Crusader Kings II: Legacy of Rome
  • Crusader Kings II: The Old Gods
  • Crusader Kings II: Rajas of India
  • Crusader Kings II: The Republic
  • Crusader Kings II: Sons of Abraham
  • Crusader Kings II: Sunset Invasion
  • Crusader Kings II: Sword of Islam
  • Commander: Conquest of the Americas
  • Darkest Hour
  • Arsenal of Democracy
  • Europa Universalis III Complete
  • Divine Wind
  • Europa Universalis IV
  • Europa Universalis IV: Conquest of Paradise
  • Europa Universalis IV: Wealth of Nations
  • Europa Universalis IV: Call to arms event
  • For The Glory
  • For the Motherland
  • Hearts of Iron III
  • Hearts of Iron III: Their Finest Hour
The Paradox Forum Newsletter May 2011 contained an offer to download a free copies of Crusader Kings from GamersGate.

The downloader contained a Trojan, which I believed was caught and dealt with by my AntiVirus program. Unfortunately it still managed to send out a series of emails to my hotmail contacts with infected links and adverts for Viagra.

This was not a pleasant experience.

Graham
 

Planck

Unique Username #66563
71 Badges
Feb 2, 2007
1.448
2
  • Europa Universalis IV: Pre-order
  • Sengoku
  • Sword of the Stars
  • The Showdown Effect
  • Victoria 2
  • Victoria 2: A House Divided
  • Victoria 2: Heart of Darkness
  • Warlock: Master of the Arcane
  • War of the Roses
  • 500k Club
  • Cities: Skylines
  • Cities: Skylines Deluxe Edition
  • Crusader Kings II: Holy Knight (pre-order)
  • Victoria: Revolutions
  • Pride of Nations
  • Victoria 2 A House Divided Beta
  • Crusader Kings II: Way of Life
  • Crusader Kings II: Horse Lords
  • Cities: Skylines - After Dark
  • Crusader Kings II: Conclave
  • Cities: Skylines - Snowfall
  • Stellaris
  • Hearts of Iron IV Sign-up
  • Stellaris Sign-up
  • Crusader Kings II: Reapers Due
  • Stellaris: Necroids
  • Europa Universalis III: Chronicles
  • Crusader Kings II
  • Crusader Kings II: Charlemagne
  • Crusader Kings II: Legacy of Rome
  • Crusader Kings II: The Old Gods
  • Crusader Kings II: Rajas of India
  • Crusader Kings II: The Republic
  • Crusader Kings II: Sons of Abraham
  • Crusader Kings II: Sword of Islam
  • Commander: Conquest of the Americas
  • Deus Vult
  • Dungeonland
  • Europa Universalis III
  • Cities in Motion
  • Europa Universalis III Complete
  • Divine Wind
  • Europa Universalis IV
  • Europa Universalis IV: Call to arms event
  • Hearts of Iron III
  • Heir to the Throne
  • Europa Universalis III Complete
  • Leviathan: Warships
  • Magicka
  • March of the Eagles
Are you sure it was the download from GamersGate? I downloaded it without a problem and I find it hard to believe so many people downloaded it and did not detect anything. Sometimes Anti-virus programs have warnings that are false positives, so it might be that it 'thought' the downloader was a trojan. The E-mail spam could have been an unrelated occurrence?
 

grahamh

Corporal
69 Badges
Jan 21, 2005
33
0
  • Warlock: Master of the Arcane
  • March of the Eagles
  • Europa Universalis III Complete
  • Europa Universalis IV: Res Publica
  • Victoria: Revolutions
  • Rome Gold
  • Semper Fi
  • Sengoku
  • Supreme Ruler: Cold War
  • Victoria 2
  • Victoria 2: A House Divided
  • Victoria 2: Heart of Darkness
  • Rome: Vae Victis
  • Europa Universalis III Complete
  • Warlock 2: The Exiled
  • War of the Roses
  • 500k Club
  • Cities: Skylines
  • Pride of Nations
  • Pillars of Eternity
  • Cities: Skylines - After Dark
  • Stellaris
  • Hearts of Iron IV Sign-up
  • Hearts of Iron IV: Cadet
  • Stellaris: Digital Anniversary Edition
  • Imperator: Rome - Magna Graecia
  • Europa Universalis III
  • Cities in Motion 2
  • Crusader Kings II
  • Crusader Kings II: Charlemagne
  • Crusader Kings II: Legacy of Rome
  • Crusader Kings II: The Old Gods
  • Crusader Kings II: Rajas of India
  • Crusader Kings II: The Republic
  • Crusader Kings II: Sons of Abraham
  • Crusader Kings II: Sunset Invasion
  • Crusader Kings II: Sword of Islam
  • Commander: Conquest of the Americas
  • Darkest Hour
  • Arsenal of Democracy
  • Europa Universalis III Complete
  • Divine Wind
  • Europa Universalis IV
  • Europa Universalis IV: Conquest of Paradise
  • Europa Universalis IV: Wealth of Nations
  • Europa Universalis IV: Call to arms event
  • For The Glory
  • For the Motherland
  • Hearts of Iron III
  • Hearts of Iron III: Their Finest Hour
I am not 100% certain. My antivirus program, BitDefender Pro, detected a trojan in the download and I deleted it.

As you say the email spam trojan could be from something different. It is just a very strange coincidence. It is years since I last had a virus/trojan on my pc's. To get a genuine attack just a couple of days after being warned about a Trojan from the GamersGate download is a big coincidence.

But I am not certain of the connection.

Graham
 

Teurlinx

Wicked
73 Badges
Feb 4, 2007
1.953
535
  • Crusader Kings III: Royal Edition
  • Stellaris: Federations
  • Crusader Kings III
  • Hearts of Iron IV: Expansion Pass
  • Cities: Skylines - Natural Disasters
  • Hearts of Iron IV: Field Marshal
  • Hearts of Iron IV: Colonel
  • Stellaris
  • Cities: Skylines - Snowfall
  • Cities: Skylines - After Dark
  • Stellaris - Path to Destruction bundle
  • Rise of Prussia
  • Pride of Nations
  • Hearts of Iron: The Card Game
  • Cities: Skylines
  • 500k Club
  • 200k Club
  • Rome: Vae Victis
  • Stellaris: Apocalypse
  • Stellaris: Lithoids
  • Stellaris: Ancient Relics
  • Prison Architect
  • Victoria 2: Heart of Darkness
  • Hearts of Iron IV: Expansion Pass
  • Hearts of Iron IV: Death or Dishonor
  • Heir to the Throne
  • Hearts of Iron III: Their Finest Hour
  • Hearts of Iron III
  • For the Motherland
  • For The Glory
  • Divine Wind
  • Europa Universalis III: Chronicles
  • Europa Universalis III
  • Europa Universalis III Complete
  • Deus Vult
  • Darkest Hour
  • Crusader Kings II: Sword of Islam
  • Crusader Kings II
  • Cities in Motion
  • Hearts of Iron II: Armageddon
  • Arsenal of Democracy
  • Europa Universalis: Rome
  • Victoria 2: A House Divided
  • Victoria 2
  • Sengoku
  • Semper Fi
  • Rome Gold
  • Victoria: Revolutions
  • Europa Universalis III Complete
  • Magicka
It just gave me an extra copy of CK + DV on Gamersgate, and I've downloaded the game from there more than once without issues.

I even re-downloaded both now, just in case. Still nothing.

It wouldn't be the first false-positive 'virus detection' I've seen on Gamersgate downloaders btw, they are .exe files which always are 'suspect'. Still never had issues with any of them.

I just checked the fact, and Bitdefender is explicitly listed in it: (link)

BitDefender 2009 stopped the installation due to a virus in the launch file.

Turn off real time protection in BitDefender.

NOTE: Some anti virus applications gives false positives for files in the games. Needless to say, GamersGate got the games directly from developers and publishers and the downloads do NOT include viruses or other malwares.

and:

Virus / trojan detected in the download?

There are NO viruses or trojans in the download. Its likely your anti-virus program having what is called a "false positive". It may have found something in the heuristic search, which is not always 100% accurate. The games are delivered from developers and publishers, so the risk of having an infected download is minimal.



NOTE: For BitDefender you may turn off real time protection.
 

grahamh

Corporal
69 Badges
Jan 21, 2005
33
0
  • Warlock: Master of the Arcane
  • March of the Eagles
  • Europa Universalis III Complete
  • Europa Universalis IV: Res Publica
  • Victoria: Revolutions
  • Rome Gold
  • Semper Fi
  • Sengoku
  • Supreme Ruler: Cold War
  • Victoria 2
  • Victoria 2: A House Divided
  • Victoria 2: Heart of Darkness
  • Rome: Vae Victis
  • Europa Universalis III Complete
  • Warlock 2: The Exiled
  • War of the Roses
  • 500k Club
  • Cities: Skylines
  • Pride of Nations
  • Pillars of Eternity
  • Cities: Skylines - After Dark
  • Stellaris
  • Hearts of Iron IV Sign-up
  • Hearts of Iron IV: Cadet
  • Stellaris: Digital Anniversary Edition
  • Imperator: Rome - Magna Graecia
  • Europa Universalis III
  • Cities in Motion 2
  • Crusader Kings II
  • Crusader Kings II: Charlemagne
  • Crusader Kings II: Legacy of Rome
  • Crusader Kings II: The Old Gods
  • Crusader Kings II: Rajas of India
  • Crusader Kings II: The Republic
  • Crusader Kings II: Sons of Abraham
  • Crusader Kings II: Sunset Invasion
  • Crusader Kings II: Sword of Islam
  • Commander: Conquest of the Americas
  • Darkest Hour
  • Arsenal of Democracy
  • Europa Universalis III Complete
  • Divine Wind
  • Europa Universalis IV
  • Europa Universalis IV: Conquest of Paradise
  • Europa Universalis IV: Wealth of Nations
  • Europa Universalis IV: Call to arms event
  • For The Glory
  • For the Motherland
  • Hearts of Iron III
  • Hearts of Iron III: Their Finest Hour
It would seem to be ok then. However I did search here first before reporting it in this thread. I would suggest that since specific AntiVirus products are mentioned that the Antivirus producer should be contacted. I am sure they would be happy to do something to prevent the false positive. False positives undermine confidence in the owners of the download, and the antivirus software producers.

Turning off real time protection is the last thing a person wants to do, and not something I would normally do for a freebie game.

Regards
Graham
 

Teurlinx

Wicked
73 Badges
Feb 4, 2007
1.953
535
  • Crusader Kings III: Royal Edition
  • Stellaris: Federations
  • Crusader Kings III
  • Hearts of Iron IV: Expansion Pass
  • Cities: Skylines - Natural Disasters
  • Hearts of Iron IV: Field Marshal
  • Hearts of Iron IV: Colonel
  • Stellaris
  • Cities: Skylines - Snowfall
  • Cities: Skylines - After Dark
  • Stellaris - Path to Destruction bundle
  • Rise of Prussia
  • Pride of Nations
  • Hearts of Iron: The Card Game
  • Cities: Skylines
  • 500k Club
  • 200k Club
  • Rome: Vae Victis
  • Stellaris: Apocalypse
  • Stellaris: Lithoids
  • Stellaris: Ancient Relics
  • Prison Architect
  • Victoria 2: Heart of Darkness
  • Hearts of Iron IV: Expansion Pass
  • Hearts of Iron IV: Death or Dishonor
  • Heir to the Throne
  • Hearts of Iron III: Their Finest Hour
  • Hearts of Iron III
  • For the Motherland
  • For The Glory
  • Divine Wind
  • Europa Universalis III: Chronicles
  • Europa Universalis III
  • Europa Universalis III Complete
  • Deus Vult
  • Darkest Hour
  • Crusader Kings II: Sword of Islam
  • Crusader Kings II
  • Cities in Motion
  • Hearts of Iron II: Armageddon
  • Arsenal of Democracy
  • Europa Universalis: Rome
  • Victoria 2: A House Divided
  • Victoria 2
  • Sengoku
  • Semper Fi
  • Rome Gold
  • Victoria: Revolutions
  • Europa Universalis III Complete
  • Magicka
Good luck with that, I've googled a little on this problem of Bitdefender with Gamersgate files. It seems to exist at least since 2009 for their users, and somehow they never addressed it.

- edit -

I even stumbled over an amusing article while searching some more :rofl:
 
Last edited: