TROJAN INFECTION

Miscellaneous Forums/General Discussion/TROJAN INFECTION

..I dont know about rest of you guys and girls, but, when I try to acces one of the given links to Blitz3D games (miniclip.com), I had warrning about Trojan infection..I'm using Avast antivirus, so I hope it will be useful info..

Where is the link? Did it install things like .dll's? Is it an online-type game?

EDIT:
I found the link

EDIT:
Are you talking about when visiting the site or when installing a game?

Well, I do note that the site is trying to install 'Game Loader' - it didn't do that from Firefox but IE shows that it is trying to install something to your machine.

I'm not keen on sites trying to install things to your system without you knowing what it is.

EDIT: I'd assume whatever it is it is launched via ActiveX. Might be harmless - but I chose not to install it.

..well..I cant say whats happen, but Avast making alarm noise and window with warrning message appear, showing me that it was Trojan, so I just kick it out..

Well, whatever the program is it may have 'Trojan-type' behaviour, but not be an actual trojan. It's the same with 'worms' many antivirus products are starting to develop to start looking at 'worm-type' behaviour. I get that now with online gaming whereby my AV warns me about a possible worm.

The problem is, the more sensitive your protection is, the more things it will spot when there is no real threat.

It's caused by the Retro64 loader and is documented on the Miniclip forums. The loader has been wrongly classified as a Trojan and poses no threat to your system. The same thing happened to the Pop-Cap loader a little while ago.

The loader is an activeX control that allows a blitz game (or any other) to be run within a browsers window. If you don't authorise the download you can't play the game - simple.

they should've advised you that an activeX dll is about to be downloaded in the content of the page... and not just assume the right to do it without alerting the browsing client...

who do they think they are... Microsoft...

--Mike

They do, and if you are using XP SP2 you get that bar across the top of the browser window which also warns you.

ok... so they have a lil pop up or something as part of the content of the page, that explicitly says, that you can expect a activeX control to be downloaded, that is require to run the game/demo/whatever inside your browser...

right...

then what's the problem...

i mean, i'm sure that puk would've seen this and not recoiled in fear of having the end of the world trojan horse take control of Windows and ruin the virtual surfing experience for the next week...

did you see this puk...

what about that bar across the top of your browser... didn't it tell you everything you needed to know about waht was or was not about to happen... or were you afraid to right click on it because it really didn't tell you much of anything...

(sorry... i haven't looked at the page as of yet)

--Mike

>Microsoft...

no they are miniclip, they are bigger then you and microsoft together mikie mike! :P

If anyone has missed the link or doesn't know what is being talked about I'm guessing the problem has something to do with -

http://www.miniclip.com/supergerball/supergerball.htm

This is a known problem. All the dll is doing is downloading and running an executable game. Clearly this could be used maliciously but the dll is tied to Miniclip.com and we're not going to do anything to jeopardize our business.

We give very clear instructions on all executable game pages explaining what is happening. If you don't use internet explorer then you are given a totally different set of instructions (basically download the game here).

The error only shows up in certain virus & spyware scanners and we are looking at different options for running these games so that we can get rid of the virus reports.

As has already been mentioned Pop Cap has had the same problems and they don't seem to be doing too badly.

If anyone has any questions feel free to email me ben @ miniclip.com (wthout the spaces) - I'd be more than happy to answer any queries you have.

Ben, you should leave the spaces in, that way the forum code can obscure the email address for you, only giving the real address to people who are logged in. As it is now, it's not obscured and any spambots will catch it (spaces are not a great way of odscuring e-mail addresses).