News:

Bored?  Looking to kill some time?  Want to chat with other SMF users?  Join us in IRC chat or Discord

Main Menu

Trojan found in Packages backups

Started by Sono, November 04, 2024, 08:49:42 PM

Previous topic - Next topic

Sono

Kaspersky Antivirus has just found a Trojan (Trojan.PHP.Kryptik.gen) in the backup of my forum on my computer, in the Packages\backups library. The package backup is: 2024-02-14_before_SMF4Mobile-mod.tar.gz

I still didn't scan the online copy of the file. Can I delete it just as is, or it is needed for a proper uninstall of the package?

vbgamer45

Community Suite for SMF - Grow your forum with SMF, Gallery,Store,Classifieds,Downloads,more!

SMFHacks.com - Paid Modifications for SMF

Mods:
EzPortal - Portal System for SMF
SMF Gallery Pro
SMF Store SMF Classifieds Ad Seller Pro

Sir Osis of Liver

You don't need it to uninstall the mod, it's just there as a backup in case the mod install/uninstall goes sideways and you didn't do your own backup.
When in Emor, do as the Snamors.
                              - D. Lister

Steve

It could also be a false positive. I'd check it with something else to confirm, like Malwarebytes.
My pet rock is not feeling well. I think it's stoned.

Aleksi "Lex" Kilpinen

Yeah, many definitions ending with .gen can cause false positives too, and I wouldn't be surprised if this was the case. But simply removing a backup file is safe, if everything is working correctly.
Slava
Ukraini!
"Before you allow people access to your forum, especially in an administrative position, you must be aware that that person can seriously damage your forum. Therefore, you should only allow people that you trust, implicitly, to have such access." -Douglas

How you can help SMF

Sir Osis of Liver

I've seen this several times where Kaspersky flags viruses in package backups, but nowhere else.  Don't think they're real.
When in Emor, do as the Snamors.
                              - D. Lister

Advertisement: