Page 1 of 1

pikoSzachy 3.4 is a virus ???

Posted: Thu Mar 31, 2011 9:43 pm
by Marwan
pikoSzachy 3.4 engine

Scanner/Scan result

a-squared Backdoor.Rbot!IK
Authentium W32/Heuristic-210!Eldorado (Heuristic)
ClamAV PUA.Packed.UPack-2
Comodo Packed.Win32.MUPACK.~KW
CP Secure BackDoor.W32.Hupigon.axb
F-Prot Possible W32/Heuristic-210!Eldorado (damaged, not disinfectable)
Ikarus Backdoor.Rbot
Norman W32/Packed_Upack.A
nProtect Trojan/W32.Agent.10240.GW
Panda Trj/Pupack.A
Quick Heal Trojan.Agent.ATV
Rising Trojan.Win32.Generic.125304EA
Sunbelt Trojan.Win32.Packer.Upack0.3.9 (ep)
Symantec Infostealer.Gampass
The Hacker W32/Behav-Heuristic-060
Trend Micro Cryp_Xed-12

I have Scanned this engine via virscan.org
http://virscan.org/report/3a2ac5d527b70 ... ea507.html
http://www.chess2u.com/t1696-this-engine-is-a-virus

what this guys ? :o :o

Re: pikoSzachy 3.4 is a virus ???

Posted: Fri Apr 01, 2011 6:35 am
by Mincho Georgiev
The "real sense" for _a_virus_ is a memory resident code. I've had the following case not long ago:
the compiler (icl in my case) was collecting the profiling data, generated on my pc and adds the self-injected piece of
the resident virus from memory. As a result, the executable have added piece of code from the virus, which of course is not working, but it's presence triggers a positive detection. So is not something sensational, it happens under windows if the pc
is infected. BTW sometimes is good to try other websites also, like http://virusscan.jotti.org/

Re: pikoSzachy 3.4 is a virus ???

Posted: Sat Apr 02, 2011 11:03 am
by Tony Mokonen
It's a false alarm. pikoSzachy has been packed with an exe compressor, and exe files packed with these sorts of programs are often flagged by antivirus programs as viruses. You can download an unpacked version of it here, which should be OK with virus scanners:

http://www.kalisz.mm.pl/~pic/nanochess/ ... packed.zip