Infected File Blocked

Hello

I’m not sure if this is the right place to put this.

I got a virus warning for a UE4 Engine file. I wasn’t using VS or UE4 at all at the time.

jaIzWHi.png

This is the details:

Infected object: BootstrapPackagedGame-Win32-Shipping.exe

Malware: Gen:Variant.Kazy.767225
Path: C:\Program Files\Epic Games\4.10Source\UnrealEngine\Engine\Binaries\Win32\BootstrapPackagedGame-Win32-Shipping.exe
Infected process: [6904] C:\Windows\system32\CompatTelRunner.exe

This was for 4.10.0 so maybe it doesn’t matter anymore but I thought it was odd.

Interesting, I saw a post just like this today where someone had the same virus warning.

The interesting part is here Infected process: [6904] C:\Windows\system32\CompatTelRunner.exe
Quick google search give following results.

Not ue specific, a redirector, but seems to be a fresh problem, be prepared.
You grabbed somewhere else on warez site, or while surfing unprotected on untrusted websites, most times with minimal cloth. ^^

I do surf a TON of websites each day, time for a full system scan :smiley:

I use FF with noScript addon for some years now, and it really limited the incoming attack rate.
It limits it so far, i give temporary access to a site, to use all those eyecandyfunctions there… ^^

So I’m on win7 x64. I deleted that entire unreal install and today got this warning.

Infected object: BootstrapPackagedGame-Win32-Shipping.exe

Malware: Gen:Variant.Kazy.767225
Path: D:\UnrealEngines\UE4_10\Engine\Binaries\Win32\BootstrapPackagedGame-Win32-Shipping.exe
Infected process: [1408] C:\Windows\Explorer.EXE

Sry1ivF.png

This is now the latest 4.10 version from GIT and installed on a different drive. I don’t use this computer for much at all besides work and video editing so I’m not sure what I could have gotten on here. Since it’s a different infected process it probably is something bad. I’m going to start running some scans and things but any other advice would be appreciated. Not sure why it is referencing things inside UE4.

In the Engine\Binaries\Win32 directory
iiHqEwu.png

but the BootstrapPackagedGame-Win32-Shipping_XP.target.xml file in the Engine\Build directory points to the \Binaries\Win32 directory for BuildProduct.

Bullguard is all up to date and I did full scans with that and mbam. Nothing but two ad cookies. Auto updates aren’t enabled either. I’ll keep looking and post if I get any more alerts or find something.

It’s just weird that it happened in two different engine installs when neither were being used at the time.