Content manager possible keylogger?

Hi guys,
Kaspersky reported the following:

Object: C:\Users\username\Downloads\Content Manager\Content Manager.exe
Result: Detected: Trojan-Spy.MSIL.Keylogger.csgd

So beware.
 
No country can be trusted when it comes to data gathering. So ignoring a warning from your virus scanner because you don't trust it, is pretty ignorant I think. I shared the info to help people, do with it what ever you want. Maybe the mods can lock this tread?
 
If you read the release notes in Content Manager, there have been some changes over the last few revisions to the compression methods used in the program itself. I would venture to say you're likely seeing a false positive detection based on shared code (e.g., malicious programs use the same legit compression code that CM does).

You can check the latest scan results for CM on VirusTotal by searching for the following MD5:

07dec05b07fd0a01ef05b9f4ce021448

https://www.virustotal.com/en/file/...5a938039ba20c4892b5be72a0d3b40088ce/analysis/

As CM is open-source, you can also verify the code used in the program. I'd err on the side of caution declaring that CM contains malware without doing further research. As much as ignoring security software messages is dangerous, so is blindly trusting any detection.
 
Last edited:
Just for everyone's edification, here are the entries relating to file compression from the last three revisions:
Code:
0.8.1350.26923
 Another AV fix, now in theory it should work, for example, with Kaspersky, Avast and AVG;  At least it works on my PC and in VirtualBox.

Code:
0.8.1303.26640
Urgent AV fix; Despite that it appears to be working fine, now I’ve disabled compression. Better play it safe, just in case. Maybe I’ll re-enable it later.

Code:
0.8.1303.26609
Packing changed, hopefully to solve those AV-related issues

You can look at the notes for yourself by opening CM and going to About > Release Notes.
 
@co199 thanks for the info. However I'm not a software developer thus cannot verify code. As a consumer I only have anti-virus software to rely on. I don't question a warning light in my car either.

No, absolutely - that's why I provided the additional information. I'm not a dev either, so "just check the source" isn't really helpful. I don't question warning lights in my cars, but I do look at the context of what the warning light is. Nothing wrong with asking a question!
 
No country can be trusted when it comes to data gathering. So ignoring a warning from your virus scanner because you don't trust it, is pretty ignorant I think. I shared the info to help people, do with it what ever you want. Maybe the mods can lock this tread?

Not all AV systems take all the detail that Kaspersky does... and to date Kaspersky is the only software company that has raised enough concern in the US Government that they have just specifically passed a law banning the use of the software specifically by name.
 
True,but that they would ban a security program from their adversary number one is a logical move. UK is doing the same thing. China and Russia probably as well.
In any case, it may be a false positive on content manager so I'll green flag it in Kaspersky and see what happens.
 
You may not need to mark it - make sure you have the latest version of Content Manager and the latest definition set for Kaspersky. I just rescanned the executable on VirusTotal and it wasn't detected; granted VT isn't a direct representation of every installation, but I'd update just to be sure.
 
FWIW x4fab the creator of Content Manager is highly responsive to questions and comments about CM.
Also, CM has enhanced my use of Assetto 1000 fold. If I were forced to go back to the default launcher I'd probably find another game.
 
You are ignorant! I would be more concern to fly to uk cause I can be call GRU agent!You are ignorant and selfish !What shame full of stereotype!
Did you read his other post, in which he clarifies the reason for concern? It's not a "Russian software = malware" thing at all - it's a "this software has been explicitly highlighted as untrustworthy" thing.
Regardless of whether or not you personally trust the people issuing the warning, that's simply not stereotyping.
 
Back
Top