Infected: Beware of files purchased from Sim Market

I just purchaced 5 titles from SimMarket from Illuminators (lighting upgrades). Out of the 5 files three dowload, 2 reported as infected with viruses.

I opened a ticket with their customer support and was told “Oh, its just a false positive, turn off your virus software and try again”

I did, and before opening, scanned them with two different scanners and both reported as being infected with Backdoor:Win32/Bladabindiml, a remote access malware.

They don’t seem to be interested in making good my order (they’ve got my money) and insist that the files are good.

Good or not, I don’t think I’ll be buying anything from them in the future and you should consider this as well.

6 Likes

I’ve been using simmarket for years with zero, none, nada problems whatsoever. I can’t vouch for the developer you’re talking about though. I thought those products were a bit scammy, but as with anything related to addons, buyer beware. Thanks for the heads up.

4 Likes

Anti-virus software can generate false positives sometimes and I suspect that is probably what is going on here.

As you have done, I’d make the supplier aware of the issue and they should be keen to get it cleared by the respective AV providers or suffer loss of sales as a result.

You might want to leave the file unopened until you have appropriate reassurance, ideally from a third party.

1 Like

Do the purchased mods contain .exe or .dll files? Otherwise it’s almost certainly a false positive.

Even if they do, it’s still fairly likely. Upload them to VirusTotal and check.
I’ve had false positives that yield 30%+ “infected” results there.

yeah the files are fine. False positives are almost normal when it comes to flightsim. You’ll get this all the time as soon as the addons get complexer and you will want to start to exclude any sim related floders from your AV.

1 Like

Your virus scanning software should list the kind of threat it found. If it’s a heuristic threat (anti-virus software trying to predict a virus) then a false positive is possible. If it’s a known virus then definitely remove the files.

I’m perhaps a first client in the time of simmarket never had any virus my basket are recently had 9 new titles and any problems I have 2 anti-virus and malwarmalbyte and other running permanently

I will report here any problems if there are

Thank’s for the Info !

Thanks for the heads up!
Paying customers have in the past been infected with malware purposely placed by unscrupulous developers-flight simmers are perceived to be wealthy by some.
Thankfully most developers are honest but healthy awareness of this is important.

1 Like

I’ve been buying stuff from them for years. I’ve never had any problems. I’ve bought a bunch of the Illuminator titles. No issues for me.

Hope for the best for you.

1 Like

Anti Virus software seems to be getting very twitchy of late… even code I’ve written and compiled has been flagged by my own AV as being infected! In fact it became so annoying I’ve recently changed my AV.

Predominantly AV programs check for known footprints which are easily replicated if the developer users an exe compressor after compiling their code, because it scrambles everything.

So yes, be careful, be wary, but chances are this is a false positive.

1 Like

Great autocorrect typo in the post title - have never had any trouble with Simmarket files (most recently the excellent Powersolo ultralight) but didn’t realise they also sold flies! :wink:

5 Likes

Well swatted

2 Likes

Just uninstall any scanners and never install them again. They slow down your overall performance and are entirely not necessary if you can manage to act minimum responsibly while doing downloads and any other stuff online.
Your system will perform generally more fluid and you will never be bothered by false positives again. No more pointless worries and no waste of time anymore.

Exe files… which I found odd.

I am aware of false positives, bit in this day in age you can’t afford to take anything for granted.

1 Like

Me too… years! Thats why it’s surprising. I would imagine it’s a false positive… but two files out of five… how can I in good mind just ignore that. I suspect I’m going to eat this and chalk it up to experience… but no way am I running those files and they’ve lost a customer because of their flippant response. Thankfully there are other merchants with the same stuff.

You sir must be one of those foriegn hackers the news keeps talking about

EDIT: THIS WAS SARCASM… relax, go have a chi tea or something…

Thx! It was El Paso and San Antonio fyi.

It did report the type and name if the infection. If it hadn’t been specific I’d been more inclined to ignore it as a false positive.