Page 1 of 1

RDWorks Trojan horse

Posted: Thu Aug 20, 2020
by Allan Smithee
I've downloaded RDWorks several times (several different versions) and each time I try to install it I get the message that Windows Defender has detected a Trojan Horse in the software.
Detected: Trojan:Win32/Occamy.AA
Affected items: file: C:\newpr\com\RDWorksV8Uninstall.exe
This is identified as a severe threat and the file is quarantined and/or removed.

Has anyone else had this problem? Is this a real Trojan horse or just something funky going on with the Chinese software?

I now have two versions of RDWorks installed and I'm unable to uninstall either of them without the uninstaller.
I have versions 8.01.47 and 8.01.48.
The 8.01.47 version was downloaded from the official Ruida website:
https://780083804obx.scd.wezhan.cn/news ... eId=643416
Version 8.01.48 came from Cloudray Laser Solutions:
https://www.cloudraylaser.com/pages/download-link
Both are "legitimate" sites as far as I know.
I've tried installing other versions as well with the same result.

Please let me know what to do. Now I'm worried about using the software at all and I can't even uninstall the versions I already have.

Re: RDWorks Trojan horse

Posted: Thu Aug 20, 2020
by Chris Medcalf
I think it's because the installer opens a browser window to the RuiDa website when it's done. That's enough to set alarm bells ringing in some AV software. It's safe enough. Disable Defender when running the installer.

Re: RDWorks Trojan horse

Posted: Thu Aug 20, 2020
by Allan Smithee
Chris Medcalf wrote: Thu Aug 20, 2020 I think it's because the installer opens a browser window to the RuiDa website when it's done. That's enough to set alarm bells ringing in some AV software. It's safe enough. Disable Defender when running the installer.
Great thanks for the info. I'll trust the program then. Surprised nobody has mentioned this before.
I was able to install the program but the uninstaller got removed so I'll just get that back somehow and tell Defender to ignore it.

Re: RDWorks Trojan horse

Posted: Fri Aug 21, 2020
by Matthew Roach
i always like to scan downloads and software I'm not quite sure of on a website called virus total. it doesn't like it either. so I put it on an old unused laptop with no personal info on it and I haven't seen any adverse effects after several months.
rd works trojen warning.PNG