I have recived the notification from Norton when playing Train Simulator Classic: -------------------------------------------------------- Threat name: Script:SNH-gen [Trj] Threat type: Trojan Horse - This threat pretends to be something else (e.g., picture, document, or other file) to trick you into running it and infecting your computer. Status: Aborted Detected by: Safe Web Origin: Downloaded from: http://www.railsimdownloads.com/cdn/slideshow_v1.php -------------------------------------------------------- At the same time, I no longer get a loading screen when loading the route. Other than that, the game is okay. Even if I visit: http://www.railsimdownloads.com/cdn/slideshow_v1.php, it reads "This site can’t be reached". Whether I'm the only person or is it the same with everyone, i just dont know. I couldn't even copy that notification, Norton (while it protects the computer) can sometimes annoy us. Any ideas? Alistair Cowell
I am seeing a similar error from Windows Defender. Started to appear yesterday. Problem occurs on both on V75.8 and the current version V79.0. Threat warning occurs just after starting any scenario. Wayne
I'm getting it too. I doubt it's actually unsafe, but maybe DTG have messed something up... Wouldn't exactly be the first time.
Yes, every time I fire up TSC I get a warning from Windows 11 saying a threat was found. I scan and find nothing.
Any reference to "gen" is not a specific virus or threat, it is a detected pattern which the anti-virus definitions "think" might be. There's usually a way of referring anything like this to the AV provider and they will check and usually put right in their definitions quickly if it is a false detection. John
I find that if I ignore the notice from Norton, it'll show up an hour later. I was having it happen when I run TSC via RW64.exe or via Steam. I thought I was the only one. I think it came for whatever update happened last week because I found that my profile no longer has a fav route/fav loco, which I found odd because I've been playing since TS2014.
Hey folks, thanks for bringing this up! I’ll have to wait on folks to be in on Monday for a fix, but I suspect something similarly named got put in an antivirus database those pull from and it caused this, but we’ll see.
Hello Alistair, I am using Norton Security and also had exactly same message as you. I did play TS a few times after the update last week but only had this yesterday after I installed the new patch from Just Trains (V.1.06 for Southampton Salisbury Extension)
I have a feeling that the domain hasn't been renewed, or its certificates. Might be the domain that host splash screens/screenshots that gets loaded in TSC. The domain did expire on February 6th 2026.
I did notice that the splash screens haven't been updated since Christmas, and there was no screenshot competition in January. I think they said they're going to do away with the monthly TSC screenshot competition. Obviously it’s the weekend and indeed the DTG office is closed until Monday, which means it is pretty much unsupported until then. What is www.railsimdownloads.com anyway?
Railsimdownloads.com did belong to DTG, used for ads/splash screens etc. in the menu. If you follow this guide you might be able to disable it https://steamcommunity.com/sharedfiles/filedetails/?id=1468029149
I followed the instructions in the first part of that guide to Block Railworks.exe in Windows Firewall and that stops the problem I disable the block briefly and went back in to the game for a min - the Trojan report appears again. So I re-enabled it and problem solved. The store is blocked out but that might be in my Settings I don't know if it affect Career statistics but I don't bother with them
I am also getting a similar 'threat' warning. Nothing has happened with my TS install and nothing is popping up when I play TS. It seems to have happened after DTG pushed that new update. TS is obviously showing its age...