Board Index | Search | Profile |
Page 1 of 1 |
[ 8 posts ] |
Print view | Previous topic | Next topic |
Author | Message |
---|---|
Team:
Rank: Director Main: Sk1rm1sh Level: 2032 Joined: Tue Nov 19, 2013 7:48 pm Posts: 549 |
Tried to install beta client and got the message that it's infected with TR/Crypt.XPACK.Gen (Cloud)
_________________ |
Sun Jan 04, 2015 3:24 am |
|
Content Dev
Team:
Rank: Director Main: Blue Dwarf Level: 2067 Joined: Fri Apr 29, 2011 5:39 pm Posts: 3336 |
What AV/version please?
_________________ "What you mean you killed him cha cha cha?!" Support |
Tue Jan 13, 2015 5:16 pm |
|
Team:
Rank: Director Main: Sk1rm1sh Level: 2032 Joined: Tue Nov 19, 2013 7:48 pm Posts: 549 |
Avira 14.0.7.46
_________________ |
Tue Jan 13, 2015 6:21 pm |
|
Dev Team
Team:
Rank: Officer Main: Jey123456 Level: 4359 Joined: Fri Sep 24, 2004 11:51 pm Posts: 3366 Location: who knows ? |
which specific file was claimed to be infected ? I just did a check on the beta starsonata.exe and seem clear
http://virusscan.jotti.org/en/scanresul ... bb22894df7 only clam av find something but that one has been a false positive for years xD. I submitted the file to them for whitelisting but never got a reply heh. _________________ One of the first and proud flight controller. Visit our website: http://www.ef-team.com |
Wed Jan 14, 2015 5:14 am |
|
Team:
Rank: Director Main: Sk1rm1sh Level: 2032 Joined: Tue Nov 19, 2013 7:48 pm Posts: 549 |
it was the actual installer, StarSonata_2_beta.exe.
No warning for the non-beta install file though _________________ |
Wed Jan 14, 2015 10:17 am |
|
Dev Team
Team:
Rank: Officer Main: Jey123456 Level: 4359 Joined: Fri Sep 24, 2004 11:51 pm Posts: 3366 Location: who knows ? |
I just tested the one from http://www.starsonata.com/dl/StarSonata_2_beta.exe
and it was clear (well, except yet another false positive from clam av xD). Which url did you use to download the infected exe you got ? http://virusscan.jotti.org/en/scanresul ... 22a1c6ea4a _________________ One of the first and proud flight controller. Visit our website: http://www.ef-team.com |
Wed Jan 14, 2015 12:37 pm |
|
Team:
Rank: Director Main: Sk1rm1sh Level: 2032 Joined: Tue Nov 19, 2013 7:48 pm Posts: 549 |
The URL was http://www.starsonata.com/dl/StarSonata_2_beta.exe . Hmm... same one as you posted.
Maybe avira and clam share some virus definitions? I have no idea why only the beta installer is getting reported though _________________ |
Wed Jan 14, 2015 4:52 pm |
|
Dev Team
Team:
Rank: Officer Main: Jey123456 Level: 4359 Joined: Fri Sep 24, 2004 11:51 pm Posts: 3366 Location: who knows ? |
if i were to take a guess. I would say its because of the empty stub inside (those are often used as a fake front for malware to get in).
Unlike the live installer, which contain the whole client. The beta installer contain a fake star sonata.exe which only call patchbot.exe and the pathbot handle downloading the full beta client from the starsonata server at that point. _________________ One of the first and proud flight controller. Visit our website: http://www.ef-team.com |
Wed Jan 14, 2015 5:01 pm |
|
Page 1 of 1 |
[ 8 posts ] |
All times are UTC - 5 hours |
Who is online |
Users browsing this forum: No registered users and 1 guest |
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum |