Virus attack during Auto Update

User-to-user help and troubleshooting.
TheCorsair
Posts: 2203
Joined: Thu Dec 04, 2008 12:32 pm
Location: Сою́з Сове́тски

Post by TheCorsair »

Adam4 wrote:QUOTE (Adam4 @ May 7 2009, 12:33 AM) NOD returns nothing, and NOD doesnt have "false positives"
Which NOD do you use that works with allegiance? I don't really like Avira and those damn popups!
"Neither east nor west" Image
UNITED FOREVER IN FRIENDSHIP AND LABOUR
"The clouds are fleeting over every country, we stand fast, for no kind of rain will take away our smiles."
Adam4
Posts: 2144
Joined: Sun Sep 03, 2006 9:05 am
Location: England

Post by Adam4 »

V4.0.424.0 if that helps.

This is on XP x64
sgt_baker
Posts: 1510
Joined: Wed Oct 20, 2004 7:00 am
Location: London, UK.
Contact:

Post by sgt_baker »

Why has nobody pointed out that the false-positive in question concerns a file which has absolutely nothing to do with allegiance?

It has absolutely nothing to do with Allegiance.

There.
Image
Granary Sergeant Baker - Special Bread Service (Wurf - 13th Oct 2011)
guitarism
Posts: 2240
Joined: Fri Jan 27, 2006 8:00 am
Location: Richmond

Post by guitarism »

So that means.... what then exactly?
FIZ wrote:QUOTE (FIZ @ Feb 28 2011, 04:56 PM) After Slap I use Voltaire for light reading.
CronoDroid wrote:QUOTE (CronoDroid @ Jan 23 2009, 07:46 PM) If you're going to go GT, go Exp, unless you're Gooey. But Gooey is nuts.
QUOTE [20:13] <DasSmiter> I like to think that one day he logged on and accidentally clicked his way to the EoR forum
[20:13] <DasSmiter> And his heart exploded in a cloud of fury[/quote]
parcival
Posts: 2872
Joined: Tue May 03, 2005 7:00 am
Location: Greece

Post by parcival »

What baker says.
Also, a filename doesn't mean the real thing always.

Nevertheless, it's either a false positive or a smart virus sitting somewhere (probably not in Alleg AU itself) and listening for the right opportunity to attack (specific open ports etc). I have AU many times in the past and never had something similar.
ImageImageImageImageImageImage
" There is good in everyone. You just need the eyes for it. "
Jonan
Posts: 377
Joined: Mon Mar 13, 2006 8:00 am
Location: Hyperborea

Post by Jonan »

Got it today for the first time on autoupdate. Antivir.

Sure it's false positive. What's changed?
*****
My Sig
*****
peet
Posts: 4972
Joined: Sun Jul 16, 2006 6:57 pm
Location: Holland

Post by peet »

If you suspect your anti virus system is compromised you can use one of the free LiveCD's from known brands. You boot your computer from a cd completely ignoring Windows startup.

You must make sure that boot from cd is supported on your computer.

Make a backup of the important data, and have the Windows and application software cd handy.

Burn the images to a cd on a clean computer.

Follow the directions on the manufacturers website. The three LiveCD's most easy to use are:

F Prot LiveCD
Dr Web Live CD
Avira

F prot is the only one with an update feature if you have a working internet connection. The other 2 must be thrown away if a new version is published.
Last edited by peet on Wed May 06, 2009 9:32 pm, edited 1 time in total.
Image
Grimmwolf_GB
Posts: 3711
Joined: Wed Jul 02, 2003 7:00 am
Location: Germany
Contact:

Post by Grimmwolf_GB »

sgt_baker wrote:QUOTE (sgt_baker @ May 6 2009, 08:59 PM) Why has nobody pointed out that the false-positive in question concerns a file which has absolutely nothing to do with allegiance?
Looking at the folder of the file I see:
Xenocode\Sandbox
I guess it has to do with Allegiance/ASGS.
raumvogel
Posts: 5910
Joined: Sun Jul 20, 2003 7:00 am
Location: My lawn
Contact:

Post by raumvogel »

It's easy to say it's a false positive or to "get another game",but that isn't going to stop this from chasing away players.
It just happened to me..same directory:
C:\Documents and Settings\E\Local Settings\Application Data\Xenocode\Sandbox\2.2.3337.18747\2009.02.19T16.33\Native\STUBEXE\@PROGRAMFILES@\COMMON~1\MICROS~1\DW\DW20.EXE
I'll ignore it,but it's giving us a bad name.
Image
Grimmwolf_GB
Posts: 3711
Joined: Wed Jul 02, 2003 7:00 am
Location: Germany
Contact:

Post by Grimmwolf_GB »

For the people with some knowledge, it is giving the av programmes a bad name.
Post Reply