Virus attack during Auto Update

User-to-user help and troubleshooting.
parcival
Posts: 2872
Joined: Tue May 03, 2005 7:00 am
Location: Greece

Post by parcival »

I use Avast. During the auto update I got a popup from it stating that a virus was trying to run in my system.
Here is what Avast recorded in it's logs:
Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\...\Local Settings\Application Data\Xenocode\Sandbox\2.2.3337.18747\2009.02.19T16.33\Native\STUBEXE\@PROGRAMFILES@\COMMON~1\MICROS~1\DW\DW20.EXE" file.

I chose to permanently delete the file (one of Avast's options) and then ASGS popped a message box stating that it can no longer run. ASGS closed and I reopened it. From then on everything went fine and I could play CC04 normally. It seemed that auto update worked but at the same time a virus tried an attack. Has anyone else experienced this?
ImageImageImageImageImageImage
" There is good in everyone. You just need the eyes for it. "
Grimmwolf_GB
Posts: 3711
Joined: Wed Jul 02, 2003 7:00 am
Location: Germany
Contact:

Post by Grimmwolf_GB »

http://www.freeallegiance.org/forums/index...showtopic=49898

I think it is avast posting a false positive.
Deathrender
Posts: 1405
Joined: Sun Jan 04, 2009 5:22 pm
Location: Alberta

Post by Deathrender »

Avira does the same.
phoenix1 wrote:QUOTE (phoenix1 @ Jul 22 2017, 05:58 PM) Mini ac gunner mount was removed because somewhere along the lines we had a core dev that said, "I really hate Terran and want him to be miserable." And all core devs ever since have agreed.
TheCorsair
Posts: 2203
Joined: Thu Dec 04, 2008 12:32 pm
Location: Сою́з Сове́тски

Post by TheCorsair »

Deathrender wrote:QUOTE (Deathrender @ May 6 2009, 08:05 AM) Avira does the same.
Same here... and now it keeps coming up every so often no matter how many times I select "ignore" I guess I'll have to delete it next time or move to quarantine.
"Neither east nor west" Image
UNITED FOREVER IN FRIENDSHIP AND LABOUR
"The clouds are fleeting over every country, we stand fast, for no kind of rain will take away our smiles."
Cheezits
Posts: 254
Joined: Tue Mar 11, 2008 12:15 pm
Location: Boston!!

Post by Cheezits »

AVG as well.....
parcival
Posts: 2872
Joined: Tue May 03, 2005 7:00 am
Location: Greece

Post by parcival »

The strange thing is that AU seems to worked although this file was prohibited from launching and was permanently deleted. Like it wasn't doing anything "useful". What does this file do?
ImageImageImageImageImageImage
" There is good in everyone. You just need the eyes for it. "
TheCorsair
Posts: 2203
Joined: Thu Dec 04, 2008 12:32 pm
Location: Сою́з Сове́тски

Post by TheCorsair »

parcival wrote:QUOTE (parcival @ May 6 2009, 08:44 AM) The strange thing is that AU seems to worked although this file was prohibited from launching and was permanently deleted. Like it wasn't doing anything "useful". What does this file do?
I don't know myself but this is what I found on google

http://www.processlibrary.com/directory/files/dw20/
http://dotnetwithme.blogspot.com/2007/04/i...ing-you_18.html
Last edited by TheCorsair on Tue May 05, 2009 10:50 pm, edited 1 time in total.
"Neither east nor west" Image
UNITED FOREVER IN FRIENDSHIP AND LABOUR
"The clouds are fleeting over every country, we stand fast, for no kind of rain will take away our smiles."
Adam4
Posts: 2144
Joined: Sun Sep 03, 2006 9:05 am
Location: England

Post by Adam4 »

NOD returns nothing, and NOD doesnt have "false positives"
sgt_baker
Posts: 1510
Joined: Wed Oct 20, 2004 7:00 am
Location: London, UK.
Contact:

Post by sgt_baker »

This has been widely reported, yet not universally. Either we're dealing with a small number of false positives, or everyone else is already infected with a virus that disables all known AV suites.

I know which is more likely.
Image
Granary Sergeant Baker - Special Bread Service (Wurf - 13th Oct 2011)
peet
Posts: 4972
Joined: Sun Jul 16, 2006 6:57 pm
Location: Holland

Post by peet »

Check for yourself who to trust.

First disable your poor AV product that gives a false positive :)

DW20.EXE is one of the few files M$ has digitally signed. Rightclick EXE, click properties, click tab Signatures, click on MIcrosoft..., click Details. Verify the file is not compromised.

Also you can upload the EXE to e.g. VirusTotal and have it analyzed for free by almost every AV manufacturer.

If you still doubt, get another game.
Last edited by peet on Wed May 06, 2009 4:42 pm, edited 1 time in total.
Image
Post Reply