Author Topic: Question about a game file  (Read 5313 times)

0 Members and 1 Guest are viewing this topic.

celeste

  • Guest
Question about a game file
« on: June 05, 2009, 02:45:30 AM »
I use this program for an online game I play..when i download it avast says it's clean [no virus] but a few days later the same file shows up as a virus. I pay to use this program and the programmer says that it's clean, they say that it shows up as a false positive because the security they use to prevent their code can't be stolen to use for cracked versions. I was wondering if anyone could test the file and see what comes up?

The program is called s-bot and here's the link http://www.bot-cave.net/
There is only one download and it's on the homepage.

Thanks,
Leah

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Question about a game file
« Reply #1 on: June 05, 2009, 02:59:16 AM »
It may be because of the packing method, etc. used but the info asked for below may point to that.

What is the malware name, the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ? 
Check the avast! Log Viewer (right click the avast 'a' icon), Warning section, this contains information on all avast detections. C:\Program Files\Alwil Software\Avast4\ashLogV.exe - Or check the source file using notepad C:\Program Files\Alwil Software\Avast4\DATA\log\Warning.log

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

John2009

  • Guest
Re: Question about a game file
« Reply #2 on: June 05, 2009, 05:07:59 AM »
Avast very rarely has FPs so probably not.

celeste

  • Guest
Re: Question about a game file
« Reply #3 on: June 05, 2009, 06:43:01 AM »
On the forum, which u have to have a paid account to access, they say other anti viruses picked this up too cause of the security. Those anti viruses included avg and nod32, they said those were false positives too but i think its weird because at first avast doesnt recognize it as a virus then one day when i try to start it up it does.

Here's the virustotal results:
http://www.virustotal.com/analisis/34497105193125b3637d46bbea8e0d552149d2891ecf633c0c32d59dd1ed8253-1244148927

Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1777
  • Thinking with Portals
Re: Question about a game file
« Reply #4 on: June 05, 2009, 07:07:34 AM »
-= Maybe it was run on startup so, avast resident scanner was alerted about its existence..? ???
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1

celeste

  • Guest
Re: Question about a game file
« Reply #5 on: June 05, 2009, 07:35:41 AM »
I haven't restarted my computer, plus it only detected it when i opened the folder the file was contained in. I've been using this program for around 6 months with no problems until recently, but it is updated at least once a week with new versions.



Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1777
  • Thinking with Portals
Re: Question about a game file
« Reply #6 on: June 05, 2009, 09:52:49 AM »
-= The new version must've probably been infected..
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1

cinchez

  • Guest
Re: Question about a game file
« Reply #7 on: June 05, 2009, 09:57:04 AM »
Probably, IMO its the only possible statement that we can get from ur latest statement^^

-AnimeLover^^

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Question about a game file
« Reply #8 on: June 05, 2009, 04:32:41 PM »
On the forum, which u have to have a paid account to access, they say other anti viruses picked this up too cause of the security. Those anti viruses included avg and nod32, they said those were false positives too but i think its weird because at first avast doesnt recognize it as a virus then one day when i try to start it up it does.

Here's the virustotal results:
http://www.virustotal.com/analisis/34497105193125b3637d46bbea8e0d552149d2891ecf633c0c32d59dd1ed8253-1244148927


New signatures are constantly added as some signatures and the generic signatures are also modified to increase detections, or the inclusion of new unpackers, etc. so it isn't unusual to find something that previously wasn't detected is now detected.

The VT results show 13/39 detections which is high one third of all the scanners. This would normally be conclusive, however many of those detections are generic, some detecting on the encryption or packing methods (some commonly used by malware) and also heuristic detection. So there is no clear signature detection.

I have no problem with an author trying to protect their work, but when that it detected by one third of scanners I feel they should investigate other methods. Perhaps you should show him the VirusTotal results link as that is I would imagine a greater number of detections that he things.

You can submit the detected file to avast for further analysis as a possible false positive, but if avast aren't able to unpack/decrypt it to do any analysis, there will always be an area of suspicion about the file.
« Last Edit: June 05, 2009, 04:47:55 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Question about a game file
« Reply #9 on: June 05, 2009, 05:12:28 PM »
I think it's conclusive: malware!
At least, the one in your computer, maybe the infection changed the original game file.
The best things in life are free.

celeste

  • Guest
Re: Question about a game file
« Reply #10 on: June 06, 2009, 06:07:59 AM »
update: after avast updated today the same game file that was detected no longer is, dont know what this means..

Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1777
  • Thinking with Portals
Re: Question about a game file
« Reply #11 on: June 06, 2009, 09:25:56 AM »
update: after avast updated today the same game file that was detected no longer is, dont know what this means..

-= Huh..? Why not try sending a sample to ALWIL so they could act on it..?
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Question about a game file
« Reply #12 on: June 06, 2009, 01:59:15 PM »
update: after avast updated today the same game file that was detected no longer is, dont know what this means..

Well, I can't believe that all other antivirus are just detecting this file as a false positive, but if you said so (that avast is no longer detecting it).
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Question about a game file
« Reply #13 on: June 06, 2009, 04:34:49 PM »
update: after avast updated today the same game file that was detected no longer is, dont know what this means..


What it means is that you or someone else submitted the file (as suggested above) and it has been further analysed and confirmed as a false positive and a correction made. This is then added to the next VPS Update to correct the detection.

That is why we suggest a) confirmation via virustotal and b) submission to avast if considered a false positive.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security