Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
You can add manually via Setup -> Computer protection -> gear icon on the right -> Edit exclusions, but yea, it's quite a hassle.
In the past I wrote all major AV companies but it takes some time until they react and they marked it then as false positive.
For the SophosML case, we can't do much. It was not even possible to ask them to check the file thoroughly.
You can for the time being mark it locally as false positive or contact your AV provider (if you don't trust us). I'll to this myself soon but we probably try a different obfuscation method first.
Edit: https://www.virustotal.com/gui/file/91c74ccd968cec5542d8097a88b7171feebcbd07b8a66005dacc78a396f03c99/detection
"We have removed the detection. Please follow the steps below to clear cached detection and obtain the latest malware definitions.
1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender
2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
3. Run "MpCmdRun.exe -SignatureUpdate"
Alternatively, the latest definition is available for download here: https://www.microsoft.com/en-us/wdsi/definitions
Thank you for contacting Microsoft."
It is happening again today. I suppose the file has been changed/updated.
I have marked once again as a false positive.
As soon as possible I will raise a case with Sophos, or I may very well change AV provider!
Thanks a lot.
-<ESET>
-<LOG>
-<RECORD>
<COLUMN NAME="Zeit">13.09.2020 15:46:53</COLUMN>
<COLUMN NAME="Scanner">Echtzeit-Dateischutz</COLUMN>
<COLUMN NAME="Objekttyp">Datei</COLUMN>
<COLUMN NAME="Objekt">G:\Steam\steamapps\downloading\1016920\UnrailedGame.exe</COLUMN>
<COLUMN NAME="Erkennung">Suspicious Object</COLUMN>
<COLUMN NAME="Aktion">Gesäubert durch Löschen</COLUMN>
<COLUMN NAME="Benutzer">XXXXXXXXXXXXXX</COLUMN>
<COLUMN NAME="Information">Ereignis beim Bearbeiten einer Datei durch die Anwendung: F:\Program Files (x86)\Steam\steam.exe (A28E81FC6998C3F28BE6E4F5229F16DF16C2EE85).</COLUMN>
<COLUMN NAME="Hash">254120098F64C662F23E5DB53806801666BC3D80</COLUMN>
<COLUMN NAME="Zuerst hier gesehen">13.09.2020 13:43:46</COLUMN>
</RECORD>
</LOG>
</ESET>
https://i.imgur.com/KkjtcuW.png