Virtual Desktop

Virtual Desktop

SynAcks 2017년 9월 25일 오후 10시 32분
Why Is Virtual Desktop trying to take me to a harmful website? sawebservice.red-gate.com
So whenever I exit Virtual Desktop, I'm getting a pop-up from Malwarebytes that says it blocked access to a potentially harmful website called "sawebservice.red-gate.com". Looking that site up on ThreatCrowd.org shows that it is, in fact, a heavily used site by hackers. Why is Virtual Desktop trying to take me there when I exit the application?
SynAcks 님이 마지막으로 수정; 2017년 9월 25일 오후 10시 36분
< >
전체 댓글 7개 중 1~7개 표시 중
ggodin  [개발자] 2017년 9월 26일 오후 1시 11분 
As I've mentioned in the past, the RedGate website is used for telemetry and crash reports. It is not harmful.
SynAcks 2017년 9월 27일 오후 7시 51분 
Ok, but givem that it has hundreds of viruses associated with it, wouldn't it make senese to move the telemetry and crash reports to a more reputable host? Just a few of the malware and virus items associated with that site are:

[Trojan.Injector.AF] [W32/Backdoor.BAQH-3189] [TR/Dynamer.ac.1733] [Win32/DfInject.BZ] [Trojan.Delfinject.ag.n8] [Trojan.Mybot-10022] [Trojan.DownLoader.50961] [Win32/TrojanDropper.Delf.NJH] [W32/Dropper.DB!tr] [W32/Backdoor2.XVS] [IRC/BackDoor.SdBot4.SEO] [Trojan.Win32.ProcessHijack] [Trojan ( 00028ee21 )] [Backdoor.Win32.Rbot.hyj] [Trojan.Inject.DF] [BackDoor-EFI] [Trojan.DL.Win32.Mnless.fhz] [Troj/Delf-FFY] [Suspicious.Bifrose] [TROJ_DELF.SMX] [Backdoor.Rbot]
[Trojan-FDWX!79346D1A8FC7] [Trojan ( 003e61701 )] [Trojan ( 003e61701 )] [Trojan.Barys.D4191] [Trojan.Win32.BJT.dyapax] [a variant of MSIL/Injector.BJT] [BehavesLike.Win32.Trojan.fh] [W32/Trojan.BTQJ-3584] [TR/AD.Bladabindi.Y.11353] [Backdoor:MSIL/Bladabindi!rfn] [Trojan.Win32.Z.Injector.331264.F[h]] [Trj/CI.A] [Trojan.MSIL.Injector] [MSIL9.AEPY] [Trojan.MSIL.Injector.BJT] [Win32/Trojan.84f]
[Trojan.DownLoader10.25001] [Win.Backdoor.Bladabindi-1] [Trojan.MSIL.Disfa] [Troj/MSIL-HX] [Trojan.MSIL.Bladabindi] [W32/Backdoor.IJZX-4825] [Error Scanning File] [Backdoor*MSIL/Bladabindi.AJ] [Trojan ( 700000121 )] [Atros2.QSG] [Backdoor.Bot!4E4F]
[Trojan.MSIL2] [Trojan*Win32/Dynamer!ac] [Packed.DeepSea.B.uimj.mg] [Trojan.MulDrop5.7410] [MSIL/Bladabindi.F!tr] [Trojan ( 700000121 )] [MSIL2.IXX] [Win.Trojan.Njrat-1] [TROJ_BL.D83B33B1] [W32/Trojan2.OGWI] [Win32/Tnega.ZTQaCcB] [MSIL/Bladabindi.F] [Trojan.Bladabindi.Win32.55107] [W32/Trojan.BORX-4733] [Win32/Tnega.ZTQaCcB] [Packed.DeepSea.B.uimj.mg] [MSIL/Bladabindi.F] [MSIL2.IXX] [Trojan ( 700000121 )] [Trojan*Win32/Skeeyah.A!rfn] [W32/Trojan.BORX-4733] [W32/Trojan2.OGWI] [Trojan.MSIL2] [Trojan.Bladabindi.Win32.55135] [TROJ_BL.D83B33B1] [Win.Trojan.Njrat-1] [Trojan.MulDrop5.7410] [BDS/Bladabindi.aloia] [Trojan.60AEB21139855B4A] [MSIL/Injector.CJV] [MSIL3.AVFD] [Trojan ( 700000121 )] [Trojan*Win32/Dacic.A!rfn] [Trojan.MSIL] [Trojan.Injector.Win32.315730] [Trojan.Dotfus.A] [Backdoor.DarkKomet] [Win32.HLLW.Autoruner.25074]
ggodin  [개발자] 2017년 9월 27일 오후 10시 29분 
Virtual Desktop isn't taking you to any websites, it just sends telemetry and crash reports to a database in the cloud (it doesn't download anything). Viruses aren't attached to a website but to executables so I'm not sure how your tool compiles that list of viruses...
SynAcks 2017년 9월 28일 오후 9시 10분 
So these viruses are not directly related to that site, but rather they are known to exist and depend upon red-gate.com's existence. This is all publicly available data on www.threatcrowd.org. You hosting your telemetry and crash reports there is ostensibly like running a Best Buy inside of a crack house. Yes, what you are doing is probably legitimate business, but it's very unlikely that most of your reporting will make it to you from computers protected by Malwarebytes, such as mine. Malwarebytes continually tells me that it's blocked access to a potentially dangerous website, "Red-Gate". One would think that you would have noticed this by now, perhaps wondering why your telemetry data is not in line with the number of sales you have of your product.

REPORT FROM MALWAREBYTES DETECTION:
Blocked Website Details
Malicious Website: 1
Blocked, [-1], [-1],0.0.0

-Website Data-
Domain: sawebservice.red-gate.com
IP Address: 52.16.59.228
Port: [53658]
Type: Outbound
File: C:\Program Files (x86)\Steam\steamapps\common\Virtual Desktop\Virtual Desktop.exe

If you've had this reported before, why don't you just move it to a more reputable hosting platform?
SynAcks 2017년 9월 28일 오후 9시 14분 
No need to continue this. I like your software and I'm not trying to be argumentative. Just flag this for the suggestion box. =)
Bowlcut 2017년 9월 30일 오후 6시 07분 
SynAcks님이 먼저 게시:
You hosting your telemetry and crash reports there is ostensibly like running a Best Buy inside of a crack house.

That is unfair. Redgate is not like a crack house. They are a legitimate company. Malwarebytes is being a little overzealous here.
< >
전체 댓글 7개 중 1~7개 표시 중
페이지당 표시 개수: 1530 50

게시된 날짜: 2017년 9월 25일 오후 10시 32분
게시글: 7