Virtual Desktop
Why Is Virtual Desktop trying to take me to a harmful website? sawebservice.red-gate.com
So whenever I exit Virtual Desktop, I'm getting a pop-up from Malwarebytes that says it blocked access to a potentially harmful website called "sawebservice.red-gate.com". Looking that site up on ThreatCrowd.org shows that it is, in fact, a heavily used site by hackers. Why is Virtual Desktop trying to take me there when I exit the application?
Автор останньої редакції: SynAcks; 25 верес. 2017 о 22:36
< >
Показані коментарі 17 із 7
ggodin  [розробник] 26 верес. 2017 о 13:11 
As I've mentioned in the past, the RedGate website is used for telemetry and crash reports. It is not harmful.
Ok, but givem that it has hundreds of viruses associated with it, wouldn't it make senese to move the telemetry and crash reports to a more reputable host? Just a few of the malware and virus items associated with that site are:

[Trojan.Injector.AF] [W32/Backdoor.BAQH-3189] [TR/Dynamer.ac.1733] [Win32/DfInject.BZ] [Trojan.Delfinject.ag.n8] [Trojan.Mybot-10022] [Trojan.DownLoader.50961] [Win32/TrojanDropper.Delf.NJH] [W32/Dropper.DB!tr] [W32/Backdoor2.XVS] [IRC/BackDoor.SdBot4.SEO] [Trojan.Win32.ProcessHijack] [Trojan ( 00028ee21 )] [Backdoor.Win32.Rbot.hyj] [Trojan.Inject.DF] [BackDoor-EFI] [Trojan.DL.Win32.Mnless.fhz] [Troj/Delf-FFY] [Suspicious.Bifrose] [TROJ_DELF.SMX] [Backdoor.Rbot]
[Trojan-FDWX!79346D1A8FC7] [Trojan ( 003e61701 )] [Trojan ( 003e61701 )] [Trojan.Barys.D4191] [Trojan.Win32.BJT.dyapax] [a variant of MSIL/Injector.BJT] [BehavesLike.Win32.Trojan.fh] [W32/Trojan.BTQJ-3584] [TR/AD.Bladabindi.Y.11353] [Backdoor:MSIL/Bladabindi!rfn] [Trojan.Win32.Z.Injector.331264.F[h]] [Trj/CI.A] [Trojan.MSIL.Injector] [MSIL9.AEPY] [Trojan.MSIL.Injector.BJT] [Win32/Trojan.84f]
[Trojan.DownLoader10.25001] [Win.Backdoor.Bladabindi-1] [Trojan.MSIL.Disfa] [Troj/MSIL-HX] [Trojan.MSIL.Bladabindi] [W32/Backdoor.IJZX-4825] [Error Scanning File] [Backdoor*MSIL/Bladabindi.AJ] [Trojan ( 700000121 )] [Atros2.QSG] [Backdoor.Bot!4E4F]
[Trojan.MSIL2] [Trojan*Win32/Dynamer!ac] [Packed.DeepSea.B.uimj.mg] [Trojan.MulDrop5.7410] [MSIL/Bladabindi.F!tr] [Trojan ( 700000121 )] [MSIL2.IXX] [Win.Trojan.Njrat-1] [TROJ_BL.D83B33B1] [W32/Trojan2.OGWI] [Win32/Tnega.ZTQaCcB] [MSIL/Bladabindi.F] [Trojan.Bladabindi.Win32.55107] [W32/Trojan.BORX-4733] [Win32/Tnega.ZTQaCcB] [Packed.DeepSea.B.uimj.mg] [MSIL/Bladabindi.F] [MSIL2.IXX] [Trojan ( 700000121 )] [Trojan*Win32/Skeeyah.A!rfn] [W32/Trojan.BORX-4733] [W32/Trojan2.OGWI] [Trojan.MSIL2] [Trojan.Bladabindi.Win32.55135] [TROJ_BL.D83B33B1] [Win.Trojan.Njrat-1] [Trojan.MulDrop5.7410] [BDS/Bladabindi.aloia] [Trojan.60AEB21139855B4A] [MSIL/Injector.CJV] [MSIL3.AVFD] [Trojan ( 700000121 )] [Trojan*Win32/Dacic.A!rfn] [Trojan.MSIL] [Trojan.Injector.Win32.315730] [Trojan.Dotfus.A] [Backdoor.DarkKomet] [Win32.HLLW.Autoruner.25074]
ggodin  [розробник] 27 верес. 2017 о 22:29 
Virtual Desktop isn't taking you to any websites, it just sends telemetry and crash reports to a database in the cloud (it doesn't download anything). Viruses aren't attached to a website but to executables so I'm not sure how your tool compiles that list of viruses...
So these viruses are not directly related to that site, but rather they are known to exist and depend upon red-gate.com's existence. This is all publicly available data on www.threatcrowd.org. You hosting your telemetry and crash reports there is ostensibly like running a Best Buy inside of a crack house. Yes, what you are doing is probably legitimate business, but it's very unlikely that most of your reporting will make it to you from computers protected by Malwarebytes, such as mine. Malwarebytes continually tells me that it's blocked access to a potentially dangerous website, "Red-Gate". One would think that you would have noticed this by now, perhaps wondering why your telemetry data is not in line with the number of sales you have of your product.

REPORT FROM MALWAREBYTES DETECTION:
Blocked Website Details
Malicious Website: 1
Blocked, [-1], [-1],0.0.0

-Website Data-
Domain: sawebservice.red-gate.com
IP Address: 52.16.59.228
Port: [53658]
Type: Outbound
File: C:\Program Files (x86)\Steam\steamapps\common\Virtual Desktop\Virtual Desktop.exe

If you've had this reported before, why don't you just move it to a more reputable hosting platform?
No need to continue this. I like your software and I'm not trying to be argumentative. Just flag this for the suggestion box. =)
Цитата допису SynAcks:
You hosting your telemetry and crash reports there is ostensibly like running a Best Buy inside of a crack house.

That is unfair. Redgate is not like a crack house. They are a legitimate company. Malwarebytes is being a little overzealous here.
< >
Показані коментарі 17 із 7
На сторінку: 1530 50

Опубліковано: 25 верес. 2017 о 22:32
Дописів: 7