Half-Life
SANTIAGO 27 ENE 2014 a las 2:13
Win95.cih.remnants in my old half-life cd... Lol ?
F:/Manual/ar40fra.exe contains sample of Win95 CIH virus ...


My cd is an original one (Half-Life Generation) , not some pirated ♥♥♥♥.

Seriously, what the ♥♥♥♥ ?

All the antiviruses I had by the past (Norton, Avast, Antivir, Kaspersky, Microsoft Security Essentials, Windows Defender (now) ...) , they ALL detected it, so I highly doubt it was a false positive...

< >
Mostrando 1-11 de 11 comentarios
constancejill 27 ENE 2014 a las 12:14 
Unless you plan on installing Acrobat Reader 4 in french, why should you care?
SANTIAGO 27 ENE 2014 a las 12:17 
I never said I cared, but that just seems odd to have such a violent virus on an OFFICIAL cd ...
constancejill 27 ENE 2014 a las 14:24 
Well maybe it's a virus that got discovered later than the game's release date. Just uploaded it to virustotal and indeed, 27 out of 50 AVs say it's infected or suspicious.

What's weirder though IMHO is that the version on Adobe's FTP server ( here : ftp:/ftp.adobe.com/pub/adobe/acrobatreader/win/4.x/ar40fra.exe ) is the exact same size and has many null bytes where the version from the CD does not (you can check that by performing a binary comparison between the two files).
constancejill 27 ENE 2014 a las 23:34 
Publicado originalmente por Pokepokemans:
And if it detected it, it's 100% true
www.malwarebytes.org
You're saying it like Malwarebytes never gave any false positive... though it does sometimes, else they would not have a dedicated section for it on their forums.
SANTIAGO 28 ENE 2014 a las 6:38 
I sent it to VirusTotal too... I got the same results. That's pretty suspicious.

Yep, I noticed that odd thing about the file bytes ... I'd rather not open it, or open it on my virtual Windows 98 SE machine
SANTIAGO 28 ENE 2014 a las 7:03 
Publicado originalmente por Pokepokemans:
Well, you tried all the meh antiviruses.
Now try this:
And if it detected it, it's 100% true
www.malwarebytes.org

Malwarebytes isn't perfect either.
sombrez 9 ABR 2014 a las 19:07 
hmm i have this original half life cd too and it didn't give me a ar40fra.exe
weird
constancejill 9 ABR 2014 a las 23:09 
Your CD probably isn't the french edition then.
sombrez 1 MAY 2014 a las 7:55 
oh, i have the english version so yeah
Tomidaru 22 ABR 2023 a las 12:40 
I have it on my European cd, got it in the UK.
Flan 22 ABR 2023 a las 18:13 
Publicado originalmente por SANTIAGO:
I never said I cared, but that just seems odd to have such a violent virus on an OFFICIAL cd ...
That's a way viruses spread back then, the extra 3rd party stuff packaged in gets done carelessly with files that "I just got it from some ftp, looks legit" or something by the publisher adjacent localisation teams and no one notices but luckily its in a spot where it didn't really matter.

Half-life did have an infection problem with the .cih virus that the devs were aware of I remember, this could be related.

Publicado originalmente por constancejill:
Well maybe it's a virus that got discovered later than the game's release date. Just uploaded it to virustotal and indeed, 27 out of 50 AVs say it's infected or suspicious.

What's weirder though IMHO is that the version on Adobe's FTP server ( here : ftp:/ftp.adobe.com/pub/adobe/acrobatreader/win/4.x/ar40fra.exe ) is the exact same size and has many null bytes where the version from the CD does not (you can check that by performing a binary comparison between the two files).

Yes that's how the cih virus works, it inserts bits of itself into the null bytes of a exe file.

Since Sierra is long dead you could contact valve directly since it is a real virus on their product even though it's from more than 20 years ago, they might give you an answer.
Última edición por Flan; 22 ABR 2023 a las 18:23
< >
Mostrando 1-11 de 11 comentarios
Por página: 1530 50

Publicado el: 27 ENE 2014 a las 2:13
Mensajes: 10