Установить Steam
войти
|
язык
简体中文 (упрощенный китайский)
繁體中文 (традиционный китайский)
日本語 (японский)
한국어 (корейский)
ไทย (тайский)
Български (болгарский)
Čeština (чешский)
Dansk (датский)
Deutsch (немецкий)
English (английский)
Español - España (испанский)
Español - Latinoamérica (латиноам. испанский)
Ελληνικά (греческий)
Français (французский)
Italiano (итальянский)
Bahasa Indonesia (индонезийский)
Magyar (венгерский)
Nederlands (нидерландский)
Norsk (норвежский)
Polski (польский)
Português (португальский)
Português-Brasil (бразильский португальский)
Română (румынский)
Suomi (финский)
Svenska (шведский)
Türkçe (турецкий)
Tiếng Việt (вьетнамский)
Українська (украинский)
Сообщить о проблеме с переводом
Sorry, it was a false detection. It will be fixed.
Thank you for your help.
Best regards,
Pavel Sinenko, Malware Analyst, Kaspersky Lab
As of the time of this posting, Kaspersky no longer false positives on any of the three EXEs.
Submission ID: 5d84211f-a6ee-4ca2-9400-a13ead5399d0
Analyst comments:
... We have reviewed the file and we have removed the detection. Please try the following steps to clear cached detections and obtain the latest malware definitions. 1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender 2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures” The latest definition is available for download here: https://www.microsoft.com/en-us/wdsi/definitions Best regards, Windows Defender Response
As of the time of this posting, the Microsoft: line shows Clean for all three EXEs.
In relation to submission 98522.
Upon further analysis and investigation we have verified your submission
and, as such, the detection(s) for the following file(s) will be removed
from our products:
File name: ConfigTool.exe
MD5: 9EB4CDF87633EB906EBCA243EA828A42
SHA256:ACC574F2F9FB388F07F74722F35C7BA395336B73E75014B021A796E64E055E9A
As of the time of this posting, Symantec shows Clean on Virustotal for the config tool and magrathea, but is still throwing a false positive on Scavenger.exe:
"ML.Attribute.HighConfidence"
They haven't replied to me yet about that. I'll re-report it if I don't hear something soon.
It is worthwhile to note that the virustotal.com results change day by day - sometimes just pushing "rescan" results in a slightly different set of results. This is not a precise science apparently.
Thank you for your submission.
It is a false positive of our scanner and this issue will be fixed in the
next update of detection engine.
Regards,
ESET Malware Response Team
As of the time of this posting, ESET-NOD32 now shows Clean on VirusTotal for all three EXEs.
Based on our analysis we have decided to disabled the detection on the following file:
Scavenger.exe - MD5:862d698a8032f88f5dbcfe57eeec4e59
We regret any inconvenience this might have caused you. The detection will be removed in our earliest possible Virus Signature update.
As of this posting, Fortinet shows Clean on VirusTotal for all three EXEs.
McAfee: Scavenger.exe, "RDN/Generic.dx", configtool, "RDN/Generic.hbg", magrathea, "RDN/Generic.RP"
McAfee-GW-Edition: Scavenger.exe, "BehavesLike.Win32.Dropper.jc", configool "RDN/Generic.hbg", magrathea.exe "BehavesLike.Win32.Dropper.gh"
They haven't gotten back to me with a human being yet. As of this posting, both McAfee products on virustotal false positive on all three of my executables.
1) I basically can't patch the game code after this.
If I change my signatures, by pushing another patch to the game, every single one of these whitelisted reports and changes with the AV vendors will become invalid. It will be seen as a new program, and the manually entered exception on file with all these vendors will no longer apply.
To patch anything in the code, I'd have to resubmit every single one of these reports.
That doesn't necessarily mean 1.095 is the Last Edition Ever of Scavenger SV-4, but it does mean the *code* isn't gonna change from here out. v1.10 is therefore more likely to be something like a texture improvement pack to try to improve the look of things a little.
2) If you get an antivirus quarantine alert, and it isn't for one that I've already talked about as a known open vendor ticket in this thread, please let me know here.
Virustotal.com isn't perfect, and doesn't cover everything, and I otherwise have no way of knowing it happens if you don't tell me. I'm happy to try to fix this situation for your use case, but you have to let me know.
scavenger.exe, 16/67
configtool.exe, 17/67
magrathea.exe, 5/67
Open tickets: McAfee, Symantec
Current snapshot:
scavenger.exe, 15/67
configtool, 17/67
magrathea, 5/67
The file d:\steam\steamapps\common\scavenger sv-4\configtool.exe is infected with Trojan.GenericKD.31075384 and was moved to quarantine.
scavenger.exe, 12/67
configtool 18/67
magrathea, 4/67
McAfee is thus far being less than helpful. They are trying to act like my false positive report is a suspicious files report, when that is exactly the opposite. More updates to follow.