Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
So let me give some more information about the findings.
I have been monitoring for a while now.
When in the main menu not doing anything but launching the game it sends all sorts of data across various of servers(ip addresses) and later when a bunch of data has been send ( Receive/Send ) there is a constant flow between a google server that is run though smartphone tycoon app.
So far all information found run by the program:
172.217.168.195
172.217.20.109
224.0.0.251
fra02s28-in-f13.1e100.net
239.255.255.250
But strange that a singleplayer game is sending so much data for no specific reason over the internet.
Picture proof of ip addresses.
https://i.imgur.com/sENp7RO.png
Thanks for your patience.
We have just received the response of our analysts to your request.
No malicious software was found in the attached file. If you have further questions, our Kaspersky Lab support team and I will be happy to assist you.
I wish you a nice day and thank you for the nice cooperation.
https://gyazo.com/09b7ce46422569a939773efc0193ce14
https://gyazo.com/ae494b05b889340f4d34e3f0e7c4f62e
what in the actual ♥♥♥♥ delete this game now and all of the files or/and block it from accessing the internet.
When i check my web data file thats in the directory that originalblackbook said i find things
Also i check many of these files and it checks all my extensions as someone else mentioned, my google version, last time i searched for something
https://gyazo.com/763041c4f9639830ce0760af98249801
If you not famiiar with NWJS stop trolling about Virus etc..
NWJS use Chromium as backend.
Read more: https://nwjs.io/ ( open source: https://github.com/nwjs/nw.js )
@Aston Martin Valkyrie - What you show us is only Databse Structure from Chromium. But no entrys. Click "Browse Data" on your SQLBrowser Tool , i'm sure its all empty.
Of course use this game Internet to connect with other server. SteamAPI example or Debug Service etc and of cource Chromium it self contact Google server.
So, stop make panic here.
Does not explain why there is data transfer to their servers for a singleplay game.
This is midgame not when it crashes! It even sends data when you are in the main menu?
Program: smartphone tycoon.exe
Product version: nwjs 0.36.0 from The NW.js Community
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
Array: ["gaia.l.a.r", []]
Additional information:
https://chromium.googlesource.com/chromium/src/+/master/google_apis/gaia
https://www.google.com/support/enterprise/static/gsa/docs/admin/70/admin_console_help/cloud_google_apps.html
Related to this "fra16s18-in-f13.1e100.net"... It's the endpoint for the mentioned GoogleIP
Serverlocation -> Amsterdam, Noord-Holland
172.217.16.163
https://www.gstatic.com/chrome/config/plugins_3/plugins_win.json
gstatic -> Plugins_win.json -> for Google Talk, Java Runtime, Realplayer, Adobe Flash/Shockwave/Reader, Quicktime, MediaPlayer, DivX, Silverlight and some more
User-Agent:
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (@ac9418ba9c3bd7f6baaffa0b055dfe147e0f8364) (KHTML, like Gecko, Chrome, Safari) NWjs/0.36.0
Crashlytics
http://rezbaaqglrhn
http://aqiigaijlayapcq
http://ljeyxpat
239.255.255.250
---
One valid point... For singleplayergames no external connections are necessary. Especially when there is no information on the product page or a real reason. And i mean no "legitimate interest" or "technically necessary"... Here or elsewhere. But that's another topic and only my opinion.
Well, long speech, short sense.... easy way is to block the exe.
https://drive.google.com/file/d/1XvheinYpTn6rH0zh6rG4Cv78QP17uAHI/view?usp=sharing