Exvalcore Nov 4, 2021 @ 7:52am
Developer Alert(Trojan:Win32/Sabsik.FL.A!ml)
When wrapping a exe file with steam drm this virus was detected from within the new build.
If there is any information on this I like you to post about it, I find this very strange for sure.

Something went wrong while displaying this content. Refresh

Error Reference: Community_9721151_
Loading CSS chunk 7561 failed.
(error: https://community.fastly.steamstatic.com/public/css/applications/community/communityawardsapp.css?contenthash=789dd1fbdb6c6b5c773d)
Showing 1-11 of 11 comments
[N]ebsun Nov 4, 2021 @ 8:00am 
Likely your computer has been infected with a trojan that is trying to spread
Exvalcore Nov 4, 2021 @ 8:03am 
Highly unlikely its the single file, the .exe of the game was added to the
Security DRM Tab was wrapped on server side & sent back with the Trojan.
ShelLuser Nov 4, 2021 @ 8:08am 
What virus scanner and more so: what game? Defo sounds like a false positive at first glimpse to me.
Exvalcore Nov 4, 2021 @ 8:31am 
Windows defender, it does seem to work normally
when I reinstalled the game's from it's online depot.
It could have been a virus within the browser hooking
to the download, is nothing safe these days, I guess
it's working now I just didn't know what to make of it.
aiusepsi Nov 4, 2021 @ 8:40am 
I would suspect the "!ml" suffix there suggests that it was detected by a machine learning algorithm, so it may well be a false positive.

The point of the Steam DRM wrapper is to obfuscate the executable to make it harder to reverse-engineer, so it's not unlikely that it could end up looking a bit like a virus to a machine-learning algorithm, given that viruses also have reason to be obfuscated to prevent reverse-engineering.
Daggoth Nov 4, 2021 @ 11:30am 
If it was during the download it probably picked up the partially downloaded file as a phantom positive. IE the file briefly had a signature that defender thought looked like a virus simply because the file was changing while being downloaded.
It's suggested to exclude the downloading folder from real-time scanning for this reason.
Phoenix Nov 4, 2021 @ 1:30pm 
Why ask this on the forums on not adress support directly?
nullable Nov 4, 2021 @ 1:53pm 
Originally posted by Exvalcore:
When wrapping a exe file with steam drm this virus was detected from within the new build.
If there is any information on this I like you to post about it, I find this very strange for sure.

False positives aren't that strange.
Satoru Nov 4, 2021 @ 1:54pm 
Originally posted by Snakub Plissken:
Originally posted by Exvalcore:
When wrapping a exe file with steam drm this virus was detected from within the new build.
If there is any information on this I like you to post about it, I find this very strange for sure.

False positives aren't that strange.

tbh for MS Defender its actually quite strange to get a false positive.

I mostly recommend it because it generates the least amount of false positives imho compared to other consumer level stuff. Most consumer AV is so desperate to justify its own existence it will alert you for every possible nonsensical thing imaginable. MS Defender actually has a good threshold of user notification (which is kinda funny given how UAC used to be so utterly annoying)
Last edited by Satoru; Nov 4, 2021 @ 1:55pm
rawWwRrr Nov 4, 2021 @ 4:04pm 
Originally posted by Exvalcore:
When wrapping a exe file with steam drm this virus was detected from within the new build.
If there is any information on this I like you to post about it, I find this very strange for sure.
If you're developing for Steam, why not make use of the Steamworks Development group where you'd probably get a better group of users experienced with what you're doing.
https://steamcommunity.com/groups/steamworks
nullable Nov 4, 2021 @ 4:38pm 
Originally posted by Satoru:
Originally posted by Snakub Plissken:

False positives aren't that strange.

tbh for MS Defender its actually quite strange to get a false positive.

I mostly recommend it because it generates the least amount of false positives imho compared to other consumer level stuff. Most consumer AV is so desperate to justify its own existence it will alert you for every possible nonsensical thing imaginable. MS Defender actually has a good threshold of user notification (which is kinda funny given how UAC used to be so utterly annoying)

Well one of my favorite developer quotes is, "Saying something almost never happens is just another way to say, 'it happens'".

An individual might not expect it or be surprised by a false positive. But they still occur regardless of user expectation. Sure, do your due diligence. Better safe than sorry and all that jazz. But at least keep the option on the table to rule out before kicking up too much fuss.
Showing 1-11 of 11 comments
Per page: 1530 50

Date Posted: Nov 4, 2021 @ 7:52am
Posts: 11