Epic Launcher update contains virus
Just updated Epic launcher. Avast tells me one of the files is infected. Could be a false positive but ....
Epic
Sigh
< >
Affichage des commentaires 1 à 15 sur 44
{ИЯm} Keith a écrit :
Epic Launcher update contains virus

Just updated Epic launcher. Avast tells me one of the files is infected. Could be a false positive but ....
Epic
Sigh

It is a false positive.

:qr:
Dernière modification de cSg|mc-Hotsauce; 25 oct. 2020 à 9h37
Avast is not really the best AV these days. Sometimes Windows Defender can give false positives on files too. Like that Scrap Garden game.
Mona Lizzard a écrit :
Avast is not really the best AV these days. Sometimes Windows Defender can give false positives on files too. Like that Scrap Garden game.

Yeah Avast has really gone down hill. I used to recommend them to my customers. I use bitdefender at work, it's fairly solid and doesn't false positive. Avira's G.U.I. makes me want to eat a bullet. I seriously considered Commodo but I found it popped a lot up and I really prefer my virus scan to have a solid retroactive scan.
I mostly just use Avast because it doesn't bother me much.
This is probably my last windows machine anyway, going forward I'll game on linux with some sort of boxed or emulated windows for my old games.
Kasper Skywalker a écrit :
It is known the third party antivirus softwares would always screw things up when you try to play games, problem is they dont really work when things are screwed by actual virus, so I would rather not put any third party antivirus softwares on gaming PCs.
So what about Norton? I guess Bitdefender would be better.
Mona Lizzard a écrit :
Kasper Skywalker a écrit :
It is known the third party antivirus softwares would always screw things up when you try to play games, problem is they dont really work when things are screwed by actual virus, so I would rather not put any third party antivirus softwares on gaming PCs.
So what about Norton? I guess Bitdefender would be better.

I'm actually not a fan of Norton or Mcafee.
I used to use Norton but they added a lot of other apps into their main virus scanner window and it made the program really slow to open. (not what you want in an emergency)
From our testing Mcafee doesn't have good results. (misses viruses)

I don't know about third party being the issue. While microsoft did make Microsoft Anti-Virus (MSAV), they really weren't all that responsible for the virus protection for decades. Up until Windows 10, windows defender wasn't / isn't even a true virus scanner. They did make Microsoft security essentials but still.

https://www.av-test.org/en/antivirus/home-windows/
Bit Defender is listed at 6-6-5.5 while Norton is 6-6-6 but Bitdefender has one of the highest detection rates. There is also resource use to consider.
Dernière modification de {ИЯm} Keith; 25 oct. 2020 à 10h55
If it's a LokiBot Trojan, then that's valid and real!

The LokiBot campaign is attempting to infect users by impersonating the Epic game launcher, it's a fake download.

The LokiBot Trojan Malware first emerged in 2015. In 2019, impersonated as WHO faking information in regards to COVID-19 in a spear phishing email. However in Feb 2020, it's come out again, masked at the Epic Client launcher as a disguise, while trying to avoid detection by heavily obfuscating it's code. The malware attempts to steal usernames, passwords, bank details, and the contents of cryptocurrency wallets.

Ensure the launcher is from the official website.

If it's from the valid website, then upload it as a false positive to your anti-virus to confirm and remove from the blacklist.

Avast False Positive File Upload:
https://www.avast.com/en-us/false-positive-file-form.php

---

Also note: If you have a dated Nvidia GeForce Experience or even the Steam Client, you should update those as there's an exploit in older version of their Web Helper, which could allow remote code execution or DoS (Denial-of-Service) attacks.

It's not just Epic Games being targeted, but Gamers in general.

In other news, TikTok has less pivacy issues and security concerns. That was just Xenophobia.
Dernière modification de Azza ☠; 25 oct. 2020 à 11h35
easy to verify

Epic have 53 Files Total of 31,308 B EpicGamesLauncher.exe 3,483,536B
if your Epic is specific to this it's not invested or Maleware

Virus scanners are so useless they like a broken sock.
Abisha a écrit :
easy to verify

Epic have 53 Files Total of 31,308 B EpicGamesLauncher.exe 3,483,536B
if your Epic is specific to this it's not invested or Maleware

Virus scanners are so useless they like a broken sock.

Virus scanners are critical, specially during a pandemic and over in USA at the moment which are being hammered by malware campaigns, because they just ignore it.

File: EpicGamesLauncher.exe
Size: 2.65 MB
Date: 2020-10-25 18:37:59 UTC
Date signed: 08:26 PM 10/22/2020 (valid digital certificate)

https://www.virustotal.com/gui/file-analysis/NjE3OTE0MDJkZDU1OGU5YTUyOGEyMGE2OTU1OTM1ZGY6MTYwMzY1MTA3OQ==/detection

Detection: 0 out of 70 virus databases

Either your anti-virus has out-of-date definitions (you need to update it) or it's not that file?
Dernière modification de Azza ☠; 25 oct. 2020 à 11h42
Azza ☠ a écrit :
Abisha a écrit :
easy to verify

Epic have 53 Files Total of 31,308 B EpicGamesLauncher.exe 3,483,536B
if your Epic is specific to this it's not invested or Maleware

Virus scanners are so useless they like a broken sock.

Virus scanners are critical, specially during a pandemic and over in USA at the moment which are being hammered by malware campaigns, because they just ignore it.

File: EpicGamesLauncher.exe
Size: 2.65 MB
Date: 2020-10-25 18:37:59 UTC

https://www.virustotal.com/gui/file-analysis/NjE3OTE0MDJkZDU1OGU5YTUyOGEyMGE2OTU1OTM1ZGY6MTYwMzY1MTA3OQ==/detection

Detection: 0 out of 70 virus databases

Either your anti-virus has out-of-date definitions or it's not that file?

you missing data from you EpicGamesLauncher.exe are you using the 64 Bit version?
Abisha a écrit :
Azza ☠ a écrit :

Virus scanners are critical, specially during a pandemic and over in USA at the moment which are being hammered by malware campaigns, because they just ignore it.

File: EpicGamesLauncher.exe
Size: 2.65 MB
Date: 2020-10-25 18:37:59 UTC

https://www.virustotal.com/gui/file-analysis/NjE3OTE0MDJkZDU1OGU5YTUyOGEyMGE2OTU1OTM1ZGY6MTYwMzY1MTA3OQ==/detection

Detection: 0 out of 70 virus databases

Either your anti-virus has out-of-date definitions or it's not that file?

you missing data from you EpicGamesLauncher.exe are you using the 64 Bit version?

As for the installation file itself:
https://launcher-public-service-prod06.ol.epicgames.com/launcher/api/installer/download/EpicGamesLauncherInstaller.msi

https://www.virustotal.com/gui/url/a45326e8ff379bd4cc6e8be43456114302ef8aa24ea452eb67bd7b0ef261e11f/detection

Detection: 0 out of 80 virus databases

And yes, I'm using 64-Bit.
Dernière modification de Azza ☠; 25 oct. 2020 à 11h45
Azza ☠ a écrit :
Abisha a écrit :

you missing data from you EpicGamesLauncher.exe are you using the 64 Bit version?

As for the installation file itself:
https://launcher-public-service-prod06.ol.epicgames.com/launcher/api/installer/download/EpicGamesLauncherInstaller.msi

https://www.virustotal.com/gui/url/a45326e8ff379bd4cc6e8be43456114302ef8aa24ea452eb67bd7b0ef261e11f/detection

Detection: 0 out of 80 virus databases

dude do you think virus scanners knows the code of any program exist? it just check the data size to see if it's tempered with the same thing i do.

your 32 Bit version is to small it's 2,779,536

the real question would be wtf do you use x32 still it's been outdated for over 20 years now.
Abisha a écrit :
Azza ☠ a écrit :

As for the installation file itself:
https://launcher-public-service-prod06.ol.epicgames.com/launcher/api/installer/download/EpicGamesLauncherInstaller.msi

https://www.virustotal.com/gui/url/a45326e8ff379bd4cc6e8be43456114302ef8aa24ea452eb67bd7b0ef261e11f/detection

Detection: 0 out of 80 virus databases

dude do you think virus scanners knows the code of any program exist? it just check the data size to see if it's tempered with the same thing i do.

your 32 Bit version is to small it's 2,779,536

the real question would be wtf do you use x32 still it's been outdated for over 20 years now.

Oh you are talking about:

File: EpicGamesLauncher.exe
Size: 31.04 MB (32546704 bytes)
Date signed: 08:26 PM 10/22/2020

https://www.virustotal.com/gui/file/98124a180f000ee406ae7f4eaaeb73339a1c3e8378e0decd35f37ef940d4f6bb/detection

Detection: 0 out of 62 virus databases

It's the same deal, but yeah you are right, I was checking the 32-bit EXE in the first post. My bad, I do use the 64-bit, but grabbed the wrong EXE by mistake.

The icon shortcut on the desktop is:
"C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe"

Yet, the 64-bit version is:
"C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe"

I have scanned over the entire lot however.

Duration: 13 seconds
Objects scanned: 8,123
No threats detected
Dernière modification de Azza ☠; 25 oct. 2020 à 11h55
Azza ☠ a écrit :
Abisha a écrit :

dude do you think virus scanners knows the code of any program exist? it just check the data size to see if it's tempered with the same thing i do.

your 32 Bit version is to small it's 2,779,536

the real question would be wtf do you use x32 still it's been outdated for over 20 years now.

Oh you are talking about:

File: EpicGamesLauncher.exe
Size: 31.04 MB (32546704 bytes)
Date signed: 08:26 PM 10/22/2020

https://www.virustotal.com/gui/file/98124a180f000ee406ae7f4eaaeb73339a1c3e8378e0decd35f37ef940d4f6bb/detection

Detection: 0 out of 62 virus databases

It's the same deal, but yeah you are right, I was checking the 32-bit EXE in the first post. My bad, I do use the 64-bit, but grabbed the wrong EXE by mistake.

we don't match up that's bit weird need a other data set to know which one is correct.
Abisha a écrit :
Azza ☠ a écrit :

Oh you are talking about:

File: EpicGamesLauncher.exe
Size: 31.04 MB (32546704 bytes)
Date signed: 08:26 PM 10/22/2020

https://www.virustotal.com/gui/file/98124a180f000ee406ae7f4eaaeb73339a1c3e8378e0decd35f37ef940d4f6bb/detection

Detection: 0 out of 62 virus databases

It's the same deal, but yeah you are right, I was checking the 32-bit EXE in the first post. My bad, I do use the 64-bit, but grabbed the wrong EXE by mistake.

we don't match up that's bit weird need a other data set to know which one is correct.

Right-click the EXE and select Properties.

There will be a digital signature and counter signature (which gets signed off by an anti-virus company, in this case Symantec which works with Norton).

Epic Games Inc.
‎Friday, ‎October ‎23, ‎2020 09:26:39
Symantec Time Stamping Services Signer - G4
Valid from: 2018-02-18 to 2021-03-02

If you are using the 32-bit version:

Size: 2.65 MB (would be 2,779,536 bytes)
Size on disk: 2.65 MB (would be 2,781,184 bytes)

64-bit version:

Size: 31.0 MB (would be 32,546,704 bytes)
Size on disk: 31.0 MB (would be 32,546,816 bytes)

The anti-virus databases would check all of that for you as well, including the file hash:

MD5 c143c349954c24e5ac75555eda3dcb14
SHA-1 edcb99dd548ad40eed9f5332751204408cef7b7e
SHA-256 98124a180f000ee406ae7f4eaaeb73339a1c3e8378e0decd35f37ef940d4f6bb
Vhash 03708666655d15656555532z10911zd47zd045z92z6e031z22c294z2
Authentihash 6fc070684b879997c994526ceac8e7c7bb1b5ca46e91aabb4136fc05a36fc3f4
Imphash 478fc0958e681cab38c1223b5a3fec97
Rich PE header hash a3b0091c8e0cb3d140d657f659352b59
SSDEEP 393216:DJXxQkdOgupriBGBNIeIy0frLUeavERG64XEisedNS0G6SWctDE+1wermOpEVyX9:DJCIPRedwNW+j9
TLSH T15C67495273F800D5E0BAC2B8DA3A9416EBB0389A4734A7DB0691C5575FB7BE099FC710
File type Win32 EXE
Magic PE32+ executable for MS Windows (GUI) Mono/.Net assembly
File size 31.04 MB (32546704 bytes)

As well as the digital signature, behaviours with other files and their relationships, etc.
Dernière modification de Azza ☠; 25 oct. 2020 à 12h15
Meanwhile, I am trying to figure out a way to register Epic Games launcher as malware.
< >
Affichage des commentaires 1 à 15 sur 44
Par page : 1530 50

Posté le 25 oct. 2020 à 9h36
Messages : 45