Home
Forum
Rules
Search
Login
Register
November 21, 2024, 08:16:06 pm
Welcome,
Guest
. Please
login
or
register
.
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News:
Join Soldat's community on Discord!
You can follow and get involved in the developing process at the development related channels, as well as play arranged competitive matches at the
#gather
channel.
Official Soldat Forums
Soldat Talk
General Discussions
(Moderators:
xurich
,
SDFilm
,
SadistAtHeart
,
Bonecrusher
,
Furai
)
alert on soldat dl page & vir
« previous
next »
Pages: [
1
]
Author
Topic: alert on soldat dl page & vir (Read 1915 times)
0 Members and 1 Guest are viewing this topic.
mrhx
Major(1)
Posts: 3
alert on soldat dl page & vir
«
on:
March 10, 2015, 04:42:08 pm »
http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http%3A%2F%2Fsoldat.pl%2Fen%2Fdownload%2Fsoldatserver2.7.8_1.6.8.zip&client=googlechrome&hl=en
So I checked the
soldatserver2.7.8_1.6.8.zip
and Avira found trojan. Virustotal 6/57 -
https://www.virustotal.com/pl/file/ade8dcf6e12aac6daae22aed9120d89f7e4c4e6c4363147bcdbd997c1d29ed4a/analysis/1426023042/
Maybe false positive but
soldatserver2.7.5_1.6.5.zip
0/57 on virustotal.
Logged
Shoozza
Retired Soldat Developer
Veteran
Posts: 1632
Soldat's Babysitter
Re: alert on soldat dl page & vir
«
Reply #1 on:
March 11, 2015, 02:04:53 am »
Thanks, we were notified by a user about download warnings a few days ago but didn't know why they happened.
I scanned the executable files in the zip file:
soldatserver_legacy.exe 15 / 57
soldatserver_osx 0 / 54
soldatserver 0 / 54
soldatserver.exe 1 / 55
(WS.Reputation.1 20141120)
soldatserver_legacy 0 / 54
The only file that might be problematic is soldatserver_legacy.exe.
To be sure I suggest to only use the non legacy version for now.
More scans here:
soldatserver2.7.7_1.6.7.zip 3 / 55
(1 / 48 before rescan - only Avira detected someting 9 months ago)
soldatserver2.7.6_1.6.6.zip 0 / 57
soldatserver2.7.5_1.6.5.zip 0 / 57
My assumption is that the "scriptcore plugin/extension system" (loading of dlls in non safe mode) is falsely detected as a Trojan.
I submitted the soldatserver_legacy.exe to Avira for review, let's see how that works out.
Apparently the detection was a false positive:
https://analysis.avira.com/en/status?uniqueid=dcSsNJ5Tv8vFU8Ry6LjSwOXRY13LcOFx&incidentid=1839382
For future reference:
http://www.techsupportalert.com/content/how-report-malware-or-false-positives-multiple-antivirus-vendors.htm
«
Last Edit: March 13, 2015, 08:39:23 am by Shoozza
»
Logged
Rules
Tools:
ARSSE
-
SARS
-
SRB
-
chatMod
Name
Soldier
Posts: 126
Re: alert on soldat dl page & vir
«
Reply #2 on:
March 15, 2015, 11:03:35 am »
Did we have enough yet?
Logged
Pages: [
1
]
« previous
next »
Official Soldat Forums
Soldat Talk
General Discussions
(Moderators:
xurich
,
SDFilm
,
SadistAtHeart
,
Bonecrusher
,
Furai
)
alert on soldat dl page & vir