Virus found.

Post Reply
User avatar
P'Ter
Posts: 6
Joined: Mon 12. Sep 2011, 13:15

Virus found.

Post by P'Ter »

HI all,
This morning My virus scanner (F-Secure) reports:
Virus detected, Heur.Zygug.3 in UruLauncher.exe ...\Urulauncher.exe Quarantined!

Could you Please check what is going on here?

Cheers,
P'Ter

User avatar
Scarchu
Posts: 152
Joined: Mon 22. Aug 2011, 18:58
TOC-MOUL Name: Scarchu
TOC-MOUL KI#: 3349
TOC-TPOTS Name: Scarchu
TOC-TPOTS KI#: 36096
MOULa Name: Scarchu_BG
MOULa KI#: 11995668
Location: Bulgaria

Re: Virus found.

Post by Scarchu »

P'ter, this file is local for your computer, so the problem is in your machine not in the server!
Image

User avatar
P'Ter
Posts: 6
Joined: Mon 12. Sep 2011, 13:15

Re: Virus found.

Post by P'Ter »

Hi Scarchu,
Scarchu wrote:P'ter, this file is local for your computer, so the problem is in your machine not in the server!
I know that, this was not the question.
This executable has been modified and recompiled by the TOC team. My question was why does my virus scanner suddenly flip over it? (and only this file)
Is the team sure that there was nothing wrong on the development machine during this compilation-linking step that introduces a virus-like thing in this executable
before it was transfered to my machine to patch/launch the app.
I just want to ring the bell so the developer team can check.

Cheers,
P'Ter

User avatar
Jogi
Posts: 64
Joined: Tue 28. Feb 2012, 16:49
TOC-MOUL Name: Jogi
TOC-MOUL KI#: 103367
TOC-TPOTS Name: Jogi
TOC-TPOTS KI#: 36461
MOULa Name: Jogi.de
MOULa KI#: 16673208
DI Name: Jogi
DI KI#: 142405
Gehn Shard Name: Jogi
Gehn Shard KI#: 32678
Location: Germany BW

Re: Virus found.

Post by Jogi »

P'Ter wrote:
This morning My virus scanner (F-Secure) reports:[...]

[...]

[...] before it was transfered to my machine to patch/launch the app.
Did that mean you did the TOC update this morning?
Otherwise you should try a new copy of your UruLauncher.exe first and run a new patcher update.
There is nothing you can loose and it is only three steps. Just to be sure.
P'Ter wrote: I just want to ring the bell so the developer team can check.

Cheers,
P'Ter
My scanner (ClamWin Free Antivirus) didn't find anything.
Image

User avatar
Mystler
Development Manager
Posts: 651
Joined: Mon 11. Jul 2011, 16:14
Gender: Male
TOC-MOUL Name: Mystler
TOC-MOUL KI#: 346
MOULa Name: Mystler
MOULa KI#: 150272
Location: Germany
Contact:

Re: Virus found.

Post by Mystler »

I can assure you that there is no malicious code in the client nor in it's compiling stuff. You're the first one having an Antivirus tool detecting the client... What Virus software do you use?

User avatar
RockArdemar
Posts: 184
Joined: Tue 4. Oct 2011, 09:04
TOC-MOUL KI#: 42627
MOULa KI#: 34143
DI KI#: 235532
Gehn Shard KI#: 17785
Minkata KI#: 70951
Location: Barcelona, Catalonia

Re: Virus found.

Post by RockArdemar »

Thank you P'ter for communicating the incidence :)
It is always good to double-check and be sure.

According to my Panda though, everything seems OK here:

Image
KI 42627 - FB | T

User avatar
P'Ter
Posts: 6
Joined: Mon 12. Sep 2011, 13:15

Re: Virus found.

Post by P'Ter »

Hi All,

After much testing I got it working now.
AntiVirus is F-Secure. The Heuristic algo's from this scanner always detect this "virus" ;)
Had to disable the antivirus. Reinstall the hole thing and reapply the patch etc...
As soon as the file came down the pipe the bells where ringing here and the file got quarantined.
So I had to do the hole thing again but first I excluded this item from the scanner list so it stays there and runs.
I tested the file also on two other scanners and they did not find anything either.
Must have been and scanning soft update in the background I was unaware of.
Still strange that it only detects the new patcher not the original one and also not the one in URU-live.
Anyway we are back online now :)

Although frequently crashing in the COD...

Cheers,
P'Ter

User avatar
Max
Posts: 32
Joined: Mon 26. Sep 2011, 13:36
TOC-MOUL Name: Max
TOC-MOUL KI#: 33481

Re: Virus found.

Post by Max »

P'ter .. I had a very similar problem with my Norton. Every change to the patcher or the .exe-file
was *detected* as Malicious! With Norton's peculiar *Logic* every file it Didn't recognice MUST be
Malicios. Thus get Deleted and Quaranteed! I lost count how many times I had to Override Norton.
Shut it off .. And AFAIK, download totally Virus-Free stuff.

It's good to be cautious and well aware of what You're downloading. But if a Anti-Virus program can't see
the differance of a perfecly sound program code and Rotten Apples, then it's works on wrong parameters.

As You migt guess .. I'm Not using Norton any more and never will ..

/ Max /

User avatar
Opa
Posts: 280
Joined: Mon 11. Jul 2011, 19:16

Re: Virus found.

Post by Opa »

Oh, I see someone found out that I added a Virus to our shard. <-------THIS IS A JOKE :lol:

No really, we have not added any malicious software to our game.

Opa

User avatar
Jogi
Posts: 64
Joined: Tue 28. Feb 2012, 16:49
TOC-MOUL Name: Jogi
TOC-MOUL KI#: 103367
TOC-TPOTS Name: Jogi
TOC-TPOTS KI#: 36461
MOULa Name: Jogi.de
MOULa KI#: 16673208
DI Name: Jogi
DI KI#: 142405
Gehn Shard Name: Jogi
Gehn Shard KI#: 32678
Location: Germany BW

Re: Virus found.

Post by Jogi »

P'Ter wrote: [...]
As soon as the file came down the pipe the bells where ringing here and the file got quarantined.
[..]
That sounds as F-Secure is just monitoring whether an original file is modified or completely overwritten, among other things. That's not the worst thing to prevent from viruses. I know this from olden times of MS-DOS! And as you see, this principle is still used, and can lead to false alarms.
Image

Post Reply