Virus in install file?

If you need support, you can get help here!
Silaence
Guardian
 
Posts: 1
Joined: Mar 17, 2012 08:08

Postby Silaence » Mar 07, 2017 05:42

I ran Uthgard several years back and didn't have any issues, but recently I decided to get back into it and can't get it installed. My anti-virus has blocked the download link for the Uthgard client. Even when I added the download link as an exception, and get the uthgard.setup.exe file downloaded, I can't run it. My Avast Antivirus swears up and down that it found a virus with this file. It shows up as Malware when I run a scan on the file directly.

Has anyone else run into this issue?

User avatar
Blue
Developer
Developer
 
Posts: 15813
Joined: Apr 22, 2005 00:00

Postby Blue » Mar 07, 2017 12:37

Its a false positive. I can only guess its because it a) patches a dll inmemory and b) downloads executable files from internet.

See the report https://virustotal.com/en/file/07208ef0 ... 488882931/

Not sure what we can do about it, but its no virus ofcourse.
It's done when it's done. Thanks for your patience.
Every bug gets fixed. Sooner or later.

"It is an inescapable law of nature that the amount of satisfaction one gains from achieving something
is related to how hard it is and easy things can only elicit a fleeting superficial sort of pleasure."


Blue says, "you used macro tools or macro keyboard"
Pala says, "i am disabled. and i have a mechanic left hand that can be programed. its hard to play woith one hand"

[Appeal] Bxxxxxxxx: "why is RA first aid cann man i stealth use and not unstealth cann man ra if man use unstealth ?????????"
BannedUser: "i was not using automate game action my hand was fall on keyboard during i was sleep .... i was completly fall on keyboard ..."

NiDo
Guardian
 
Posts: 2
Joined: Mar 27, 2017 22:37

Postby NiDo » Mar 27, 2017 22:54

Hi!

I wanted to install yesterday, but my virus scanner deleted the file directly after it was saved to disc. So I tested with virustotal and there 15% of scanners detected something. I do know about possible false positives, but some of the major scanners reported behaviour like ransom-ware. This discouraged me for now.

If you are sure, that the executable is not compromised, please add some details to the download page explaining these issues.

I would also like to suggest adding some kind of signature to the account page, showing the hash for the uthgard.setup.exe independently of the downloaded file. Those should be computed on the build server and transferred with any new versions of the exe.
Btw my download had a sha256sum of 07208ef0adde92988da39f6fe9fcdc9d634fbef8b1404791216b506b7c54b482.

Thanks
NiDo

NiDo
Guardian
 
Posts: 2
Joined: Mar 27, 2017 22:37

Postby NiDo » Mar 29, 2017 23:13

Hi again!

Replying to myself, to indicate that I am not stuck and that I was pointed to a nice solution (thanks M) for the virus problem.

It seems, that the setup was created using the NullSoftInstaller or NSIS. These executables can be extracted by 7zip (my favorite packing/unpacking tool). So when you manage to get the file past your scanner, you open it in 7zip. There you only need the uthgard.exe in the root directory. Checking this file showed no infections at all, virustotal found no problems using 62 scanners. I placed the file in my DAoC directory and went to the website. Before pressing the "Play" button on the top right use the "+" button next to it so set your DAoC installation directory (and for now do not fiddle with the other settings :-P). After saving the settings and pressing "play", around 300MB of patch data are downloaded and extracted in multiple steps.

I still would prefer, if some comments are included in the getting started section on the possible false positives and what part of the regular setup behaviour makes the scanners issue the positives. And please, include a signature, so everybody can verify, that the exe has not been tampered with.

Thanks
NiDo

OlivsGirip
Guardian
 
Posts: 1
Joined: Jun 07, 2021 15:37

Postby OlivsGirip » Aug 03, 2021 15:49

I also tried to install it a couple of days ago, but my anti-virus just refuses to allow it. It keeps on saying that this file contains viruses. Are you sure that it is a false positive? I do not want to get any viruses on my computer as I am also using it for many other purposes. It is my work computer, and I have a lot of crucial files on it. So I do not want to send any damaged files to my customers. Though, I am using secure file sharing with my clients. However, I do not want to risk it.
Last edited by OlivsGirip on Aug 06, 2021 15:54, edited 1 time in total.

User avatar
Abydos
Game Master
Game Master
 
Posts: 6836
Joined: Jan 22, 2011 21:14

Postby Abydos » Aug 03, 2021 21:04

Yes, it is a false positive.


Return to Support

Who is online

Users browsing this forum: No registered users and 8 guests

cron

Friday, 19. April 2024

Artwork and screen shots Copyright © 2001-2004 Mythic Entertainment, Inc. All rights reserved. Used with permission of Mythic Entertainment. Mythic Entertainment, the Mythic Entertainment logo, "Dark Age of Camelot," "Shrouded Isles," "Foundations," "New Frontiers," "Trials of Atlantis," "Catacombs," "Darkness Rising," the Dark Age of Camelot and subsequent logos, and the stylized Celtic knot are trademarks of Mythic Entertainment, Inc.

Valid XHTML & CSS | Original Design by: LernVid.com | Modified by Uthgard Staff