View previous topic :: View next topic |
Author |
Message |
Moogle1 Scourge of the Seas Halloween 2006 Creativity Winner
Joined: 15 Jul 2004 Posts: 3377 Location: Seattle, WA
|
Posted: Sat Nov 01, 2008 12:30 pm Post subject: ATTN: Virus in Blob's Tale |
|
|
See Calehay's posts in http://www.slimesalad.com/forum/viewtopic.php?p=7988, or just know that you should not download this game. Admins, please remove it ASAP. If you've already downloaded the game, you should run a thorough virus check. _________________
|
|
Back to top |
|
|
Newbie_Power
Joined: 04 Sep 2006 Posts: 1762
|
Posted: Sat Nov 01, 2008 12:34 pm Post subject: |
|
|
Gosh dangit.
Better check my computer... _________________
TheGiz> Am I the only one who likes to imagine that Elijah Wood's character in Back to the Future 2, the kid at the Wild Gunman machine in the Cafe 80's, is some future descendant of the AVGN? |
|
Back to top |
|
|
Calehay ...yeah. Class B Minstrel
Joined: 07 Jul 2004 Posts: 549
|
Posted: Sat Nov 01, 2008 12:37 pm Post subject: |
|
|
To clarify, blobtale.exe (The namesake of the game) is the virus. The .msi also installs Blob Story.exe and Blob Story.rpg, which is the game.exe and an actual .rpg file. Those two are safe to use, but as the name of the game is supposed to be "Blob Tale," and the name sake of the virus file is such, one can only assume what KnightAdmin's intentions were. _________________ Calehay |
|
Back to top |
|
|
Inferior Minion Metric Ruler
Joined: 03 Jan 2003 Posts: 741 Location: Santa Barbara, CA
|
Posted: Sat Nov 01, 2008 1:37 pm Post subject: |
|
|
Calehay wrote: | To clarify, blobtale.exe (The namesake of the game) is the virus. The .msi also installs Blob Story.exe and Blob Story.rpg, which is the game.exe and an actual .rpg file. Those two are safe to use, but as the name of the game is supposed to be "Blob Tale," and the name sake of the virus file is such, one can only assume what KnightAdmin's intentions were. |
Can I ask what virus scanner you used? I've moved the file so you cannot download it from the gamelist, but had some inconsistency when verifying the presence of a virus.
ClamAV identified 922/922.zip: Trojan.Delf-624 FOUND, however neither Norton nor McAfee (latest versions, fully updated) identified the file as a threat. I have a feeling it is a false positive as a result of the MSI creation program used by KnightAdmin. I highly doubt KnightAdmin was maliciously attempting to distribute a virus.
In any case, I'll look into having ClamAV scan every file uploaded prior to adding it to the game list. Thanks for the warning.
~IM _________________
|
|
Back to top |
|
|
Calehay ...yeah. Class B Minstrel
Joined: 07 Jul 2004 Posts: 549
|
Posted: Sat Nov 01, 2008 1:44 pm Post subject: |
|
|
Inferior Minion wrote: | Calehay wrote: | To clarify, blobtale.exe (The namesake of the game) is the virus. The .msi also installs Blob Story.exe and Blob Story.rpg, which is the game.exe and an actual .rpg file. Those two are safe to use, but as the name of the game is supposed to be "Blob Tale," and the name sake of the virus file is such, one can only assume what KnightAdmin's intentions were. |
Can I ask what virus scanner you used? I've moved the file so you cannot download it from the gamelist, but had some inconsistency when verifying the presence of a virus. |
I used Avira Antivir, Free Version.
http://www.free-av.com/ _________________ Calehay |
|
Back to top |
|
|
Inferior Minion Metric Ruler
Joined: 03 Jan 2003 Posts: 741 Location: Santa Barbara, CA
|
Posted: Sat Nov 01, 2008 1:48 pm Post subject: |
|
|
Calehay wrote: | Inferior Minion wrote: | Calehay wrote: | To clarify, blobtale.exe (The namesake of the game) is the virus. The .msi also installs Blob Story.exe and Blob Story.rpg, which is the game.exe and an actual .rpg file. Those two are safe to use, but as the name of the game is supposed to be "Blob Tale," and the name sake of the virus file is such, one can only assume what KnightAdmin's intentions were. |
Can I ask what virus scanner you used? I've moved the file so you cannot download it from the gamelist, but had some inconsistency when verifying the presence of a virus. |
I used Avira Antivir, Free Version.
http://www.free-av.com/ |
OK, I actually ran the MSI and both Norton and McAffee identified the same virus. I guess neither program is as smart as ClamAV when it comes to scanning the MSI contents prior to extraction.
Given that I have the fully extracted contents minus the virus, I could create a proper .zip file for download. As Calehay pointed out, though, the actual contents of this game are quite sparse.
Thanks again,
~IM
Edit: Should have read the Slime Salad thread prior to my initial post. After looking at the actual contents of the game, I agree with Calehay's assessment regarding the creator's intention. _________________
|
|
Back to top |
|
|
Gizmog1 Don't Lurk In The Bushes!
Joined: 05 Mar 2003 Posts: 2257 Location: Lurking In The Bushes!
|
Posted: Sat Nov 01, 2008 9:31 pm Post subject: |
|
|
I mentioned in my thread that he was in IRC. He appears as Anonymous at the end of this log, and I don't know if there's any information that can be gleaned from that. http://castleparadox.com/logs/castleparadox/2008-09-08.log
(Warning: Typical IRC antics involved. It's the Wild West in there. Look at your own risk)
In hindsight, it seems like a pretty obvious trap. Do I need to install an antivirus program, or do you think Spybot Search and Destroy would take care of it? |
|
Back to top |
|
|
Bob the Hamster OHRRPGCE Developer
Joined: 22 Feb 2003 Posts: 2526 Location: Hamster Republic (Southern California Enclave)
|
Posted: Sat Nov 01, 2008 9:49 pm Post subject: |
|
|
I have removed it from the monthly mirror. I'm also adding automated scanning to the mirror script.
I do notice that ClamAV identifies "The Crystal Globe" as containing Trojan.Agent-55637 ... but that zip file contains only a text file and an rpg, no executable at all, so I kinda suspect a false positive. |
|
Back to top |
|
|
Shadowiii It's been real.
Joined: 14 Feb 2003 Posts: 2460
|
Posted: Sun Nov 02, 2008 11:00 pm Post subject: |
|
|
If it does, I have no knowledge of it.
Maybe that virus program is interpreting .rpg files as a virus of some sort? That would be something worth checking out. _________________ But enough talk, have at you! |
|
Back to top |
|
|
Gizmog1 Don't Lurk In The Bushes!
Joined: 05 Mar 2003 Posts: 2257 Location: Lurking In The Bushes!
|
Posted: Sun Nov 02, 2008 11:23 pm Post subject: |
|
|
Wasn't there an issue a few years ago with Sword of Jade rpg files registering a false positive? |
|
Back to top |
|
|
Moogle1 Scourge of the Seas Halloween 2006 Creativity Winner
Joined: 15 Jul 2004 Posts: 3377 Location: Seattle, WA
|
Posted: Sun Nov 02, 2008 11:43 pm Post subject: |
|
|
No, there was an issue with Sword of Jade registering a correct positive. _________________
|
|
Back to top |
|
|
Bob the Hamster OHRRPGCE Developer
Joined: 22 Feb 2003 Posts: 2526 Location: Hamster Republic (Southern California Enclave)
|
Posted: Mon Nov 03, 2008 8:46 am Post subject: |
|
|
I re-scanned the Crystal Globe again today on the same machine, and it came up clean. I am pretty sure that it was a false positive caused by a bad over-general signature, which was removed since then. |
|
Back to top |
|
|
FyreWulff Still Jaded
Joined: 02 Apr 2005 Posts: 406 Location: The Internet
|
Posted: Mon Nov 03, 2008 10:46 am Post subject: |
|
|
Moogle1 wrote: | No, there was an issue with Sword of Jade registering a correct positive. |
A virus that didn't exist in the wild until 2 months after we released the game in fact |
|
Back to top |
|
|
LeRoy_Leo Project manager Class S Minstrel
Joined: 24 Sep 2003 Posts: 2683 Location: The dead-center of your brain!
|
Posted: Tue Nov 04, 2008 7:07 pm Post subject: |
|
|
What a clever child. Unfortunate that everyone here is so computer savvy. _________________ Planning Project Blood Summons, an MMORPG which will incinerate all of the others with it's sheer brilliance...
---msw188 ---
"Seriously James, you keep rolling out the awesome like gingerbread men on a horror-movie assembly line. " |
|
Back to top |
|
|
Bob the Hamster OHRRPGCE Developer
Joined: 22 Feb 2003 Posts: 2526 Location: Hamster Republic (Southern California Enclave)
|
Posted: Tue Dec 16, 2008 3:00 pm Post subject: |
|
|
My antivirus scanner is claiming that the zip file for Crescent Dream (which contains an exe installer) is infected by Trojan.Banker-151
I have a feeling this is a false positive, but I would appreciate it if somebody else could check with another virus scanner. |
|
Back to top |
|
|
|