Virus or false positive?

All topics about ZGameEditor goes here.

Moderator: Moderators

User avatar
Ats
Posts: 131
Joined: Fri Sep 28, 2012 10:05 am
Contact:

Virus or false positive?

Postby Ats » Thu Jul 19, 2018 7:54 am

I just discovered that each and every exe files generated by ZGameEditor gives a positive to a lot of anti-virus software.
Here's the scan for my last version of Omeganaut:
https://www.virustotal.com/#/file/2d659 ... /detection

My problem is that, because of the update I uploaded yesterday, my website was listed by Google as malicious and everything you could download on it is now blocked by Chrome... I already saw that in old example files on your forum. Do you know what can I do?

User avatar
VilleK
Site Admin
Posts: 1920
Joined: Mon Jan 15, 2007 4:50 pm
Location: Stockholm, Sweden
Contact:

Re: Virus or false positive?

Postby VilleK » Thu Jul 19, 2018 8:56 am

Hi, perhaps try a version that is not Upx compressed? Some AV-software give false positives on all compressed executables.

User avatar
Ats
Posts: 131
Joined: Fri Sep 28, 2012 10:05 am
Contact:

Re: Virus or false positive?

Postby Ats » Thu Jul 19, 2018 9:24 am

Here's the result for the uncompressed version: https://www.virustotal.com/#/file/17a13 ... /detection
It's a bit better :lol:

Somehow, I managed to produce a zip that is "virus" free: https://www.virustotal.com/#/url/b5e0e8 ... /detection
Don't know how or why. It seems very random...

Now I can only wait for googlebot to rescan my website and mark it as not malicious.

User avatar
Ats
Posts: 131
Joined: Fri Sep 28, 2012 10:05 am
Contact:

Re: Virus or false positive?

Postby Ats » Fri Jul 20, 2018 9:58 am

So after some research, it appears that all exe files made out of Delphi/Pascal always gives a false positive on anti-virus softwares that are scanning files heuristicaly. And once Google bots decides that a file hosted on your website is infected, it automatically prevents ALL downloads from your website in Chrome.

In order to repair that, you have to:


Google has received and processed your security review request. Google systems indicate that http://www.txori.com/ no longer contains links to harmful sites or downloads. The warnings visible to users are being removed from your site. This may take a few hours to happen.


YEAH!!!!!

User avatar
Ats
Posts: 131
Joined: Fri Sep 28, 2012 10:05 am
Contact:

Re: Virus or false positive?

Postby Ats » Thu Sep 27, 2018 11:56 am

I'm back again for some ZGE. But player.bin is missing from my folder. I don't remember why...
So I tried to download the current version of ZGE but it was instantly blocked by Windows Defender:

Trojan:Win32/Zpevdo.A
Alert level: Severe
Status: Active

Recommended action: Remove the threat now.

Category: Trojan
Details: This program is dangerous and executes commands from an attacker.
Affected items:
containerfile: C:\Users\Ats\Downloads\ZGameEditor_beta.zip
file: C:\Users\Ats\Downloads\ZGameEditor_beta.zip->ZGameEditor/Player.bin
webfile: C:\Users\Ats\Downloads\ZGameEditor_beta.zip|http://www.zgameeditor.org/files/ZGameEditor_beta.zip|pid:38020,ProcessStart:131825217330341242


That's new... :(

User avatar
Kjell
Posts: 1648
Joined: Sat Feb 23, 2008 11:15 pm

Re: Virus or false positive?

Postby Kjell » Thu Sep 27, 2018 12:23 pm

Hi Ats,

I just updated my Windows Defender definitions and had it scan my ZGameEditor folder ... got the same false-positive :(

K

User avatar
VilleK
Site Admin
Posts: 1920
Joined: Mon Jan 15, 2007 4:50 pm
Location: Stockholm, Sweden
Contact:

Re: Virus or false positive?

Postby VilleK » Thu Sep 27, 2018 1:27 pm

Yep, same here. Annoying. Anyone know how to tell Defender that this is a false positive? It is not even compressed.

User avatar
VilleK
Site Admin
Posts: 1920
Joined: Mon Jan 15, 2007 4:50 pm
Location: Stockholm, Sweden
Contact:

Re: Virus or false positive?

Postby VilleK » Fri Sep 28, 2018 7:00 am

I submitted the file to Microsoft as a false positive. Btw, when I update the definitions today it does no longer seem to indicate that the file is malware so maybe it is already fixed?

User avatar
Ats
Posts: 131
Joined: Fri Sep 28, 2012 10:05 am
Contact:

Re: Virus or false positive?

Postby Ats » Fri Sep 28, 2018 10:32 pm

This seems to be working :D
Thanks


Return to “General discussion”

Who is online

Users browsing this forum: No registered users and 0 guests