Castle Paradox Forum Index Castle Paradox

 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 Gamelist   Review List   Song List   All Journals   Site Stats   Search Gamelist   IRC Chat Room

ATTN: Virus in Blob's Tale
Goto page 1, 2  Next
 
Post new topic   Reply to topic    Castle Paradox Forum Index -> The Soapbox
View previous topic :: View next topic  
Author Message
Moogle1
Scourge of the Seas
Halloween 2006 Creativity Winner
Halloween 2006 Creativity Winner



Joined: 15 Jul 2004
Posts: 3377
Location: Seattle, WA

PostPosted: Sat Nov 01, 2008 12:30 pm    Post subject: ATTN: Virus in Blob's Tale Reply with quote

See Calehay's posts in http://www.slimesalad.com/forum/viewtopic.php?p=7988, or just know that you should not download this game. Admins, please remove it ASAP. If you've already downloaded the game, you should run a thorough virus check.
_________________
Back to top
View user's profile Send private message Visit poster's website AIM Address
Newbie_Power




Joined: 04 Sep 2006
Posts: 1762

PostPosted: Sat Nov 01, 2008 12:34 pm    Post subject: Reply with quote

Gosh dangit.

Better check my computer...
_________________

TheGiz> Am I the only one who likes to imagine that Elijah Wood's character in Back to the Future 2, the kid at the Wild Gunman machine in the Cafe 80's, is some future descendant of the AVGN?
Back to top
View user's profile Send private message
Calehay
...yeah.
Class B Minstrel



Joined: 07 Jul 2004
Posts: 549

PostPosted: Sat Nov 01, 2008 12:37 pm    Post subject: Reply with quote

To clarify, blobtale.exe (The namesake of the game) is the virus. The .msi also installs Blob Story.exe and Blob Story.rpg, which is the game.exe and an actual .rpg file. Those two are safe to use, but as the name of the game is supposed to be "Blob Tale," and the name sake of the virus file is such, one can only assume what KnightAdmin's intentions were.
_________________
Calehay
Back to top
View user's profile Send private message AIM Address
Inferior Minion
Metric Ruler



Joined: 03 Jan 2003
Posts: 741
Location: Santa Barbara, CA

PostPosted: Sat Nov 01, 2008 1:37 pm    Post subject: Reply with quote

Calehay wrote:
To clarify, blobtale.exe (The namesake of the game) is the virus. The .msi also installs Blob Story.exe and Blob Story.rpg, which is the game.exe and an actual .rpg file. Those two are safe to use, but as the name of the game is supposed to be "Blob Tale," and the name sake of the virus file is such, one can only assume what KnightAdmin's intentions were.


Can I ask what virus scanner you used? I've moved the file so you cannot download it from the gamelist, but had some inconsistency when verifying the presence of a virus.

ClamAV identified 922/922.zip: Trojan.Delf-624 FOUND, however neither Norton nor McAfee (latest versions, fully updated) identified the file as a threat. I have a feeling it is a false positive as a result of the MSI creation program used by KnightAdmin. I highly doubt KnightAdmin was maliciously attempting to distribute a virus.

In any case, I'll look into having ClamAV scan every file uploaded prior to adding it to the game list. Thanks for the warning.

~IM
_________________
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address MSN Messenger
Calehay
...yeah.
Class B Minstrel



Joined: 07 Jul 2004
Posts: 549

PostPosted: Sat Nov 01, 2008 1:44 pm    Post subject: Reply with quote

Inferior Minion wrote:
Calehay wrote:
To clarify, blobtale.exe (The namesake of the game) is the virus. The .msi also installs Blob Story.exe and Blob Story.rpg, which is the game.exe and an actual .rpg file. Those two are safe to use, but as the name of the game is supposed to be "Blob Tale," and the name sake of the virus file is such, one can only assume what KnightAdmin's intentions were.


Can I ask what virus scanner you used? I've moved the file so you cannot download it from the gamelist, but had some inconsistency when verifying the presence of a virus.


I used Avira Antivir, Free Version.

http://www.free-av.com/
_________________
Calehay
Back to top
View user's profile Send private message AIM Address
Inferior Minion
Metric Ruler



Joined: 03 Jan 2003
Posts: 741
Location: Santa Barbara, CA

PostPosted: Sat Nov 01, 2008 1:48 pm    Post subject: Reply with quote

Calehay wrote:
Inferior Minion wrote:
Calehay wrote:
To clarify, blobtale.exe (The namesake of the game) is the virus. The .msi also installs Blob Story.exe and Blob Story.rpg, which is the game.exe and an actual .rpg file. Those two are safe to use, but as the name of the game is supposed to be "Blob Tale," and the name sake of the virus file is such, one can only assume what KnightAdmin's intentions were.


Can I ask what virus scanner you used? I've moved the file so you cannot download it from the gamelist, but had some inconsistency when verifying the presence of a virus.


I used Avira Antivir, Free Version.

http://www.free-av.com/


OK, I actually ran the MSI and both Norton and McAffee identified the same virus. I guess neither program is as smart as ClamAV when it comes to scanning the MSI contents prior to extraction.

Given that I have the fully extracted contents minus the virus, I could create a proper .zip file for download. As Calehay pointed out, though, the actual contents of this game are quite sparse.

Thanks again,

~IM

Edit: Should have read the Slime Salad thread prior to my initial post. After looking at the actual contents of the game, I agree with Calehay's assessment regarding the creator's intention.
_________________
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address MSN Messenger
Gizmog1
Don't Lurk In The Bushes!




Joined: 05 Mar 2003
Posts: 2257
Location: Lurking In The Bushes!

PostPosted: Sat Nov 01, 2008 9:31 pm    Post subject: Reply with quote

I mentioned in my thread that he was in IRC. He appears as Anonymous at the end of this log, and I don't know if there's any information that can be gleaned from that. http://castleparadox.com/logs/castleparadox/2008-09-08.log

(Warning: Typical IRC antics involved. It's the Wild West in there. Look at your own risk)

In hindsight, it seems like a pretty obvious trap. Do I need to install an antivirus program, or do you think Spybot Search and Destroy would take care of it?
Back to top
View user's profile Send private message Send e-mail AIM Address
Bob the Hamster
OHRRPGCE Developer




Joined: 22 Feb 2003
Posts: 2526
Location: Hamster Republic (Southern California Enclave)

PostPosted: Sat Nov 01, 2008 9:49 pm    Post subject: Reply with quote

I have removed it from the monthly mirror. I'm also adding automated scanning to the mirror script.

I do notice that ClamAV identifies "The Crystal Globe" as containing Trojan.Agent-55637 ... but that zip file contains only a text file and an rpg, no executable at all, so I kinda suspect a false positive.
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Shadowiii
It's been real.




Joined: 14 Feb 2003
Posts: 2460

PostPosted: Sun Nov 02, 2008 11:00 pm    Post subject: Reply with quote

If it does, I have no knowledge of it.
Maybe that virus program is interpreting .rpg files as a virus of some sort? That would be something worth checking out.
_________________
But enough talk, have at you!
Back to top
View user's profile Send private message Send e-mail
Gizmog1
Don't Lurk In The Bushes!




Joined: 05 Mar 2003
Posts: 2257
Location: Lurking In The Bushes!

PostPosted: Sun Nov 02, 2008 11:23 pm    Post subject: Reply with quote

Wasn't there an issue a few years ago with Sword of Jade rpg files registering a false positive?
Back to top
View user's profile Send private message Send e-mail AIM Address
Moogle1
Scourge of the Seas
Halloween 2006 Creativity Winner
Halloween 2006 Creativity Winner



Joined: 15 Jul 2004
Posts: 3377
Location: Seattle, WA

PostPosted: Sun Nov 02, 2008 11:43 pm    Post subject: Reply with quote

No, there was an issue with Sword of Jade registering a correct positive. Sad...
_________________
Back to top
View user's profile Send private message Visit poster's website AIM Address
Bob the Hamster
OHRRPGCE Developer




Joined: 22 Feb 2003
Posts: 2526
Location: Hamster Republic (Southern California Enclave)

PostPosted: Mon Nov 03, 2008 8:46 am    Post subject: Reply with quote

I re-scanned the Crystal Globe again today on the same machine, and it came up clean. I am pretty sure that it was a false positive caused by a bad over-general signature, which was removed since then.
Back to top
View user's profile Send private message Send e-mail Visit poster's website
FyreWulff
Still Jaded




Joined: 02 Apr 2005
Posts: 406
Location: The Internet

PostPosted: Mon Nov 03, 2008 10:46 am    Post subject: Reply with quote

Moogle1 wrote:
No, there was an issue with Sword of Jade registering a correct positive. Sad...


A virus that didn't exist in the wild until 2 months after we released the game in fact
Back to top
View user's profile Send private message Visit poster's website AIM Address
LeRoy_Leo
Project manager
Class S Minstrel



Joined: 24 Sep 2003
Posts: 2683
Location: The dead-center of your brain!

PostPosted: Tue Nov 04, 2008 7:07 pm    Post subject: Reply with quote

What a clever child. Unfortunate that everyone here is so computer savvy.
_________________
Planning Project Blood Summons, an MMORPG which will incinerate all of the others with it's sheer brilliance...

---msw188 ---
"Seriously James, you keep rolling out the awesome like gingerbread men on a horror-movie assembly line. "
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address
Bob the Hamster
OHRRPGCE Developer




Joined: 22 Feb 2003
Posts: 2526
Location: Hamster Republic (Southern California Enclave)

PostPosted: Tue Dec 16, 2008 3:00 pm    Post subject: Reply with quote

My antivirus scanner is claiming that the zip file for Crescent Dream (which contains an exe installer) is infected by Trojan.Banker-151

I have a feeling this is a false positive, but I would appreciate it if somebody else could check with another virus scanner.
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Castle Paradox Forum Index -> The Soapbox All times are GMT - 8 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group