Author Topic: Kaspersky is envious, or: Which Weidu version shall we use?  (Read 3372 times)

Offline Kulyok

  • Global Moderator
  • Planewalker
  • *****
  • Posts: 6253
  • Gender: Female
  • The perfect moment is now.
Kaspersky is envious, or: Which Weidu version shall we use?
« on: February 14, 2009, 03:01:19 AM »
http://www.shsforums.net/index.php?showtopic=38877
(and this one http://forums.gibberlings3.net/index.php?showtopic=16687)

- Maybe it's Weidu-related?

I checked Weidu 208, and here's what Virus Total gives:
http://www.virustotal.com/analisis/05ba0c70c5f518a454890cd5287566f1
(14 false positives)

Weidu 210:
http://www.virustotal.com/analisis/6aa08ba91a72d3d2ecf68d09743c579e
(1 false positive = almost nothing)

I think I'll go and replace my Weidu 208's with 210's. Posting this, because obviously there was something in Weidu 208(and it's missing in Weidu 210), something antivirus software is taking for a virus.


Offline the bigg

  • The Avatar of Fighter / Thieves
  • Moderator
  • Planewalker
  • *****
  • Posts: 3804
  • Gender: Male
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #1 on: February 14, 2009, 07:10:12 AM »
Meh, I don't even have a bullshit dispenser antivirus, because the harm is greater than the gain. Since WeiDU uses upx for compressing the executable (3 MB to 400 kB), it's entirely possible that a random signature is generated in the compressed section.
Author or Co-Author: WeiDU (http://j.mp/bLtjOn) - Widescreen (http://j.mp/aKAiqG) - Generalized Biffing (http://j.mp/aVgw3U) - Refinements (http://j.mp/bLHoCc) - TB#Tweaks (http://j.mp/ba02Eg) - IWD2Tweaks (http://j.mp/98OFYY) - TB#Characters (http://j.mp/ak8J55) - Traify Tool (http://j.mp/g1Ry9A) - Some mods that I won't mention in public
Maintainer: Semi-Multi Clerics (http://j.mp/9UeIwB) - Nalia Mod (http://j.mp/dng9l0) - Nvidia Fix (http://j.mp/aRWjjg)
Code dumps: Detect custom secondary types (http://j.mp/hVzzXG) - Stutter Investigator (http://j.mp/gdtBn8)

If possible, send diffs, translations and other contributions using Git (http://j.mp/aBZFrq).

Offline Kulyok

  • Global Moderator
  • Planewalker
  • *****
  • Posts: 6253
  • Gender: Female
  • The perfect moment is now.
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #2 on: February 14, 2009, 07:29:54 AM »
Sigh. I'll do the updates sometime this weekend, then. Here's hoping that evil corporate people won't touch small helpless Weidu again with their wicked software.

Offline jcompton

  • Niche Exploiter
  • Administrator
  • Planewalker
  • *****
  • Posts: 7246
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #3 on: February 14, 2009, 11:29:44 AM »
Usually the AV companies are responsive to "hey this is a false positive" report--and I notice in the Studios thread that Kaspersky fessed up but AVG didn't, which is intriguing. I too was getting hits on WeiDU 208 from AVG in the past week, but have been a little too wrapped up in my own hradksik krash problems to deal with the report, I'm afraid.
Cespenar says, "Kelsey and friends be at the Pocket Plane? Ohhh yesssss!" http://www.pocketplane.net

Offline GeN1e

  • Planewalker
  • *****
  • Posts: 267
  • Gender: Male
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #4 on: February 14, 2009, 12:25:09 PM »
Well, I fully share bigg's opinion - AVs are bad.

Offline Kulyok

  • Global Moderator
  • Planewalker
  • *****
  • Posts: 6253
  • Gender: Female
  • The perfect moment is now.
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #5 on: February 15, 2009, 06:06:33 AM »
Hey, folks,

I just got a report from avg.com - yes, it was a false positive. (I sent them our RE_v4.exe file, archived, with a note it's an unofficial expansion for Baldur's Gate - not that it matters).

Offline jcompton

  • Niche Exploiter
  • Administrator
  • Planewalker
  • *****
  • Posts: 7246
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #6 on: February 16, 2009, 09:41:04 AM »
I sent out a few false positive reports and got "oops! our mistake!" responses from Avira and Ikarus (although I sent the report to Emsi, so I guess they're the same company, or partners, or some such.)

It had been my idea to go down the entire list, but I admit that I got bored, as well as annoyed by the submission schemes which required you to stick the file in a password-protected archive, so I didn't nail them all. Hopefully the news will filter downstream.
Cespenar says, "Kelsey and friends be at the Pocket Plane? Ohhh yesssss!" http://www.pocketplane.net

Offline the bigg

  • The Avatar of Fighter / Thieves
  • Moderator
  • Planewalker
  • *****
  • Posts: 3804
  • Gender: Male
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #7 on: February 16, 2009, 09:52:11 AM »
It had been my idea to go down the entire list, but I admit that I got bored, as well as annoyed by the submission schemes which required you to stick the file in a password-protected archive, so I didn't nail them all. Hopefully the news will filter downstream.
I guess they need the passworded archive to avoid a random antivirus-enabled mail server/client/whatever from detecting and blocking the email.
Author or Co-Author: WeiDU (http://j.mp/bLtjOn) - Widescreen (http://j.mp/aKAiqG) - Generalized Biffing (http://j.mp/aVgw3U) - Refinements (http://j.mp/bLHoCc) - TB#Tweaks (http://j.mp/ba02Eg) - IWD2Tweaks (http://j.mp/98OFYY) - TB#Characters (http://j.mp/ak8J55) - Traify Tool (http://j.mp/g1Ry9A) - Some mods that I won't mention in public
Maintainer: Semi-Multi Clerics (http://j.mp/9UeIwB) - Nalia Mod (http://j.mp/dng9l0) - Nvidia Fix (http://j.mp/aRWjjg)
Code dumps: Detect custom secondary types (http://j.mp/hVzzXG) - Stutter Investigator (http://j.mp/gdtBn8)

If possible, send diffs, translations and other contributions using Git (http://j.mp/aBZFrq).

Offline jcompton

  • Niche Exploiter
  • Administrator
  • Planewalker
  • *****
  • Posts: 7246
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #8 on: February 16, 2009, 11:24:15 AM »
I guess they need the passworded archive to avoid a random antivirus-enabled mail server/client/whatever from detecting and blocking the email.

Yeah, I know--but it doesn't speak very well to the flexibility of their product if they can't designate a single inbox as "do not scan." Especially when competitors do precisely that, or have Web-based upload interfaces.
Cespenar says, "Kelsey and friends be at the Pocket Plane? Ohhh yesssss!" http://www.pocketplane.net

Offline the bigg

  • The Avatar of Fighter / Thieves
  • Moderator
  • Planewalker
  • *****
  • Posts: 3804
  • Gender: Male
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #9 on: February 16, 2009, 11:28:30 AM »
Yeah, I know--but it doesn't speak very well to the flexibility of their product if they can't designate a single inbox as "do not scan." Especially when competitors do precisely that, or have Web-based upload interfaces.
Heh. There's still the risk that your SMTP server scans for outgoing viruses (especially if you're at University).
Author or Co-Author: WeiDU (http://j.mp/bLtjOn) - Widescreen (http://j.mp/aKAiqG) - Generalized Biffing (http://j.mp/aVgw3U) - Refinements (http://j.mp/bLHoCc) - TB#Tweaks (http://j.mp/ba02Eg) - IWD2Tweaks (http://j.mp/98OFYY) - TB#Characters (http://j.mp/ak8J55) - Traify Tool (http://j.mp/g1Ry9A) - Some mods that I won't mention in public
Maintainer: Semi-Multi Clerics (http://j.mp/9UeIwB) - Nalia Mod (http://j.mp/dng9l0) - Nvidia Fix (http://j.mp/aRWjjg)
Code dumps: Detect custom secondary types (http://j.mp/hVzzXG) - Stutter Investigator (http://j.mp/gdtBn8)

If possible, send diffs, translations and other contributions using Git (http://j.mp/aBZFrq).

Offline jcompton

  • Niche Exploiter
  • Administrator
  • Planewalker
  • *****
  • Posts: 7246
Re: Kaspersky is envious, or: Which Weidu version shall we use?
« Reply #10 on: February 16, 2009, 11:35:08 AM »
Ah, good point. A lot of consumer AV has outgoing mail scanners, for that matter. Well, anyway, that only further makes the case for a Web interface (or anonymous FTP, or whatever.)

Anyway, I'm glad it all turned out to be a false alarm. There was an instance years and years ago where Wes somehow put out an infected version of one mod. (early version of Tactics? I can't remember.)
Cespenar says, "Kelsey and friends be at the Pocket Plane? Ohhh yesssss!" http://www.pocketplane.net

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Warning: this topic has not been posted in for at least 120 days.
Unless you're sure you want to reply, please consider starting a new topic.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
What color is grass?:
What is the seventh word in this sentence?:
What is five minus two (use the full word)?: