RegisterRegister    Log inLog in    SearchSearch   

Post new topic   Reply to topic
 
View previous topic :: View next topic  
Author Message
nicke157



PostPosted: Fri Oct 01, 2010 9:39 pm    Post subject: NOD32 suspecting malware in GameCreate Client Reply with quote

Hey. I tried download the GameCreate Client for windows but my antivirus application (Eset NOD32) blocked the download.

Quote:
2010-10-01 12:40:28 HTTP filter file http://www.gamecreate.com/files/GameCreate-Setup.msi probably unknown NewHeur_PE virus connection terminated - quarantined NT AUTHORITY\SYSTEM Threat was detected upon access to web by the application: C:\WINDOWS\system32\vmnat.exe.


I also tested with VirusTotal and there says same thing:

Code:
[i]Antivirus results[/i]
AhnLab-V3 - 2010.10.01.00 - 2010.09.30 - -
AntiVir - 7.10.12.95 - 2010.10.01 - -
Antiy-AVL - 2.0.3.7 - 2010.10.01 - -
Authentium - 5.2.0.5 - 2010.09.30 - -
Avast - 4.8.1351.0 - 2010.09.30 - -
Avast5 - 5.0.594.0 - 2010.09.30 - -
AVG - 9.0.0.851 - 2010.10.01 - -
BitDefender - 7.2 - 2010.10.01 - [color=red]Gen:Trojan.Heur.LP.kG4@aGFoEGpi [/color]
CAT-QuickHeal - 11.00 - 2010.10.01 - -
ClamAV - 0.96.2.0-git - 2010.10.01 - -
Comodo - 6252 - 2010.10.01 - -
DrWeb - 5.0.2.03300 - 2010.10.01 - -
Emsisoft - 5.0.0.50 - 2010.10.01 - [color=red]Gen.Trojan!IK [/color]
eSafe - 7.0.17.0 - 2010.09.30 - -
eTrust-Vet - 36.1.7886 - 2010.10.01 - -
F-Prot - 4.6.2.117 - 2010.09.30 - -
F-Secure - 9.0.15370.0 - 2010.10.01 - [color=red]Gen:Trojan.Heur.LP.kG4@aGFoEGpi [/color]
Fortinet - 4.1.143.0 - 2010.09.30 - -
GData - 21 - 2010.10.01 - [color=red]Gen:Trojan.Heur.LP.kG4@aGFoEGpi [/color]
Ikarus - T3.1.1.90.0 - 2010.10.01 - [color=red]Gen.Trojan [/color]
Jiangmin - 13.0.900 - 2010.09.30 - -
K7AntiVirus - 9.63.2648 - 2010.09.30 - -
Kaspersky - 7.0.0.125 - 2010.10.01 - -
McAfee - 5.400.0.1158 - 2010.10.01 - -
McAfee-GW-Edition - 2010.1C - 2010.10.01 - -
Microsoft - 1.6201 - 2010.10.01 - -
NOD32 - 5494 - 2010.10.01 - [color=red]probably unknown NewHeur_PE [/color]
Norman - 6.06.07 - 2010.10.01 - -
nProtect - 2010-10-01.02 - 2010.10.01 - -
Panda - 10.0.2.7 - 2010.09.30 - -
PCTools - 7.0.3.5 - 2010.10.01 - -
Prevx - 3.0 - 2010.10.01 - -
Rising - 22.67.02.07 - 2010.09.30 - -
Sophos - 4.58.0 - 2010.10.01 - -
Sunbelt - 6954 - 2010.10.01 - -
SUPERAntiSpyware - 4.40.0.1006 - 2010.10.01 - -
Symantec - 20101.2.0.161 - 2010.10.01 - -
TheHacker - 6.7.0.1.041 - 2010.10.01 - -
TrendMicro - 9.120.0.1004 - 2010.10.01 - -
TrendMicro-HouseCall - 9.120.0.1004 - 2010.10.01 - -
VBA32 - 3.12.14.1 - 2010.10.01 - -
ViRobot - 2010.8.31.4017 - 2010.10.01 - -
VirusBuster - 12.66.8.0 - 2010.09.30 - -
[i]File info:[/i]
MD5: 172a7f3e0cd4ff212a42ad5014f47da7
SHA1: cfcd6f70a48d67ce79a2989773c6f83b7bd2e4be
SHA256: 6939c9d6c6bd04a1dbd501503da8a025b986bed076378283b952533c7fb4119a
File size: 2076160 bytes
Scan date: 2010-10-01 11:30:54 (UTC)


So check before download.
Back to top
View user's profile Send private message
adbot



PostPosted: Thu Mar 31, 2011 3:57 am 

ryguy222



PostPosted: Sat Oct 02, 2010 3:44 am    Post subject: Reply with quote

Virus scanners are given a list of possible threats from the security compnay that sells or distributes the scanner. However, there are also mechanisms within the virus scanner that look for patterns that usually all virus's have. These patterns are various binaries, and also messages that could be executed when started.

A trojan is normally a desireable piece of software, that often will spam you with uncontrollable advertisements, or can give someone un-authorized access to your computer.

This IS true about the game create client (except for the spamming part it doesn't do that) It needs to be able to accept commands from the control panel (the online interface) and from that execute commands on the remote system. Because of it's ability to do such actions, many virus scanners mark it as a Trojan.

Since this program sort of has a decent level of access to a system, I would never run it on my personal computer. Not to say that GameCreate has ill intentions, but if anything were to ever be changed, or hacked, I wouldn't want hackers to have a front door into my personal computer.

Instead I have a few systems that I rent at Data Centers, and keep weekly backups on it that go to an offsite location. None of my personal info is stored on those machines, and none of my clients info is on there either. Just game servers, which isn't really valuable to most hackers. If something were to happen, I could simply wipe the machine, and restore the backup.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Forum powered by phpBB © 2001, 2005 phpBB Group
GameCreate Service Terms | Privacy Policy | © Copyright Mammoth Media 2001-2007
GameCreate™ is a trademark of Mammoth Media Pty Ltd. GameCreate® is a registered trademark in Australia.