Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> virustotal report

 
post Apr 30 2017, 20:53
Post #1
Cleavs



A certain pervert. OT expert. Just dancing around in the game.
***********
Group: Gold Star Club
Posts: 24,313
Joined: 18-January 07
Level 500 (Ponyslayer)


i'm looking at this and maybe i'm growing a bit paranoid, lol (IMG:[invalid] style_emoticons/default/heh.gif)

i sent a file (a widescreen fix for NFS Carbon, which is on 4/3 ratio natively, afaik) to virustotal to analyze, and this is the result:

[www.virustotal.com] https://www.virustotal.com/it/file/7d2db2cf...sis/1493555937/

two "infected" files, and these are the partial scans:

[www.virustotal.com] https://www.virustotal.com/it/file/f8dbac94...sis/1493578178/

[www.virustotal.com] https://www.virustotal.com/it/file/7122caf5...sis/1493578229/

now, there doesn't seem to be sort of an agreement on what said malware could be and i had the chance to use a similar thing for another game and worked fine, so i'm prompt to assume that it's a false positive and the results are due to some instructions that deal with memory or osmething like that, but better safe than sorry, as they say. any opinions, anyone?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 30 2017, 22:37
Post #2
blue penguin



in umbra, igitur, pugnabimus
***********
Group: Gold Star Club
Posts: 10,046
Joined: 24-March 12
Level 500 (Godslayer)


QUOTE(Scremaz @ Apr 30 2017, 19:53) *
Sending a ZIP to an AV scan is pretty useless. The signature checkers can find anything in there because pretty much anything can be in there. On the other hand, unless you use some shitty software from the '90s you can't go wrong with unzipping a file (and unless you double click it and have some shitty software configured to open it). Whatever is in the file should never even reach close to the instruction pointer, that should be guaranteed by the design of the unzipper.

QUOTE
[www.virustotal.com] https://www.virustotal.com/it/file/f8dbac94...sis/1493578178/

[www.virustotal.com] https://www.virustotal.com/it/file/7122caf5...sis/1493578229/

now, there doesn't seem to be sort of an agreement on what said malware could be and i had the chance to use a similar thing for another game and worked fine, so i'm prompt to assume that it's a false positive and the results are due to some instructions that deal with memory or osmething like that, but better safe than sorry, as they say. any opinions, anyone?
It probably is better to check the first, say, 64-128 bytes at the beginning of the file to see if the magical number (google it) and the file extension matches. Googling .ASI gave me a borland assembly include, which I would not run.

Taking the first bytes and comparing with a list of them (e.g. from [en.wikipedia.org] wikipedia) also gives a good idea of what the file may be designed to look as. Borland assembly includes are not there (and probably cannot be cause borland had the bad habit of not using magic numbers) but if you find your file in there you get some info.

Or you could just be unlucky and some moronic developer decided to name a file .asi because these are the initials of his mother and never heard of magic numbers or file construction standards (or any other standards for that reason).
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 30 2017, 22:44
Post #3
Cleavs



A certain pervert. OT expert. Just dancing around in the game.
***********
Group: Gold Star Club
Posts: 24,313
Joined: 18-January 07
Level 500 (Ponyslayer)


pretty sure that ASI is an extension for NFS games (unofficial) mods. no clue where it does come from though - since there's no track in the official game. [www.wsgf.org] according to developer it's [thirteenag.github.io] a plugin which should "convert" 4:3 NFS native format into 16:9. to do so, i guess it heavily manipulates memory, so could it be those instructions are seen as malicious?

i know because another older game had the same mechanic too. but it didn't give me all those results, so i'm asking (IMG:[invalid] style_emoticons/default/heh.gif)

here are the scans for the similar hack for NFS:MW:

zip (yep, useless but i had to start somewhere (IMG:[invalid] style_emoticons/default/tongue.gif) ): [www.virustotal.com] https://www.virustotal.com/it/file/4a28d4c5...sis/1493585140/

again, the troublesome one seems to be the ASI (though TrID classifies it as Visual C++, and with way less results): [www.virustotal.com] https://www.virustotal.com/it/file/e7c3956c...sis/1493585340/

This post has been edited by Scremaz: Apr 30 2017, 22:56
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post May 1 2017, 02:29
Post #4
Usagi =



Veteran Poster
********
Group: Gold Star Club
Posts: 2,923
Joined: 29-October 13
Level 453 (Dovahkiin)


Looking at the link you provided, it should be fine.

They provided the sources on github, has a twitch stream, a patreon and a nice comment section with comments from people with similar concern to yours.

Someone wanting to spread viruses won't bother with all these.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post May 1 2017, 02:36
Post #5
Cleavs



A certain pervert. OT expert. Just dancing around in the game.
***********
Group: Gold Star Club
Posts: 24,313
Joined: 18-January 07
Level 500 (Ponyslayer)


ah, yes. fair enough. he also posted a WIP in which he showed how he could cut the number of detections: [github.com] https://github.com/ThirteenAG/WidescreenFixesPack/issues/157

and if it's open source, well... it should speak for itself. guess that tomorrow i'll try it. if you don't see me around for a couple of days, you know why (IMG:[invalid] style_emoticons/default/laugh.gif)


for now, thank you both for your answers (IMG:[invalid] style_emoticons/default/smile.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post


Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


Lo-Fi Version Time is now: 18th July 2025 - 18:25