Gannon8 Posted April 19, 2009 Report Posted April 19, 2009 (edited) There appears to be a worm in some of the .svn directories and some other files. I downloaded a fresh copy from the SVN server and scanned it. The complete log is attached, the infected files are here:./disc_client/zones/.svn/text-base/test.svn-base: Worm.Stration.WR FOUND ./disc_client/zones/test: Worm.Stration.WR FOUND ./disc_client/bin/zones/.svn/text-base/test.svn-base: Worm.Stration.WR FOUND ./disc_client/bin/zones/test: Worm.Stration.WR FOUND ./disc_client/old/Unit Tests/Modules/.svn/text-base/ModuleManager.dll.svn-base: Worm.Stration.WR FOUND ./disc_client/old/Unit Tests/Modules/ModuleManager.dll: Worm.Stration.WR FOUND A couple days after downloading, a worm appeared on my system that messed with my Windows Explorer settings and copied itself onto my USB drive. Still trying to get it off of my system. I don't know if discretion is the cause, but the only other virus my scanner detected was CSEdit.exe, which I know is safe.EDIT2: One of the computers in my class had a worm on it, which transferred itself onto my thumbdrive. This worm isn't affiliated with the discretion virus. Scanned with ClamAV EDIT: http://www.viruslist.com/en/viruses/encycl...?virusid=140652scan.log Edited April 25, 2009 by Gannon8 Quote
Bak Posted April 19, 2009 Author Report Posted April 19, 2009 that's not good, my virus scanner doesn't pick it up even if I manually scan the file :/. Is the binary release on sourceforge okay? Quote
Sass Posted April 19, 2009 Report Posted April 19, 2009 (edited) Yikes! I checked my pc and no registry entries matching the viruslist data. Edited April 19, 2009 by Sass Quote
CRe Posted April 19, 2009 Report Posted April 19, 2009 that's not good, my virus scanner doesn't pick it up even if I manually scan the file :/. Is the binary release on sourceforge okay? Nope, It's affected. -CRe> Quote
Bak Posted April 20, 2009 Author Report Posted April 20, 2009 I have confirmed the virus.Did you confirm it using ClamAV or another virus scanner? Like Sass, I checked for the malicious executable in my system directory as well as the registry keys and don't see it. It may be a false positive, but I took off the binary from sourceforge as a precaution while we figure things out. Quote
Kilo Posted April 20, 2009 Report Posted April 20, 2009 (edited) I've heard of at least one program which uses auto-update functionality being caught as false-positives on certain virus scanners (since some viruses include capability to download new programs.) Might want to keep that in mind. Edited April 20, 2009 by Kilo Quote
Gannon8 Posted April 25, 2009 Report Posted April 25, 2009 I've heard of at least one program which uses auto-update functionality being caught as false-positives on certain virus scanners (since some viruses include capability to download new programs.) Might want to keep that in mind.I do not believe the auto-update program would be in a file called "zone/test" not the module manager, so I do not believe that is the problem. Quote
Bak Posted May 2, 2009 Author Report Posted May 2, 2009 okay! 0.32 has been rereleased. The suspected worm files have been deleted (I still say it was a false positive but who cares they weren't being used); the svn should also be clean. There's also an update to allow continuum-style custom tilesets, and we have a new map and tileset in the test zone thanks to Sass (thanks Sass)!! https://sourceforge.net/project/showfiles.p...lease_id=672062 Quote
Gannon8 Posted May 8, 2009 Report Posted May 8, 2009 Great, thanks a lot I will get onto making that star background rendering program. I am working on 50 different things at once so Quote
darksol Posted May 19, 2009 Report Posted May 19, 2009 Keep up the work, It's looking good so far. I'm on linux waiting for a good linux SS client. love and peace. Quote
Russky Posted May 19, 2009 Report Posted May 19, 2009 Awesome client you've got going here, does it connect to any other zones? Common zones that everyone plays? Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.