<
>
 Thread (16 posts)
_Kyle_  3/07/08 10:45:48 PM

Rank: 10/100 Rank: 10/100 Rank: 10/100 Rank: 10/100 Rank: 10/100

Novice Member

Joined: 12/14/03
Posts: 301

IGNs: Krileon, Xellia, Neeshka, Xavier, Krayven, Sinolian

These idiots can't even compile a dang EXE properly.

They've encrypted the files within the EXE (BIG red flag for some anti-virus software), which has given the individual files random names.

Upon downloading of the Stonehenge Patch (WTF? Why is it a manual download? Idiots.). If you use such software as Avast or AVG or other good anti-virus software. It'll claim the program is introducing a trojan.

Now obviously it's not, but why should this matter you say?

Because a company that can't even properly compress an encrypted EXE is making your game! How do you solve this false positive? You put the damn EXE in a RAR or ZIP. Problem solved. Why is that so hard for them to do?

My MAJOR concern is why is it a manual download and WHY is it so insanely encrypted. I've never encountered issues like this before, because any encrypted files I've downloaded was compressed properly (who the hell puts low compression EXE up anyway?).

I've come to the conclusion that they encrypted the files and made it a seperate download because they wanted to prevent modders from making SP knock offs of the stonehenge content, which is a very good reason to encrypt it, but why so extensively to randomize file names? I just can't find a good explination for their actions.

I KNOW it's not a virus it is a FALSE POSITIVE (a red flag trigger from files that present LIKENESS to a real virus), BUT I refused to give the game another try simply because of their incompetense. Not to mention from what i've been told Stonehenge is roughly 1 hour of content. Not including the endlessly boring gear grind (no where near as fun as Diablo2 gear grind.. as you actually did this with a full group of people and had a blast.. grouping barely brings better gear the difficulty gets INTENSE when you add to many people).

So take from this what you will, but i'm done with Hellgate and FSS. IMO they're a bunch of incompetent designers and it really makes you wonder why they "left" blizzard.

[ Played ] 2Moons, Anarchy Online, City of Heroes, City of Villains, Dark Age of Camelot, Everquest, Everquest II, Guild Wars, HellGate: London, Lord of the Rings Online, Rappelz, RF Online, Shadowbane, Star Wars Galaxies, Sword of the New World, Tabula Rasa, Vanguard: Saga of Heroes, World of Warcraft, Last Chaos, Earth & Beyond, EVE Online, Holic, Seal Online, Dream Of Mirror Online, Age of Conan

[ Playing ] NONE

[ Waiting ] Huxley, Stargate Worlds, Earthrise

extragonk  3/08/08 4:54:57 AM

Rank: 17/100 Rank: 17/100 Rank: 17/100 Rank: 17/100 Rank: 17/100

Novice Member

Joined: 12/04/07
Posts: 15

theres loads of games and other product that highlight as virus activity, sticking to the gaming world - Mircosofts own xbox development environment also comes up as having virus components.

Your post doesnt make a point, you ask why then supply the reason, it looks like an ok reason to me, certainly it didnt make me uptight and aggro over the fact i had to click 1 more button to download it <gasp>.

 
_Kyle_  3/09/08 1:44:01 PM

Rank: 10/100 Rank: 10/100 Rank: 10/100 Rank: 10/100 Rank: 10/100

Novice Member

Joined: 12/14/03
Posts: 301

IGNs: Krileon, Xellia, Neeshka, Xavier, Krayven, Sinolian

In 12 years of gaming, I've never had a manual patch trigger anti-virus.. ever.. that's because the developers are smart enough not to package and encrypt files in suspicious ways.

Get this. My attempt to warn others against downloading ANYTHING that triggers a red flag on their forums and posts of other people having the exact same issues.. were all deleted. All of them. I didn't even break any rules in my posts. I was just giving an unbiased opinion on the matter. So they deleted my posts. They also gave NO warning. NO e-mail. NO pm. NOTHING. The posts and any reference to the posts, VANISHED.

Lets go down a list of why this is a problem:

1) Why is it a manual MANDATORY patch? It's certainly not to big to download through in game patcher. (300mb)

2) There is NO official comment from FSS about this issue on their forums.

3) They are deleting any posts that are against or suspicious of such activity.

4) The viruses that attempted to download was traced back DIRECTLY to their file. It was not a spawn of a pre-existing virus. The patch generated the files it self.

5) Why are these randomly named files plugged into the temp folder as .exe format? This is the pattern of a trojan. (I've done over 10 scans with roughly 6 different programs. It is NOT a pre-existing virus. I've done spyware removals from 3 different sources and I've done 2 rootkit scans.)

So you people that ignored the warning and installed the patch. All I can say is you potentially now have a Rootkit on your system. It is probably spawning files in your temp folder. If you see things like 3521jfsa.exe in your temp folder or close to it or have a anti-virus trigger presenting such file. Then it is spawning viruses or attempted to.

I am not one to take suspicious behavior litely. I aim to insure my system is secure. Is it a false positive? That's a posibility, but I ask you.. are you willing to take that chance? This coming from a company that's done nothing more but epically fail at creating a quality game and bring nothing but short comings. It's your choice to ignore it or not and hay I could be wrong, but again.. are you willing to take that risk. I'm just here trying to give a friendly warning.

So be honest to your selves. Connect the dots and then tell me you aren't even the least bit suspicious of such activity. Continue to ask your self, "WHY is a mandatory patch manually downloaded instead of through the file by file patcher." The reason being is the patcher will download faster/fast as manual download and presents a guaranteed pause/resume with no file corruption. So why is it manual?

Good luck folks.

 

[ Played ] 2Moons, Anarchy Online, City of Heroes, City of Villains, Dark Age of Camelot, Everquest, Everquest II, Guild Wars, HellGate: London, Lord of the Rings Online, Rappelz, RF Online, Shadowbane, Star Wars Galaxies, Sword of the New World, Tabula Rasa, Vanguard: Saga of Heroes, World of Warcraft, Last Chaos, Earth & Beyond, EVE Online, Holic, Seal Online, Dream Of Mirror Online, Age of Conan

[ Playing ] NONE

[ Waiting ] Huxley, Stargate Worlds, Earthrise

Radiohedwig  3/13/08 9:01:57 PM

Rank: 1/100 Rank: 1/100 Rank: 1/100 Rank: 1/100 Rank: 1/100

Novice Member

Joined: 10/16/06
Posts: 6

people who trust antivirus programs should not use computers.

 

The fault of the false positive isn't FSS, it's your antivirus.  BTW avast is a horrible antivirus.

 
Katashi-kun  3/13/08 9:05:40 PM

Rank: 1/100 Rank: 1/100 Rank: 1/100 Rank: 1/100 Rank: 1/100

Novice Member

Joined: 9/22/07
Posts: 527

Umm, yeah HGL is a Trojan in itself!

Yeah I forced myself through the entire game, and was just horrified at how poorly the game was put together!  I really can't see why they even call this a game, let alone list it as an MMO!  Heck Diablo should be listed an MMO then if this one is! 


Kemih ~ 13 Red Mage | Currently playing FFXI & LOTRO, awaiting Warhammer Online & Aion...

Woopin  3/13/08 9:40:21 PM

Rank: 100/100 Rank: 100/100 Rank: 100/100 Rank: 100/100 Rank: 100/100

MMORPG.COM Staff

Joined: 3/14/07
Posts: 366

Trojans can also lay dormant and add them selvs to random files. It is not forced to be the patch.

----------------
The views expressed in this post are entirely my own and do not represent the views of MMORPG.com, its associates, or affiliates.

R.I.P. * Laura "Taera" Genender *

_Kyle_  3/15/08 12:00:33 AM

Rank: 10/100 Rank: 10/100 Rank: 10/100 Rank: 10/100 Rank: 10/100

Novice Member

Joined: 12/14/03
Posts: 301

IGNs: Krileon, Xellia, Neeshka, Xavier, Krayven, Sinolian

 

Originally posted by Woopin

Trojans can also lay dormant and add them selvs to random files. It is not forced to be the patch.

I'm aware of this, but all it takes is a little trace work and you can find the source.

 

The trojans were generated directly from their server once I made a connection to initiate the download. The trojans was riding a long with the patch. I don't think the patch is compromised, but I do believe their FTP server possibly was, which isn't hard to do.

And to the fool who says not to believe anti-viruses.. good luck. As said this is the first time in years i've had any game related files be "mistaken" for a virus. It's not hard to create a damn executeable that doesn't run with virus like behavior.. it's not re-inventing damn rocket science.. it's just compiling a couple freaken files properly.. not hard to do.. obviously in FSS case.. it was hard to do, but as I also said. That's not my major concern. You and everyone else STILL fails to explain why a tiny 300mb mandatory patch is downloaded manually. There is no excuse for this.

Also, Avast works perfectly fine. It's not the best in the world i'd admit, but nothing is. There's always something that's bound to slip in, which is why I have 2 other AVs that I do bootup scans with regularly. I'm considering buying the ZoneAlarm Security Suite and getting spyware, adware, rookit, virus, firewall protection all in 1 bundle.

[ Played ] 2Moons, Anarchy Online, City of Heroes, City of Villains, Dark Age of Camelot, Everquest, Everquest II, Guild Wars, HellGate: London, Lord of the Rings Online, Rappelz, RF Online, Shadowbane, Star Wars Galaxies, Sword of the New World, Tabula Rasa, Vanguard: Saga of Heroes, World of Warcraft, Last Chaos, Earth & Beyond, EVE Online, Holic, Seal Online, Dream Of Mirror Online, Age of Conan

[ Playing ] NONE

[ Waiting ] Huxley, Stargate Worlds, Earthrise

Unicorns_Pwn  3/15/08 12:15:06 AM

Rank: 38/100 Rank: 38/100 Rank: 38/100 Rank: 38/100 Rank: 38/100

Apprentice Member

Joined: 3/03/07
Posts: 350

Just for your benefit and my amusement I am downloading the stonehenge patch direct from their server and will be doing a scan with both NOD32 and Kaspersky and tell you what the results are.  You claim that is is the fault of FSS yet do not even take into consideration that it may be a false positive and a problem with  whatever AV software you are using.

 

I'll let you know in about 15 minutes what my results are.

 
sparkz0214  3/15/08 12:27:49 AM

Rank: 14/100 Rank: 14/100 Rank: 14/100 Rank: 14/100 Rank: 14/100

Novice Member

Joined: 9/13/07
Posts: 1

wow .. a little paranoid are we? Do you practice getting  your keys out and unlocking your door in case  a serial killer ever chases you home?

btw I'm lovin HGL and I think it is only gonna get better as time goes on. I switch between it and Eve regularly while I wait for AoC 

 
Unicorns_Pwn  3/15/08 12:38:38 AM

Rank: 38/100 Rank: 38/100 Rank: 38/100 Rank: 38/100 Rank: 38/100

Apprentice Member

Joined: 3/03/07
Posts: 350

Patch_NA_Europe_Germany_MP_1.0_(1.0.27.4101.a)

scanned with NOD32 v2.70.39  Virus signat