1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

[Avira flags virus in a game I've been using for 6 months?]

Discussion in 'Security and Privacy' started by TAYLORBOY, 2010/10/02.

  1. 2010/10/02
    TAYLORBOY

    TAYLORBOY Inactive Thread Starter

    Joined:
    2009/09/28
    Messages:
    30
    Likes Received:
    0
    Hi,

    Just a quick one for someone who may know.
    I have had a game installed on my computer for about six months. Just now avira came up flashing saying that it had found a virus in this game. Obviously best to just delete, but im just wondering why it only flags it as a virus now considering I play the game regularly and avira has never flagged it before:confused:
     
  2. 2010/10/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It may be false positive.
    Upload the file, which triggers Avira here: http://www.virustotal.com/ for security check.
    If the file is listed as already analyzed, click on Reanalyse file now button.
     

  3. to hide this advert.

  4. 2010/10/03
    TAYLORBOY

    TAYLORBOY Inactive Thread Starter

    Joined:
    2009/09/28
    Messages:
    30
    Likes Received:
    0
    Hi Broni,

    I have done what you have advised and once again the only one that picked up anything was avira, this is the information from the scan-

    File name:
    age2_x1.exe
    Submission date:
    2010-10-03 10:31:40 (UTC)
    Current status:
    finished
    Result:
    1/ 43 (2.3%)

    Do you think it is safe to continue playing this game???
    I do not understand why it all of a sudden picks up a virus, many thanks for your help :)
     
  5. 2010/10/03
    Whiskeyman Lifetime Subscription

    Whiskeyman Inactive Alumni

    Joined:
    2005/09/10
    Messages:
    1,772
    Likes Received:
    37
    There is a zip file containing age2_x1.exe that is a CD crack for Age of Empires II that can be used to replace the original file in the game. Avira could be warning of this if you downloaded and used it.
     
  6. 2010/10/03
    TAYLORBOY

    TAYLORBOY Inactive Thread Starter

    Joined:
    2009/09/28
    Messages:
    30
    Likes Received:
    0
    I do not think it is anything that I have downloaded though to be honest, as I first installed the game six months ago and since then I have not downloaded anything to do with this game . I have also played this game pretty regularly and had no problems before that :)
     
  7. 2010/10/03
    Whiskeyman Lifetime Subscription

    Whiskeyman Inactive Alumni

    Joined:
    2005/09/10
    Messages:
    1,772
    Likes Received:
    37
    Then it is probably a false positive.
     
  8. 2010/10/03
    TAYLORBOY

    TAYLORBOY Inactive Thread Starter

    Joined:
    2009/09/28
    Messages:
    30
    Likes Received:
    0
    I dont mean to be a pain, but how can I tell definitely if it is or not??

    When I delete the virus with avira, then the game is unplayable. When I reinstall the whole game from the file folder avira still flags it up, would you just ignore????
     
  9. 2010/10/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Since online check came clean, put that file into Avira exceptions.
     
  10. 2010/10/04
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    It could be because of it's behavior. For example; there is a program I use called Protected Storage PassView (pspv.exe), used to retrieve encrypted usernames and passwords from Internet Explorer and Outlook Express, contained in the registry. Avast flags it as a bad file to have. Why? For the code that it contains to decrypt Internet Explorer and Outlook usernames and passwords, the same type of code a trojan might possess. A false positive? If the file is known to be legit.
    As to why AOEII is doing this I do not know. I have AOEIII installed and get nothing from Avast on it.
    This page has the file creation date, file size, md5, and it's version number.
    December 31, 2005
    2,695,213 bytes
    version 2.1.0
    MD5: B1B52D891550029ADEFD6A0A5C33ECBE
    Using the MD5 you can verify if it is the very same exact file as released from Microsoft, any added or altered code would change the MD5. The below link has a MD5 checker.
    http://www.softpedia.com/progDownload/MD5-Checker-Download-22900.html
     
  11. 2010/10/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's the whole point.
    All AV programs are flagged by two types of files:
    - files, which are already in AV program database (no false positives here)
    - files, which are not there yet, but their pattern fits malicious files behavior (heuristic method, which may produce false positive)

    I also had couple of files from totally legit programs, which were flagged by Avast.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.