Sven Co-op

Sven Co-op

 This topic has been pinned, so it's probably important
Adambean  [developer] 21 Apr, 2019 @ 3:04pm
-- PLEASE READ -- Trojan detected in "svends.exe"
We are well aware of releases 5.19 and 5.20 becoming flagged by some (2nd rate) anti-virus solutions, mainly BitDefender, for having a trojan. Typically this is infection named similar to "Trojan.Heur.Hype.qv0@amPrru" and is found (and I use the word "found" wrongly) within our dedicated server launcher executable, "SvenDS.exe".

We've already reported this as a false positive report multiple times, however the vendors involved don't seem to care. We do not consider those vendors reputable at all if they can't even favour us with a response. If you're unsure whether to trust our binary files and want a second opinion, that's fine, you can submit them to a multi-vendor scanning tool such as VirusTotal[www.virustotal.com] or Jotti's scanner[virusscan.jotti.org]. You'll see that the majority of the vendors return "clean" with only a minority showing a heuristics match (but not a definite match), which is a good consensus that the file you sent for scanning is very legitimate.

Looking more specifically into the threat name, it's a subset of "Heur", which means heuristics mechanism. This is a technique used in an attempt to detect currently unknown/unconfirmed threats by the behaviour of the binary instructions, which does not make the detection true or verified even slightly. You can read more about how heuristics work (if you care) here: https://en.wikipedia.org/wiki/Heuristic_analysis

Heuristic analysis is capable of detecting many previously unknown viruses and new variants of current viruses. However, heuristic analysis operates on the basis of experience (by comparing the suspicious file to the code and functions of known viruses). This means it is likely to miss new viruses that contain previously unknown methods of operation not found in any known viruses. Hence, the effectiveness is fairly low regarding accuracy and the number of false positives.

Finally the "qv0@amPrru" on the end is a random generation because the threat detected by heuristics has no well known name/meaning, which will be pending further investigation by your anti-virus vendor. They may decide to realise this as a false positive, a genuine threat (thus giving it a real name), or nothing at all. (This can take a long time for files with low match rates.)

Please do not open further threads about a virus or trojan being found unless this explanation really doesn't answer your query.
< >
Showing 1-2 of 2 comments
Adambean  [developer] 29 Jan, 2021 @ 10:37am 
To elaborate further, Windows Defender is now claiming that "svends.exe" contains threats "Trojan:Win32/Wacatac.B!ml[www.microsoft.com]", Trojan:Win32/Woreflint.A!cl[www.microsoft.com], and Trojan:Win32/CryptInject!ml[www.microsoft.com]. This is nonsense, and we're awaiting a deeper analysis from Microsoft to rectify this.

--

Update: Microsoft have accepted our opinion that "svends.exe" is not malicious, and have stated their detection will be removed.

https://cdn.discordapp.com/attachments/170051548284583937/804862554068615188/unknown.png

1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender 2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures” 3. Run "MpCmdRun.exe -SignatureUpdate"
Last edited by Adambean; 29 Jan, 2021 @ 4:02pm
< >
Showing 1-2 of 2 comments
Per page: 1530 50