- May 16, 2019
- 25
- 31
That's because it's an „System Watcher“ detection, which is a 0-Day component in „Kaspersky“ which checks for ransomware, system file edits or RAT activity, it is extremely good tool, in a league of it's on in terms of AV standards, the only time I personally got such a false flag, was running a „Windows memory rearranging script along with other system file editing script“, this game shouldn't make such a flag, since it doesn't have an „Anti-Cheat or DRM (Like „Starforce“)“Kaspersky stopped the game and deleted it as a trojan. this is a first. I launched the game and was skipping the text. As soon as i got to the main part of the game Kaspersky shows that it found a trojan in the game and suggests curing. The game files were clean when i checked the zip.
Now analysis, the main file in question has capabilities of recording your screen and it also has administrator regulatory mode.
NOW THE BIG THING! It has an malware downloader, which connect's to a server using a Buer Loader with a string name
of: „ ;A;];k;w; “
SHA256:
1bac8144a7b4af7b5e887f98053361c29a08fea890fe734ac3502ba4cca0f169