Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
9,377
82,681
with me it actually responded in less than 1 minute, so woudn't count on the 10 minute rule imo
Its in the script though.
Actually it creates a timestamp file. (thats prob what your antivir detected)
Then if the the timestamp file exist after another 10 minutes it downloads stuff.
 
  • Thinking Face
Reactions: DragonsFear

DragonsFear

Member
Jan 8, 2022
143
145
Its in the script though.
Actually it creates a timestamp file. (thats prob what your antivir detected)
Then if the the timestamp file exist after another 10 minutes it downloads stuff.
casn it be counting up, so lets say multiple runs of 1 or 2 minutes that triggers it ? (after 10 minutes in total ? )
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
9,377
82,681
casn it be counting up, so lets say multiple runs of 1 or 2 minutes that triggers it ? (after 10 minutes in total ? )
10 minutes twice:

if datetime.now() - first_run < timedelta(minutes=10):
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
9,377
82,681
Which file has this script?
Maybe only R3 is affected? I played R1-R2
Yes only R3 was affected.
it was the leaked latest update for r3, you can safely download the old r3 version
The links are now fine I cleaned it up and reuploaded PC (that was the only version affected).

Also my compression is and was fine.
 

SonsOfLiberty

Board Buff
Compressor
Sep 3, 2022
18,449
151,454
Hmm. I used a Sandbox to test and check, got no warnings etc. It also list every try to connect to the internet, etc. Gonna inform Sam.

WELL MOTHER FUCKER
It can hide from VM"s and the like.

Trojan:Win32/Wacatac.H!ml can evade detection by performing checks to ensure it is not being executed in a debug environment, on a virtual machine, or in a banned country. While being present in nearly any malware, country checks are most commonly seen in malware that originates from ex-USSR countries.

Additionally, it establishes persistence in the attacked environment by creating a randomly named copy in a random directory in the AppData or LocalAppData folder of a user directory and adding a corresponding value to the Run entry of the system registry. By doing this, malware makes itself harder to stop and remove, ensuring that its execution will not be interrupted by restarts or file deletion.

Wacatac.H!ml is also a false positive in a lot of cases as well due to the nature of machine learning, it was the one that was going around during the last "big" outbreak and most, if not, all were false positives.

Machine Learning or Artificial Intelligence detection.

Machine Learning is a system at your antivirus developer that tries to identify features common to malware. It could be any kind of malware, could be a potentially unwanted program(ie. adware), could be a false positive.
 
  • Like
Reactions: pitao

Badjourasmix

Conversation Conqueror
Sep 22, 2017
6,755
15,085
It can hide from VM"s and the like.




Wacatac.H!ml is also a false positive in a lot of cases as well due to the nature of machine learning, it was the one that was going around during the last "big" outbreak and most, if not, all were false positives.
So as long as you're running the game on a sandbox or VM it won't activate?
 

SonsOfLiberty

Board Buff
Compressor
Sep 3, 2022
18,449
151,454
So as long as you're running the game on a sandbox or VM it won't activate?
It can from what I've read, if you want to do a deep dive, just Google/Bing the name.

You will see it can be dangerous and as you can see on the A/V threads on Reddit be the worst pita false positive possible.

You can also use something like this and have more control of what access's the internet.

For firewall to monitor or allow connections (I've said and some others) some good add-on apps for Windows Firewall.

- Can watch everything and see where it goes to, free just has monitor.

- Gives more control and can allow/block as everything is blocked at first and you have to allow

- Same as above, both small and lightweight, basically zero footprint.
 

Badjourasmix

Conversation Conqueror
Sep 22, 2017
6,755
15,085
It can from what I've read, if you want to do a deep dive, just Google/Bing the name.

You will see it can be dangerous and as you can see on the A/V threads on Reddit be the worst pita false positive possible.

You can also use something like this and have more control of what access's the internet.
In sandboxie I have it so anything running in the sandbox can't connect to the internet. Would that be enough?
 

lawlawkagurL

Active Member
Nov 12, 2021
732
514
I read a few pages back coz of the commotion and I believe it's something urgent.

Question, is this game safe to download as of this time? Has there been a remedy already to the situation or should we hold off for a bit until the f95 team sort this threat out or at least get a non-virus copy of the latest game?
thank you.
 

Badjourasmix

Conversation Conqueror
Sep 22, 2017
6,755
15,085
I read a few pages back coz of the commotion and I believe it's something urgent.

Question, is this game safe to download as of this time? Has there been a remedy already to the situation or should we hold off for a bit until the f95 team sort this threat out or at least get a non-virus copy of the latest game?
thank you.
The links have been udpated to a clean version so it is safe to download now. If you want to be extra safe, you can download a sandbox software and run the game from there.
 
Jun 5, 2023
26
29
I did a full scan with Windows Defender and it said 0 threats detected but my PC restarted randomly, am I just being paranoid or is my PC still infected?
 

Badjourasmix

Conversation Conqueror
Sep 22, 2017
6,755
15,085
More than likely, the next logical step though is to make it effect save files, as there have been instances of infected save files.
Well if save files can also be infected, that kind of defeats the purpose of using it since I can't use the saves outside of the sandbox. I guess I will just have to wait a few days after a game is posted before I download it and see if no one has reported any infections.
 
4.30 star(s) 108 Votes