Renegade Public Forums
C&C: Renegade --> Dying since 2003™, resurrected in 2024!
Home » General Discussions » General Discussion » Possible virus in renegadeserver.exe
Possible virus in renegadeserver.exe [message #433385] Sat, 24 July 2010 00:59 Go to next message
jonwil is currently offline  jonwil
Messages: 3555
Registered: February 2003
Karma: 0
General (3 Stars)

My AVG Anti-Virus reports that renegadeserver.exe from the renegade FDS is infected with a virus. Does anyone else get reports for that file?

Windows says the file is 94,208 bytes in size, does this match with what everyone else gets?

Just trying to confirm if its a genuine report or not.


Jonathan Wilson aka Jonwil
Creator and Lead Coder of the Custom scripts.dll
Renegade Engine Guru
Creator and Lead Coder of TT.DLL
Official member of Tiberian Technologies
Re: Possible virus in renegadeserver.exe [message #433387 is a reply to message #433385] Sat, 24 July 2010 01:13 Go to previous messageGo to next message
Goztow is currently offline  Goztow
Messages: 9726
Registered: March 2005
Location: Belgium
Karma: 13
General (5 Stars)
Goztoe
jonwil wrote on Sat, 24 July 2010 09:59

My AVG Anti-Virus reports that renegadeserver.exe from the renegade FDS is infected with a virus. Does anyone else get reports for that file?

Windows says the file is 94,208 bytes in size, does this match with what everyone else gets?

Just trying to confirm if its a genuine report or not.


My renegadeserver.exe is 27 KB (date: 19 Jan 2005)


You can find me in The KOSs2 (TK2) discord while I'm playing. Feel free to come and say hi! TK2 discord
Re: Possible virus in renegadeserver.exe [message #433390 is a reply to message #433385] Sat, 24 July 2010 01:49 Go to previous messageGo to next message
danpaul88 is currently offline  danpaul88
Messages: 5795
Registered: June 2004
Location: England
Karma: 0
General (5 Stars)
As far as I know renegadeserver.exe is just a launcher for server.dat anyway and you can just rename server.dat to server.exe and delete renegadeserver.exe.

http://steamsignature.com/card/1/76561197975867233.png
Re: Possible virus in renegadeserver.exe [message #433391 is a reply to message #433385] Sat, 24 July 2010 02:18 Go to previous messageGo to next message
Sladewill is currently offline  Sladewill
Messages: 291
Registered: January 2009
Location: United Kingdom
Karma: 0
Recruit

yes our AVG does that as well it goes as far as deleting it everytime so we have to keep putting it back on serverbox

FT-Owners - Sladewill,Snazy2007,Willdy
http://FT-Gaming.com for more info...
Re: Possible virus in renegadeserver.exe [message #433392 is a reply to message #433390] Sat, 24 July 2010 02:30 Go to previous messageGo to next message
Omar007 is currently offline  Omar007
Messages: 1711
Registered: December 2007
Location: Amsterdam
Karma: 0
General (1 Star)
danpaul88 wrote on Sat, 24 July 2010 10:49

As far as I know renegadeserver.exe is just a launcher for server.dat anyway and you can just rename server.dat to server.exe and delete renegadeserver.exe.

You could compare the renegadeserver.exe->server.dat(exe) relation with the client's Renegade.exe that launches Game.exe Thumbs Up


http://tiberiumredux.omarpakker.nl/Old Unused Parts/Plaatjes/PromoteBanner_Hades_small.jpg
Re: Possible virus in renegadeserver.exe [message #433393 is a reply to message #433385] Sat, 24 July 2010 02:31 Go to previous messageGo to next message
jonwil is currently offline  jonwil
Messages: 3555
Registered: February 2003
Karma: 0
General (3 Stars)

I sent the file to AVG as a "possible false positive" so they can confirm whether its a bogus report or not (and if its a bogus report, fix AVG in the next update to not report on it)


Jonathan Wilson aka Jonwil
Creator and Lead Coder of the Custom scripts.dll
Renegade Engine Guru
Creator and Lead Coder of TT.DLL
Official member of Tiberian Technologies
Re: Possible virus in renegadeserver.exe [message #433422 is a reply to message #433385] Sat, 24 July 2010 14:09 Go to previous messageGo to next message
Sladewill is currently offline  Sladewill
Messages: 291
Registered: January 2009
Location: United Kingdom
Karma: 0
Recruit

hopefully they will sort it out coz thats rlly annoying

FT-Owners - Sladewill,Snazy2007,Willdy
http://FT-Gaming.com for more info...
Re: Possible virus in renegadeserver.exe [message #434142 is a reply to message #433385] Mon, 02 August 2010 19:45 Go to previous messageGo to next message
jonwil is currently offline  jonwil
Messages: 3555
Registered: February 2003
Karma: 0
General (3 Stars)

The AVG team got back to me and said "there was virus code in those files" (both RenegadeServer.exe and Register.exe were triggering AVG) and sent the following files back as clean files:
http://www.cncmods.net/files/clean.zip

Given that others have reported this issue, it sounds like the actual FDS installer on the Westwood FTP may be infected with this virus.

If anyone has any information one way or the other (I doubt that all the people with problems actually have a virus that infected their RenegadeServer.exe files separately) please post here.
I am going to send an email to the new EA community guy explaining the situation so they can possibly look into it.


Jonathan Wilson aka Jonwil
Creator and Lead Coder of the Custom scripts.dll
Renegade Engine Guru
Creator and Lead Coder of TT.DLL
Official member of Tiberian Technologies
Re: Possible virus in renegadeserver.exe [message #434143 is a reply to message #433385] Mon, 02 August 2010 20:12 Go to previous messageGo to next message
Lone0001 is currently offline  Lone0001
Messages: 2112
Registered: August 2006
Location: Ontario, Canada
Karma: 0
General (2 Stars)

I'm not sure about that tbh, it sounds like a false positive to me.

Try downloading this one: http://downloads.cncfps.com/Westwood/renegade/dedicatedserver/renegade_fds_1037. exe I copied the entire westwood ftp and got it uploaded there, while downloading things I did not get any messages from my Anti-Virus (Nod32 ftw) saying something was infected.

PS. Is it the paid or free version of AVG? If free, why even use that still when Microsoft made a free Anti-Virus that would be 5x better, imo anyways.


Re: Possible virus in renegadeserver.exe [message #434145 is a reply to message #433385] Mon, 02 August 2010 20:34 Go to previous messageGo to next message
jonwil is currently offline  jonwil
Messages: 3555
Registered: February 2003
Karma: 0
General (3 Stars)

Its the free version.
And the MS product is NOT better than AVG, at least not on Windows XP.

Also, its not an infection in renegadefds_1037.exe, its an infection in a file inside RenegadeFDS_1037.exe (which your AV isn't likely to pick up since AVs dont generally understand that particular installer format and cant scan inside it)

I seriously doubt the AVG people would have said "those files you send do contain a virus, here are clean versions" (the clean versions ARE different to the other versions btw) unless they actually DID contain a virus.

I downloaded http://downloads.cncfps.com/Westwood/renegade/dedicatedserver/renegade_fds_1037. exe and unpacked it with an installer unpacker and the files in that one ALSO contain the virus.

The same register.exe (the one that causes AVG to trigger) was also shipped with various builds of RA:APB and was (after I told people to scan it) tripping several AV programs.


Jonathan Wilson aka Jonwil
Creator and Lead Coder of the Custom scripts.dll
Renegade Engine Guru
Creator and Lead Coder of TT.DLL
Official member of Tiberian Technologies
Re: Possible virus in renegadeserver.exe [message #434147 is a reply to message #433385] Mon, 02 August 2010 21:07 Go to previous messageGo to next message
Lone0001 is currently offline  Lone0001
Messages: 2112
Registered: August 2006
Location: Ontario, Canada
Karma: 0
General (2 Stars)

I'm still not sure tbh, I scanned a few copies register.exe (and renegadeserver.exe) from a few installers from a few different sources, none of them were detected as viruses, another Nod32 user (who also didn't detect them as viruses) I know has submitted both files to ESET (makers of Nod32) so I won't know for sure until he gets response back from them.

I'm not saying it's impossible that my AV could be wrong, that is still to be seen, I'm going to try a few different AVs now tbh.



[Updated on: Mon, 02 August 2010 21:09]

Report message to a moderator

Re: Possible virus in renegadeserver.exe [message #434148 is a reply to message #433385] Mon, 02 August 2010 21:19 Go to previous messageGo to next message
raven
Messages: 595
Registered: January 2007
Location: Toronto, Ontario
Karma: 0
Colonel
How odd..

both the RenegadeServer.exe executables were detected as viruses on the Jelly box.. they have since been replaced however its weird that this all just happened recently :\


-Jelly Administrator
-Exodus Administrator
Re: Possible virus in renegadeserver.exe [message #434150 is a reply to message #433385] Mon, 02 August 2010 21:35 Go to previous messageGo to next message
Craziac is currently offline  Craziac
Messages: 157
Registered: September 2007
Karma: 0
Recruit
I suppose they just added the definition recently. How odd.

http://demonshall.net/Stewie/images/OblivStewieSig.jpg
Re: Possible virus in renegadeserver.exe [message #434155 is a reply to message #433385] Tue, 03 August 2010 02:01 Go to previous messageGo to next message
snpr1101 is currently offline  snpr1101
Messages: 425
Registered: June 2007
Location: Australia
Karma: 0
Commander
IT'S A CONSPIRACY!

DUN DUN DUN

On a more serious note, this is quite odd, yes.

[Updated on: Tue, 03 August 2010 02:04]

Report message to a moderator

Re: Possible virus in renegadeserver.exe [message #434156 is a reply to message #433385] Tue, 03 August 2010 02:46 Go to previous messageGo to next message
jonwil is currently offline  jonwil
Messages: 3555
Registered: February 2003
Karma: 0
General (3 Stars)

Per (the new community guy at EA) said this
"Thank you for the heads up. I'll send it to the studio so they can make sure it gets sorted."


Jonathan Wilson aka Jonwil
Creator and Lead Coder of the Custom scripts.dll
Renegade Engine Guru
Creator and Lead Coder of TT.DLL
Official member of Tiberian Technologies
Re: Possible virus in renegadeserver.exe [message #434191 is a reply to message #433385] Tue, 03 August 2010 16:15 Go to previous messageGo to next message
Sladewill is currently offline  Sladewill
Messages: 291
Registered: January 2009
Location: United Kingdom
Karma: 0
Recruit

Talking of this avast reported it as a virus the other day, my pc then went into meltdown deleted all the exe files on my pc coz loads of temp files we're getting created. Then the computer was unusable had to reinstall windows on it.

FT-Owners - Sladewill,Snazy2007,Willdy
http://FT-Gaming.com for more info...
Re: Possible virus in renegadeserver.exe [message #434204 is a reply to message #433385] Tue, 03 August 2010 22:29 Go to previous messageGo to next message
Rocko
Messages: 833
Registered: January 2007
Location: Long Beach, California
Karma: 0
Colonel
yos'is just axd my homboi dat werk at EA clinnin the john and he da 1 who told me dat some1 put da viriz up in der fo payback about renegade 2 mel gibson style

black and proud
Re: Possible virus in renegadeserver.exe [message #434558 is a reply to message #433385] Wed, 11 August 2010 08:10 Go to previous messageGo to next message
trooprm02 is currently offline  trooprm02
Messages: 3266
Registered: August 2005
Location: Canada
Karma: 0
General (3 Stars)
I think just some style of code WW used as a "hack" to launch server.dat may have been copied (just by chance) in some new kind of virus/trojan...I wouldn't ever trust AVG, instead try uploading the individual .exe's to something like www.virustotal.com where it will be scanned by 20-30 different AV's at once.

[Updated on: Wed, 11 August 2010 08:10]

Report message to a moderator

Re: Possible virus in renegadeserver.exe [message #434693 is a reply to message #433385] Fri, 13 August 2010 05:48 Go to previous messageGo to next message
jonwil is currently offline  jonwil
Messages: 3555
Registered: February 2003
Karma: 0
General (3 Stars)

3 things here:
1.I did submit it to virus-total and a few others picked it up as well as AVG
2.Others have reported things other than AVG picking it up
and 3.The AVG team (who are presumably experts in their field) would not have sent me an email saying "the file you submitted does contain a virus, here is a cleaned file" unless it actually did contain one


Jonathan Wilson aka Jonwil
Creator and Lead Coder of the Custom scripts.dll
Renegade Engine Guru
Creator and Lead Coder of TT.DLL
Official member of Tiberian Technologies
Re: Possible virus in renegadeserver.exe [message #434731 is a reply to message #433385] Fri, 13 August 2010 13:04 Go to previous messageGo to next message
Rocko
Messages: 833
Registered: January 2007
Location: Long Beach, California
Karma: 0
Colonel
you should try installing it and see what it does to really confirm if it does have a virus or not

black and proud
Re: Possible virus in renegadeserver.exe [message #435561 is a reply to message #433385] Thu, 26 August 2010 11:50 Go to previous messageGo to next message
cnc95fan is currently offline  cnc95fan
Messages: 1260
Registered: July 2007
Karma: 0
General (1 Star)
I just did a scan there and Avast! found that the Register.exe in APB BETA, WDUMP.exe from Renegade Public Tools, Register.exe from the FDS and RenegadeServer.exe all contained the same "Injected AZ" thing.. I downloaded my FDS from Game-Maps

Cabal8616 wrote on Sun, 27 April 2008 15:50

I say a personal fanning of the genitals would be awesome.


RA3 AUTOMATICLY SUCKS
www.battlefordune.co.uk
Re: Possible virus in renegadeserver.exe [message #435597 is a reply to message #433385] Thu, 26 August 2010 22:15 Go to previous messageGo to next message
Gen_Blacky is currently offline  Gen_Blacky
Messages: 3250
Registered: September 2006
Karma: 1
General (3 Stars)
Must be a false positive the only thing RenegadeServer.exe does is launch server.dat and if crashes RenegadeServer.exe will restart server.dat. It might read some stuff from the config file. Like danpaul said just rename server.dat to somthing.exe and it will start the fds and if you close it wont try to restart. If you run server.dat instead of the luancher I think it will have problems with xwis.

Mine is the same as jonwills 92.0 KB (94,208 bytes). Microsoft
Security Essentials dosent pick anything up.


http://s18.postimage.org/jc6qbn4k9/bricks3.png

[Updated on: Thu, 26 August 2010 22:20]

Report message to a moderator

Re: Possible virus in renegadeserver.exe [message #435862 is a reply to message #434145] Mon, 30 August 2010 18:06 Go to previous messageGo to next message
The Party is currently offline  The Party
Messages: 546
Registered: February 2009
Location: Chapel Hill, NC
Karma: 0
Colonel
TrendMicro FTW!

War is Peace.
Ignorance is Strength.
Freedom is Slavery.
Re: Possible virus in renegadeserver.exe [message #435869 is a reply to message #433385] Mon, 30 August 2010 21:35 Go to previous messageGo to next message
jonwil is currently offline  jonwil
Messages: 3555
Registered: February 2003
Karma: 0
General (3 Stars)

Regardless of what different anti-virus programs pick up (or don't pick up), the AVG people (who's day job is reverse engineering and disassembling viruses) said that the files I sent them contained viruses. If these experts say they contain viruses (and have supplied files that dont contain viruses) then that's good enough for me to assume that there was SOMETHING wrong with the files.


Jonathan Wilson aka Jonwil
Creator and Lead Coder of the Custom scripts.dll
Renegade Engine Guru
Creator and Lead Coder of TT.DLL
Official member of Tiberian Technologies
Re: Possible virus in renegadeserver.exe [message #437425 is a reply to message #433385] Sun, 03 October 2010 19:11 Go to previous messageGo to previous message
halo2pac is currently offline  halo2pac
Messages: 659
Registered: December 2006
Location: Near Cleveland, Ohio
Karma: 0
Colonel
I believe the false positive comes from the register tool and the other exe checking the register for a 'serial' key. probably sends a harvesting Trojan false positive.

http://img339.imageshack.us/img339/1991/nefobbygenyunoreleasere.jpg
Rene-Buddy | Renegade X
Join the fight against Obsessive-Compulsive Posting Disorder. Cancel is ur friend.
*Renegade X Dev Team Member*
Previous Topic: Tanya was going to be in CnC Renegade?
Next Topic: Renegade is not dead
Goto Forum:
  


Current Time: Tue May 07 20:58:24 MST 2024

Total time taken to generate the page: 0.01154 seconds