AAO25.com

Assist => Feedback & Suggestions => Bug Reports => Topic started by: OICURMT2! on Sunday, July 14, 2013, 04:20:01 AM

Title: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 04:20:01 AM

25Assist v7.32 - AVG Threat Detection.

Screenshot enclosed.

(https://aao25.com/forum/proxy.php?request=http%3A%2F%2Fi115.photobucket.com%2Falbums%2Fn290%2FOh_I_See_You_Are_Empty%2FAUSAAO25%2F25Assist-AVGThreatDetection.png&hash=e85d7d12800b01a466a3fc229787a4d3)
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Possessed on Sunday, July 14, 2013, 04:34:31 AM
I don't think it has to do with assist, but: http://www.bleepingcomputer.com/forums/t/176761/virus-found-win32cryptor/
Title: Re: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 04:44:44 AM
Interesting v7.31 didn't do this...

v7.32 spawns an executable in the 25Assist (under roaming) area and then tries to execute it...

I'll check for Malware, I'm very careful about running software/programs.

OIC!
Title: Re: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 04:57:06 AM
I don't think it has to do with assist, but: http://www.bleepingcomputer.com/forums/t/176761/virus-found-win32cryptor/

The plot thickens... Malwarebyte detected nothing...  and we have another Aussie player who is in the same situation.

What is interesting is that the executable that 25Assist creates differs in name every time.  It is only created when you click on "Join Server".

I've never been able to use 25Assist to update, so I generally download the zipfile via a mirror.  I'll try a different mirror to see if the malware was put in the zipfile at the mirror repo.

OIC!
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Mixk on Sunday, July 14, 2013, 05:01:13 AM
Avast also says there is problem for me when I let assist update. I just told Avast to ignore it for now.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Possessed on Sunday, July 14, 2013, 05:02:45 AM
hmm
I packed my 25Assist.exe and uploaded the file to Jotti
http://virusscan.jotti.org/pt-br/scanresult/1290ab3ba4f4379cb456755c43544b8fed0a70b0
Title: Re: 25Assist v7.32 - AVG Detection
Post by: IGC Wolf^ on Sunday, July 14, 2013, 05:06:32 AM
i use avg too but didn't have any issues, no threats found on the latest update or any update at all.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Rob_LD on Sunday, July 14, 2013, 05:09:51 AM
@OICURMT2!

You should quarantine the file and send it over to the lab for review.
It maybe a false positive.

For more information see:
http://forums.avg.com/us-en/avg-forums?sec=thread&act=show&id=395
or
http://samplesubmit.avg.com/de-de/false-detection



You might as well send it to me to have it checked:
newmal (at) arcor (dot) de


@Possessed
Already done:
https://www.virustotal.com/de/file/b92071cb71ea66aac39a428ab83810145aa3d907d1482a66c13fcbfec6c166cb/analysis/
Title: Re: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 05:21:29 AM
@OICURMT2!

You should quarantine the file and send it over to the lab for review.
It maybe a false positive.

For more information see:
http://forums.avg.com/us-en/avg-forums?sec=thread&act=show&id=395
or
http://samplesubmit.avg.com/de-de/false-detection



You might as well send it to me to have it checked:
newmal (at) arcor (dot) de


@Possessed
Already done:
https://www.virustotal.com/de/file/b92071cb71ea66aac39a428ab83810145aa3d907d1482a66c13fcbfec6c166cb/analysis/

I've never known 25Assist to spawn randomly named executables.  Therefore, I have to conclude that either 25Assist was infected when zipped up or that somehow I have acquired malware.  I highly doubt if it is a false positive on a randomly named spawned exe file.

Looks like I'm in for the long haul to track this problem down...
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Possessed on Sunday, July 14, 2013, 05:21:35 AM
http://virusscan.jotti.org/pt-br/scanresult/cba6194006ba06f2559ea5225540b31f6309cafd
must be false a  positive, win 32 crypto is in the family http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Win32/Sefnit for other AV's, only 2 have triggered it and I checked for possible left dlls etc etc, found nothing,I checked msconfig and it has no new entries.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 05:22:30 AM
Avast also says there is problem for me when I let assist update. I just told Avast to ignore it for now.

Now there's a person willing to take a chance... lol
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Rob_LD on Sunday, July 14, 2013, 05:33:38 AM
@OICURMT2!

Quote
I've never known 25Assist to spawn randomly named executables.
It's not a randomly named file but the mutex of 25Asssist.exe.

While 25Assist.exe is the hard disk file, "vfcnp2v0.exe" is loaded to memory.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 05:34:24 AM
http://virusscan.jotti.org/pt-br/scanresult/cba6194006ba06f2559ea5225540b31f6309cafd
must be false a  positive, win 32 crypto is in the family http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Win32/Sefnit for other AV's, only 2 have triggered it and I checked for possible left dlls etc etc, found nothing,I checked msconfig and it has no new entries.

Your first link... does 25Assist spawn a randomly named executable? (gReUUMjG.exe  in this case)...
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Speedluke on Sunday, July 14, 2013, 05:35:40 AM
I have the same problem..Virus was found by AVG 2013.The name of virus is Win32/cryptor.I tried to check my aa pack by http://virusscan.jotti.org/en but it did not find anything.The virus is always opened by pressing "Join Game".
Title: Re: 25Assist v7.32 - AVG Detection
Post by: JonnyM on Sunday, July 14, 2013, 05:36:52 AM
Don't worry guys, that exe spawns everytime with a different file name to stop people tampering with it and preventing assist getting your hardware ID. Its about making life more difficult for hackers and thats always a good thing, shame its cauing false detections though.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Rob_LD on Sunday, July 14, 2013, 05:37:41 AM
We could bring this case to an end if even on AVG-user would follow those instructions:

Quote
For more information see:
http://forums.avg.com/us-en/avg-forums?sec=thread&act=show&id=395
or
http://samplesubmit.avg.com/de-de/false-detection
Title: Re: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 05:40:04 AM
@OICURMT2!
It's not a randomly named file but the mutex of 25Asssist.exe.

While 25Assist.exe is the hard disk file, "vfcnp2v0.exe" is loaded to memory.

Your first link... does 25Assist spawn a randomly named executable? (gReUUMjG.exe  in this case)...

Filename seems to change every time you hit "Deploy"
Title: Re: 25Assist v7.32 - AVG Detection
Post by: JonnyM on Sunday, July 14, 2013, 05:40:57 AM
Don't worry guys, that exe spawns everytime with a different file name to stop people tampering with it and preventing assist getting your hardware ID. Its about making life more difficult for hackers and thats always a good thing, shame its cauing false detections though.

i willl submit a false detection report to avg.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Mixk on Sunday, July 14, 2013, 05:41:15 AM
Now there's a person willing to take a chance... lol
LOL  I just tried to launch assist on my laptop and it is running AVG and it to gave an Win32/cryptor found and shuts assist down. It's definitely in the update.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 05:41:26 AM
We could bring this case to an end if even on AVG-user would follow those instructions:

Assuming it is a false positive...

Are you confirming it is?
Title: Re: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 05:42:25 AM
i willl submit a false detection report to avg.

Good enough for me... I'll include it in the white-list...
Title: Re: 25Assist v7.32 - AVG Detection
Post by: IGC Wolf^ on Sunday, July 14, 2013, 05:46:28 AM
Guys I cannot join the error comes up.

When I open the assist and try join the server the avg anti virus detects a threat called ''Cryptus''
(https://aao25.com/forum/proxy.php?request=http%3A%2F%2Flightpics.fr%2Fimages%2F2013%2F07%2F14%2Fq2tZ0.png&hash=ac29eba32838141a5ae9c9070ee25506)
Then the table with an error comes up:(https://aao25.com/forum/proxy.php?request=http%3A%2F%2Flightpics.fr%2Fimages%2F2013%2F07%2F14%2FPEmt5.png&hash=9b6cb25070f376bfb7b8f10c7686e6cf)
then it shuts down assist, please fix it i was able to play fine until new update.:(
Title: Re: 25Assist v7.32 - AVG Detection
Post by: JonnyM on Sunday, July 14, 2013, 05:48:12 AM
Have submitted a false positive report to AVG, you will have to wait until they update it. Until then you can white-list it or temporarily turn off avg.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Rob_LD on Sunday, July 14, 2013, 05:49:45 AM
You have to either make an exception for "25Assist.exe" or wait till an updated virus definition will be released.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: IGC Wolf^ on Sunday, July 14, 2013, 05:49:55 AM
Yeh turning off avg and joining the server works:) thanks jonny

Just turn off avg and it will work but now i get open slot kick...omg even tho my connection is very good.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Mixk on Sunday, July 14, 2013, 06:00:36 AM
Seeing a lot of people getting kicked for closed auth slot this morning then they rejoin and about two minutes they are getting kicked again.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: noobslayer on Sunday, July 14, 2013, 06:06:38 AM
same problem here mehhh, ill put my avg off
Title: Re: 25Assist v7.32 - AVG Detection
Post by: IGC Wolf^ on Sunday, July 14, 2013, 06:08:07 AM
fix the problem jonny i wanna play lol, yeh mixk same 2 min and getting kied all the time, tried pb reinstall nothing works
Title: Re: 25Assist v7.32 - AVG Detection
Post by: noobslayer on Sunday, July 14, 2013, 06:11:35 AM
Yeh turning off avg and joining the server works:) thanks jonny

Just turn off avg and it will work but now i get open slot kick...omg even tho my connection is very good.

turn avg off ''till you reboot pc''
you're probably clicking on ''temp avg off for 5 mins'' which causes it I guess.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: IGC Wolf^ on Sunday, July 14, 2013, 06:12:14 AM
no i turned it till i restart my laptop nothing works
Title: Re: 25Assist v7.32 - AVG Detection
Post by: BiG_SerGiO on Sunday, July 14, 2013, 06:14:58 AM
The problem isn0t Assist but people using AVG :P

Please install http://www.bitdefender.com/solutions/free.html ;)
Title: Re: 25Assist v7.32 - AVG Detection
Post by: IGC Wolf^ on Sunday, July 14, 2013, 06:16:10 AM
sergio but it was fine until the latest update, and this would mean removing avg from pc?
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Possessed on Sunday, July 14, 2013, 06:16:41 AM
sergio but it was fine until the latest update, and this would mean removing avg from pc?
no,
Title: Re: 25Assist v7.32 - AVG Detection
Post by: IGC Wolf^ on Sunday, July 14, 2013, 06:23:40 AM
The problem isn0t Assist but people using AVG :P

Please install http://www.bitdefender.com/solutions/free.html ;)

doesn't work
Title: Re: 25Assist v7.32 - AVG Detection
Post by: [SWISS]Merlin on Sunday, July 14, 2013, 07:06:55 AM
Don't worry guys, that exe spawns everytime with a different file name to stop people tampering with it and preventing assist getting your hardware ID. Its about making life more difficult for hackers and thats always a good thing, shame its cauing false detections though.

gj !
Title: Re: 25Assist v7.32 - AVG Detection
Post by: OICURMT2! on Sunday, July 14, 2013, 08:17:54 AM
The problem isn0t Assist but people using AVG :P

Please install http://www.bitdefender.com/solutions/free.html ;)

It isn't that simple... AVG may have a false positive this time, but maybe another AV may have it next time... best way is to make sure the fingerprint is registered with AV programs so that there is no further false positives...
Title: Re: 25Assist v7.32 - AVG Detection
Post by: IGC Wolf^ on Sunday, July 14, 2013, 08:20:24 AM
auth slot kick should be fixed now, it fixed mine.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Mixk on Sunday, July 14, 2013, 08:21:01 AM
It isn't that simple... AVG may have a false positive this time, but maybe another AV may have it next time... best way is to make sure the fingerprint is registered with AV programs so that there is no further false positives...
As I stated Avast says its a virus also.
Title: A Virus?
Post by: DailyWreak on Sunday, July 14, 2013, 09:00:36 AM
Hello so I try joining a server to play on and it comes up wit this message:

[ An exception of class NilObjectException was not handled. The application must shut down. ]

So I press Ok and aa25assist shuts down.

Then my antivirus detects a virus in my 25assist file so I remove it then I try getting into a server again, but the same message keeps popping up... :oops:

Can you guys please help?

Thanks.
Title: Re: A Virus?
Post by: Possessed on Sunday, July 14, 2013, 09:02:04 AM
what is your anti virus?
Title: Re: A Virus?
Post by: IGC Wolf^ on Sunday, July 14, 2013, 09:21:31 AM
Hello so I try joining a server to play on and it comes up wit this message:

[ An exception of class NilObjectException was not handled. The application must shut down. ]

So I press Ok and aa25assist shuts down.

Then my antivirus detects a virus in my 25assist file so I remove it then I try getting into a server again, but the same message keeps popping up... :oops:

Can you guys please help?

Thanks.


Disable your antivures and try joining the server, should be okay.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: krIz+ on Sunday, July 14, 2013, 09:24:32 AM
i dont have AV at all :)
Title: Re: A Virus?
Post by: noobslayer on Sunday, July 14, 2013, 09:36:13 AM

Disable your antivures and try joining the server, should be okay.

This... or ignore the ''virus'' with your antivirus, don't delete it and it will work aswell
Title: Re: 25Assist v7.32 - AVG Detection
Post by: DailyWreak on Sunday, July 14, 2013, 10:47:40 AM
Oooh thanks guys i've disabled my AVG for the meantime and yh it works thx a bunch <3
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Spanky on Sunday, July 14, 2013, 12:30:08 PM
Sounds like an overbearing anti-virus that slows your computer down. Real glad I stopped using AVG a long time ago.
Title: Re: 25Assist v7.32 - AVG Detection
Post by: Possessed on Wednesday, July 17, 2013, 10:59:35 AM
AVG no longer detects the file as a virus.

Before:
Detection Rate 5 / 45
2013-07-14 09:19:51 UTC

Now:
Detection Rate 4 / 45
2013-07-17 14:49:01 UTC

Still:
Ikarus
McAfee
McAfee-GW-Edition
TrendMicro-HouseCall

Title: Re: 25Assist v7.32 - AVG Detection
Post by: JonnyM on Wednesday, July 17, 2013, 12:08:20 PM
Not bothered about this anymore, in the next update the hwid will be read natively without external exe.