Jump to content



Photo
- - - - -

WARNING ! Malware loaded in latest 10.6 10/6/2019 upload!

Vpinball virus malware

  • Please log in to reply
6 replies to this topic

#1 WilsonB

WilsonB

    Enthusiast

  • Members
  • PipPipPip
  • 71 posts
  • Location:Colorado Springs

  • Flag: United States of America

  • Favorite Pinball: Funhouse

  • 360 Gamer Tag: GermanMeatBeatU

Posted 01 November 2019 - 04:55 AM

WARNING!!

 

Malware loaded in latest 10.6 10/6/2019 upload!!!

Packed.Win32.MUPX.Gen@1

VPinballX.exe

 

Verified with COMODO

 

 

Track down and BAN !

 

 

 


Oculus Quest w/ Virtual Desktop for Steam Oculus Rift emulation. Win 10 Pro64/i7-9700kCPU 3.6GHz /  Nvidia RTX 2080 Super


#2 Thalamus

Thalamus

    VPF Veteran

  • Platinum Supporter
  • 5,001 posts

  • Flag: Norway

  • Favorite Pinball: GOT, Alien Star, LOTR, TOM

Posted 01 November 2019 - 05:58 AM

My answer to that is - then COMODO sucks.

Have you tried to upload it to https://www.virustot...gui/home/upload and see what other virus scanners say about the file ?


From now on. I won't help anyone here at VPF. Please ask Noah why that is.


#3 toxie

toxie

    VPF Veteran

  • VP Dev Team
  • PipPipPipPipPipPip
  • 5,740 posts
  • Location:berlin, germany

  • Flag: Germany

  • Favorite Pinball: AFM

Posted 01 November 2019 - 10:43 AM

Yup, bogus false positive!



#4 DCLXVI

DCLXVI

    Neophyte

  • Members
  • Pip
  • 1 posts

  • Flag: France

  • Favorite Pinball: T2

Posted 23 November 2019 - 02:18 PM

Well that new release is very strange.

 

The installer itself VPX6setup.exe is detected as containing trojan/malware by 7 engines

 

https://www.virustot...873fc/detection

 

I don't see why it should access registries like :

  • HKLM\System\CurrentControlSet\Services\LDAP
  • HKLM\System\CurrentControlSet\Services\LDAP\UseOldHostResolutionOrder
  • HKLM\System\CurrentControlSet\Services\LDAP\UseHostnameAsAlias

 

The pinMane32.exe is detected by 3 engines

 

https://www.virustot...248f1/detection

 

Not sure why it's opening C:\Users\<USER>\Downloads ??? , It's also playing with LDAP, and it seems to be creating a lot of files, going all the places checking permissions of dlls.

 

And VPinballX.exe is detected by Comodo. Again not sure why it's accessing those registries.

 

https://www.virustot...eaeccab/details

  • \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\996E.exe
  • \Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
  • \Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
  • \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled
  • \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers

 

That does not look like a false positive.


Edited by DCLXVI, 23 November 2019 - 02:18 PM.


#5 zeek11

zeek11

    Neophyte

  • Members
  • Pip
  • 9 posts

  • Flag: Canada

  • Favorite Pinball: Tron

Posted 21 July 2021 - 03:27 PM

Hey team...had the same kick back when scanning the 10.7 file with Comodo. However, when scanned with Defender...no hits. ?



#6 Thalamus

Thalamus

    VPF Veteran

  • Platinum Supporter
  • 5,001 posts

  • Flag: Norway

  • Favorite Pinball: GOT, Alien Star, LOTR, TOM

Posted 21 July 2021 - 03:47 PM

Take 60 virus scanners - take almost any binary that can access hardware like vp does, there will be false positives. If you are in doubt. Source code is on github, vscode is free  - have at it.


From now on. I won't help anyone here at VPF. Please ask Noah why that is.


#7 zeek11

zeek11

    Neophyte

  • Members
  • Pip
  • 9 posts

  • Flag: Canada

  • Favorite Pinball: Tron

Posted 21 July 2021 - 04:56 PM

Understood and that's what I suspected. Thank you for the response. I will look forward to upgrading to 10.7 :otvclap: