Spyware/Adware in Natural Selection 2?

CupOfSquirrelsCupOfSquirrels Join Date: 2010-05-31 Member: 71910Members
edited May 2010 in NS2 General Discussion
Hi guys, I have the NS2 special pre-order on my Steam account, and today got the following message from my anti-virus, F-Secure:

<!--quoteo--><div class='quotetop'>QUOTE </div><div class='quotemain'><!--quotec-->Spyware deteced:
Type: adware
Family:
Name: AdWare.Win32.AdMedia
Object: C:\Program Files\Steam\steamapps\common\natural selection 2\Builder.exe<!--QuoteEnd--></div><!--QuoteEEnd-->

It says the same about the Cinematic Editor.exe and LaunchPad.exe.

This may just be my anti-virus being paranoid, or the .exes became somehow infected by external malware, but I just thought I'd let you guys and the Unknown Worlds team know about it. Has anyone else encountered this?

Comments

  • ObraxisObraxis Subnautica Animator & Generalist, NS2 Person Join Date: 2004-07-24 Member: 30071Super Administrators, Forum Admins, NS1 Playtester, Forum Moderators, NS2 Developer, Constellation, NS2 Playtester, Squad Five Silver, WC 2013 - Supporter, Subnautica Developer, Pistachionauts
    False positive. Happens every now and then.
  • MaxMax Technical Director, Unknown Worlds Entertainment Join Date: 2002-03-15 Member: 318Super Administrators, Retired Developer, NS1 Playtester, Forum Moderators, NS2 Developer, Constellation, Subnautica Developer, Pistachionauts, Future Perfect Developer
    We scan with AVG and McAffee which don't show any problems.
  • cmc5788cmc5788 Join Date: 2009-10-06 Member: 68959Members
    edited May 2010
    Yeah I think I saw this answered on the bug report site for the engine test awhile back and it was confirmed to be a false positive. Norton's?
  • Dalin SeivewrightDalin Seivewright 0x0000221E Join Date: 2007-10-20 Member: 62685Members, Constellation
    <!--quoteo(post=1772941:date=May 31 2010, 12:02 PM:name=Max)--><div class='quotetop'>QUOTE (Max @ May 31 2010, 12:02 PM) <a href="index.php?act=findpost&pid=1772941"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->We scan with AVG and McAffee which don't show any problems.<!--QuoteEnd--></div><!--QuoteEEnd-->

    Not that I think there are any problems, but for spyware, I think you should stick with SpyBot/Adaware (conflicting) and Malwarebytes' Anti-malware. AVG and McAffee are historically for Viruses, whether the have newer features for covering spyware or not.
  • PipiPipi Join Date: 2009-12-09 Member: 69550Members
    It's certainly a false positive. I've scanned it with Bitdefender. Anyone has NOD32 could do it too, if both aren't detecting anything, there's probably nothing to it.

    For a second I thought guys at UWE have a super duper ninja spyware that is checking if we're still playing NS1 ... o_0
  • OnozkiOnozki Join Date: 2005-04-20 Member: 48948Members, Reinforced - Supporter
    <!--quoteo(post=1772951:date=May 31 2010, 04:37 PM:name=Pipi)--><div class='quotetop'>QUOTE (Pipi @ May 31 2010, 04:37 PM) <a href="index.php?act=findpost&pid=1772951"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->For a second I thought guys at UWE have a super duper ninja spyware that is checking if we're still playing NS1 ... o_0<!--QuoteEnd--></div><!--QuoteEEnd-->


    No need for that. The microchip in your brain works much better for that cause.
  • MaxMax Technical Director, Unknown Worlds Entertainment Join Date: 2002-03-15 Member: 318Super Administrators, Retired Developer, NS1 Playtester, Forum Moderators, NS2 Developer, Constellation, Subnautica Developer, Pistachionauts, Future Perfect Developer
    <!--quoteo(post=1772950:date=May 31 2010, 01:04 PM:name=Dalin Seivewright)--><div class='quotetop'>QUOTE (Dalin Seivewright @ May 31 2010, 01:04 PM) <a href="index.php?act=findpost&pid=1772950"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->Not that I think there are any problems, but for spyware, I think you should stick with SpyBot/Adaware (conflicting) and Malwarebytes' Anti-malware. AVG and McAffee are historically for Viruses, whether the have newer features for covering spyware or not.<!--QuoteEnd--></div><!--QuoteEEnd-->
    Well, checking for spyware doesn't really make sense since we wrote the code! If our build machine had a virus, then the exe could be infected and modified before we released it, which is why we run virus checkers.
  • FehaFeha Join Date: 2006-11-16 Member: 58633Members
    Besides, a good game is usually also a good spyware (think tf2 and many other valve games). It should keep statistics over what kind of stuff is used and such, as that makes it much more easy for devs to balance the game.

    What is more problematic to justify would however be if they spied on external data.
  • cmc5788cmc5788 Join Date: 2009-10-06 Member: 68959Members
    <!--quoteo(post=1773002:date=Jun 1 2010, 08:31 AM:name=Feha)--><div class='quotetop'>QUOTE (Feha @ Jun 1 2010, 08:31 AM) <a href="index.php?act=findpost&pid=1773002"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->What is more problematic to justify would however be if they spied on external data.<!--QuoteEnd--></div><!--QuoteEEnd-->

    I could see some sort of cheating-prevention system using this kind of behavior in theory, but that's certainly not what's going on here.
  • steppin'razorsteppin'razor Join Date: 2008-09-18 Member: 65033Members, Constellation
    <!--quoteo(post=1773008:date=Jun 2 2010, 12:21 AM:name=cmc5788)--><div class='quotetop'>QUOTE (cmc5788 @ Jun 2 2010, 12:21 AM) <a href="index.php?act=findpost&pid=1773008"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->I could see some sort of cheating-prevention system using this kind of behavior in theory, but that's certainly not what's going on here.<!--QuoteEnd--></div><!--QuoteEEnd-->
    I think that is what WoW's warden thing does.
  • cmc5788cmc5788 Join Date: 2009-10-06 Member: 68959Members
    <!--quoteo(post=1773009:date=Jun 1 2010, 09:22 AM:name=steppin'razor)--><div class='quotetop'>QUOTE (steppin'razor @ Jun 1 2010, 09:22 AM) <a href="index.php?act=findpost&pid=1773009"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->I think that is what WoW's warden thing does.<!--QuoteEnd--></div><!--QuoteEEnd-->

    Yeah, it reads process names and compares them to known "bad" programs. It doesn't set off any virus/adware detection alerts as far as I know, though.
  • EvilSmooEvilSmoo Join Date: 2008-02-16 Member: 63662Members
    6/9/2010 1:47:29 AM Detected: not-a-virus:AdWare.Win32.AdMedia.kq E:\Games\Steam\SteamApps\common\natural selection 2\Builder.exe
    6/9/2010 1:47:29 AM Detected: not-a-virus:AdWare.Win32.AdMedia.ko E:\Games\Steam\SteamApps\common\natural selection 2\Cinematic Editor.exe
    6/9/2010 1:47:34 AM Detected: not-a-virus:AdWare.Win32.AdMedia.kn E:\Games\Steam\SteamApps\common\natural selection 2\LaunchPad.exe
    6/9/2010 1:47:36 AM Detected: not-a-virus:AdWare.Win32.AdMedia.kp E:\Games\Steam\SteamApps\common\natural selection 2\Viewer.exe

    Yeah, somehow it managed to hit false positives in all 4 for Kaspersky. :/
  • TravCarpTravCarp Join Date: 2010-06-04 Member: 71962Members, Reinforced - Supporter
  • DarthNinjaDarthNinja Join Date: 2010-06-16 Member: 72067Members
    <!--quoteo(post=1774045:date=Jun 9 2010, 01:49 AM:name=EvilSmoo)--><div class='quotetop'>QUOTE (EvilSmoo @ Jun 9 2010, 01:49 AM) <a href="index.php?act=findpost&pid=1774045"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->6/9/2010 1:47:29 AM Detected: not-a-virus:AdWare.Win32.AdMedia.kq E:\Games\Steam\SteamApps\common\natural selection 2\Builder.exe
    6/9/2010 1:47:29 AM Detected: not-a-virus:AdWare.Win32.AdMedia.ko E:\Games\Steam\SteamApps\common\natural selection 2\Cinematic Editor.exe
    6/9/2010 1:47:34 AM Detected: not-a-virus:AdWare.Win32.AdMedia.kn E:\Games\Steam\SteamApps\common\natural selection 2\LaunchPad.exe
    6/9/2010 1:47:36 AM Detected: not-a-virus:AdWare.Win32.AdMedia.kp E:\Games\Steam\SteamApps\common\natural selection 2\Viewer.exe

    Yeah, somehow it managed to hit false positives in all 4 for Kaspersky. :/<!--QuoteEnd--></div><!--QuoteEEnd-->
    I'm getting those 4 with Zone Alarm as I posted <a href="http://www.unknownworlds.com/ns2/forums/index.php?showtopic=109848&st=0&gopid=1775022" target="_blank">Here</a>.
  • WhiteZeroWhiteZero That Guy Join Date: 2004-06-24 Member: 29511Members, Constellation
    edited August 2010
    Something in the exes are probably just setting off some scanner's heuristics, creating a false positive.
    If you are even concerned about a FP, just send the file to VirusTotal.com and get better confirmation.
    <a href="http://www.virustotal.com/file-scan/report.html?id=519b30fbbb846396205f77598929eafeea263bb182d7f16e9d56ca82d4d808df-1282737206" target="_blank">http://www.virustotal.com/file-scan/report...08df-1282737206</a>

    Also, Max... AVG and McAfee? For shame...
    I do a lot of virus/anti-virus research, and those two tend to disappoint. Especially when McAfee released that deffinition update that brought 10s of thousands of PCs to their knees by detecting a critical Windows system file and deleting it. haha
    However, they are far better than nothing and using the two in conjuncture helps confirm FPs.

    NOD32, Kaspersky, and avast! are at the top of my recommendations.

    <!--quoteo(post=1796220:date=Aug 25 2010, 07:17 AM:name=gone09)--><div class='quotetop'>QUOTE (gone09 @ Aug 25 2010, 07:17 AM) <a href="index.php?act=findpost&pid=1796220"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->Hello.I have scanned with Kasperky antivirus but i did not find any viruses.I am sure that my antivirus is a good one because I updated it from top ten best antiviruses <a href="http://www.best-antivirus.co/" target="_blank">http://www.best-antivirus.co/</a>
    good luck<!--QuoteEnd--></div><!--QuoteEEnd-->
    Never trust "Top Ten" sites like that.
    I'd go somewhere like <a href="http://www.av-comparatives.org/index.php" target="_blank">AV Comparatives</a> or <a href="http://www.virusbtn.com/index" target="_blank">Virus Bulletin</a>.
  • AvalonAvalon Join Date: 2007-03-04 Member: 60224Members
    <!--quoteo(post=1772941:date=May 31 2010, 07:02 PM:name=Max)--><div class='quotetop'>QUOTE (Max @ May 31 2010, 07:02 PM) <a href="index.php?act=findpost&pid=1772941"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->We scan with AVG and McAffee which don't show any problems.<!--QuoteEnd--></div><!--QuoteEEnd-->

    Max, I'd recommend MSE, Avast, or Avira over AVG for your free anti virus. They all have better detection rates, and generally are much more light on system resources. Just a friendly heads up!
  • WhiteZeroWhiteZero That Guy Join Date: 2004-06-24 Member: 29511Members, Constellation
    edited August 2010
    <!--quoteo(post=1796233:date=Aug 25 2010, 09:36 AM:name=Avalon)--><div class='quotetop'>QUOTE (Avalon @ Aug 25 2010, 09:36 AM) <a href="index.php?act=findpost&pid=1796233"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->Max, I'd recommend MSE, Avast, or Avira over AVG for your free anti virus. They all have better detection rates, and generally are much more light on system resources. Just a friendly heads up!<!--QuoteEnd--></div><!--QuoteEEnd-->
    They may be using the pay-for version of AVG. Either way, it's fairly lame. Although, it's better than McAfee.
    MSE is great for mom-and-pop home users, but I wouldn't recommend it for power-users, you can't tweak it at all.
  • WatchMakerWatchMaker Join Date: 2003-09-26 Member: 21233Members, Constellation
    Is it just me, or does talking about what anti-virus programs the team use and why they use them seem like a bad idea? I don't really see someone on these forums going the distance to do anything malicious, but the last thing I want to see is NS2 go down in indie history as the botnet we paid to join! (See, now I'm doing it.)
  • WhiteZeroWhiteZero That Guy Join Date: 2004-06-24 Member: 29511Members, Constellation
    <!--quoteo(post=1796249:date=Aug 25 2010, 11:28 AM:name=WatchMaker)--><div class='quotetop'>QUOTE (WatchMaker @ Aug 25 2010, 11:28 AM) <a href="index.php?act=findpost&pid=1796249"><{POST_SNAPBACK}></a></div><div class='quotemain'><!--quotec-->Is it just me, or does talking about what anti-virus programs the team use and why they use them seem like a bad idea? I don't really see someone on these forums going the distance to do anything malicious, but the last thing I want to see is NS2 go down in indie history as the botnet we paid to join! (See, now I'm doing it.)<!--QuoteEnd--></div><!--QuoteEEnd-->
    Yeah, bet we're bored and need something to talk about.

    Thread lock or move in 3..2...1....
  • FocusedWolfFocusedWolf Join Date: 2005-01-09 Member: 34258Members
    I just scanned the NS2 folder with Norton 360 v4 and got "No viruses or spyware detected".
  • BRICEBRICE Join Date: 2010-07-16 Member: 72453Members
    In my case ignorance is bliss :)
    Dont ask and i dont say xD
  • WheeeeWheeee Join Date: 2003-02-18 Member: 13713Members, Reinforced - Shadow
    <a href="http://www.virustotal.com/" target="_blank">http://www.virustotal.com/</a>

    i just scanned all 4 of them and there was nothing.
  • WhiteZeroWhiteZero That Guy Join Date: 2004-06-24 Member: 29511Members, Constellation
    If you <b>really</b> wanna see what a potential virus infected file does, try <a href="http://www.threatexpert.com/submit.aspx" target="_blank">http://www.threatexpert.com/submit.aspx</a>
Sign In or Register to comment.