View Full Version : ESS Error with Japan Sudden Attack...
icekiller
December 4th, 2008, 02:01 AM
Im trying to play Sudden Attack the FPS game thats in Japanese, When I go to update I keep getting this error.
-{ Quote: "12/3/2008 10:51:57 PM HTTP filter file http://gamehi.nefficient.jp/./gamehi/suddenattack/sa_patch/suddenattack.exe.cab a variant of Win32/Packed.Themida application connection terminated - quarantined WHAT-A846AA8E8F\icekiller Threat was detected upon access to web by the application: C:\Program Files\RedBanana\SuddenAttack\GHSALNCR.exe." }-
-{ Quote: "12/3/2008 10:48:18 PM HTTP filter file http://gamehi.nefficient.jp/./gamehi/suddenattack/sa_patch/game/cshell.dll.cab a variant of Win32/Packed.Themida application connection terminated - quarantined WHAT-A846AA8E8F\icekiller Threat was detected upon access to web by the application: C:\Program Files\RedBanana\SuddenAttack\GHSALNCR.exe." }-
Im on Virus DB - 3662
Any idea mates?
Kayracc
December 4th, 2008, 02:43 AM
-{ Quote: "Im trying to play Sudden Attack the FPS game thats in Japanese, When I go to update I keep getting this error.
Im on Virus DB - 3662
Any idea mates?" }-
send them the link
but it's detecting the packer, meaning it's not malicious, it just uses the same packer that many malicious programs use to hide themselves
Marcos
December 4th, 2008, 05:16 AM
You have enabled potentially unwanted applications. The file detected is packed with Themida, a packer that is often misused by malware to evade detection. If you are certain that a file detected as a potentially unsafe/unwanted application is downloaded by legit software, simply exclude it from detection. V4 will alert you with a yellow alert window in the case of usafe/unwanted applications and will always offer you an action to take (e.g. Disconnect / No action).
funkydude
December 4th, 2008, 06:51 AM
A better option would be to exclude that game from http filtering, put a cross in it in web browsers. Although I'm not sure if it's such a great idea false positive wise to be detecting anything packed this way, that's ESET's choice.
Marcos
December 4th, 2008, 09:49 AM
-{ Quote: "Although I'm not sure if it's such a great idea false positive wise to be detecting anything packed this way, that's ESET's choice." }-
To puth things right, if the vendors were building Themida-packed applications properly, they wouldn't be detected. Oreans, the vendor of Themida, already agreed with the rules for Themida detection. It's not at all that every Themida-packed file is reported as an unwanted application ;)
icekiller
December 4th, 2008, 10:55 AM
-{ Quote: "You have enabled potentially unwanted applications. The file detected is packed with Themida, a packer that is often misused by malware to evade detection. If you are certain that a file detected as a potentially unsafe/unwanted application is downloaded by legit software, simply exclude it from detection. V4 will alert you with a yellow alert window in the case of usafe/unwanted applications and will always offer you an action to take (e.g. Disconnect / No action)." }-
Could you further explain how to do this?
Marcos
December 4th, 2008, 11:25 AM
-{ Quote: "Could you further explain how to do this?" }-
If you develop applications and use Themida to protect them, please PM me with a link to the website where the application can be downloaded from and we'll provide you with more details.
icekiller
December 4th, 2008, 02:20 PM
It won't let me send a Pm, Im currently at school but the games website is at
"suddenattack.redbanana.jp"
the game is in Japanese FYI. Since I cannot send a pm could you please post details on how to allow the game. Thanks Marcos
-Justin
Marcos
December 4th, 2008, 02:25 PM
-{ Quote: "It won't let me send a Pm, Im currently at school but the games website is at
"suddenattack.redbanana.jp"
the game is in Japanese FYI. Since I cannot send a pm could you please post details on how to allow the game. Thanks Marcos
-Justin" }-
Since you're referring to that game and not your own application packed with Themida, I can only suggest you the following:
- disable unwanted applications. You must have enabled them intentionally during installation and thus you agreed with detection of packers often misused by malware as well.
- exclude that url and the whole game folder from scanning
icekiller
December 4th, 2008, 07:15 PM
I did everything you said and Im still getting the same errors.
http://i33.tinypic.com/1z3awqv.png
http://i34.tinypic.com/2q33er4.png
Marcos
December 5th, 2008, 04:02 AM
-{ Quote: "I did everything you said and Im still getting the same errors.
http://i33.tinypic.com/1z3awqv.png
http://i34.tinypic.com/2q33er4.png" }-
The HTTP exlusions don't commence with *, that's why it doesn't work. Also disabling potentially unwanted applications in the web protection setup would work.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums