Log inRegister an accountBrowse CSDbHelp & documentationFacts & StatisticsThe forumsAvailable RSS-feeds on CSDbSupport CSDb Commodore 64 Scene Database
You are not logged in - nap
CSDb User Forums


Forums > C64 Coding > ICU64 suddenly gone?
2024-03-23 21:10
ws

Registered: Apr 2012
Posts: 228
ICU64 suddenly gone?

I just observed that my ICU64 is suddenly gone, and after getting the "Sorry, but this file contains a virus" warning upon trying to re-download it from the official google drive, i noticed that my antivirus quietly has anihilated the file, reason : "Trojan Generik.LBYTBYU".

I already contacted mathfigure about it, but i cannot believe that this is anything else but a false positive.
 
... 4 posts hidden. Click here to view all posts....
 
2024-03-24 06:19
ws

Registered: Apr 2012
Posts: 228
It seems that only this version of ICU64 for VICE from CSDb acts the same as the version from mathfigures google drive (that version is inaccessible now):
ICU64 for VICE 3.x V0.1.3
The frodo versions are not impacted.

But this version of ICU for VICE is now also useless, since it reqires the icu64.exe of the "flagged" version above:
ICU64 for VICE 3.7 V0.1.3
2024-03-24 10:59
Martin Piper

Registered: Nov 2007
Posts: 634
Quote: huh... totally no idea what to make of this https://www.virustotal.com/gui/file/980e8d8750aa8a66a8e02183cd2..

This looks like a heuristic scan result, meaning it saw some code that was similar to code used in another virus, but it wasn't a precise match and it might or might not be malicious.

But given ICU64 launches a process and uses some form of process memory injection or inspection to get the emulated C64 memory, then this might itself be flagged as "maybe suspicious". I mean, doing such things with external processes is often used by suspicious code, so it's not a surprise it gets flagged during a scan.

But in this case we know ICU does this kind of process tweaking for legitimate reasons, so it's probably safe to ignore unless there is an exact and specific match with a known virus.
2024-03-24 12:18
tlr

Registered: Sep 2003
Posts: 1714
Quoting Martin Piper
But in this case we know ICU does this kind of process tweaking for legitimate reasons, so it's probably safe to ignore unless there is an exact and specific match with a known virus.

Some antivirus programs just rip away the binary on the fly and don't let you override that though.

Sometimes there isn't even a warning about it. I'm pointing at you windows defender!
2024-03-24 13:02
Fungus

Registered: Sep 2002
Posts: 616
This is due to AV's not being anything other than garbage anymore and they use "AI" which is so smart all it does it check that string literals match some crap someone reported. It will mistake EXE files for js exploits etc (defender is the worst at this) but other AV companies trade signatures and they get out there and then perfectly legit stuff is flagged. It's incredibly annoying...
2024-03-24 16:26
ws

Registered: Apr 2012
Posts: 228
I have now submitted the .exe alongside a false positive mail, according to their rules, to ESET. Lets see if they can grasp the idiocy of the situation.
2024-03-24 20:22
ws

Registered: Apr 2012
Posts: 228
Adding the ICU64.exe to your virus-scan exceptions also seems to work as a workaround. (If you are using ESET, you can use the hashes provided by the virustotal link under DETAILS above, make sure to add path to VICE and also path to the ICU exe in both exclusion options (the second option requires the hash)).

Not great, not terrible.
2024-03-26 09:03
ws

Registered: Apr 2012
Posts: 228
Ok ESET Support confirmed: "It is a false positive that was fixed already in the latest update. Please update your ESET product."

so, if your antivirus kills ICU64.exe, it is now officially a good idea to submit a false positive mail to them. For ESET it is now fixed.
2024-03-26 09:35
Martin Piper

Registered: Nov 2007
Posts: 634
\\Yay//
2024-03-29 22:19
goerp

Registered: Feb 2006
Posts: 20
thanks for all the tips here!
i never thought reporting a false positive would work, so i never tried and kept using a very old version
i use a different AV but i'll try to report it there
2024-03-30 02:49
Martin Piper

Registered: Nov 2007
Posts: 634
I used to work for a security software company. Handling false positives was important because it was related to accuracy of the product offering. If people saw the product was not accurate they wouldn't buy it.
Previous - 1 | 2 - Next
RefreshSubscribe to this thread:

You need to be logged in to post in the forum.

Search the forum:
Search   for   in  
All times are CET.
Search CSDb
Advanced
Users Online
jmin
Guests online: 94
Top Demos
1 Next Level  (9.8)
2 Mojo  (9.7)
3 Coma Light 13  (9.7)
4 Edge of Disgrace  (9.6)
5 Comaland 100%  (9.6)
6 No Bounds  (9.6)
7 Uncensored  (9.6)
8 Wonderland XIV  (9.6)
9 Memento Mori  (9.6)
10 Bromance  (9.5)
Top onefile Demos
1 It's More Fun to Com..  (9.7)
2 Party Elk 2  (9.7)
3 Cubic Dream  (9.6)
4 Copper Booze  (9.5)
5 TRSAC, Gabber & Pebe..  (9.5)
6 Rainbow Connection  (9.5)
7 Onscreen 5k  (9.5)
8 Wafer Demo  (9.5)
9 Dawnfall V1.1  (9.5)
10 Quadrants  (9.5)
Top Groups
1 Oxyron  (9.3)
2 Nostalgia  (9.3)
3 Booze Design  (9.3)
4 Censor Design  (9.3)
5 Crest  (9.3)
Top Swappers
1 Derbyshire Ram  (10)
2 Jerry  (9.8)
3 Violator  (9.8)
4 Acidchild  (9.7)
5 Starlight  (9.6)

Home - Disclaimer
Copyright © No Name 2001-2024
Page generated in: 0.041 sec.