Log inRegister an accountBrowse CSDbHelp & documentationFacts & StatisticsThe forumsAvailable RSS-feeds on CSDbSupport CSDb Commodore 64 Scene Database
You are not logged in - nap
CSDb User Forums


Forums > C64 Coding > ICU64 suddenly gone?
2024-03-23 21:10
ws

Registered: Apr 2012
Posts: 229
ICU64 suddenly gone?

I just observed that my ICU64 is suddenly gone, and after getting the "Sorry, but this file contains a virus" warning upon trying to re-download it from the official google drive, i noticed that my antivirus quietly has anihilated the file, reason : "Trojan Generik.LBYTBYU".

I already contacted mathfigure about it, but i cannot believe that this is anything else but a false positive.
2024-03-23 21:15
iAN CooG

Registered: May 2002
Posts: 3136
which AV? you better report the false positive and also run the test at virustotal, providing the url of the result is a plus but if 1-2 report a "generic" detection while others say it's OK should be enough to tell them to fix their signatures.
2024-03-23 22:47
ws

Registered: Apr 2012
Posts: 229
I am using ESET. I have actually no experience with reporting false positives, but that is a good idea. Will look into it.
2024-03-23 23:19
ws

Registered: Apr 2012
Posts: 229
huh... totally no idea what to make of this https://www.virustotal.com/gui/file/980e8d8750aa8a66a8e02183cd2..
2024-03-23 23:47
iAN CooG

Registered: May 2002
Posts: 3136
We're witnessing a new religion in the making: a lie spread so many times, now most take it as a truth.
Are all the ICU64 on csdb generating this alarm or just a specific one?
2024-03-24 06:19
ws

Registered: Apr 2012
Posts: 229
It seems that only this version of ICU64 for VICE from CSDb acts the same as the version from mathfigures google drive (that version is inaccessible now):
ICU64 for VICE 3.x V0.1.3
The frodo versions are not impacted.

But this version of ICU for VICE is now also useless, since it reqires the icu64.exe of the "flagged" version above:
ICU64 for VICE 3.7 V0.1.3
2024-03-24 10:59
Martin Piper

Registered: Nov 2007
Posts: 644
Quote: huh... totally no idea what to make of this https://www.virustotal.com/gui/file/980e8d8750aa8a66a8e02183cd2..

This looks like a heuristic scan result, meaning it saw some code that was similar to code used in another virus, but it wasn't a precise match and it might or might not be malicious.

But given ICU64 launches a process and uses some form of process memory injection or inspection to get the emulated C64 memory, then this might itself be flagged as "maybe suspicious". I mean, doing such things with external processes is often used by suspicious code, so it's not a surprise it gets flagged during a scan.

But in this case we know ICU does this kind of process tweaking for legitimate reasons, so it's probably safe to ignore unless there is an exact and specific match with a known virus.
2024-03-24 12:18
tlr

Registered: Sep 2003
Posts: 1722
Quoting Martin Piper
But in this case we know ICU does this kind of process tweaking for legitimate reasons, so it's probably safe to ignore unless there is an exact and specific match with a known virus.

Some antivirus programs just rip away the binary on the fly and don't let you override that though.

Sometimes there isn't even a warning about it. I'm pointing at you windows defender!
2024-03-24 13:02
Fungus

Registered: Sep 2002
Posts: 624
This is due to AV's not being anything other than garbage anymore and they use "AI" which is so smart all it does it check that string literals match some crap someone reported. It will mistake EXE files for js exploits etc (defender is the worst at this) but other AV companies trade signatures and they get out there and then perfectly legit stuff is flagged. It's incredibly annoying...
2024-03-24 16:26
ws

Registered: Apr 2012
Posts: 229
I have now submitted the .exe alongside a false positive mail, according to their rules, to ESET. Lets see if they can grasp the idiocy of the situation.
2024-03-24 20:22
ws

Registered: Apr 2012
Posts: 229
Adding the ICU64.exe to your virus-scan exceptions also seems to work as a workaround. (If you are using ESET, you can use the hashes provided by the virustotal link under DETAILS above, make sure to add path to VICE and also path to the ICU exe in both exclusion options (the second option requires the hash)).

Not great, not terrible.
 
... 4 posts hidden. Click here to view all posts....
 
Previous - 1 | 2 - Next
RefreshSubscribe to this thread:

You need to be logged in to post in the forum.

Search the forum:
Search   for   in  
All times are CET.
Search CSDb
Advanced
Users Online
Asphodel
csabanw
Elder0010/G★P
Mr SQL
celticdesign/G★P/M..
saimo/RETREAM
jmin
MAT64
Guests online: 114
Top Demos
1 Next Level  (9.8)
2 Mojo  (9.7)
3 Coma Light 13  (9.7)
4 Edge of Disgrace  (9.6)
5 Comaland 100%  (9.6)
6 No Bounds  (9.6)
7 Uncensored  (9.6)
8 Wonderland XIV  (9.6)
9 Memento Mori  (9.6)
10 Bromance  (9.5)
Top onefile Demos
1 It's More Fun to Com..  (9.7)
2 Party Elk 2  (9.7)
3 Cubic Dream  (9.6)
4 Copper Booze  (9.5)
5 TRSAC, Gabber & Pebe..  (9.5)
6 Rainbow Connection  (9.5)
7 Dawnfall V1.1  (9.5)
8 Quadrants  (9.5)
9 Daah, Those Acid Pil..  (9.5)
10 Birth of a Flower  (9.5)
Top Groups
1 Nostalgia  (9.3)
2 Oxyron  (9.3)
3 Booze Design  (9.3)
4 Censor Design  (9.3)
5 Crest  (9.3)
Top Diskmag Editors
1 Jazzcat  (9.4)
2 Magic  (9.4)
3 hedning  (9.2)
4 Elwix  (9.1)
5 A Life in Hell  (9.1)

Home - Disclaimer
Copyright © No Name 2001-2024
Page generated in: 0.044 sec.