Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


OMG VIRUS!!!
Goto page Previous  1, 2, 3 ... , 33, 34, 35  Next
 
Post new topic   This topic is locked: you cannot edit posts or make replies.    Cheat Engine Forum Index -> Cheat Engine
View previous topic :: View next topic  
Author Message
Dark Byte
Site Admin
Reputation: 465

Joined: 09 May 2003
Posts: 25567
Location: The netherlands

PostPosted: Sat May 21, 2022 12:20 pm    Post subject: Reply with quote

you may have to add an exception for the temp folder explicitly.

But the message "Operation did not complete successfully because the file contains a virus or potentially unwanted software." usually comes from either "realtime protection" or "reputation based protection" still being enabled (it's not defender)

_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
geekgirl101
How do I cheat?
Reputation: 0

Joined: 21 May 2022
Posts: 2

PostPosted: Sat May 21, 2022 12:48 pm    Post subject: Reply with quote

Dark Byte wrote:
you may have to add an exception for the temp folder explicitly.

But the message "Operation did not complete successfully because the file contains a virus or potentially unwanted software." usually comes from either "realtime protection" or "reputation based protection" still being enabled (it's not defender)


Thank you, I forgot to turn off realtime protection. That allowed it to be installed.
Back to top
View user's profile Send private message
Jake78
How do I cheat?
Reputation: 0

Joined: 10 Jul 2022
Posts: 4
Location: somewhere

PostPosted: Sun Jul 10, 2022 4:55 am    Post subject: Antivirus Reply with quote

Bit Defender won't let me install it even after I disable realtime protection because it detects malicious behaviour of installer. (And I don't want to disable last line of defense - behavior based detection. I had already reset my Windows several times due to persistent infections which had been bogging down my Hard disk making PC almost unusable. I built source from GitHub but it doesn't contain kernel mode driver so I can't enable speed hack. Can you tell me how to add kernal driver to git-hub build? Confused
Back to top
View user's profile Send private message
Dark Byte
Site Admin
Reputation: 465

Joined: 09 May 2003
Posts: 25567
Location: The netherlands

PostPosted: Sun Jul 10, 2022 5:11 am    Post subject: Reply with quote

you need to compile the speedhack dll's from the sourcecode, not the driver
_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
Jake78
How do I cheat?
Reputation: 0

Joined: 10 Jul 2022
Posts: 4
Location: somewhere

PostPosted: Wed Jul 20, 2022 10:08 pm    Post subject: Cheat Engine compilation Reply with quote

Dark Byte wrote:
you need to compile the speedhack dll's from the sourcecode, not the driver

How do I do it? I compiled the cheatengine.lpi project file as per your instructions on Github. Used "build x86-64" as choosing "build all"/other builds give errors. I thought that lpi had all features combined but apparently it wasn't.
There is a speedhack lpi file in source, but how can I add two lpi's together? (cheat engine lpi and speedhack lpi) I want to compile all features in cheat engine source, is it possible? If so how to do it? Confused
Back to top
View user's profile Send private message
Dark Byte
Site Admin
Reputation: 465

Joined: 09 May 2003
Posts: 25567
Location: The netherlands

PostPosted: Thu Jul 21, 2022 4:07 am    Post subject: Reply with quote

Same way I do it. Just open the speedhack.lpr in lazarus, and then build.

The Change build mode button (left of the play button) has a dropdown menu where you can select the version to build (32/64 bit)
You can also use run->compile many modes and then compile the 32 and 64 bit builds from there

_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
Jake78
How do I cheat?
Reputation: 0

Joined: 10 Jul 2022
Posts: 4
Location: somewhere

PostPosted: Wed Aug 24, 2022 11:15 am    Post subject: Bundled Malware Reply with quote

This is posted on Quora as an answer to "Is cheat engine safe to download?"

Answer by "Guillaume Tera
·
Follow
Former Avionic Mechanic (2018–2019) Jul 3
No, Cheat Engine is no longer safe to download. It was when we had an alternative way to downloading it.

Any downloads from now on will attempt to install “OfferCore” which is a nice little malware. It’s not the worst thing, but the issue is that it creates huge weaknesses in your security that can, and surely will, be exploited by someone else.

Offercore will also modify things in your registry and other places you don’t want it to modify.

Offercore will install itself in your windows, and even worse, windows defender will only desinstall it. But it will reinstall itself later on because it infects other parts in your PC.

There are alternatives such as ArtMoney instead of Cheatengine. Those work just as well if you just want to modify some memory values.

But what if you already installed cheatengine?

I highly suggest you get MalwareByte and run a scan. It will detect also changes in registry. For my case, OfferCore modified 11 files in my system that MalwareByte found. And I have no idea if my system is now 100% clean.

Windows defender only found 1 file out of 11."

Any Comment?
Back to top
View user's profile Send private message
Dark Byte
Site Admin
Reputation: 465

Joined: 09 May 2003
Posts: 25567
Location: The netherlands

PostPosted: Wed Aug 24, 2022 2:14 pm    Post subject: Reply with quote

Just fearmongering of uneducated people who freak out when their anti virus tells them something is dangerous. And then freak out even more when they try to delete it and aren't allowed to, because their anti virus is blocking them disk access to the files it thinks are dangerous (And especially hilarious when they tell the AV to delete it for them, and then the AV fails to delete it, because it's blocking itself)

It doesn't attempt to 'install' offercore. It just uses a third party advertiser network to download optional software you may or may not be interested in (AV Like Mcafee, or avast, VPN, file management tools, etc...)
It likely records which software you have installed before, so it won't offer those again


It is verified and up to downloader/advertiser rules and does not do anything besides offer the software download, and if clicked on accept, downloads the software, else it won't do a single thing

Here's a recent execution of the installer on my main system and goes into what it actually installs.
https://www.youtube.com/watch?v=v7QsS5qp0og
Is my system fucked after running it? No. Did it install anything after making this video? No? Is my anti virus still disabled? No, I turned it back on, and it still hasn't detected anything (Besides the cheat engine installer file)

Also, just noticed that noxplayer on bignox.com uses the same advertiser network

Anyhow,
if you're too afraid of this 'installcore' then join the CE patreon and get a version without it. (Your antivirus will still complain, it tends to have even more virus detections, but no ads)

_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
Jake78
How do I cheat?
Reputation: 0

Joined: 10 Jul 2022
Posts: 4
Location: somewhere

PostPosted: Wed Aug 24, 2022 8:03 pm    Post subject: Reply with quote

Thanks for the reply. It is nice to know you knowingly didn't add malware Cool. But I hope antivirus vendors be a little more careful about which they block and which they won't, otherwise, users have to switch off their antivirus frequently, and consequently, they will get into a habit of opting out of blocks and eventually fall prey to malware because they become careless of choice which they should unblock and which they shouldn't. Also, antivirus programs didn't give much of an insight into the reason they block or quarantine a particular program other than some technically savvy, brief, and generic explanations which are generally hard to search even online due to them differing from one vendor to another. Furthermore, Reporting false positives is with some vendors are lengthy affair since they provide no such option in their main program hence users have to manually search Google/Bing to find their sample submitting service page and manually upload the item. (of course, you have to manually restore the item from quarantine first.) For most non-technically non-savvy people this is a boring task even if they know or find how to do it. For a critical industry like it, this is a huge weakness in particular. Of course, this has nothing to do with the Cheat engine or Darkbyte or Cheat engine but I intended to mention this because it affects Cheat Engine too.

By the way, your program is great and I've heard some young engineers in their early careers prefer Cheat Engine over professional tools like IDA pro or Ghidra for reverse engineering and disassembly because they are used to Cheat Engine as a Game hacking tool. Of course, the Cheat engine is by no means unprofessional, just that it is fine-tuned for gaming (or I think so). We all love Very Happy Cheat Engine (other than the game developers of course). Please kindly keep up the good work! Many many thanks! Smile
Back to top
View user's profile Send private message
LeFiXER
Grandmaster Cheater Supreme
Reputation: 20

Joined: 02 Sep 2011
Posts: 1065
Location: 0x90

PostPosted: Thu Aug 25, 2022 9:00 am    Post subject: Re: Bundled Malware Reply with quote

Jake78 wrote:
This is posted on Quora as an answer to "Is cheat engine safe to download?"

Answer by "Guillaume Tera
·
Follow
Former Avionic Mechanic (2018–2019) Jul 3
No, Cheat Engine is no longer safe to download. It was when we had an alternative way to downloading it.

Any downloads from now on will attempt to install “OfferCore” which is a nice little malware. It’s not the worst thing, but the issue is that it creates huge weaknesses in your security that can, and surely will, be exploited by someone else.

Offercore will also modify things in your registry and other places you don’t want it to modify.

Offercore will install itself in your windows, and even worse, windows defender will only desinstall it. But it will reinstall itself later on because it infects other parts in your PC.

There are alternatives such as ArtMoney instead of Cheatengine. Those work just as well if you just want to modify some memory values.

But what if you already installed cheatengine?

I highly suggest you get MalwareByte and run a scan. It will detect also changes in registry. For my case, OfferCore modified 11 files in my system that MalwareByte found. And I have no idea if my system is now 100% clean.

Windows defender only found 1 file out of 11."

Any Comment?


This avionic mechanic clearly does not know the difference between malicious software and a simple advertisement. People overgeneralise things and as a result spread misinformation which people happen to believe just because the person spreading the misinformation holds a title that is somewhat respected. Malware is software with the intent of being malicious; Cheat Engine is not such software. I would suggest people actually educate themselves about things that can cause harm and then ask themselves is Cheat Engine unsafe? Antivirus vendors are often paid large sums of money to detects things as unsafe, or the converse, detect things as unsafe until they are paid large sums of money to be granted a signature/licence which deems the software safe.
Back to top
View user's profile Send private message
timomajere
How do I cheat?
Reputation: 0

Joined: 20 Oct 2022
Posts: 2
Location: Canada

PostPosted: Thu Oct 20, 2022 9:10 am    Post subject: Reply with quote

Hello, new guy to these forums and this cheat engine.
Not gonna delve into what I know and don't, just wanted to ask a straight forward question.
My alert isnt saying Trojan, its.. showing this..

PUADlManager:Win32/OfferCore
affected files is the installer.

webfile: C:\Users\MYNAME\Downloads\CheatEngine74.exe|XXXXX://d3l9r5lew7psag.cloudfront.net/installer/7592316402693636/8338005|pid:4648,ProcessStart:133107515540832852

The XXXXX is https It says i cant post links yet...

I just want to know what all that is if the files needed exist in the installer i just downloaded?

Not a panic thing here.. I ain't worried. Just asking a question.
Thank you.
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Dark Byte
Site Admin
Reputation: 465

Joined: 09 May 2003
Posts: 25567
Location: The netherlands

PostPosted: Thu Oct 20, 2022 9:24 am    Post subject: Reply with quote

i think the part after the .exe is metadata added to the file by your browser to show where you downloaded it from

the warning shows that part after the .exe as information to inform you

_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
timomajere
How do I cheat?
Reputation: 0

Joined: 20 Oct 2022
Posts: 2
Location: Canada

PostPosted: Thu Oct 20, 2022 9:42 am    Post subject: Reply with quote

Dark Byte wrote:
i think the part after the .exe is metadata added to the file by your browser to show where you downloaded it from

the warning shows that part after the .exe as information to inform you


Cool. Thank you muchly.
Trying to show someone it is NOT malicious and i thought mebee an auto-update request but was not sure.
i know little of the code.
Have a great day!
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Rifmaster
How do I cheat?
Reputation: 0

Joined: 04 Feb 2023
Posts: 1
Location: GERMANY

PostPosted: Sat Feb 04, 2023 3:14 am    Post subject: Re: OMG VIRUS!!! Reply with quote

Dark Byte wrote:
Yes, we know your crappy AV thinks CE is a virus. No need to tell us.

There are 4 solutions to this problem:
1: Don't install CE
2: Send ce to your av vendor and tell them to remove the detection and wait a few years till they do it...
3: Uninstall your anti virus
4: If your AV supports it: Add ce to the ignore list




Wouldn't it be easier for you to get a virus scanner that also works?

Norton, AVG or Avira is not used by anyone who has even dealt with the subject of 'virus scanners' because of all the errors and false alarms.
Back to top
View user's profile Send private message
hcova
How do I cheat?
Reputation: 0

Joined: 11 Feb 2023
Posts: 1

PostPosted: Sat Feb 11, 2023 4:21 pm    Post subject: Reply with quote

I run virustotal and there are many AVG that reports it as a malware. Desktop Malwarebytes and McAfee programs say the same.


ChatEngine VirusTotal Scan.jpg
 Description:
 Filesize:  373.67 KB
 Viewed:  58825 Time(s)

ChatEngine VirusTotal Scan.jpg


Back to top
View user's profile Send private message AIM Address
Display posts from previous:   
Post new topic   This topic is locked: you cannot edit posts or make replies.    Cheat Engine Forum Index -> Cheat Engine All times are GMT - 6 Hours
Goto page Previous  1, 2, 3 ... , 33, 34, 35  Next
Page 34 of 35

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites