gametechmods

Robot Arena => Discussion => Topic started by: Stagfish on November 12, 2010, 12:53:36 PM

Title: Sad News
Post by: Stagfish on November 12, 2010, 12:53:36 PM
The DSL download in Sages sig has the virus "Win32PowerRegScheduler" which is very difficult to remove. The virus appears on my computer whenever I download DSL from sages sig.
 
EDIT: Also in the virus details (it tells me stuff about it when its deleted) It said it originated from the DSL folder.
Title: Re: Sad News
Post by: Scorpion on November 12, 2010, 12:56:00 PM
 :eek:
Don't suppose you know what that virus does?
Title: Re: Sad News
Post by: lloopp D lloopp on November 12, 2010, 12:58:55 PM
Oh dear.
Title: Re: Sad News
Post by: SKBT on November 12, 2010, 01:04:53 PM
SAGE!!!

Are you trying to force us to play stock by infecting all who play DSL?


EDIT: on a more serious note....

I've got a virus free version of DSL if anyone wants to host it somewhere.
Title: Re: Sad News
Post by: Reier on November 12, 2010, 01:08:02 PM
Heyyyyy I think my antivirus deleted some file from DSL a while back...name seems pretty close from what I remember.
Title: Re: Sad News
Post by: Scorpion on November 12, 2010, 01:11:21 PM
I just scanned a DSL file I downloaded from sages sig not that long ago, and AVG found nothing, when did you download yours stagfish?
Title: Re: Sad News
Post by: Stagfish on November 12, 2010, 01:41:33 PM
I downloaded mine half an hour ago, the first time I downloaded it was a couple of months back I got the same virus.
Title: Re: Sad News
Post by: Scorpion on November 12, 2010, 01:43:40 PM
Hmmm, interesting then.
Are their any noticable effects of the virus?
Title: Re: Sad News
Post by: GroudonRobotWars on November 12, 2010, 01:44:19 PM
I just downloaded another version a few days ago from Sage's sig and nothing about a virus appeared.
Title: Re: Sad News
Post by: Stagfish on November 12, 2010, 01:47:09 PM
PowerRegScheduler is a product registration system used by some legitimate software programs. It collects demographic data for vendors who use PowerRegScheduler as a product registration reminder. PowerRegScheduler collects data such as your name, address, e-mail, place of purchase, product serial number, etc. This data is transmitted to PowerRegScheduler servers and is then made available to the manufacturer of the purchased product.
 
PowerRegScheduler commonly installs itself to the current and global users' startup folders, using the filename "powerreg scheduler<version>.exe" or "powerreg scheduler.exe".
 
The program may also modify the registry in order to run automatically each time Windows starts:
Creates value: PowerReg Scheduler
With data: <path>\PowerReg SchedulerV2.exe
in subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 
PowerRegScheduler may remain on the computer after the product registration task has been completed.
Title: Re: Sad News
Post by: Scorpion on November 12, 2010, 01:50:17 PM
Ah, that sounds quite nasty, does anybody know where the DSL download on sages sig is hosted?

Also, offtopic, who keeps rating me down, if you have a problem with something I say just say it.
Title: Re: Sad News
Post by: FOTEPX on November 12, 2010, 01:54:18 PM
I got this, easily got around by using system restore and restoring it to a week ago, yet it somehow kept DSL and removed the virus. Try that.

EVEN SADDER NEWS

MY -160 REP IS GONE  :eek:
Title: Re: Sad News
Post by: Stagfish on November 12, 2010, 01:57:42 PM
Windows Security Essentials easily deleted it.
Title: Re: Sad News
Post by: Badnik96 on November 12, 2010, 02:31:10 PM
This could be what Wafflez is talking about, he downloaded DSL from Sage's sig and now he has a virus... I thought it was from something else (he's been bugging me about the virus for the past two weeks at school), but now I see it's from this. Thank god that's cleared up.
Title: Re: Sad News
Post by: 70 CUDA on November 12, 2010, 02:37:04 PM
dose it affect the game. AVG finds nothing but after about 2 days i have to uppack a new copy from the .rar due to not being able to run any exhibition matches with a human bot. well it realy just gives me no bot preview and picks a random bot from a random team of mine. any free AVs to get rid of it?
Title: Re: Sad News
Post by: Stagfish on November 12, 2010, 04:03:52 PM
Windows security essentials works, and its free.
Title: Re: Sad News
Post by: S.T.C. on November 12, 2010, 04:18:59 PM
Infogrames Product Registration uses that.
Title: Re: Sad News
Post by: Serge on November 12, 2010, 04:46:47 PM
The DSL download in Sages sig has the virus "Win32PowerRegScheduler" which is very difficult to remove.

EVERYBODY CALM THE F--- DOWN

It's the infogrames registration tool. False positive. Oh, and you can delete it by right clicking it and selecting "Delete". Big bloody deal.

Or you can just not run it, but apparently you're too stupid for that and have the habit of clicking on every .exe you see.
Title: Re: Sad News
Post by: Sage on November 12, 2010, 05:11:21 PM
no virus when i download. I'll host it on my ra2 server.

EDIT: it WAS hosted by gametechmods.com. Ill reupload a new version.
Title: Re: Sad News
Post by: S.T.C. on November 12, 2010, 05:17:43 PM
The DSL download in Sages sig has the virus "Win32PowerRegScheduler" which is very difficult to remove.

EVERYBODY CALM THE F--- DOWN


It's the infogrames registration tool.
Right.
Title: Re: Sad News
Post by: powerrave on November 12, 2010, 05:53:29 PM
now it makes me wonder. why , on a certain amount of systems, is it being detected as a virus? it's no biggy, i can get into that. but this is just something that bugs me.

and before asuming, i didn't get my RA2 from Sage his sig. i had found the installer i use 3 years ago ;]
Title: Re: Sad News
Post by: Serge on November 12, 2010, 05:58:29 PM
Because it depends on the antivirus software?
Title: Re: Sad News
Post by: 70 CUDA on November 12, 2010, 11:36:30 PM
ok then what the heck is wrong with my DL? i just had to re export it cause it did it twice today. i know it isnt a virus but what is causing it?
Title: Re: Sad News
Post by: Serge on November 13, 2010, 03:40:31 AM
ok then what the heck is wrong with my DL? i just had to re export it cause it did it twice today. i know it isnt a virus but what is causing it?

It's the infogrames registration tool. False positive.

And it's not because it's Sage's download, or because it was hosted on GTM, or because it was hosted when the moon was in it first quarter phase. The same utility is on the original RA2 CD that you bought from a store. Recent antivirus software has something called heuristics, which means that viruses are not only checked by signatures, but also unknown programs are being disassembled and their code is being reviewed to see whether it could be malicious. Here it is detected as one, since it does place itself in the CurrentVersion\Run\ key (which can be later easily deleted), which is kind of worm-y, but I don't really know when. I remember running that utility a long time ago and nothing like that happened.