AntiVir is silent now

Monday, May 26. 2008
I just got the response from Avira, the company behind the popular virus scanner "AntiVir":

MobMapInstaller.exe CLEAN

Die Datei 'MobMapInstaller.exe' wurde als 'CLEAN' eingestuft. Unsere Analytiker haben in dieser Datei keinen Schadcode gefunden.


(it is in German because it's a german company, but it means something like: The file 'MobMapInstaller.exe' has been classified as clean. Our Analysts could not find any malicious code in this file.)

And Avira has already updated the signatures accordingly - the MobMapUpdater is not being found to contain a virus anymore!

This seems to apply to the "Webwasher Gateway", too, which probably uses AntiVir as its scanning engine.

[update] And while I was writing this, the Austrian company behind the virus scanner "Ikarus" responded:

Sehr geehrter Herr Schneider,
der Fehlalarm wurde ausgebaut und tritt mit dem nächsten Update nicht mehr
auf!

Mit freundlichen Grüßen
IKARUS Support Team
Christian SCHWARZ


("Dear Mr. Schneider, the false alarm has been removed and will not occur anymore with the next update.")

[update 2] Okay, this is strange: The file "MobMapUpdater.exe" does not trigger the AntiVir alarm anymore, but the installer package "MobMapInstaller.exe" still does (though it just contains the MobMapUpdater.exe which is not triggering the alarm when it's scanned)!

Funny thing: I had to recompile the Installer package using a different compression setting in Inno Setup (that is the program I use to create the package) to get rid of the false alarm. Recompiling with the same setting did not help. Maybe the compression setting I used earlier was confusing AntiVir somehow...well, the alarm is fixed, so who cares ;-)

Goddammit - It's Kaspersky again...

Friday, May 23. 2008
Kaspersky does again believe to find the virus 'Trojan-PSW.Win32.WOW.bai' in the latest MobMapUpdater.exe :( And it's again the only scanner engine that finds it (the other ones, like the G-Data scanner or F-Secure, use the Kaspersky engine, so they suffer from the same false alarms).

Seems that history is repeating, just with the new version of the MobMapUpdater. I've already sent the new version to Kaspersky for manual analysis.

Seems that I have to do this for every single update of the MobMapUpdater now, just so Kaspersky can assure themselves that I don't put viruses into my software...

[update] There we got it - at least they do respond quite fast:

Hello,

MobMapUpdater.exe

We are sorry, it is false alarm. It will be fixed as soon as possible. Thank you for your help.

Please quote all when answering.

--
Best regards, Andrey Ladikov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/


I just hope they'll update their definitions soon, it makes me mad to know that potentially thousands of users might get upset by this false alarm again.

[update 2] Okay, the web-based scanner from Kaspersky does not detect the "virus" anymore, so it seems that they've updated their definition files. But now AntiVir thinks that there's a virus...man, I'm starting to really hate this anti-virus shit...

[update 3] The request to AntiVir for a manual check and a fix is out, I hope they're as quick as Kaspersky with checking and responding.

[update 4] AntiVir unfortunately hasn't answered yet, but Fortinet has sent this:

Dear Rene Schneider,

Detection to your submission "MobMapUpdater.exe" will be removed in our next AV update.

Best Regards,
AV Lab - Bernard


So well, one less on my list :)

[update 5] AntiVir seems to need quite some time to respond to my inquiry, the file I uploaded is still being marked as "in progress" in their tracking system. That's especially bad because many users use the free AntiVir Personal Classic Edition, so I get quite some amount of mails regarding this whole subject.

But at least Fortinet and all Kaspersky-based virus scanners have rolled out their new definitions which do not classify my updater as malware anymore. There's still a scanner from a company called "Quick Heal" which raises false alarm, but they've been contacted already yesterday, so that will hopefully be fixed soon, too. And then there's the Webwasher Gateway, which doesn't seem to have an own virus lab, but uses several anti-virus detection engines from other companies, so I suspect this scanner uses either the Quick Heal engine or the AntiVir engine, which means this problem will be solved as soon as those scanners get updated definition files. And then there's Prevx, for which I haven't found an address to send stuff for manual verification yet.

MobMap v2.01

Thursday, May 22. 2008
The first (and hopefully last) bugfix release after version 2.00 is now online. This version addresses some issues which came up here in the blog comments:

v2.01:
- fixed: MobMap does not throw errors when completing quests anymore if Fizzwidgets Levelator is installed
- fixed: The minimap dots now stay where they should be and don't "move" around while you approach the target position
- fixed: The recipe minimum level number fields are now more tolerant to wider custom fonts


Besides that, I've got to say that the new quest comment feature is being accepted quite well. There have already been 60 perfectly useful comments submitted (well, for the german version - the english version only has 14 atm, but that's probably because MobMap seems to be way more popular in the german-speaking realm than with english-speaking people), and some more which unfortunately didn't make it into the database because they didn't really contain any new and useful information (please remember that every single comment uses a little memory of the MobMap users, which is why I hand-select the comments and why I have to be way more selective while choosing which comments get in and which don't than the web-based databases have to be).

If you've been a comment author, let me thank you for your efforts of improving MobMap even further!

MobMap v2.0 is out!

Monday, May 19. 2008
So there it is - version 2.0 of MobMap. This release is on one hand a maintenance release: the MobMap database format has been changed slightly to solve a limitation that it was suffering from lately, and there are several new filters in place which sort out some serious crap from the database, which in turn results in a slightly smaller memory footprint (or, in some cases, a much smaller one - for example the fishing database, which is now 60% smaller). And I've fine-tuned those quicksearch buttons a little.

On the other hand - and this is what justifies the jump in the version number - MobMap has gained a quest comment system based on user-created input. In the essence this works just like you know it from the big WoW database sites: you can write a comment about any quest that's in the MobMap quest database - of course in-game. These comments are then being uploaded together with the other data you've been collecting. But now there's a major difference: as every comment enlarges the MobMap comment database memory footprint (of course the comments are stored in a compressed way, but nevertheless they tend to add up...), I don't just blindly put every comment into the database. Instead, every comment that's being uploaded will be reviewed, and only those comments that give some new information for a quest and have been written in a reasonably readable way are included.

You can of course write the comments completely anonymously, but you can also identify yourself (that is: the name of your in-game character and realm) as the author of a comment - it's your choice.

This system will hopefully help in making MobMap even more useful for solving quests - it is primarily intended to allow MobMap to be helpful even for quests which have goals like "Find some position". The quest comment system does automatically convert NPC names and coordinates into clickable links in-game for maximum ease of use.

Okay, so now it's your turn - I'm waiting for the first comments ;-) If there are any problems, errors or whatever with this new version (or the new version of the MobMapUpdater program, which has been updated as well), please leave me a comment here in the blog. Make sure to grab a new database version when you're updating though, because the format change renders all old databases useless.

--------------------------------------------
Patch notes of v2.00:
- added: MobMap does now support user-created quest comments! You can write comments as well as read comments written by other players. This functionality can be disabled in the options if you don't want to use it.
- changed: The database format has been changed to incorporate the quest comments as well as extend a limitation in the old format. YOU WILL NEED TO UPDATE YOUR DATABASE COPY WHEN UPDATING MOBMAP!
- changed: The functionality of the quicksearch buttons next to quest titles has been improved. These buttons should now find the correct quest even if multiple quests have the same title.
- added: There are now quicksearch buttons at questgivers. They can of course be disabled optionally, like the other quicksearch buttons.

MobMap v1.62 fixes patch 2.4.2 problems

Wednesday, May 14. 2008
There was a slight problem with MobMap v1.61 since patch 2.4.2 went live: a lua error was thrown whenever a corpse with money in it was looted. This quickly created and released v1.62 should fix the problem.

However, there's a bigger MobMap update in the pipeline for the near future that will finally add some truly new functionality which I hope will prove useful - more about this soon, so stay tuned :o)

Please report if there are any immediate problems with MobMap v1.62 and patch 2.4.2.