About that trojan alarm in MobMap

So now it has happened to MobMap, too: the heuristic algorithms of a virus checker program thought they had found a trojan horse named "trojan-PSW.Win32.WOW.arr" in the MobMap installer file.

The virus scanner was the one from Kaspersky Labs. Though no other virus scanner (besides those which use the Kaspersky engine) found anything suspicious in the MobMapInstaller.exe, the alert from one of those programs together with the fact that a trojan horse with this name actually exists set quite some people up and made them suspicious. In the light of the situation of WoW being one of the top priority targets of account thefts all over the world, this is a perfectly normal reaction, even though heuristic algorithms are known to produce way more false alarms than signature-based virus checks.

But thanks to Regnor from EU-Rexxar, who quickly sent the warning in to Kaspersky for further analysis, we can be certain that there is no trojan hidden in the MobMap installer file:

Hello,

MobMapInstaller.exe

We are sorry, it is false alarm. It will be fixed as soon as possible. Thank you for your help.

Please quote all when answering.

--
Best regards, XXX
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/


Kaspersky has reacted quite fast and updated their virus signature files. I ran the MobMapInstaller file through the Kaspersky scanner myself last night, and the scanner didn't find the mysterious trojan anymore. To be as secure as possible, I also ran a full system scan on my development machine last night with two different virus scanner programs (none of them reported anything), and I checked my servers and especially the files that are stored for download for any signs of manipulation - but there were no signs to be found.

Of course, that still might not be enough to convince everybody that the MobMap installer file and updater are 100% virus-free. If you are one of those people, I'd suggest you to manually download MobMap and the database from the MobMap website in the form of zip archives. These archives don't contain any executable programs where trojans could possibly be hidden; they consist of only lua and XML files which cannot contain trojans (or, to be precise: there is no known way to inject malicious code that could break out of WoWs UI Runtime system into these files as of today; any good programmer can assure you that it is not entirely impossible that such a way is found one day).

I'd like to personally thank Regnor from EU-Rexxar here for sending that report to Kaspersky! Thanks to him, this entire thing was already fixed by Kaspersky when I saw the first trojan reports here in the comments.

[Edit] Now this is really funny: I just tried to login to the WoW forums and got an error message. Then I logged into account management and found my WoW account to be frozen - which should not be possible, as I had a recurring subscription up and running which I have never cancelled. The last paid timeframe just expired this weekend, but instead of billing my bank account for another six months, Blizzard for some reason decided to freeze my account instead.

I first got a shock because I thought this had something to do with the trojan warning from Kaspersky (maybe someone reported the false positive to Blizzard as a "sure thing", which might cause them to freeze my account because it's no secret that I'm the author of MobMap). But it turned out that Blizzard just "forgot" to bill my bank account - after I had set up the subscription another time, my account was instantly reactivated. Phew...my raid participation tonight is safe again ;-)

Trackbacks

    No Trackbacks

Comments

Display comments as (Linear | Threaded)

  1. Regnor says:

    Hi Slarti ,

    I'm glad that everything took a good end and we can now use Mobmap again without the fear of losing our accounts.
    I hope this incidence didn't cause damage to the reputation of Mobmap and yourself,but I'm sure people will understand that this all was a mistake on the side of Kaspersky Labs.


    Greetings from Rexxar
    Regnor

    PS:
    Do not only thank me,also thank Kaspersky for their fast reaction of my report.

  2. Slarti says:

    Well, the Kaspersky people get paid for making their heuristics as accurate as possible, and that especially includes fixing false positives - those are essentially errors in their scanner routines. No one paid you to quickly report that trojan alert to Kaspersky and to post the response ;-)

  3. Tobias says:

    Well, I think it's time to thank you for the great job you do with this fantastic addon! I'm really glad to hear from Kaspersky that it was a false alert.

    Thank you once again!

  4. vaknov says:

    I was looking for an item it is listed in a recipe but it is not in the database it is "shadowgem" not sure who to report this to

  5. Smallface says:

    There is errors, sometimes mobmap show wrong positions.
    Some of the loots dont show up in he database, the "orange" types fx. but allso other loots dont show.

  6. Hyura says:

    I'm glad it was a mistake, but I'm getting a weird problem with MobMapUpdater.
    I just can't open the updater window anymore =X

  7. lytienza says:

    Didnt really know where to send this comment but here ya go.....i have noticed that when i use mob map to look at vendors in shat there are a few ones that dont really exist and when you click on them it boots you from the game......druid vendor in shat?....and there is another one that in the description it says "where ya buy da shit :)"

  8. Colin says:

    Hi, I couldn't find any other way to contact you, but I was wondering if there was a way to start out with a blank database, and have only the user-recorded information appear in the database (for mobs). Any help would be appreciated.

  9. Redtopp says:

    I see it is already reported, the upload isn't working. And since I misread the numbers, I updated my database and lost around 1000 quests (I cant get that I did that many though :)
    But I know I have done a lot which was not on mobmap... :(

  10. Redtopp says:

    ...and btw, it maxes out my cpu, for a long time (log says: building xml-file)

    Did I mention: Great addon :P

  11. Redtopp says:

    hmmm. Sorry...It took a while, a long while, but it got there at last.
    I guess I should upload more often :/

    Well, still a great addon :)

  12. Xarantula says:

    sorry, but i didnt find another section to write this:
    with the latest patch (todays) i have some probs while picking money, an error msg appears in a red splash, a 'gold lua.' isnt correct.
    can you plz fix it? i wont miss my precious mobmap
    thanks in advance


Add Comment


Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA 1CAPTCHA 2CAPTCHA 3CAPTCHA 4CAPTCHA 5