Renegade Public Forums
C&C: Renegade --> Dying since 2003™, resurrected in 2024!
Home » Archived Forums » RenGuard Client » your product steals my information
your product steals my information [message #448824] Wed, 15 June 2011 14:41 Go to next message
fredcow9 is currently offline  fredcow9
Messages: 32
Registered: December 2005
Karma: 0
Recruit
your program is malicious as detected by my antivirus, thanks for making it impossible for me to play on noobstories now.
Re: your product steals my information [message #448827 is a reply to message #448824] Wed, 15 June 2011 14:55 Go to previous messageGo to next message
Omar007 is currently offline  Omar007
Messages: 1711
Registered: December 2007
Location: Amsterdam
Karma: 0
General (1 Star)
If you got RenGuard from here, it's not malicious.
It does get false-positives on some scanners afaik.

Aside from that, you shouldn't use RenGuard anymore imo. It's outdated anyway.


http://tiberiumredux.omarpakker.nl/Old Unused Parts/Plaatjes/PromoteBanner_Hades_small.jpg
Re: your product steals my information [message #449415 is a reply to message #448827] Mon, 04 July 2011 14:09 Go to previous messageGo to next message
sla.ro(master) is currently offline  sla.ro(master)
Messages: 610
Registered: September 2010
Location: Romania
Karma: 0
Colonel
Omar007 wrote on Thu, 16 June 2011 00:55

If you got RenGuard from here, it's not malicious.
It does get false-positives on some scanners afaik.

Aside from that, you shouldn't use RenGuard anymore imo. It's outdated anyway.


some communities like n00bstories can force you to use RenGuard and yes, is outdated.


Creator of Mutant Co-Op
Developer of LuaTT
Re: your product steals my information [message #449636 is a reply to message #448827] Fri, 15 July 2011 07:44 Go to previous messageGo to next message
reborn is currently offline  reborn
Messages: 3231
Registered: September 2004
Location: uk - london
Karma: 0
General (3 Stars)
Omar007 wrote on Wed, 15 June 2011 17:55


it's not malicious


How can you be sure?



Re: your product steals my information [message #449637 is a reply to message #448824] Fri, 15 July 2011 09:23 Go to previous messageGo to next message
Omar007 is currently offline  Omar007
Messages: 1711
Registered: December 2007
Location: Amsterdam
Karma: 0
General (1 Star)
It gives on 2 out of 43 AV programs a message. And not even a message that says it is. Just 'Suspicious' or 'Looks Like'.
I'd say it's not malicious, just false positives.

Attached is a Virus Total printout. If you don't even trust the printout, you can always submit it yourself Wink


http://tiberiumredux.omarpakker.nl/Old Unused Parts/Plaatjes/PromoteBanner_Hades_small.jpg

[Updated on: Fri, 15 July 2011 09:25]

Report message to a moderator

Re: your product steals my information [message #449648 is a reply to message #448824] Fri, 15 July 2011 13:49 Go to previous messageGo to next message
reborn is currently offline  reborn
Messages: 3231
Registered: September 2004
Location: uk - london
Karma: 0
General (3 Stars)
The program connects to v00d00.org to download the renguard master server list. It does this by downloading index.bin, which is processed by the client.

Who maintains the file hosted on v00d00.org? Why does it connect to v00d00's site, and not BHS's?

Would it be possible for the index.bin file to contain additional instructions to be processed by the client?

Try to visit v00d00.org in your browser... Likely just some asshat reported the site, or some dousche messed with it, but still...

I am not convinced that it's entirely harmless, but that's just me.



Re: your product steals my information [message #449652 is a reply to message #448824] Fri, 15 July 2011 15:53 Go to previous messageGo to next message
Omar007 is currently offline  Omar007
Messages: 1711
Registered: December 2007
Location: Amsterdam
Karma: 0
General (1 Star)
v00d00.org does not exist. It can't find the address 0o

http://tiberiumredux.omarpakker.nl/Old Unused Parts/Plaatjes/PromoteBanner_Hades_small.jpg
Re: your product steals my information [message #449755 is a reply to message #448824] Wed, 20 July 2011 06:25 Go to previous messageGo to next message
danpaul88 is currently offline  danpaul88
Messages: 5795
Registered: June 2004
Location: England
Karma: 0
General (5 Stars)
Actually as I recall the reason for the false positives is because its packaged using the same utility as a lot of malware is packaged with, hence some virus scanners just blindly assume its probably malware itself.

The packaging is also the reason it doesn't work on 64bit operating systems.



reborn;
I believe there are several URLs to download index.bin from (BRenBot certainly knows of more than one) to provide redundancy and, to some extent, load balancing. It *should* randomly choose from the available URLs, so you may find it connects to a different URL each time it is loaded.


http://steamsignature.com/card/1/76561197975867233.png

[Updated on: Wed, 20 July 2011 06:27]

Report message to a moderator

Re: your product steals my information [message #449775 is a reply to message #449755] Wed, 20 July 2011 16:33 Go to previous message
iRANian is currently offline  iRANian
Messages: 4308
Registered: April 2011
Karma: 0
General (4 Stars)
danpaul88 wrote on Wed, 20 July 2011 06:25

Actually as I recall the reason for the false positives is because its packaged using the same utility as a lot of malware is packaged with


lol


Long time and well respected Renegade community member, programmer, modder and tester.

Scripts 4.0 private beta tester since May 2011.

My Renegade server plugins releases
Previous Topic: Game Error
Next Topic: Your lack of appreciation and what it causes
Goto Forum:
  


Current Time: Thu Nov 21 02:26:03 MST 2024

Total time taken to generate the page: 0.00766 seconds