Jump to content

Windows Defender - Mwo Being Tagged Win32/peals.f!cl

General

15 replies to this topic

#1 Thinice

    Rookie

  • Big Brother
  • Big Brother
  • 1 posts
  • LocationMN

Posted 03 January 2018 - 10:10 PM

Fired up MWO to get a round in before bed and... got some sort of Inner Sphere scum hackery!

Not sure if this matters to anyone but if it happens for others I figured we can pile up in this thread to see if it's just me or Windows Defender ...

Anyone else get this?
Posted Image

#2 Ssamout

    Member

  • PipPipPipPipPipPipPip
  • 643 posts
  • LocationPihalla

Posted 03 January 2018 - 10:55 PM

You should not download stuff like random.exe and run them as admin.

Edited by McValium, 04 January 2018 - 03:39 AM.
just no...


#3 N0ni

    Member

  • PipPipPipPipPipPipPipPipPip
  • The Nightmare
  • The Nightmare
  • 2,357 posts
  • LocationIn a GTR Simulator Cockpit

Posted 03 January 2018 - 11:32 PM

This is why you don't trust Davions.

They appear all friendly, get buddy-buddy with you having a good time at the bar and the next thing you know they infect your electronics when you're out cold.

In seriousness, run a full scan of malwarebytes in case there's more than that. MB is free.

#4 Vellron2005

    Member

  • PipPipPipPipPipPipPipPipPipPip
  • The Blood-Eye
  • The Blood-Eye
  • 5,445 posts
  • LocationIn the mechbay, telling the techs to put extra LRM ammo on.

Posted 04 January 2018 - 03:33 AM

Turn off your Win Defender.. that thing is cancer and pain rolled up in blood sacrifices to the unnamed gods.. Just use 3rd party Antivirus..

#5 D V Devnull

    Member

  • PipPipPipPipPipPipPipPipPip
  • 4,390 posts
  • Locationis something I can not say... I keep landing up lurking...

Posted 04 January 2018 - 03:57 AM

View PostThinice, on 03 January 2018 - 10:10 PM, said:

Fired up MWO to get a round in before bed and... got some sort of Inner Sphere scum hackery!

Not sure if this matters to anyone but if it happens for others I figured we can pile up in this thread to see if it's just me or Windows Defender ...

Anyone else get this?
<<<image from https://i.imgur.com/TwXoVwi.png>>>

Thinice, tell Windows Defender to "Restore" and "Ignore"... Then, use a Third-Party, Reliable AntiVirus like NOD32 (https://www.eset.com/us/home/antivirus/) to check your computer for infections. MicroSoft's own utilities can NOT always be trusted. <_<

After that, run MWO's Repair Tool (or if on Steam, tell that to Verify Game Install) to make sure the last patch you did hasn't got a weird bug. When you do this step, ONLY if you're using the MWO Repair Tool, also...
  • Click "Options"
  • Uncheck ALL those checkboxes (This is in order to avoid doing something more than just repairing MWO's install. We NEVER want to blow away your Local Player Profile Data here!!!)
  • Click "OK"
...and then you can finally tell it to "Start Scan" to let it Check For Errors in the most safe of manners possible. B)

Hopefully, you'll be back underway soon enough. ^_^

~Mr. D. V. "...wishing Micro$oft would stop trying to tell people what valid apps that they can have on their computers..." Devnull

#6 Krist Smith

    Senior Engineer

  • Developer
  • Developer
  • 629 posts

Posted 04 January 2018 - 12:06 PM

View PostThinice, on 03 January 2018 - 10:10 PM, said:

Fired up MWO to get a round in before bed and... got some sort of Inner Sphere scum hackery!

Not sure if this matters to anyone but if it happens for others I figured we can pile up in this thread to see if it's just me or Windows Defender ...

Anyone else get this?



Thank you very much for reporting this issue. I can assure you that we do virus and malware scans of all of our files prior to release. This is either a false-positive being reported by Microsoft or, more unlikely, the result of pre-existing malware on your system. To be on the safe side, I would highly recommend doing a full system scan with both Defender and a third-party scanner. Sometimes it's just one scanner that adds new rules that result in false positives, so using a second scanner (or even third, if you get conflicting results from the other two) should clear up any concerns. If other scanners don't see any problems with the game's exe, then you can create an exclusion for the file in Defender. As mentioned above, you can get the executable back by using the MWO Repair Tool (or, if you're using Steam, verify the game cache).

In the meantime, we've contacted Microsoft to help us identify whether or not this is simply a false positive. If it is, then we are hoping that the next set of Defender definitions handle the game's executable properly. If not, then we will work to identify the particular section of code being flagged and correct the issue.

In the meantime, we apologize for the inconvenience,

#7 Jman5

    Member

  • PipPipPipPipPipPipPipPipPip
  • Littlest Helper
  • Littlest Helper
  • 4,914 posts

Posted 04 January 2018 - 01:03 PM

Hey, I got the same message last night right after I logged off from MWO. Only difference is it blamed a different file.

Posted Image

Looking around the internet, I found this reddit thread.

Seems to indicate from some of the comments it could be a false positive.

Edited by Jman5, 04 January 2018 - 01:04 PM.


#8 Mole

    Member

  • PipPipPipPipPipPipPipPipPip
  • Ace Of Spades
  • Ace Of Spades
  • 3,314 posts
  • LocationAt work, cutting up brains for a living.

Posted 04 January 2018 - 01:10 PM

This is the second thread I've seen today reporting this problem where Windows Defender is reporting MWO's .exe file as a Trojan. When I saw the first thread I thought the guy had malware on his computer infecting other files but I remember last night before I went to bed my Windows 10 PC wanted to update. I'm sure it did while I was sleeping. Which means everyone else's Windows 10 PC probably updated last night as well. How much you wanna bet they updated something in Windows Defender that is making it give false positives?

Edited by Mole, 04 January 2018 - 01:12 PM.


#9 N0ni

    Member

  • PipPipPipPipPipPipPipPipPip
  • The Nightmare
  • The Nightmare
  • 2,357 posts
  • LocationIn a GTR Simulator Cockpit

Posted 04 January 2018 - 01:38 PM

If it's a Windows 10 update causing it i'm glad to be on 8.1 with zero issue. Posted Image

#10 Ssamout

    Member

  • PipPipPipPipPipPipPip
  • 643 posts
  • LocationPihalla

Posted 04 January 2018 - 02:45 PM

Well there should be more than two cases then.

#11 Tarl Cabot

    Member

  • PipPipPipPipPipPipPipPipPipPip
  • Tai-sho
  • Tai-sho
  • 7,824 posts
  • LocationImperial City, Luthien - Draconis Combine

Posted 04 January 2018 - 02:52 PM

View PostSsamout, on 04 January 2018 - 02:45 PM, said:

Well there should be more than two cases then.

Unless most others are actually using 3rd party antivirus software and not MS version Posted Image And it would only affect those who play MWO regularly or do not have antivirus program disabled, etc.

Edited by Tarl Cabot, 04 January 2018 - 02:53 PM.


#12 D V Devnull

    Member

  • PipPipPipPipPipPipPipPipPip
  • 4,390 posts
  • Locationis something I can not say... I keep landing up lurking...

Posted 04 January 2018 - 07:34 PM

View PostN0ni, on 04 January 2018 - 01:38 PM, said:

If it's a Windows 10 update causing it i'm glad to be on 8.1 with zero issue. Posted Image

Win 7 here, and happy to be using that with Eset NOD32 AntiVirus and Comodo FireWall... and NOT lousy & problematic Micro$oft Windows Defender. Yes, my family and I paid for Eset's NOD32 AntiVirus Update Subscription on what limited funds we have, but it's well more than worth avoiding problems like we're seeing here from Micro$oft Windows Defender. But yeah, I heard about Win 8's interface, and avoided it like it was a plague. Those tiles aren't for everyone. :)

~D. V. "Beware Micro$oft... They're merely an unavoidable, overcharging annoyance we all have to use." Devnull

#13 Thorqemada

    Member

  • PipPipPipPipPipPipPipPipPipPip
  • 6,396 posts

Posted 04 January 2018 - 10:17 PM

Win10 + Avast does not report any issue...

#14 N0ni

    Member

  • PipPipPipPipPipPipPipPipPip
  • The Nightmare
  • The Nightmare
  • 2,357 posts
  • LocationIn a GTR Simulator Cockpit

Posted 04 January 2018 - 11:06 PM

View PostD V Devnull, on 04 January 2018 - 07:34 PM, said:

But yeah, I heard about Win 8's interface, and avoided it like it was a plague. Those tiles aren't for everyone. Posted Image

8 was bad all around. 8.1 is great with all the bug fixes from 8's problems, more customizable, etc. Dunno what tiles you refer to unless it's the stuff when you hit the windows button... even then you can just right click the symbol and do stuff the old fashion way. Even has a few options if you just mouse over to the side on the desktop. I don't mind it, to each their own i guess.

#15 Krist Smith

    Senior Engineer

  • Developer
  • Developer
  • 629 posts

Posted 05 January 2018 - 10:41 AM

So we just heard back from Microsoft. They confirmed that the MWO game exe is clean. One thing to note is that they performed their scan with definition version 1.259.1187.0, which was just released yesterday. It's possible that this new version fixed the false positives from Defender.

So, it does appear as though the issue may have been resolved. We'll continue to monitor the situation. Please, anyone who has had this issue should perform a full scan at least with Defender itself, if not a third-party scanner. While it does appear to have been a false positive in the definitions, we cannot say for sure that it wasn't another piece of pre-existing malware infecting the MWO exe, so it's worth being sure that your system is clean.

If anyone else gets this threat detection from Defender, please let us know about it, and also let us know what version of the definitions you have. This information can be obtained by going into the Defender Control Center in Windows settings, click on "Virus & threat protection" and click on "Protection updates" at the bottom of the window.

#16 Krist Smith

    Senior Engineer

  • Developer
  • Developer
  • 629 posts

Posted 05 January 2018 - 10:47 AM

Confirmed false positive from Mircrosoft:
https://www.microsof...in32/Peals.F!cl





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users