Quote:
Originally Posted by InZiDeR
The issue is that many files are flagged as false positives because they're packed. Unfortunately, this has become the norm, which is quite risky. It allows PServer owners to embed injections and backdoors, taking advantage of the trust people place in these files, thinking they're safe.
There will always be black sheeps.
|
The reality is that this is such a reach and just doesn't happen. 99% of "pSrO dEvS" lack the knowledge to do such a thing. Those who do have the skill & ability to do so have already proven themselves to be trustable by the majority of the community. With 95% of servers using 1 of 2 filters (MaxiGuard & vPlus), with no other external DLLs, you can pretty much assure that there is nothing sketchy going on.
--
To the OP, an explanation:
You'll notice almost every client has the same detections on the same files. It's nothing to be worried about, it happens for two reasons:
1.) Original v1.188 files were flagged by Joymax after the files leaked.
2.) Custom DLLs are packed for protection against reversing/bypassing.
If you look into the detection labels, you'll notice that the majority of the "virus names" are nonsense - just AI detections for a suspicious program. So many valid applications and games face the same issue, just eventually getting whitelisted. Of course, the same does not apply for SRO as the files are pirated.
There are only 3 detections to worry about if found in a SRO client:
Jeefo, Ramnit, or Neshta.
Those are NOT normal and WILL cause harm to your system. Many people make the mistake of automatically adding an exclusion to any freshly downloaded client before the first use because they are so used to having to do this, after that, RIP.
The rest of the detections are completely harmless (thusfar).
Still, it's very rare to find a client infected with any of these viruses lately because of Elitepvpers' virustotal regulations for thread publishing. Such stuff isn't commonly found across the community anymore like how it was 5-6 years ago.
If you're really worried, just scan the directory before opening the client. You know the names to avoid, the rest are irrelevant.
Good luck!