Hi, first I would like to mention I know near to nothing about malware analysis. I just wanted to play a discontinued old game on a private server but keep my PC secure at the same time.
I first checked files with Bitdefender, it shows a clear result. Then I wanted to check at least the exe file with VirusTotal and it showed 3 malicious flags. I also checked the file with Intezer Analyze, it also flagged it as malicious. I asked to discord server of the game, they claimed it is a false positive. I tried to find a sandbox program but saw you guys don't recommend it. I also learned I should check the first time in VT. It seems old but doesn't know what to do with that info. Today, the number of flags are increased to 5 but still no companies like Kaspersky or BitDefender. I saw a little menu in VT> behavior and check things like zenbox, virustotal observer, etc and saw registry actions like :
hash : 2896a701817b3d0d42f94f75078a098a87bc795c8a676aaecb82088c5a55f5b3
VirusTotal
I first checked files with Bitdefender, it shows a clear result. Then I wanted to check at least the exe file with VirusTotal and it showed 3 malicious flags. I also checked the file with Intezer Analyze, it also flagged it as malicious. I asked to discord server of the game, they claimed it is a false positive. I tried to find a sandbox program but saw you guys don't recommend it. I also learned I should check the first time in VT. It seems old but doesn't know what to do with that info. Today, the number of flags are increased to 5 but still no companies like Kaspersky or BitDefender. I saw a little menu in VT> behavior and check things like zenbox, virustotal observer, etc and saw registry actions like :
- HKEY_CURRENT_USER\Software\Wine
- HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option (this also occurs on legit programs)
hash : 2896a701817b3d0d42f94f75078a098a87bc795c8a676aaecb82088c5a55f5b3
VirusTotal
Last edited by a moderator: