edcellwarrior
03/02/21 05:14AM
Changer's "Cassandra's Christmas Surprise" Virus?
Changer, a well known game dev here, has made a game that is triggering my antivirus. And after a quick google search, almost every website it is hosted on has user complaints about that as well.

Has anyone had any experience running the game? I would like to play it but I'm certainly not going to install a trojan (windows defender is detecting it as a Glupteba trojan).

A link to the game can be found here: hypnochanger.itch.io/cassandras-christmas-surprise
Argonis
03/02/21 05:47AM
It may be a false positive, i doubt he's really trying to put a virus on your system.
edcellwarrior
03/02/21 05:49AM
Argonis said:
It may be a false positive, i doubt he's really trying to put a virus on your system.


I 100% believe Changer wouldn't do anything intentionally, but I can't afford to fix/restore my computer if anything goes wrong, so I was just going by "better safe than sorry" in this case.
hypnofish
03/02/21 05:56AM
i've downloaded and used it. as far as i can tell, there's nothing actually wrong with it. i ran multiple checks with multiple programs afterwards and they didn't find anything.
edcellwarrior
03/02/21 05:59AM
hypnofish said:
i've downloaded and used it. as far as i can tell, there's nothing actually wrong with it. i ran multiple checks with multiple programs afterwards and they didn't find anything.


Thank you for checking. I'm going to assume it's Windows Defender giving a false positive then.
Sir_Lurksalaot
03/02/21 06:37AM
Between this and your issues earlier with the site, it may be worth trying to do some deeper cleaning of your PC or something of that nature.
Changer
03/02/21 07:40AM
Pretty much every executable I export gets false-tagged as a virus by several anti-virus programs lately. I think something about the way stencyl packages executables upsets the virus scanners, or it may be that they just don't like executables that they don't have in their whitelist.

I had to manually whitelist them on my computer too because windows defender auto deleted them as soon as they were compiled several times in a row on my own computer too.
akaece
03/02/21 08:45AM
It's possible that software that was used to create the game has been compromised - that's how many exploits are spread. If one common package gets compromised - I won't go into all the ways this can happen, but it's nowhere near impossible - it can have a cascading effect that's very difficult to detect even for experienced devs. (It's even possible that it was a targeted attack on you, specifically, given that your games are downloaded and executed by a decent number of people.) I would not pass this up as AVs suddenly malfunctioning; I would recommend that you do as deep an investigation of your development toolkit as you can manage, make sure that your hosted files match the ones you're compiling, etc. If nothing else, having AVs screaming about your product is obviously not good, and you might find a way to clear that up even if it is a false positive.

ETA: If your own system was infected, it could also cause projects you compile on it to be infected. Maybe try compiling on another system or in a sandbox environment?
Changer
03/02/21 09:30AM
I have tried to research it. I've found a couple instances of other people using stencyl having the issue, but the developers of the engine didn't have any useful advice on it. I've tried submitting one of my projects to be verified as virus free with microsoft's site, but never heard back. Since I make adult content it's entirely possible they didn't consider it worth looking at, or immediately discarded it.

There really isn't much more I can do about it from a practical standpoint. All evidence points to it being a case of overzealous antivirus software. Outside of the false positives, there haven't been any reports that i've seen of any ill effects occurring after playing my games.
Hypnomaid20
03/02/21 08:56PM
One thing about the game that kinda threw me off were the hands when playing as a girl. Are they the same hands as for the male? Because they just felt kinda... Bulky.
Changer
03/02/21 09:27PM
It depends on which artist is doing the CG mostly, some of the artists I think are better or worse at differentiating male and female hands.
edcellwarrior
03/02/21 10:11PM

Sir_Lurksalaot said:
Between this and your issues earlier with the site, it may be worth trying to do some deeper cleaning of your PC or something of that nature.


The earlier issues were caused by the site’s blacklist limitations, this issue was caused by the program Changer uses to make games.
edcellwarrior
03/02/21 10:13PM
akaece said:
It's possible that software that was used to create the game has been compromised - that's how many exploits are spread.


I had considered this, but when I tried using a different antivirus (Malwarebytes) it didn’t recognize the program as a trojan. I’m assuming it’s a false positive from Windows Defender.
1


Reply | Forum Index