lazylaunch2.exe tagged as Malware by Avast

Started by ad1999, March 01, 2010, 05:04:14 PM

Previous topic - Next topic

ad1999

ive been using lazylauncher for the past 4 days now... Avast never detected it as malware -- either by signature or behavior.


Avast did get an update as i was playing, and when i was done and started again, boom... msg and block for the app. i can of course add the file to the safe list, but wtf...
(i kno the story being why hacking tools are detected as malware)

itsarabbit

Want Beta key! :D

RaTcHeT302

Quote from: itsarabbit on March 01, 2010, 05:05:35 PM
sooo, whats your point, exactly?
His antivirus releaved lazy town as a virus wich is kind of annoing. Right OP?

xida1125

#3
same here, goto your avast main page, and turn off real time shields, problem solved.

or the other hand, i can't seem to be able to DL lazylauncher2 anymore nor extract the old one i had, anyone else have this issue?

ad1999

Quote from: RaTcHeT302 on March 01, 2010, 05:08:36 PM
Quote from: itsarabbit on March 01, 2010, 05:05:35 PM
sooo, whats your point, exactly?
His antivirus releaved lazy town as a virus wich is kind of annoing. Right OP?


yes very annoying. ALSO avast doesnt give u option to ignore, just to leave it alone.. but at the same time, it blocks access to it, by the OS and by the user...
i have added the file to the exclude list, but it hasnt done the trick. in the past, it has worked for my malware folder (yes i collect samples).


there might be a chance something infected the file. considering the only thing else that accessed it was the Starcraft II - Beta Launcher.exe that would the the first clue (its the new 0.15 version ... )

itsarabbit

Oh, it blocked. must've misread, sorry.
It's probably thanks to the update.
I would consider Avira antivir a better antivirus program though... so, you should get it! :)
Want Beta key! :D

ad1999

Quote from: xida1125 on March 01, 2010, 05:08:55 PM
same here, goto your avast main page, and turn off real time shields, problem solved.

or the other hand, i can't seem to be able to DL lazylauncher2 anymore nor extract the old one i had, anyone else have this issue?


no, problem not solved! for me its the regular shield. security is a layered process... every lil thing counts to getting secure.


from the avasts help file,
"Standard Shield checks the programs you start and the files you access. It will not allow an infected program to be started - so, the virus code cannot be activated."


now if i were to disable it, then any malware i would click (the malware would look like a regular program AND act as a regular program + malicious code activated i wouldnt kno abt) would be activated.. AND untill i would run the AV which in my case is once a week, id be infected... with AIDS... lol joking.. electronic AIDS!!!!

ad1999


7 on 22 (32%)  AVs detected it as malware... could all be false positive .. but really, thats what they all say btc cracks/keygens and 1/2 is malware  -- i risk it all the time, but i trust some of the sources




>>>> detailed results (btw, the exe ran is directly from the rar... so in theory it shouldnt have been infected by something else... )http://scanner.novirusthanks.org/analysis/3486029d85f26df4c9f732620ab7b034/bGF6eWxhdW5jaC5leGU=/ 

ad1999

#8
from teknogods. com (http://teknogods.com/phpbb/viewtopic.php?f=13&t=2036&sid=fe7b5a3398c6dff72ce738f624b62d43 )  ... the guys that came with it if im not mistaken...
"The md5sum of a legit lazylaunch2.exe:
dbee2e9c3c9ab695f707d4b7262ba4b4"

and mine...
# MD5 checksums generated by MD5summer  http://www.md5summer.org

# Generated 3/1/2010 5:30:37 PM

3486029d85f26df4c9f732620ab7b034 *lazylaunch.exe

CLEARLY they dont match ... unless they md5sumed the rar... but it says its the exe...    wtf???


any clues guys?




****** CORRECTION ******
the sum is dbee2e9c3c9ab695f707d4b7262ba4b4  not what i had before. so they are both the same.

Gamewiz

Quote from: ad1999 on March 01, 2010, 05:33:13 PM
from teknogods. com (http://teknogods.com/phpbb/viewtopic.php?f=13&t=2036&sid=fe7b5a3398c6dff72ce738f624b62d43 )  ... the guys that came with it if im not mistaken...
"The md5sum of a legit lazylaunch2.exe:
dbee2e9c3c9ab695f707d4b7262ba4b4"

and mine...
# MD5 checksums generated by MD5summer  http://www.md5summer.org

# Generated 3/1/2010 5:30:37 PM

3486029d85f26df4c9f732620ab7b034 *lazylaunch.exe

CLEARLY they dont match ... unless they md5sumed the rar... but it says its the exe...    wtf???


any clues guys?


If they don't match, delete the one you have and download from their site, which is the original source. Never download from a 3rd party if you don't trust them.

ad1999

Quote from: Gamewiz on March 01, 2010, 05:40:50 PM
Quote from: ad1999 on March 01, 2010, 05:33:13 PM
from teknogods. com (http://teknogods.com/phpbb/viewtopic.php?f=13&t=2036&sid=fe7b5a3398c6dff72ce738f624b62d43 )  ... the guys that came with it if im not mistaken...
"The md5sum of a legit lazylaunch2.exe:
dbee2e9c3c9ab695f707d4b7262ba4b4"

and mine...
# MD5 checksums generated by MD5summer  http://www.md5summer.org

# Generated 3/1/2010 5:30:37 PM

3486029d85f26df4c9f732620ab7b034 *lazylaunch.exe

CLEARLY they dont match ... unless they md5sumed the rar... but it says its the exe...    wtf???


any clues guys?


If they don't match, delete the one you have and download from their site, which is the original source. Never download from a 3rd party if you don't trust them.


it was from their site, but ive mistaken the md5sum, its the correct one, dbee2e9c3c9ab695f707d4b7262ba4b4


also the ^ is from the one i rared recently... i still cannot access the one avast reported as malware (but avast reports the same thing abt the file : / )


sorry abt incorrect md5sum. then it would apper that the AVs are starting to tag it as malware :(  ... its only a time till comodo firewall starts harassing me abt it ...

Gamewiz

Quote from: ad1999 on March 01, 2010, 05:47:15 PM
Quote from: Gamewiz on March 01, 2010, 05:40:50 PM
Quote from: ad1999 on March 01, 2010, 05:33:13 PM
from teknogods. com (http://teknogods.com/phpbb/viewtopic.php?f=13&t=2036&sid=fe7b5a3398c6dff72ce738f624b62d43 )  ... the guys that came with it if im not mistaken...
"The md5sum of a legit lazylaunch2.exe:
dbee2e9c3c9ab695f707d4b7262ba4b4"

and mine...
# MD5 checksums generated by MD5summer  http://www.md5summer.org

# Generated 3/1/2010 5:30:37 PM

3486029d85f26df4c9f732620ab7b034 *lazylaunch.exe

CLEARLY they dont match ... unless they md5sumed the rar... but it says its the exe...    wtf???


any clues guys?


If they don't match, delete the one you have and download from their site, which is the original source. Never download from a 3rd party if you don't trust them.


it was from their site, but ive mistaken the md5sum, its the correct one, dbee2e9c3c9ab695f707d4b7262ba4b4


also the ^ is from the one i rared recently... i still cannot access the one avast reported as malware (but avast reports the same thing abt the file : / )


sorry abt incorrect md5sum. then it would apper that the AVs are starting to tag it as malware :(


Ah ok. Well, let me assure you lazylaunch is perfectly clean, they even warn in the beginning some Anti-Virus programs will think it's a type of virus, but it's not. Really good programs like Kaspersky, ESET Nod32, etc., have all come up with it being clean. Just disable your AV while trying to play, or find a way to add it to an exclude list so your AV doesn't keep blocking it from executing.

ad1999

my thoughts exactly. this is not the first time such thing happened to me... been playin cracked games since 2002.
avast need more polish, since it has no option to unblock (give back access) the file it blocked with its 'standard shield' , a feature that looks over files you execute and gives it a quick scan in the background -- no performance issues ever noticed.
cant do anything abt it, no options to. i guess ill have to take teh shield down... i still got the firewall with its av running... so im ok .. untill i forget to turn on the shield and dbl click some baddies

Dariusz

#13
Same problem just pop up here :/ Was ok since yesterday there was no update and now its wrrr T_T


Problem solved... You have to add it to Exclusions in 
A Summary >Current Status( Change settings on right ) > Exclusions > add folder 
B Real Time Shields > Expert Settings > Exclusions > add folder 
Gl to all :) 

War_Machine

Spybot S&D
CCleaner
t + T vius removal

all FTW

btw these are all false positives that you get when you scan these files. They show up as clean with my programs. Virus showing up is the result of crappy programs like AVG