Virus: Evidence of False Positive?

Discussion in 'General Discussion' started by Stunji, Sep 12, 2020.

  1. Stunji
    Offline

    Stunji Member

    Joined:
    Sep 7, 2020
    Messages:
    2
    Likes Received:
    3
    TLDR: Is there proof that the virus is a false positive?

    This is in regards to all the "false positive" trojan threads I've been reading on the forums.

    Is there any evidence that this is a false positive?
    I get the impression that people are blindly believing this is a false positive since I can't find any evidence anywhere else.
    When searching for detections using the MD5 hash, there are red flags from the following reputable entities Symantec, McAfee, Crowdstrike, Endgame, and FireEye.

    MD5 Hash
    MapleRoyals.Exe - 4f198da735d841ee953aed0a79d3bd8b

    I got paranoid when I've had multiple instances of UAC and my AV reacting to MapleRoyals when I hadn't interacted with the executable at all.
    There wasn't anything strange when running through scheduled tasks, so there might be something that was installed that calls onto a process or service associated with MapleRoyals.
    Please help.
     
  2. Racingtrack
    Offline

    Racingtrack Well-Known Member

    Joined:
    Jan 4, 2015
    Messages:
    46
    Likes Received:
    11
    Gender:
    Male
    Well i dunno about the technical details in this and what is true or not. However, in all my years of playing different private servers of maple, this has always been the case. Anti-viruses always detect trojans in the client for reasons unknown to me. And im with you on that paranoia. However my solution that im using is that i download and play private servers on a separate computer that i dont really care too much about and dont have anything of value on. But again, the thing about the client being a trojan has always been a case when it comes to maple private servers as far as i know, so its nothing new.
    In the end its up to you wanna take the risk or not
     
    Bish4Life likes this.
  3. nosebleed
    Offline

    nosebleed Well-Known Member

    Joined:
    Jan 10, 2018
    Messages:
    1,086
    Likes Received:
    1,643
    Gender:
    Male
    Country Flag:
    All you need is for us to tell you that it's a false positive. Just listen - we are correct.

    Edit: I'll explain but fuck I hate people like you so much lol


    In simple terms it's related to how the game is/was packed with Themida that is also (far more) commonly used to pack viruses, thus triggering all anti-viruses to go off when something is packed with it - they determined long ago that Themida was so commonly used for viruses that any time something is packed with it ends up on your computer, it triggers your antivirus to detect is as malicious. gMS used it too, only they had digitally signed certifications for their clients (Royals does not) which made it so that their client was recognized as safe and in turn wasn't detected as malicious by AV programs from the very moment it was downloaded.
     
    Last edited: Sep 12, 2020
    Levi0sa, Tsue and Stunji like this.
  4. Stunji
    Offline

    Stunji Member

    Joined:
    Sep 7, 2020
    Messages:
    2
    Likes Received:
    3
    I knew I'd be giving someone a hard time by inquiring, and I really appreciate your response.

    Themida sounds a lot like VMProtect. Maybe Themida is causing all the flags from AVs because it's used more maliciously.
    It's still weird that the MD5 for MapleRoyals would be listed as malware unless AVs detect a signature from Themida.
    After my AV randomly alerted me on something out of the MapleRoyals's directory, I panicked; I thought maybe there was some beacon or established persistence.
     
    Tsue, Stan and Javier like this.
  5. zoeng
    Offline

    zoeng Well-Known Member

    Joined:
    Nov 10, 2015
    Messages:
    380
    Likes Received:
    164
    Country Flag:
    Just whitelist the entire MapleRoyals folder and play on! :love::o
     
  6. threesat
    Offline

    threesat Well-Known Member

    Joined:
    May 31, 2019
    Messages:
    132
    Likes Received:
    48
    Country Flag:
    Previously, I’ve had a case where it was detecting malware in some temporarily file directory outside of my royals folder right when I launched the game. Kinda sketchy so I stopped playing, although I’d recommend if you still want to play to do it through a vm
     
  7. Dave Deviluke
    Offline

    Dave Deviluke Forum Moderator

    Joined:
    Oct 5, 2017
    Messages:
    10,999
    Likes Received:
    10,569
    Gender:
    Male
    Location:
    MapleRoyals Discord
    Country Flag:
    IGN:
    CygnusQueen
    Level:
    110
    Guild:
    WorldTour
    Royals is being recognized as a malware/trojan cause Nexon told the anti-virus companies that all modified files = illegal

    Do take note that this can happen to legit files released by Nexon as well, Royal is not actually a virus but Anti Virus have to identify them as virus to prevent conflicts with Nexon

    Example of Nexon files recognized as virus - https://maplestory.nexon.net/news/24299/known-issue-anti-virus-false-detections
     

Share This Page