# Virus in the launcher

**URL:** <https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127>\
**Category:** The Garage\
**Created:** [April 3, 2020, 11:38pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127 "2020-04-03T23:38:41Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Umbra.Animo](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/umbra.animo/32/3258_2.png) [@Umbra.Animo](https://discourse.cataclysmdda.org/u/Umbra.Animo)\
**Post date:** [April 3, 2020, 11:38pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/1 "2020-04-03T23:38:41Z")

</div>

so since I have not only been gone for a while I also changed and upgraded computers and have recently opted to get the launcher again. but my anti virus stuff detects a Sever Trojan virus in the most recent launcher.

---

<div class="post-metadata">

**Author:** ![Malkeus](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/malkeus/32/12037_2.png) [@Malkeus](https://discourse.cataclysmdda.org/u/Malkeus)\
**Post date:** [April 3, 2020, 11:41pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/2 "2020-04-03T23:41:39Z")

</div>

> [@CDDA Game Launcher (Automatic updates and more!)](https://discourse.cataclysmdda.org/t/cdda-game-launcher-automatic-updates-and-more/11168/212):
>
> From [the launcher FAQ](https://github.com/remyroy/CDDA-Game-Launcher#my-antivirus-product-detected-the-launcher-as-a-threat-what-can-i-do): Poor antivirus products are known to detect the launcher as a threat and block its execution or delete the launcher. A simple workaround is to add the launcher binary in your antivirus whitelist or select the action to trust this binary when detected. If you are paranoid, you can always inspect the source code yourself and build the launcher from the source code. You are still likely to get false positives. There is little productive efforts we can do as software deve…

---

<div class="post-metadata">

**Author:** ![Umbra.Animo](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/umbra.animo/32/3258_2.png) [@Umbra.Animo](https://discourse.cataclysmdda.org/u/Umbra.Animo)\
**Post date:** [April 3, 2020, 11:43pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/3 "2020-04-03T23:43:55Z")

</div>

oh… thanks  
at least that means I can use the lancher  
know if only I knew how to do the whole add the launcher binary thing

---

<div class="post-metadata">

**Author:** ![Malkeus](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/malkeus/32/12037_2.png) [@Malkeus](https://discourse.cataclysmdda.org/u/Malkeus)\
**Post date:** [April 4, 2020, 12:47am UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/4 "2020-04-04T00:47:30Z")

</div>

The exact procedure is largely dependent on which anti virus program you’re using. Basically, you want to find the quarantine section which should contain the launcher executable file and find the option to add an exception or allow this file. I really can’t explain it better than the faq, sorry.

Alternatively, use an older version. I haven’t bothered to update since 1.4.2 or maybe its 1.4.3.

---

<div class="post-metadata">

**Author:** ![S\_Gray](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/s_gray/32/7413_2.png) [@S\_Gray](https://discourse.cataclysmdda.org/u/S_Gray)\
**Post date:** [April 16, 2020, 10:30am UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/5 "2020-04-16T10:30:44Z")

</div>

Kaspersky Endpoint Security had detected _HEUR:Trojan-Banker.Win32.Emotet.pef_ in the main executable of version 10534. Version 10376 has no problem.

---

<div class="post-metadata">

**Author:** ![Gilliph](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/gilliph/32/10493_2.png) [@Gilliph](https://discourse.cataclysmdda.org/u/Gilliph)\
**Post date:** [April 16, 2020, 12:56pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/6 "2020-04-16T12:56:39Z")

</div>

huh, this explains why my launcher keeps deleting itself.

---

<div class="post-metadata">

**Author:** ![S\_Gray](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/s_gray/32/7413_2.png) [@S\_Gray](https://discourse.cataclysmdda.org/u/S_Gray)\
**Post date:** [April 17, 2020, 4:51am UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/7 "2020-04-17T04:51:12Z")

</div>

Our digital security engineer approved this is a new harmware

---

<div class="post-metadata">

**Author:** ![Gotdamnmiracle](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/gotdamnmiracle/32/7660_2.png) [@Gotdamnmiracle](https://discourse.cataclysmdda.org/u/Gotdamnmiracle)\
**Post date:** [April 17, 2020, 4:52pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/8 "2020-04-17T16:52:20Z")

</div>

Which versions contain the trojan? I don’t know how yo check and I don’t trust my antivirus.

---

<div class="post-metadata">

**Author:** ![Dany\_Raven](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/dany_raven/32/8544_2.png) [@Dany\_Raven](https://discourse.cataclysmdda.org/u/Dany_Raven)\
**Post date:** [April 17, 2020, 4:57pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/9 "2020-04-17T16:57:30Z")

</div>

1.4.8

but that and the previous version crash to desktop with this kind of error log

CDDA Game Launcher version: 1.4.7

OS: Windows-10-10.0.18362-SP0 (64-bit)

Type: \<class ‘ValueError’\>

Value: Humanization of the ‘weeks’ granularity is not currently translated in the ‘it’ locale. Please consider making a contribution to this locale.

Traceback:

File “cddagl\ui\views\main.py”, line 774, in timeout

File “lib\site-packages\arrow\arrow.py”, line 1053, in humanize

---

<div class="post-metadata">

**Author:** ![dpwb](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/dpwb/32/2609_2.png) [@dpwb](https://discourse.cataclysmdda.org/u/dpwb)\
**Post date:** [April 19, 2020, 2:08pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/10 "2020-04-19T14:08:15Z")

</div>

Really? lol

Its a heuristic, its a false positive. The code is open-source at [https://github.com/remyroy/CDDA-Game-Launcher](https://github.com/remyroy/CDDA-Game-Launcher)

Can your “digital security engineer” confirm where in this freely available code the “harmware” is?

---

<div class="post-metadata">

**Author:** ![Dany\_Raven](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/dany_raven/32/8544_2.png) [@Dany\_Raven](https://discourse.cataclysmdda.org/u/Dany_Raven)\
**Post date:** [April 19, 2020, 3:41pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/11 "2020-04-19T15:41:25Z")

</div>

> [@CDDA Game Launcher (Automatic updates and more!)](https://discourse.cataclysmdda.org/t/cdda-game-launcher-automatic-updates-and-more/11168/212):
>
> Poor antivirus products

A.k.a windows defender lol

---

<div class="post-metadata">

**Author:** ![Necrosian](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/necrosian/32/9959_2.png) [@Necrosian](https://discourse.cataclysmdda.org/u/Necrosian)\
**Post date:** [April 19, 2020, 4:49pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/12 "2020-04-19T16:49:27Z")

</div>

Wanted to play CDDA after an update. Couldn’t start launcher an thought antivirus ate it, checked quarantine, logs, nothing. Reinstalled, saw windows defender popup.

One time Win defender decides to do something, it fails miserably.

---

<div class="post-metadata">

**Author:** ![S\_Gray](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/s_gray/32/7413_2.png) [@S\_Gray](https://discourse.cataclysmdda.org/u/S_Gray)\
**Post date:** [April 21, 2020, 11:44pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/13 "2020-04-21T23:44:11Z")

</div>

> [@dpwb](#):
>
> Can your “digital security engineer” confirm where in this freely available code the “harmware” is?

I tried to bluff it was a false positive, but he told me it is a harmware recently announced by Information Security Competency Center of Rosenergoatom Concern. I did not specify any more so as not to attract additional attention. So I give you the information “as is”

PS forgive my poor English (little practice) if I was not clear enough that the virus was not in the launcher, but in the _game_.exe

---

<div class="post-metadata">

**Author:** ![GiggleGrassGatherer](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/gigglegrassgatherer/32/7743_2.png) [@GiggleGrassGatherer](https://discourse.cataclysmdda.org/u/GiggleGrassGatherer)\
**Post date:** [April 23, 2020, 10:24am UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/14 "2020-04-23T10:24:49Z")

</div>

> [@S\_Gray](#):
>
> Rosenergoatom

Eh, government agency. Be glad they don’t count Wordpad as a virus because it can change text files.

---

<div class="post-metadata">

**Author:** ![Valase](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/valase/32/6972_2.png) [@Valase](https://discourse.cataclysmdda.org/u/Valase)\
**Post date:** [April 23, 2020, 10:59am UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/15 "2020-04-23T10:59:12Z")

</div>

This reminds me of that time when Windows Defender detected Windows OS as a threat…  
Lesson learned: Never install the newest Windows updates at the moment they are pushed out.  
Not sure if it was Windows XP or Vista, but man, that was a hell of a ride.

Although… I mean… Windows Defender probably wasn’t **that** wrong…

---

<div class="post-metadata">

**Author:** ![S\_Gray](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/s_gray/32/7413_2.png) [@S\_Gray](https://discourse.cataclysmdda.org/u/S_Gray)\
**Post date:** [December 13, 2020, 3:22am UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/16 "2020-12-13T03:22:13Z")

</div>

In any case… looking for the game version about 10376 not newer then 01.01.2020  
Any new version is being shredded by Kaspersky

---

<div class="post-metadata">

**Author:** ![Dialo.Malison](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/dialo.malison/32/7220_2.png) [@Dialo.Malison](https://discourse.cataclysmdda.org/u/Dialo.Malison)\
**Post date:** [December 13, 2020, 7:44am UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/17 "2020-12-13T07:44:58Z")

</div>

[Cataclysm-DDA experimental build #10376](https://github.com/CleverRaven/Cataclysm-DDA/releases/tag/cdda-jenkins-b10376) can be found here. It was released on Feb 28.

[Cataclysm-DDA experimental build #10103](https://github.com/CleverRaven/Cataclysm-DDA/releases/tag/cdda-jenkins-b10103) can be found here and was released on Jan 1.

---

<div class="post-metadata">

**Author:** ![Zhilkin](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/zhilkin/32/3749_2.png) [@Zhilkin](https://discourse.cataclysmdda.org/u/Zhilkin)\
**Post date:** [December 13, 2020, 2:52pm UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/18 "2020-12-13T14:52:40Z")

</div>

That is not true.

---

<div class="post-metadata">

**Author:** ![TheZoneWizard](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/thezonewizard/32/1397_2.png) [@TheZoneWizard](https://discourse.cataclysmdda.org/u/TheZoneWizard)\
**Post date:** [December 14, 2020, 1:41am UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/19 "2020-12-14T01:41:37Z")

</div>

Thanks for this information. I had no idea we have access to old variants. Really helpful.

---

<div class="post-metadata">

**Author:** ![Dialo.Malison](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.cataclysmdda.org/dialo.malison/32/7220_2.png) [@Dialo.Malison](https://discourse.cataclysmdda.org/u/Dialo.Malison)\
**Post date:** [December 14, 2020, 6:19am UTC](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127/20 "2020-12-14T06:19:47Z")

</div>

You’re Welcome.

(20 characters)

[Next page](https://discourse.cataclysmdda.org/t/virus-in-the-launcher/23127.md?page=2)
