Author Topic: Potential Malware at Gensokyo.org  (Read 23357 times)

CyberAngel

  • Retired
Re: Potential Malware at Gensokyo.org
« Reply #30 on: November 05, 2014, 12:28:49 PM »
Oh, I see. I'm not all-knowing, but I try to make sure I know what I'm talking about, and I think I'm technically savvy enough to make heads or tails of different information. Of course, I'm all up for explanations from someone with more knowledge on the matter, so your help is appreciated.

MaronaPossessed

  • I am free to dream of my own dream
  • and so I shall dream
Re: Potential Malware at Gensokyo.org
« Reply #31 on: November 05, 2014, 01:15:11 PM »
Oh, I see. I'm not all-knowing, but I try to make sure I know what I'm talking about, and I think I'm technically savvy enough to make heads or tails of different information. Of course, I'm all up for explanations from someone with more knowledge on the matter, so your help is appreciated.
Same *pats* I'm going by experience myself. Hey, more answers from people with different experience, the better and more confidence we have in this situation XD

I think MaronaPossessed mentioned definitions as the virus definitions. Like, an AV may see the file as normal today, then flag it (or more often portion of the file) as malicious/suspicious the next day.
In the 10D English patcher's case, Symantec seems to have flagged, unflagged, then flagged the file numerous times, most likely because of changes in their generic/heuristic detections:

Yeah that's what I meant:)

Hakkai

  • Celestial
    • Touhou.net
Re: Potential Malware at Gensokyo.org
« Reply #32 on: November 11, 2014, 03:28:56 AM »
I don't know exactly how things are there, but from what I read here, the admins will probably never bother with fixing/touching the site again. So, perhaps it'd be best to create a new one to serve as a host for replays. (Similar to what happened between touhou wikia/touhou wiki). This may prove as a difficult task, though...  :(

It's not really that difficult, actually we already made one on our french board but it's restricted for registered members only right now.
We can help in creating a new one or open ours to anonymous users if it's needed.

Re: Potential Malware at Gensokyo.org
« Reply #33 on: January 21, 2015, 11:32:14 PM »
Has there been any word from gensokyo.org and the English patches they host? I can definitely see the possibility that the files are or but I am still wary about the site itself.

Is there any site that the community knows that is secure and hosts the said patches?
Or is it possible for shrinemaiden.org to host/give out a new secure location?

CyberAngel

  • Retired
Re: Potential Malware at Gensokyo.org
« Reply #34 on: January 22, 2015, 07:55:56 AM »
Has there been any word from gensokyo.org and the English patches they host? I can definitely see the possibility that the files are or but I am still wary about the site itself.

It seems like we're never hearing from that site's admin again, but a security specialist looked into both file and site. Both are safe.

Ghaleon

  • Long twintail-o-holic
Re: Potential Malware at Gensokyo.org
« Reply #35 on: January 24, 2015, 07:45:26 AM »
Just to point out said security specialist said awhile ago:
Quote
I would like to get back to the report of the reporting user though. The ones flagged are only the files/patchers but not the site's webpages & such, fortunately, so there is unlikely "hacking" involved. I'd also like to ask what AV cr0gon is using, and what the specific trojan detections were (screenshots, maybe), since he was the one who reported it & such.
I checked the site itself just to make sure though: no suspicious things or scripts found.

If you want more information regarding the matter, I suggest providing more to the people asking...I don't mean that snarky-like, I realize the quote was asked some time before your original question, I probably would stop checking too at that point.