Update re: wall-e inspired game

Well, for what it's worth, I haven't been able to find anything nefarious in either the UK or USA targeted installers for the wall-e inspired game that Symantec detects as a keylogger.  Wayne reports that Sunbelt's new VIPRE product has found nothing.  TrendMicro also does not detect a problem.

I have installed the US and UK versions of the software in a VM with Process Monitor running and did not see any sign of Ardamax being installed by the game demo.  I have not tracked down why there is a difference in file size.

There is a chance, of course, that the installers that I downloaded behave differently in a VM, and I don't have a sacrificial box available for live testing at the moment, but be that as it may, until and unless I find evidence to the contrary, I am assuming that the Symantec alert is a false positive, hoping I don't have to eat crow later.

I note that there has been an update posted to the Timeless Journeys website. 

And Christopher Boyd weighs in.

My personal opinion is that Symantec screwed up.  That being said, it will be interesting to watch as events transpire.

Comments

# re: Update re: wall-e inspired game

Sunday, August 03, 2008 6:55 AM by Paperghost

I found nothing with VIPRE or VirusScan On Demand, I'm also testing it on a VM though which could make a difference.

I really hope this is a f/p, though I'm still curious as to the file size difference...