Page 1 of 1

FTL triggering virus warning in NOD32

Posted: Wed Sep 12, 2012 7:41 pm
by HairySammoth
Hey guys - just a quick heads up, the latest version of FTL from Steam is triggering a virus warning from ESET's (usually excellent) NOD32 antivirus.

Image
Image

I'm 99.999...% certain this is a false positive... and VirusTotal agrees with me. ESET seems to be the only antivirus product which doesn't like the file. Interestingly, I'm not the first person to run this test at VirusTotal - so others have had this issue too. Uninstalling/deleting local content and reinstalling triggers the same warnings. I haven't tried it with the GOG DRM-free version yet.

I'm happy to pootle along with the FTL directory in my exclusions list, I just thought you guys might appreciate some warning in case someone starts accusing you of hacking their PC!

Re: FTL triggering virus warning in NOD32

Posted: Wed Sep 12, 2012 7:51 pm
by geldonyetich

Re: FTL triggering virus warning in NOD32

Posted: Wed Sep 12, 2012 7:59 pm
by HairySammoth
Cool - I'll leave this topic up as it isn't mentioned anywhere on these forums (that search can find). I didn't check the bug report site as I don't really consider a virus false positive as a bug :oops: . If anything, it's a bug with NOD32. Thanks though!

Re: FTL triggering virus warning in NOD32

Posted: Wed Sep 12, 2012 9:31 pm
by curithwin
Virus checkers go through the EXE code looking for set patterns in the code and if it finds them it flags it as a virus. So it can be easy to make a false positive if someone messed up ONE byte of code in the virus definitions.

Re: FTL triggering virus warning in NOD32

Posted: Wed Sep 12, 2012 10:21 pm
by HairySammoth
I doubt it's even a mistake in the virus definitions, honestly - it's almost certainly just some quirk of NOD32's heuristics for identifying novel threats. Hence the "probably unknown virus" part. Either way though, definitely a false positive.