Page 1 of 2

Trojan in the WAR-64.exe file

Posted: Tue May 05, 2020 12:48 am
by Farfalla
My anti-virus program had an alert after the last patch. It alerted me with the following:

file: D:\ReturnOfReckoning-March2020\Warhammer Online - Return of Reckoning\WAR-64.exe
Threat detected:Trojan:Win32/Bomitag.D!ml

Any suggestions?

Re: Trojan in the WAR-64.exe file

Posted: Tue May 05, 2020 12:52 am
by Permabad
I'm in the exact same boat.

Re: Trojan in the WAR-64.exe file

Posted: Tue May 05, 2020 1:08 am
by Boulderbolg
Same thing here, using Windows Defender. The solution is to allow the file to run, but frankly, I am uncomfortable allowing it. This just started happening today.

Re: Trojan in the WAR-64.exe file

Posted: Tue May 05, 2020 1:12 am
by Permabad
Boulderbolg wrote: Tue May 05, 2020 1:08 am Same thing here, using Windows Defender. The solution is to allow the file to run, but frankly, I am uncomfortable allowing it. This just started happening today.
Yeah, it's Windows Defender. I agree, with it specifically being "Trojan:Win32/Bomitag.D!ml" that is uncomfortable. Admittedly, I don't know enough to say that it's just a false positive like the install guide suggests. Especially when I previously didn't run into any issues with install or prior patches.

Re: Trojan in the WAR-64.exe file

Posted: Tue May 05, 2020 2:10 am
by wargrimnir
It is a false positive. The way we handle files does manipulate objects in memory. This can be flagged as unknown files with trojan-like behavior. These are almost always a generic flag that can be submitted to these companies for review, if your antivirus allows that kind of thing.

The War-64.exe never existed as a live server file, so it's unknown to most databases, and the manipulation it does is to enable several 64-bit capabilities in the game engine that we found locked away. We assume they were disabled because 32-bit was very prevalent when live servers released, and a dual core processor was considered fairly high end hardware.

Re: Trojan in the WAR-64.exe file

Posted: Thu May 07, 2020 1:16 pm
by btbw2009

Re: Trojan in the WAR-64.exe file

Posted: Thu May 07, 2020 1:41 pm
by svonludwig
To bad. I deleted the game and now I cant reinstall. Perhaps my last day.

Re: Trojan in the WAR-64.exe file

Posted: Thu May 07, 2020 1:47 pm
by wargrimnir
Were you trying to make a point?

I have the same thing linked in the install instructions. Virustotal is where a lot of AV companies report their findings. Heuristic findings are automatically generated based on behavior tags, they're not actually good evaluators of what that behavior is doing, just that the behavior is used by viruses to do illegitimate things. We're just trying to make the game run properly.

Re: Trojan in the WAR-64.exe file

Posted: Thu May 07, 2020 1:55 pm
by Knatty
It is indeed being treated as a trojan since the March 6 update. On my pc and laptop both Webroot and Windows Defender were blocking the updater and quarantining the launcher.exe and updater.exe files.
I have since made the adjustments and successfully launched back into the game, #nohacksplease.

Re: Trojan in the WAR-64.exe file

Posted: Thu May 07, 2020 3:49 pm
by svonludwig
No War wasnt trying to be rude at all. I run a pc that I bought when WAR came out. I had to delete as I needed to do some secure things and didnt have time to figure it out. I have the installer running again. I went through the guide but I am still getting the 171k file download after using the new download offered. Not sure how to go around this as it just starts with the launcher.

Huge fan of the game and the wok you guys do.