Jump to content

ransomware behavior


SteelEagle

Recommended Posts

I use Bitdefender. The details are as follows. The process C:\Program Files (x86)\Renegade X\Launcher\Renegade X Launcher.exe manifests ransomware behavior and was blocked. Several files were encrypted by it and we couldn't automatically restore all of them. You can find the files to be restored below.

The file in question is connection_log_7777.txt C:\Program Files (86)\Steam\logs

Yes I run steam all the time my AV has no problem with it. 

Edited by SteelEagle
extra info
  • Thanks 1
Link to comment
Share on other sites

5 hours ago, SteelEagle said:

I use Bitdefender. The details are as follows. The process C:\Program Files (x86)\Renegade X\Launcher\Renegade X Launcher.exe manifests ransomware behavior and was blocked. Several files were encrypted by it and we couldn't automatically restore all of them. You can find the files to be restored below.

The file in question is connection_log_7777.txt C:\Program Files (86)\Steam\logs

Yes I run steam all the time my AV has no problem with it. 

To make sure: upload your "Renegade X Launcher.exe" file to VirusTotal and report back the result.
Also, for your safety, I have installed BitDefender myself to check for a false-positive.

Under no circumstance does mine warn of ransomware.

However, it is acting triggerhappy on other (online) files which could not be more clean.
So that already tanks my trust in BitDefender as to not play on the customer's fears.

Which version of BitDefender are you using exactly?

Kindly be reminded that today's ransomware attacks are overally decreasing and also shifting to businesses.
Nevertheless, do take precautions such as making an offline backup of your most sensitive or valuable files.

IF ever you fear or suspect an active ransomware encryption process: hibernate the machine.
Then unplug the power and calmly yet timely seek professional assistance. Do NOT reboot or shutdown.

Renegade X's Launcher does indeed interact with Steam.
In what way I don't know, but this is obviously a false positive. 🙂

Edited by DugeHick
  • Like 1
  • Thanks 1
Link to comment
Share on other sites

Thank you for your time and response.

I have BitDefender total security I ran the file through virus total as requested but it seems clear even with there read on BitDefender.

I appreciate the advice. I have a handful of games that I play and that was the first time something like that came up.

Once more thank you for your quick, kind, and professional response. 

Link to comment
Share on other sites

On 7/9/2020 at 11:44 PM, SteelEagle said:

I have a handful of games that I play and that was the first time something like that came up.

Once more thank you for your quick, kind, and professional response. 

Yes, I understand. I would've double-checked it too.
You're quite welcome.

EDIT: I would've loved to end this conversation on that high note, but something still bothers me about your situation.

There are still a couple of unknown variables here:
1. If this is a false-positive, why am I not getting it too? (since I now also run BitDefender with Steam)
2. The warning is extraordinarily concise, specifically claiming an encryption process. (on a simple log file..)
3. I've thoroughly searched the Launcher code, and as far as I can see it does not deal with local Steam files at all.
4. Viruses are known to inject malicious code into other - innocent - running processes, shifting blame to the latter.
5. Ransomware goes after documents and images first. .txt files will likely fall under that umbrella.

Depending on your personal level of neuroticism, I would suggest you consider that offline backup and to proceed carefully.
The Renegade X files are probably clean, but I cannot fully guarantee that the rest of your computer is too.

Perhaps you'd like to have a look at a more thorough scan, just to make sure.
Better safe than sorry.

Up to you.

Edited by DugeHick
it doesn't add up
Link to comment
Share on other sites

I appreciate the concern. I ran a full system scan with Bitdefender and nothing. I ran a scan with windows defender and nothing. I ran a scan with the link you provided some things about steam, 2 games and my gaming headset were listed as suspect. The games that were suspect were ones that I haven't updated in awhile. My headset and the usb connector are always making online connections back and forth when from discord . I think what happened is that BD was in need of an update and restart. I launched the game before this update happened. I have launched the game after the update and I haven't seen that warning since. If you downloaded BD after my post then yours would've been up to date automatically. Thats probably why you didn't get the same warning I got. 

  • Like 1
Link to comment
Share on other sites

12 hours ago, SteelEagle said:

I appreciate the concern. I ran a full system scan with Bitdefender and nothing. I ran a scan with windows defender and nothing. I ran a scan with the link you provided some things about steam, 2 games and my gaming headset were listed as suspect. The games that were suspect were ones that I haven't updated in awhile. My headset and the usb connector are always making online connections back and forth when from discord . I think what happened is that BD was in need of an update and restart. I launched the game before this update happened. I have launched the game after the update and I haven't seen that warning since. If you downloaded BD after my post then yours would've been up to date automatically. Thats probably why you didn't get the same warning I got. 

Alrighty then. Glad you're safe. :) Enjoy!

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...