#Support ruffianed

1 messages · Page 1 of 1 (latest)

vale patioBOT
#

<@&872407642302197760>

Welcome to your Support Thread

Please check if your using the latest Skytils version at #Releases then check #Faq to see if your issue is maybe there, support will come soon.

If you crash do the *crash command in Discord and follow the instructions.

wet mortar
#

shouldn't create multiple

#

I think

solar timber
#

yeah a lot of them were created and it’s a bit suspicious to me

#

and the function virustotal is saying it does is also anomalous

solar timber
#

someone explain why it’s editing registry keys and creating a non native .exe (loaddll64.exe), it doesn’t seem like this mod has any reason to be messing with registry keys or anything of that nature

wet mortar
#

have to say, it is only flagging on one vendor
have you tried just deleting the whole thing and seeing if your game still runs?
also I'm assuming you're on windows?

solar timber
#

yes i am on windows. i deleted it but also removed everything else skyblock related in case it is something malicious. despite only one vendor flagging it, the operations of the file seem very strange

wet mortar
#

not sure about it creating dlls and a bunch of folders tho

solar timber
#

why is it messing with my registry keys?

wet mortar
#

do you know which ones

solar timber
solar timber
#

does anyone have an answer to this???

#

i believe this is an important security issue that needs to be addressed

karmic herald
solar timber
#

the file itself just seems a bit suspicious

obtuse field
#

So who flagged it and what for?

solar timber
#

im not sure, but I would like for the developers to look into it because now I'm concerned if my computer has been infected from this mod

obtuse field
#

Well if we can't tell by who or for what there isn't a lot to look into

#

Probably just the normal virustotal behavior

solar timber
#

no, look at the behavior of the file... thats not normal what it's doing

obtuse field
#

Then what's it doing?

solar timber
#

it's altering key registries

obtuse field
#

Yeah all I really see is permission checks and windows error reporting

solar timber
obtuse field
solar timber
#

Conclusion:

karmic herald
#

If you tell it "accessing xyz is possibly malicious" it'll tell you that it's malicious

#

Also, in the Conclusion it's saying it like that Library is for hypixel skyblock, but it isn't, it's a java port of google's brotli stuff

karmic herald
remote urchin
remote urchin
# solar timber why is it accessing all of those folders and keys? why does it install an exte...

ok so let me ask you something-

Adobe modifies some registry keys
Notepad++ modifies some registry keys
A ton more programs free or paid have to modify registry keys

Are those programs malicious?

And to counter the other points too, other programs have to install an external executable, sometimes multiple. Those are malicious... right?

Also, werfault is, you know, the place to report problems that happen. So, you know, other programs are malicious too because they have to mess with it, right?

also, what folders? Unless you mean registry key folders, in which case see above.