Malwarebytes messages while starting re: blocking trojans and compromised sites

Discussion in 'Hardware, Software, Tech' started by Hermetic, Mar 5, 2021.

Thread Status:
Not open for further replies.
  1. Hermetic

    Hermetic Avatar

    Messages:
    231
    Likes Received:
    207
    Trophy Points:
    18
    Since installing Malwarebytes Premium when I start SOTA it pops up messages saying that it has blocked a site(it shows the IP address) "due to Trojan" or "due to Compromised". It has happened many times and shows what seems to be different IP addresses. It doesn't happen every time I start the game but often enough to be an annoyance and a concern. It happens most enough, it seems, during an update but will happen when there is no update to install.

    It keeps happening even after adding "Shroud of the Avatar.exe" and "Shroud of the Avatar - Launcher.exe" to Malwarebytes 'Allow List'.

    Searching the forums I found a mention of a problem similar to this having to do with having the "Help Upload Game Data via P2P" option selected. I have that option turned off so that shouldn't be the issue here.

    /edit: I should add that it doesn't just block one IP address per game start but that message can pop up several times while the game is loading.
     
    FrostII likes this.
  2. Echondas

    Echondas Bug Hunter Bug Moderator

    Messages:
    3,785
    Likes Received:
    4,001
    Trophy Points:
    165
    Gender:
    Male
    Location:
    NY
    Sounds like false positives based on SotA being a P2P game and connecting directly to other players in scenes with you. You should submit a support ticket to MB and see what they can offer for a solution.
     
  3. Cora Cuz'avich

    Cora Cuz'avich Avatar

    Messages:
    4,655
    Likes Received:
    7,616
    Trophy Points:
    153
    Location:
    Veritas Sanctuary
    My antivirus doesn't like the QA installer.
     
  4. Echondas

    Echondas Bug Hunter Bug Moderator

    Messages:
    3,785
    Likes Received:
    4,001
    Trophy Points:
    165
    Gender:
    Male
    Location:
    NY
    Do you use Steam for prod? Non Steam installers use P2p which might cause some false positives on endpoint AV - you can turn off seeding in the options in the installer which might help. You can also submit the binary to virustotal.com to get an idea of what major AVs think.
     
  5. Cora Cuz'avich

    Cora Cuz'avich Avatar

    Messages:
    4,655
    Likes Received:
    7,616
    Trophy Points:
    153
    Location:
    Veritas Sanctuary
    No, regular installer. I was able to install it anyway.
     
    Last edited: Mar 5, 2021
Thread Status:
Not open for further replies.