Lavisoftsoft Crashmobile has Grafter Malware

Discussion of Inner Space

Moderators: Lavish Software Team, Moderators

Post Reply
larsrystedt
GamingTools Subscriber
Posts: 2
Joined: Wed Feb 19, 2014 6:15 am

Lavisoftsoft Crashmobile has Grafter Malware

Post by larsrystedt » Wed Dec 24, 2014 6:05 am

This morning two of boxes warned of Graftor.169210 malware virus in LavishsoftCrashMobile.exe!
After removal I get an immidiate errormessage about LavishsoftCrashMobile.exe is infected and in use. This came after the latest patch.

CyberTech
GamingTools Subscriber
Posts: 5
Joined: Wed Sep 28, 2005 7:55 pm

Post by CyberTech » Wed Dec 24, 2014 6:52 am

Graftor is almost always a false positive. Note that LavishCrashMobile.exe hasn't changed since November 11th.

http://totalhash.com/analysis/cedaf8a1a ... ddd063cde2

larsrystedt
GamingTools Subscriber
Posts: 2
Joined: Wed Feb 19, 2014 6:15 am

Post by larsrystedt » Wed Dec 24, 2014 8:34 am

Cool, thank you feel a bit relieved:=)

Lax
Owner
Posts: 6634
Joined: Fri Jun 18, 2004 6:08 pm

Re: Lavisoftsoft Crashmobile has Grafter Malware

Post by Lax » Wed Dec 24, 2014 8:40 am

larsrystedt wrote:This morning two of boxes warned of Graftor.169210 malware virus in LavishsoftCrashMobile.exe!
After removal I get an immidiate errormessage about LavishsoftCrashMobile.exe is infected and in use. This came after the latest patch.
To be clear, someone e-mailed me this exact thing yesterday, including the bit about the "latest update". Turns out that guy hadn't updated Inner Space in more than a month, so he had a pre-Nov 11 version of Inner Space that did not include digital signatures, and Bit Defender was blocking the download of new versions with the digital signatures because of this false positive detection.

I suspect your issue is exactly the same. Run the Inner Space installer or ISBoxer installer to refresh the files with the latest, digitally signed versions, which should help prevent this and other false positive detections.

rviking
GamingTools Subscriber
Posts: 3
Joined: Fri May 08, 2009 3:03 pm

Post by rviking » Wed Dec 24, 2014 11:56 pm

I had that same problem yesterday.

I uninstalled Inner Space and tried re-installing it on another drive, but it still hangs on LavishCrashMobile.exe when trying to download the file. I'm sure it's Bit Defender preventing the file from coming down again but it won't let me add an exclusion for it either.

Is there a way to have the patcher skip LavishCrashMobile.exe? Or to prevent the patcher from running all together?

Thanks!

rviking
GamingTools Subscriber
Posts: 3
Joined: Fri May 08, 2009 3:03 pm

Post by rviking » Thu Dec 25, 2014 12:02 am

Disregard please, I was able to add the exception for it!

Lax
Owner
Posts: 6634
Joined: Fri Jun 18, 2004 6:08 pm

Post by Lax » Thu Dec 25, 2014 9:02 am

I've made a few minor changes to LavishCrashMobile and uploaded it to the server as the current version of the file.

virustotal.com reports that both Bit Defender and F-Secure should treat this updated version as clean, with no current false positives on any of 56 AV scanners: https://www.virustotal.com/en/file/d610 ... 419515797/

Hopefully that takes care of this for you Bit Defender / F-Secure users!

Post Reply