Skip to content

Instantly share code, notes, and snippets.

@erukiti
Last active February 23, 2018 03:42
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save erukiti/e2815bfddc4b8591fe4c31a551a13fa1 to your computer and use it in GitHub Desktop.
Save erukiti/e2815bfddc4b8591fe4c31a551a13fa1 to your computer and use it in GitHub Desktop.
おとボク3の1.1パッチで Windows Defender がトロイの木馬っぽいものを検出した (誤検出の可能性も高そう)

おそらく誤検出だと思われるが、Windows Defender によって、Trojan:Win32/Fuery.A!cl が検出された。ぐぐってみた感じだと、他にも誤検出っぽい事例が見つかった。(と言っても本当に誤検出かわからないので、動かすなら自己責任にて)

検出環境

  • Windows10 (最新状態)
  • Windows Defender (最新状態)

zipのハッシュ値

$ md5 otoboku3patch011.zip 
MD5 (otoboku3patch011.zip) = 81f81318028f13a727056ed92cd8f01e
$ shasum -a 256 otoboku3patch011.zip 
b0fab2de5f96dddf6a1a5c2e938f5d711a59f6a011430a17d201a7724cbcce02  otoboku3patch011.zip

中身のファイルのハッシュ値

$ find . -type f | xargs md5
MD5 (./Patch.exe) = b90e40874c95763cc3c31b1ca9be9cef
MD5 (./「Patch.exe」をダブルクリックして実行して下さい.txt) = 7215ee9c7d9dc229d2921a40e899ec5f
MD5 (./appdata/GameData/data9.pack) = 3af5670e749cd6bfd31917ba738327c6
MD5 (./ReadMe.txt) = e602a4243a40d477e4078275c9333b79
MD5 (./data/config.u.txt) = b5c3a62f0ee9c66bf0590850a99ae6c5
MD5 (./data/TopReadMe.txt) = d26eb1cc681ccba8c34a350bf0aff3f5
MD5 (./data/message.u.txt) = 9839c995aa250e5714ba0b10bd912e3e
MD5 (./data/icon.ico) = 690ceb4d6594a74afbf0d0175bd30794
MD5 (./data/gui.u.txt) = 9333169944f62a0061ecb455fa82f278
MD5 (./data/CopyImage.bmp) = c9e4ddeb93c3269ee62a93bbf45d84a5
$ find . -type f | xargs shasum -a 256
f30b44c11fbb2d66407b0a3905519084e6f7f7e531ef534385f181c06344f8bb  ./Patch.exe
36a9e7f1c95b82ffb99743e0c5c4ce95d83c9a430aac59f84ef3cbfab6145068  ./「Patch.exe」をダブルクリックして実行して下さい.txt
59566afe6d2f5883c83029c86aa7d34c9b625e43e4010956ed260df124f39a41  ./appdata/GameData/data9.pack
2a8168008596bfa9a3f5b2a0fa65b074060a2e91f52520a3b5b9d8290399af3d  ./ReadMe.txt
44e394e9ce4115446f2ec7ff8009d680e5e1395b0f722822cf81be7b78f5991d  ./data/config.u.txt
b1d4f18ff917f569ed15a1a4f1998d072e5ef76b8315dab610a920cb22d4235e  ./data/TopReadMe.txt
6165d084a5b25fdbc426ffc6b55299ee9f106ee22439b030ac029cc9d5d7318f  ./data/message.u.txt
3c7a20a1c92d05241b6adebefeea8c71649ad923d5a4a560803f2d0b0e5a480c  ./data/icon.ico
0320f876b36dfcb3b92991ac4acdcadefee753cd9521b1588040b2a90dd947af  ./data/gui.u.txt
1c21affabd5c89cf7364f70fda840e6a290e5722dbce620478f2f34c0ec1f1a8  ./data/CopyImage.bmp
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment