Rescue HQ - The Tycoon

Rescue HQ - The Tycoon

View Stats:
Oximat 28 Mar, 2021 @ 1:32am
suspicious dll-file in user folder
After starting this game, Microsoft Defender Antivirus pops up with a message "Virus & thread protection; Security Scan required. Your IT Administrator requires a security scan of this item..."

Looking into the Defender Log (via Event Log) it seems that Windows uploaded the DLL-File from the RHQ-Folder (C:\Users\...\AppData\Local\Temp\stillalive studios gmbh\RHQ\Player\FSX) onto its servers for further analyzing. Checking this file manually via Virustotal 5 scanners detect this file as unsafe.

Anyone with the same experience? Statement from developer?
Last edited by Oximat; 28 Mar, 2021 @ 1:32am
< >
Showing 1-14 of 14 comments
swimspud 20 Jan, 2023 @ 12:51pm 
thats scary
Crazy Old Vet 10 Aug, 2023 @ 12:48pm 
might be the boogey man
Orcat 9 Oct, 2023 @ 1:38pm 
Want to know further information about this post. Other players' experience, or reply from developer.
ska 21 Dec, 2023 @ 9:40am 
Same for me. Recognized as Trojan:Win32/Wacatac.B!ml from Windows.
Orcat 10 Mar, 2024 @ 8:29pm 
Push up this topic. It's a shame there are some games from this developer seem interesting.
CaveMan 7 Apr, 2024 @ 10:56pm 
Originally posted by Orcat:
Push up this topic. It's a shame there are some games from this developer seem interesting.

Sad part is they release unfinished stuff and just as fast as they release them, abandons them...
Same here!
Oximat 24 Apr, 2024 @ 1:14pm 
It's a shame that this is ongoing for years now wiithout further analyzing by the devs or steam
CaveMan 24 Apr, 2024 @ 8:14pm 
If you want you can upload that dll here: https://www.hybrid-analysis.com/
And see what comes up on it, sometimes it's better to get a few second opinions.
Oximat 25 Apr, 2024 @ 3:23pm 
Done
Bobby 11 Jun, 2024 @ 5:28am 
Originally posted by Oximat:
It's a shame that this is ongoing for years now wiithout further analyzing by the devs or steam

House of Steam, doesn’t care what it is or it’s function. As long as the $800 THOUSAND per steam employee keeps rolling in the door[http//Sutton], for doing nothing but sell someone else’s games and take a 30% cut. (Yeah they take 27 moolah out of a 90 game)
Steam is the biggest company out there now.
Bigger than Microsoft,Apple,Facebook, yet everyone else thinks it’s the other way around. How naive.


They have nothing to do with what a company does with its software, they tell *you* to contact the company.
Like people believing that steam is safe and virus scanned it’s hosts files… wrong.
https://hothardware.com/news/valve-pushes-two-factor-sms-to-developers-updating-games
Orcat 15 Jul, 2024 @ 2:09am 
Originally posted by hillyhaven:
Reported this to steam. Suggest you all do the same by scroll down and clicking the flag button on https://gtm.you1.cn/storesteam/app/809720/Rescue_HQ__The_Tycoon/
It took me a while to find the flag. It's beside the "Embed" button.
Billy Rex 17 Dec, 2024 @ 6:11am 
Also got a pop up for that today (after playing it several times), wondering what's up with that.
Hi,
Sorry for answering this only now.
The game uses fsharp scripting for its main logic and mods. The "suspiccous DLLs" are the compiled version of those scripts and are created on each game start.
When we released the game Virus scanners where not as paranoit about them nowadays it looks like more heuristics don't like this behaviour.
We already reported similar issues to other Virus Scanner providers as false positives and got it resolved.

That usually works like this.
  • Find the false positive report form on the provider website
  • Submit the supissious file with a short discription with context
  • Wait for their experts to have a look and resolve the issue
As devs we are not always aware if a new detection poped up, so it would be super helpfull if you as comunity could report those things to the Virus Scanner Providers.

Grettings
Jerry
Last edited by [Heinz] Template Metaprogramming; 18 hours ago
< >
Showing 1-14 of 14 comments
Per page: 1530 50

Date Posted: 28 Mar, 2021 @ 1:32am
Posts: 14