XMPlay GME plugin

Started by mrmudlord,

evknucklehead

Why would it identify as a specific type of trojan, though? Specifically, Win32/Tulim.A!cl. Logically, if it was an inability to decompress the .dll, it would trigger as a generic "Unreadable  file" style error.

I also tried telling Windows Defender to allow the file, but it detected and auto quarantined the file again anyway.

I think that for now, unless Mudlord releases another build that doesn't trigger the warning, I'll just stick with the older version, even though some things sound a little better on the newer version.

deus-ex

Quote from: evknuckleheadWhy would it identify as a specific type of trojan, though?

Beside databases with definitions of already known viruses Anti-Virus applications use heuristic analyses to search for patterns of malicious code to identify yet unknown new/modified viruses. Sometimes this leads to false alerts.

Quote from: evknuckleheadI also tried telling Windows Defender to allow the file, but it detected and auto quarantined the file again anyway.

I don't have made good experiences with Windows defender either, therefore I disabled it in favour of a better product.

kode54

For reasons I wish to understand, mudlord is packing his releases with his personal packing software, which I have a slightly old source code to. Nothing too overt, just a custom loader and LZMA compression.

I say, wish to understand, because I think the source to this software is available somewhere. I think he uses his packer on his releases because he's proud of it. I know I would be, accomplishing something like that at long last. I even helped him out a bit with getting it working on more software, including my initial attempt at handling DLL imports and exports. I think he uses a stock library for processing those now, though.

He also password protects archives on his site, using a common password you may ask him for, or ask him to post here, because he frequently posts files that get caught as false positives by virus scanners, and those files being Google indexed tends to lead to his entire domain being blacklisted by browser security lists.

I stopped having the virus scanner issue ages ago, because I pay the expensive Code Signing Certificate Tax.

saga

Quotebecause he frequently posts files that get caught as false positives by virus scanners
...such as anything packed with custom exe packers.

piovrauz

"... because I pay the expensive Code Signing Certificate Tax". You made my day.

cooli

Hello mrmudlord,

Is there any chance we see an update of your plugin one day?

FIX94

Maybe somebody is interested in it, I finally uploaded my personal changes to the plugin onto my github, have been using them for over a year now without ever pushing them up  ::)
https://github.com/FIX94/xmp-gme
see the README for the changes, and click the "releases" tab for the actual .dll file.

Ian @ un4seen

Looks like a nice update. It is up on the XMPlay support site now.

Patrick

some .GBS files are played back wrong. Sounds like the low-end of frequencies are completely gone like in an equalizer. it's really bad. I am using nezplug for now instead.