Jump to content

[FALSE POSITIVE]DCS World 2.6 trojan? worldgeneral.dll


NaOH1

Recommended Posts

Silent? They already edited the thread title; what else is needed?

 

bCDt9Ma.png

 

The entry "FALSE POSITIVE" is unfortunately not enough to convince me.

Even BIGNEWY wrote that this is probably a false alert. This means that even ED does not know what it is all about, because they have not written anything specific so far.

 

You guys are all reaaaaally new to the internet if you are freaking out so much about this stuff

 

I have been using the Internet since the late 90's, do you think it is too short? I don't understand what your post meant to mean.

Link to comment
Share on other sites

  • Replies 164
  • Created
  • Last Reply

Top Posters In This Topic

You guys are all reaaaaally new to the internet if you are freaking out so much about this stuff

 

:lol: I forgot who said: "It pays to be paranoid" (It might have been in a movie)... Hell, even today when I browsed through the Hornet's "Pics and videos" forum, as I scrolled down the last page I accidentally clicked on one of the pics (I'm still trying to get used to my new trackball) and voila... my AV hollered at me and bragged that it stopped an intrusion attack, I guess from the pic hosting website. Good job AV!:thumbup:

Link to comment
Share on other sites

It is sarcasm, a result of you guys apparently not having dealt with something like this before. If the program is a non-quantity (ie not some crapware you downloaded off an obscure filesharing site) you whitelist it and move on. Is it annoying? Yes. Does it take two seconds to deal with? Also yes.

 

@Gripes

A lot of music/pic/file sharing sites will try to insert some crap into your stream for monitoring, that's why I don't recommend using stuff like that. Certain sites have a vibe about them you can usually tell if they're safe to use. Ie pop ups and fake ''click me'' ads or ''virus warnings'' you should leave. The owners aren't curating their site. Etc

 

Paranoia is good and all, but like a lot of things, there's a degree involved. Not enough is recklessness, too much is just poor sense. We're talking about a known quantity here, DCS. They're not slipping you malware, nor are they likely to get infected without knowing it.

 

That's why you can override quarantine and whitelist, because AV aren't perfect and can hang up on safe files. You need a way to override it.


Edited by zhukov032186

Де вороги, знайдуться козаки їх перемогти.

5800x3d * 3090 * 64gb * Reverb G2

Link to comment
Share on other sites

...That's why you can override quarantine and whitelist, because AV aren't perfect and can hang up on safe files. You need a way to override it.

 

Well, I did (wisely or unwisely) on the day 2.6 was released. I guess mainly for the reasons you stated and also because I use my desktop for the single purpose of flight simming (currently DCS is the only sim running on it) and... as crazy as it sounds I've been pretty happy with performance so far. That's in SP. Can't fly MP for next 2 months so not too much bitching from me:D

Link to comment
Share on other sites

  • ED Team
The entry "FALSE POSITIVE" is unfortunately not enough to convince me.

Even BIGNEWY wrote that this is probably a false alert. This means that even ED does not know what it is all about, because they have not written anything specific so far.

 

ED have been in contact with Karpersky, and users have already reported their virus definitions updating and ignoring DCS now.

 

But it is a personal choice with security, if you are not happy it is best to wait for your definitions to update.

 

thanks

smallCATPILOT.PNG.04bbece1b27ff1b2c193b174ec410fc0.PNG

Forum rules - DCS Crashing? Try this first - Cleanup and Repair - Discord BIGNEWY#8703 - Youtube - Patch Status

Windows 11, NVIDIA MSI RTX 3090, Intel® i9-10900K 3.70GHz, 5.30GHz Turbo, Corsair Hydro Series H150i Pro, 64GB DDR @3200, ASUS ROG Strix Z490-F Gaming, HP Reverb G2

Link to comment
Share on other sites

ED have been in contact with Karpersky, and users have already reported their virus definitions updating and ignoring DCS now.

 

But it is a personal choice with security, if you are not happy it is best to wait for your definitions to update.

 

thanks

 

Thank you for your response. That is enough for me. I know what to wait for.

Greetings.

Link to comment
Share on other sites

ED have been in contact with Karpersky, and users have already reported their virus definitions updating and ignoring DCS now.

 

But it is a personal choice with security, if you are not happy it is best to wait for your definitions to update.

 

thanks

 

 

 

 

Thank you Bignewy,

 

 

 

that's the plan. Still, there's another install called "stable version", which in my case, seems to be unaffected :)

 

 

Did anyone get in contact with BitDefender as well?

Link to comment
Share on other sites

  • ED Team
Thank you Bignewy,

 

 

 

that's the plan. Still, there's another install called "stable version", which in my case, seems to be unaffected :)

 

 

Did anyone get in contact with BitDefender as well?

 

Unsure about bitdefender, but usually when one provider virus definitions update the rest of the providers update after.

 

Yes stable version is not affected. It seems some of the security changes the team made triggered the antivirus.

smallCATPILOT.PNG.04bbece1b27ff1b2c193b174ec410fc0.PNG

Forum rules - DCS Crashing? Try this first - Cleanup and Repair - Discord BIGNEWY#8703 - Youtube - Patch Status

Windows 11, NVIDIA MSI RTX 3090, Intel® i9-10900K 3.70GHz, 5.30GHz Turbo, Corsair Hydro Series H150i Pro, 64GB DDR @3200, ASUS ROG Strix Z490-F Gaming, HP Reverb G2

Link to comment
Share on other sites

Bitdefender saved the dll in quarnatine, restor it and everything is ok ! (OB not Stable)

CU you in the * AIR *  ^AirWolf

PC > BE QUIIET Power 1000 W ATX 3.0 * ROG STRIX Z690-F * i7-12700 KF * DDR5-6000 64 GB * M.2 980 EVO PRO 2 TB * RX 7900 XTX 24 MB XFX MERC 310 BLACK EDITION  *

 

 

 

Link to comment
Share on other sites

So I did everything mentioned in the thread here. After putting DCS on Whitelist of my AntiVir program (Avira) the world.dll issue seems to be solved, though I can still not start DCS, because I get a application can't start error...

I did run a repair, cleanup and everything and running out of ideas how to solve this.

Please help someone...

i7 6700k @ 4,5 Ghz | MSI 1080ti Aero | 32 GB RAM 2133 | 500 GB SSD | TM Warthog | MFG Crosswind | HTC Vive |:pilotfly:

Link to comment
Share on other sites

So I did everything mentioned in the thread here. After putting DCS on Whitelist of my AntiVir program (Avira) the world.dll issue seems to be solved, though I can still not start DCS, because I get a application can't start error...

I did run a repair, cleanup and everything and running out of ideas how to solve this.

Please help someone...

 

 

Preuss, one thing I can recommend is to have both versions installed side by side on different hard drives/SSDs, the stable version and open beta. Currently, if you want to fly, the stable version is a good way to go, no issues with that version. Second thing is that when you reinstall the open beta (after an uninstall due to virus detection issues like in my case :smilewink:) you dont have to wait for too long - the reinstall took less than 2 hours for DCS OpenBeta with all available maps and 19 modules (or so :music_whistling:) because the installer took advantage from the stable version install, where it just copied all data that the two versions have in common, instead of downloading all stuff again. Not exactly painful...

Link to comment
Share on other sites

Unsure about bitdefender, but usually when one provider virus definitions update the rest of the providers update after.

 

Yes stable version is not affected. It seems some of the security changes the team made triggered the antivirus.

 

 

Sounds like waiting for ED to figure out the root cause and antivirus providers to get used to those changes is a good way to go... :)

Link to comment
Share on other sites

There have been a lot of these false positives with 2.5.6

New hotness: I7 9700k 4.8ghz, 32gb ddr4, 2080ti, :joystick: TM Warthog. TrackIR, HP Reverb (formermly CV1)

Old-N-busted: i7 4720HQ ~3.5GHZ, +32GB DDR3 + Nvidia GTX980m (4GB VRAM) :joystick: TM Warthog. TrackIR, Rift CV1 (yes really).

Link to comment
Share on other sites

My antivirus detected this file as infected

m5V4qp5.png

 

 

Thats my current problem as well...as I have posted. BitDefender moves it to quarantine. "Restore" from quarantine doesn't work for me, DCS OB is currently unusable, it starts a lot slower thatn ever before and then, on the start up screen, it is stopped and won't let me do anything. Antivirus stops executing DCS... as for me there's now way out currently

Link to comment
Share on other sites

I was given this with:

 

 

Gen:Variant.Ursu.776114 virus detected by BitDefender. It was in the F14 modules package and that module is now unflyable :-/

 

First time I ever see it though. I wonder why we're getting different alerts though.

Link to comment
Share on other sites

I was given this with:

 

 

Gen:Variant.Ursu.776114 virus detected by BitDefender. It was in the F14 modules package and that module is now unflyable :-/

 

First time I ever see it though. I wonder why we're getting different alerts though.

 

Had the same problem, F14 was not flyable anymore.:noexpression:

 

I went trough this steps :

 

1. delete F14 module (also manual erase of files in "_download" and "mods" folder)

2. added exceptions to Bitdefender 2020 for DCS and DCS updater (example bellow)

3. REBOOT <--- this one is also crucial!

4. redownload F14 module (setup should not fail now)

 

Exceptions:

 

8xnzOW2.png

 

Hope that helps!

 

ryak84

Link to comment
Share on other sites

Nothing has changed...

 

Since the update to 2.5.6 nothing works & and nothing helps, the open beta can't even be started since then...latest hotfix 2.5.6.43931 and the update of today 2.5.6.44266 both didn't change anything. Various repairs and complete and reinstallations in vain. It still triggers antivirus (BitDefender in my case) and restoring suspicious files put under quarantine doesn't help either....ithe startup process is always stopped and I have to kill the dcs process using the task manager.

 

 

ED please, are you still working on a solution for this?

Link to comment
Share on other sites

After todays update (2.5.6.44266) - DCS will not start.

 

I got this from Bitdefender when i tried to repair with Updater Utility.

My two other machines running Windows defender are happy with the update.

 

 

 

Is it safe to make en exception for this file in BitDefender?

 

1086777643_2020-03-0420_40_10-Window.png.c0539c076e89a46dadb595c913a018fb.png


Edited by Zappovitz
Link to comment
Share on other sites

Bitdefender detected virus after update

 

After updating to latest update today Bitdefender detected a virus.

 

"The file E:\Program Files\Eagle Dynamics\DCS World OpenBeta\bin\World.dll is infected with Gen:Variant.Ursu.768621 and was moved to quarantine. It is recommended that you run a System Scan to make sure your system is clean".

 

Has anyone else experienced this?

Link to comment
Share on other sites

I got this one with the latest update (Bit Defender). I've had virus notifications for the last two updates but never before that.

 

The file D:\Program Files\Eagle Dynamics\DCS World OpenBeta\_downloads\.torrents\HEATBLUR_F-14.arch_x86_64\89\897787d58d5886c56dc7a32cc4d15908ab471b45991c3074a7c1576376be810b is infected with Gen:Variant.Ursu.776114. The threat has been successfully blocked, your device is safe.

 

Any advice guidance from ED would be appreciated.

Link to comment
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...