Jump to content

Anti-Virus picks up Trojan in ED products installer


Recommended Posts

Posted

It has never had an issue with anything from ED products until the latest update of DCS World 1.5

 

2r2vedh.jpg

 

It is picking up a Tojan-downloader.Win64.Agent.bb.

Answers to most important questions ATC can ask that every pilot should memorize:

 

1. No, I do not have a pen. 2. Indicating 250

Posted

I this a result of the new seeding strategy? Maybe a seeder was infected?

ASUS Tuf Gaming Pro x570 / AMD Ryzen 7 5800X @ 3.8 / XFX Radeon 6900 XT / 64 GB DDR4 3200 

"This was not in the Manual I did not read", cried the Noob" - BMBM, WWIIOL

  • ED Team
Posted

hmm, same report on the russian side of the forum.

looks like a false positive.

 

just for you information: dcs_updater is digitally signed, and everything it downloads from our servers is digitally signed as well. so at least it gets from the servers exactly what we put there.

files which are downloaded by torrents are checked even twice - once by the torrent code (because it works this way), and the second time - when they are decompressed.

Dmitry S. Baikov @ Eagle Dynamics

LockOn FC2 Soundtrack Remastered out NOW everywhere - https://band.link/LockOnFC2.

  • ED Team
Posted

No viruses.

lua_ED.jpg.290b0516e7b38c93e549dab7888a2e33.jpg

Men may keep a sort of level of good, but no man has ever been able to keep on one level of evil. That road goes down and down.  
Можно держаться на одном уровне добра, но никому и никогда не удавалось удержаться на одном уровне зла. Эта дорога ведёт вниз и вниз.

G.K. Chesterton

DCS World 2.5: Часто задаваемые вопросы

Posted

When I run the DCS repair and updater, the anti-virus picks it up again.

 

If I tell the antivirus to ignore it, the game hangs up and does not load more than 10%.

Answers to most important questions ATC can ask that every pilot should memorize:

 

1. No, I do not have a pen. 2. Indicating 250

Posted
When I run the DCS repair and updater, the anti-virus picks it up again.

 

If I tell the antivirus to ignore it, the game hangs up and does not load more than 10%.

 

Same

Posted

Add DCS folder to exempt list of your virus protection suite.

 

there are several things that will trigger a false positive or depending on how strict your settings are, remove files and list them as PUP (Potentially Unwanged Program).

Windows 10 Pro, Ryzen 2700X @ 4.6Ghz, 32GB DDR4-3200 GSkill (F4-3200C16D-16GTZR x2),

ASRock X470 Taichi Ultimate, XFX RX6800XT Merc 310 (RX-68XTALFD9)

3x ASUS VS248HP + Oculus HMD, Thrustmaster Warthog HOTAS + MFDs

Posted
Add DCS folder to exempt list of your virus protection suite.

 

I have and it keeps picking it up. I am dead in the water for loading the game.

Answers to most important questions ATC can ask that every pilot should memorize:

 

1. No, I do not have a pen. 2. Indicating 250

Posted

Anti-Virus conflict

 

Recently my antivirus detected and deleted a dll archive ( the file is linked below). Could someone explain what happened?

DCS.thumb.png.eae1b4bc8cc9ac513648fa448e5195c1.png

Posted
When I run the DCS repair and updater, the anti-virus picks it up again.

 

If I tell the antivirus to ignore it, the game hangs up and does not load more than 10%.

 

I have and it keeps picking it up. I am dead in the water for loading the game.

 

Same here :(

Intel i7-12700K @ 8x5GHz+4x3.8GHz + 32 GB DDR5 RAM + Nvidia Geforce RTX 2080 (8 GB VRAM) + M.2 SSD + Windows 10 64Bit

DCS Panavia Tornado (IDS) really needs to be a thing!

Tornado3 small.jpg

Posted (edited)

Kaspersky anti virus says dcs world has a trojan virus

 

Hi,

 

I'm new to DCS World and to the forum, i already played 40 hours with it and i love it but from today(27-11) i get everytime i start the game a pop up of my Anti Virus that there is a trojan file in dcs world, even if i clean the file up with kaspersky and redownloaded it from steam it gives me the same message.

 

This is what kasperky think it is: Trojan-Downloader.Win64.Agent.bb

FileName: lua-ED_demosceneAPI.dll

 

I have 4 dlc's that i bought on steam, i dont use free mods.

 

Is this a false-positive? or is steam game database hacked?

 

Thanks

Naamloos.thumb.png.e17958ab480ad444962267c5e5994c76.png

Edited by ShepherdDimaloun
Posted
Same here :(

 

Ok, it's working now after I added it to the exempt list of my virus protection software, but I don't feel really comfortable about it.

Intel i7-12700K @ 8x5GHz+4x3.8GHz + 32 GB DDR5 RAM + Nvidia Geforce RTX 2080 (8 GB VRAM) + M.2 SSD + Windows 10 64Bit

DCS Panavia Tornado (IDS) really needs to be a thing!

Tornado3 small.jpg

Posted

I chatted with Kaspersky Labs. They did a bunch of diagnostics and downloaded all the logs and a copy of the file.

 

It is being looked at by their techs. It will either get fixed or confirmed to be a virus/hack.

Answers to most important questions ATC can ask that every pilot should memorize:

 

1. No, I do not have a pen. 2. Indicating 250

Posted

Same here: lua-ED_demosceneAPI.dll

Start screen of DCS stop at 10%

Item deleted from Kaspersky quarantene....

Repair DCS: no success

Should I reinstall everything?

Posted (edited)

That's not the problem, but this program has a functionality that could be used to infect the computer with other programs.

It looks like that it works like a trojan.

 

I've asked the Kaspersky team and have to wait for an answer, untill then I will delete DCS.

 

https://securelist.social-kaspersky.com/en/descriptions/Trojan-Downloader.Win64.Agent.bb

 

I really have to ask why this program must be masked and work exactly like the named trojan program? :huh:

There was never such a message before from this program or any other!

Why now if this is not a trojan?

 

attachment.php?attachmentid=128532&stc=1&d=1448656785

 

attachment.php?attachmentid=128531&stc=1&d=1448656785

Trojaner01.PNG.b7fad06a4ac4b38f6b7e71c22a9c72c9.PNG

Trojaner02.PNG.6d13199232e116a458511371929b0fdf.PNG

Edited by Nedum

CPU: AMD Ryzen 7950X3D, System-RAM: 64 GB DDR5, GPU: nVidia 4090, Monitor: LG 38" 3840*1600, VR-HMD: Pimax Crystal, OS: Windows 11 Pro, HD: 2*2TB Samsung M.2 SSD

HOTAS Throttle: TM Warthog Throttle with TM F16 Grip, Orion2 Throttle with F15EX II Grip with Finger Lifts

HOTAS Sticks: Moza FFB A9 Base with TM F16 Stick, FSSB R3 Base with TM F16 Stick

Rudder: WinWing Orion Metal

Posted (edited)
When I run the DCS repair and updater, the anti-virus picks it up again.

 

If I tell the antivirus to ignore it, the game hangs up and does not load more than 10%.

 

Same for me!

 

Ok, it's working now after I added it to the exempt list of my virus protection software, but I don't feel really comfortable about it.

 

Would never do so!

So all other masked trojans could infekt your PC now. They only need to mask themself as the "lua-ED_demosceneAPI.dll" and you are done.

From my point of view it's EDs part to make it the right way.

I've reported this to Kaspersky and will wait what they will say.

Never ever would I believe what a developer will say to me. The program could be infected and the developer didn't noticed/knew this.

This is a way too hot for me.

Edited by Nedum
  • Like 1

CPU: AMD Ryzen 7950X3D, System-RAM: 64 GB DDR5, GPU: nVidia 4090, Monitor: LG 38" 3840*1600, VR-HMD: Pimax Crystal, OS: Windows 11 Pro, HD: 2*2TB Samsung M.2 SSD

HOTAS Throttle: TM Warthog Throttle with TM F16 Grip, Orion2 Throttle with F15EX II Grip with Finger Lifts

HOTAS Sticks: Moza FFB A9 Base with TM F16 Stick, FSSB R3 Base with TM F16 Stick

Rudder: WinWing Orion Metal

Posted
That's not the problem, but this program has a functionality that could be used to infect the computer with other programs.

It looks like that it works like a trojan.

 

I've asked the Kaspersky team and have to wait for an answer, untill then I will delete DCS.

 

https://securelist.social-kaspersky.com/en/descriptions/Trojan-Downloader.Win64.Agent.bb

 

I really have to ask why this program must be masked and work exactly like the named trojan program? :huh:

There was never such a message before from this program or any other!

Why now if this is not a trojan?

 

attachment.php?attachmentid=128532&stc=1&d=1448656785

 

attachment.php?attachmentid=128531&stc=1&d=1448656785

AV's often identify legitimate programs as potential threats just because they can be used for nefarious purposes. I've seen this with eveything from vnc to nmap and in between. Could even be that the heuristics need to be tweaked.

Posted

I agree. It opens you up to attack if you just ignore it.

Answers to most important questions ATC can ask that every pilot should memorize:

 

1. No, I do not have a pen. 2. Indicating 250

Posted

Getting the same as well. Kaspersky detects that file.

My Specs

Asus Maximus Hero IX Z270

i7 7700k @ 4.7GHz

32GB G.SKILL TridentZ 3700MHz DDR4

EVGA RTX 2080Ti

Samsung 960 Evo 1TB M.2 NVME SSD

EVGA SuperNOVA 1200 P2

Acer XB270HU 144Hz @ 1440p (IPS)

Valve Index

 

OOOOhhh, I wish I had the Alpha of a Hornet!

Posted

ZoneAlarm also detects lua-ED_demosceneAPI.dll as a virus.

Win 10, Gigabyte Aorus Ultra with i5 9600KF @ 4.6GHz, 32G DDR4 3200 RAM, GTX 1070, TrackIR 5, TM Warthog stick on VPC Warbird base, Warthog Throttle for jets & helis, CH Throttle Quadrant for props, CH Pro Pedals, 500GB SSDs for installed sims :gun_smilie:

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...