Crumpp Posted November 27, 2015 Posted November 27, 2015 It has never had an issue with anything from ED products until the latest update of DCS World 1.5 It is picking up a Tojan-downloader.Win64.Agent.bb. Answers to most important questions ATC can ask that every pilot should memorize: 1. No, I do not have a pen. 2. Indicating 250
dooom Posted November 27, 2015 Posted November 27, 2015 I this a result of the new seeding strategy? Maybe a seeder was infected? ASUS Tuf Gaming Pro x570 / AMD Ryzen 7 5800X @ 3.8 / XFX Radeon 6900 XT / 64 GB DDR4 3200 "This was not in the Manual I did not read", cried the Noob" - BMBM, WWIIOL
ED Team c0ff Posted November 27, 2015 ED Team Posted November 27, 2015 hmm, same report on the russian side of the forum. looks like a false positive. just for you information: dcs_updater is digitally signed, and everything it downloads from our servers is digitally signed as well. so at least it gets from the servers exactly what we put there. files which are downloaded by torrents are checked even twice - once by the torrent code (because it works this way), and the second time - when they are decompressed. Dmitry S. Baikov @ Eagle Dynamics LockOn FC2 Soundtrack Remastered out NOW everywhere - https://band.link/LockOnFC2.
ED Team USSR_Rik Posted November 27, 2015 ED Team Posted November 27, 2015 No viruses. Men may keep a sort of level of good, but no man has ever been able to keep on one level of evil. That road goes down and down. Можно держаться на одном уровне добра, но никому и никогда не удавалось удержаться на одном уровне зла. Эта дорога ведёт вниз и вниз. G.K. Chesterton DCS World 2.5: Часто задаваемые вопросы
Crumpp Posted November 27, 2015 Author Posted November 27, 2015 When I run the DCS repair and updater, the anti-virus picks it up again. If I tell the antivirus to ignore it, the game hangs up and does not load more than 10%. Answers to most important questions ATC can ask that every pilot should memorize: 1. No, I do not have a pen. 2. Indicating 250
Drach25 Posted November 27, 2015 Posted November 27, 2015 When I run the DCS repair and updater, the anti-virus picks it up again. If I tell the antivirus to ignore it, the game hangs up and does not load more than 10%. Same
SkateZilla Posted November 27, 2015 Posted November 27, 2015 Add DCS folder to exempt list of your virus protection suite. there are several things that will trigger a false positive or depending on how strict your settings are, remove files and list them as PUP (Potentially Unwanged Program). Windows 10 Pro, Ryzen 2700X @ 4.6Ghz, 32GB DDR4-3200 GSkill (F4-3200C16D-16GTZR x2), ASRock X470 Taichi Ultimate, XFX RX6800XT Merc 310 (RX-68XTALFD9) 3x ASUS VS248HP + Oculus HMD, Thrustmaster Warthog HOTAS + MFDs
Crumpp Posted November 27, 2015 Author Posted November 27, 2015 Add DCS folder to exempt list of your virus protection suite. I have and it keeps picking it up. I am dead in the water for loading the game. Answers to most important questions ATC can ask that every pilot should memorize: 1. No, I do not have a pen. 2. Indicating 250
Thasord Posted November 27, 2015 Posted November 27, 2015 Anti-Virus conflict Recently my antivirus detected and deleted a dll archive ( the file is linked below). Could someone explain what happened?
sobek Posted November 27, 2015 Posted November 27, 2015 False positive. Contact the AV manufacturer. Good, fast, cheap. Choose any two. Come let's eat grandpa! Use punctuation, save lives!
QuiGon Posted November 27, 2015 Posted November 27, 2015 When I run the DCS repair and updater, the anti-virus picks it up again. If I tell the antivirus to ignore it, the game hangs up and does not load more than 10%. I have and it keeps picking it up. I am dead in the water for loading the game. Same here :( Intel i7-12700K @ 8x5GHz+4x3.8GHz + 32 GB DDR5 RAM + Nvidia Geforce RTX 2080 (8 GB VRAM) + M.2 SSD + Windows 10 64Bit DCS Panavia Tornado (IDS) really needs to be a thing!
ShepherdDimaloun Posted November 27, 2015 Posted November 27, 2015 (edited) Kaspersky anti virus says dcs world has a trojan virus Hi, I'm new to DCS World and to the forum, i already played 40 hours with it and i love it but from today(27-11) i get everytime i start the game a pop up of my Anti Virus that there is a trojan file in dcs world, even if i clean the file up with kaspersky and redownloaded it from steam it gives me the same message. This is what kasperky think it is: Trojan-Downloader.Win64.Agent.bb FileName: lua-ED_demosceneAPI.dll I have 4 dlc's that i bought on steam, i dont use free mods. Is this a false-positive? or is steam game database hacked? Thanks Edited November 27, 2015 by ShepherdDimaloun
QuiGon Posted November 27, 2015 Posted November 27, 2015 Same here :( Ok, it's working now after I added it to the exempt list of my virus protection software, but I don't feel really comfortable about it. Intel i7-12700K @ 8x5GHz+4x3.8GHz + 32 GB DDR5 RAM + Nvidia Geforce RTX 2080 (8 GB VRAM) + M.2 SSD + Windows 10 64Bit DCS Panavia Tornado (IDS) really needs to be a thing!
Crumpp Posted November 27, 2015 Author Posted November 27, 2015 I chatted with Kaspersky Labs. They did a bunch of diagnostics and downloaded all the logs and a copy of the file. It is being looked at by their techs. It will either get fixed or confirmed to be a virus/hack. Answers to most important questions ATC can ask that every pilot should memorize: 1. No, I do not have a pen. 2. Indicating 250
pdrgnn Posted November 27, 2015 Posted November 27, 2015 Same here: lua-ED_demosceneAPI.dll Start screen of DCS stop at 10% Item deleted from Kaspersky quarantene.... Repair DCS: no success Should I reinstall everything?
Nedum Posted November 27, 2015 Posted November 27, 2015 (edited) That's not the problem, but this program has a functionality that could be used to infect the computer with other programs. It looks like that it works like a trojan. I've asked the Kaspersky team and have to wait for an answer, untill then I will delete DCS. https://securelist.social-kaspersky.com/en/descriptions/Trojan-Downloader.Win64.Agent.bb I really have to ask why this program must be masked and work exactly like the named trojan program? :huh: There was never such a message before from this program or any other! Why now if this is not a trojan? Edited November 27, 2015 by Nedum CPU: AMD Ryzen 7950X3D, System-RAM: 64 GB DDR5, GPU: nVidia 4090, Monitor: LG 38" 3840*1600, VR-HMD: Pimax Crystal, OS: Windows 11 Pro, HD: 2*2TB Samsung M.2 SSD HOTAS Throttle: TM Warthog Throttle with TM F16 Grip, Orion2 Throttle with F15EX II Grip with Finger Lifts HOTAS Sticks: Moza FFB A9 Base with TM F16 Stick, FSSB R3 Base with TM F16 Stick Rudder: WinWing Orion Metal
Nedum Posted November 27, 2015 Posted November 27, 2015 (edited) When I run the DCS repair and updater, the anti-virus picks it up again. If I tell the antivirus to ignore it, the game hangs up and does not load more than 10%. Same for me! Ok, it's working now after I added it to the exempt list of my virus protection software, but I don't feel really comfortable about it. Would never do so! So all other masked trojans could infekt your PC now. They only need to mask themself as the "lua-ED_demosceneAPI.dll" and you are done. From my point of view it's EDs part to make it the right way. I've reported this to Kaspersky and will wait what they will say. Never ever would I believe what a developer will say to me. The program could be infected and the developer didn't noticed/knew this. This is a way too hot for me. Edited November 27, 2015 by Nedum 1 CPU: AMD Ryzen 7950X3D, System-RAM: 64 GB DDR5, GPU: nVidia 4090, Monitor: LG 38" 3840*1600, VR-HMD: Pimax Crystal, OS: Windows 11 Pro, HD: 2*2TB Samsung M.2 SSD HOTAS Throttle: TM Warthog Throttle with TM F16 Grip, Orion2 Throttle with F15EX II Grip with Finger Lifts HOTAS Sticks: Moza FFB A9 Base with TM F16 Stick, FSSB R3 Base with TM F16 Stick Rudder: WinWing Orion Metal
Thasord Posted November 27, 2015 Posted November 27, 2015 False positive. Contact the AV manufacturer. Ok, thanks for your help!:thumbup:
Thasord Posted November 27, 2015 Posted November 27, 2015 (edited) Please let me know when they answer you. Edited November 27, 2015 by Thasord
xaoslaad Posted November 27, 2015 Posted November 27, 2015 That's not the problem, but this program has a functionality that could be used to infect the computer with other programs. It looks like that it works like a trojan. I've asked the Kaspersky team and have to wait for an answer, untill then I will delete DCS. https://securelist.social-kaspersky.com/en/descriptions/Trojan-Downloader.Win64.Agent.bb I really have to ask why this program must be masked and work exactly like the named trojan program? :huh: There was never such a message before from this program or any other! Why now if this is not a trojan? AV's often identify legitimate programs as potential threats just because they can be used for nefarious purposes. I've seen this with eveything from vnc to nmap and in between. Could even be that the heuristics need to be tweaked.
Crumpp Posted November 27, 2015 Author Posted November 27, 2015 I agree. It opens you up to attack if you just ignore it. Answers to most important questions ATC can ask that every pilot should memorize: 1. No, I do not have a pen. 2. Indicating 250
Scoggs Posted November 27, 2015 Posted November 27, 2015 Getting the same as well. Kaspersky detects that file. My SpecsAsus Maximus Hero IX Z270 i7 7700k @ 4.7GHz 32GB G.SKILL TridentZ 3700MHz DDR4 EVGA RTX 2080Ti Samsung 960 Evo 1TB M.2 NVME SSD EVGA SuperNOVA 1200 P2 Acer XB270HU 144Hz @ 1440p (IPS) Valve Index OOOOhhh, I wish I had the Alpha of a Hornet!
GeorgeLKMT Posted November 28, 2015 Posted November 28, 2015 I think that if it was infected, there would be more AVs detecting it and not only ONE. ■ L-39C/ZA Czech cockpit mod ■ My DCS skins ■
pj Posted November 28, 2015 Posted November 28, 2015 ZoneAlarm also detects lua-ED_demosceneAPI.dll as a virus. Win 10, Gigabyte Aorus Ultra with i5 9600KF @ 4.6GHz, 32G DDR4 3200 RAM, GTX 1070, TrackIR 5, TM Warthog stick on VPC Warbird base, Warthog Throttle for jets & helis, CH Throttle Quadrant for props, CH Pro Pedals, 500GB SSDs for installed sims :gun_smilie:
Recommended Posts