Jump to content

[FALSE POSITIVE]DCS World 2.6 trojan? worldgeneral.dll


NaOH1

Recommended Posts

The advice and guidance from ED in pretty much every "muh anti virus says" thread (and there are many) that there has been since 2.5.6 is to add DSC to your AV exclusions list.

MSI Tomahawk X570 Mobo, Ryzen 5600X undervolted on Artic Freezer E34 Cooler, RTX3080 FE, 32GB (2x16GB Dual Ranked) GSkil 3600 CL16 Trident Neo RAM, 2X 4th Gen M2 SSDs, Corsair RM850x PSU, Lancool 215 Case. 

Gear: MFG Crosswinds, Warthog Throttle, Virpil T50CM gen 1 stick, TIR5, Cougar MFD (OOA), D-link H7/B powered USB 2.0 Hub all strapped to a butchered Wheel stand pro, Cushion to bang head on, wall to scream at.  

Link to comment
Share on other sites

  • Replies 164
  • Created
  • Last Reply

Top Posters In This Topic

Thanks for the quick response gents. Your help is greatly appreciated.

 

I've been adding individual exceptions so far. I has two issues with the first 2.5.6 update, but I'm getting multiple ones with this latest update.

 

I must say I'm not overly keen about adding a blanket exception for the whole DCS folder (but I will I this instance). This doesn't seem like the right approach to fixing this issue, false positive or not.

 

My main question is, why does this occur now with DCS (and not before 2.5.6) and why not with other software?

 

Once I've downloaded, installed and run DCS for the first time after the update, can I then remove the blanked exception?

Link to comment
Share on other sites

  • ED Team
My main question is, why does this occur now with DCS (and not before 2.5.6) and why not with other software?

I guess it is related to the upper layer of our DRM.

Why not with other software - you just happen not to use anything with similar protection.

Dmitry S. Baikov @ Eagle Dynamics

LockOn FC2 Soundtrack Remastered out NOW everywhere - https://band.link/LockOnFC2.

Link to comment
Share on other sites

yep, got it as well

 

s\DCS World OpenBeta\bin\World.dll is infected with Gen:Variant.Ursu.768621 and was moved to quarantine

 

 

After updating to latest update today Bitdefender detected a virus.

 

"The file E:\Program Files\Eagle Dynamics\DCS World OpenBeta\bin\World.dll is infected with Gen:Variant.Ursu.768621 and was moved to quarantine. It is recommended that you run a System Scan to make sure your system is clean".

 

Has anyone else experienced this?

Win10 64, GeForce GTX1080 Ti, Rift touch, i5- 2.90GHz(o/c), 16gb Corsair Vengance RAM, X-56

KA-50-3, AH-64D, A10c II, AV-8B, MI-8, Spitfire, Viggen, FC3, F-14, F-15c,FA-18,  S/Carrier, CA, Nevada, Normandy 44, Channel,  Persian gulf, Marianas, Syria, Sth Atlantic, 

Link to comment
Share on other sites

Restored the dll from bitdefender vault, started the game, all works ok :thumbup:

 

yep, got it as well

 

s\DCS World OpenBeta\bin\World.dll is infected with Gen:Variant.Ursu.768621 and was moved to quarantine

Win10 64, GeForce GTX1080 Ti, Rift touch, i5- 2.90GHz(o/c), 16gb Corsair Vengance RAM, X-56

KA-50-3, AH-64D, A10c II, AV-8B, MI-8, Spitfire, Viggen, FC3, F-14, F-15c,FA-18,  S/Carrier, CA, Nevada, Normandy 44, Channel,  Persian gulf, Marianas, Syria, Sth Atlantic, 

Link to comment
Share on other sites

weird thing is I just had that issue with my mirrored ssd folder, and even though its not a big deal with a 400Mbit line, its really annoying since my windows alert triggered, I dont even use extra AV. Whats more conspicuos though is that my oher install wont tell me about an update, even though i just did it on the mirror, just a thought but maybe someone is messing with the torrent???

Link to comment
Share on other sites

Same here and got this lovely error message: C:\Program Files\Eagle Dynamics\DCS World OpenBeta\_downloads\Mods/aircraft/F14/bin/F14-FlightModel.dll

 

Bitdefender originally stopped this as a Trojan and I couldn't get past the update (first time ever on my system). I deleted the F-14 module within DCS and updated to the most recent version successfully. However, when I tried to reinstall the F-14 module, same error message came back.

 

I need to fly my KITTEH! ;-)

Link to comment
Share on other sites

McAfee antivirus indicates that the following are suspect and quarantined them:

 

 

DCS.dll

World.dll

F-14-HeartblurCommon.dll

 

 

To counter - retrieve them from quarantine, go to Real-Time Scanning and add them to excluded files. Restart DCSWorld beta

Link to comment
Share on other sites

  • 1 month later...

Cannot start DCS World!

 

DCS won't load says "missing libcef.dll"

 

Tried running the DCS Repair (Start menu > Programs > Eagle Dynamics > DCS > Repair DCS)

 

Didn't help.. :-/

 

Tried downloading a new libcef.dll and reinstalling in C:\Windows\SysWOW64\

No luck...

 

Then got paranoid and decided to run a full virus scan...DCS was working perfectly this morning...

Kaspersky says no threats.

 

Scanned the C:\ for all instances of libcef.dll and noticed it in the nVidia folder. Then noticed nVidia has new drivers released today...installed those.

 

I grabbed that version and copied it to Windows System Directory and tried to register it with regsrv32 at the command prompt. No luck. The library wouldn't load.

 

Then ran sfc /scannow at the command prompt. No problems found.

 

Ran some freeware from Outbyte PC Repair after determining it wasn't malware itself; it just sucks and tries to upsell you... stuck with the free version.

 

viola! DCS World 2.5.5 loads and runs perfectly again.

 

Now to uninstall that Outbyte PC Repair that I still don't trust...


Edited by Sliceback
Forgot I ran DCS Repair b4 mucking around with it
Link to comment
Share on other sites

Just got it with libcef.dll, Kaspersky just quarantined AND Deleted it from said quarantine without me having a word to say in the process... how do you do a repair of DCS? (on latest STABLE version)

 

Start menu > Programs > Eagle Dynamics > DCS > Repair DCS

i7 9700K @ stock speed, single GTX1070, 32 gigs of RAM, TH Warthog, MFG Crosswind, Win10.

Link to comment
Share on other sites

  • ED Team
Add program files eagle dynamics folder to exclusion list in advanced settings of Kaspersky File Protection antivirus cause it constantly detects 1 DLL file as Injector Virus

 

We are aware of this, best thing to do is submit the file to kerpersky for analysis, we have done the same.

 

Thanks

smallCATPILOT.PNG.04bbece1b27ff1b2c193b174ec410fc0.PNG

Forum rules - DCS Crashing? Try this first - Cleanup and Repair - Discord BIGNEWY#8703 - Youtube - Patch Status

Windows 11, NVIDIA MSI RTX 3090, Intel® i9-10900K 3.70GHz, 5.30GHz Turbo, Corsair Hydro Series H150i Pro, 64GB DDR @3200, ASUS ROG Strix Z490-F Gaming, HP Reverb G2

Link to comment
Share on other sites

I have the same problem with Kaspersky

 

E:\Program Files\Eagle Dynamics\DCS World\bin\libcef.dll Archivo: E:\Program Files\Eagle Dynamics\DCS World\bin\libcef.dll Nombre de objeto: Trojan-Dropper.Win32.Injector.uqmt Tipo de objeto: Programa troyano Hora: 16/04/2020 15:49

 

I have downloaded this:

 

https://es.dll-files.com/download/ae0f4a20ae6e15e839afc739a6cefd6c/libcef.dll.html?c=Z0pESks0djBMa1U0b09oU1VmTU9hdz09

 

from dll-files.com

 

It´s works fine to me, all solved!!!

 

DCS and kaspersky works right!!!

 

Image ti properties of file:

 

https://drive.google.com/file/d/1eUboojhXRq2ICip9jfA-XNQacTV5o_oK/view?usp=sharing

Link to comment
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...