OnCourse Software

Welcome to our Product Support Forums

PF3 Full Installer v3.16.0 blocked due to UDS:Trojan.Win32.Delf

PLEASE NOTE:

If you are reporting an issue with PF3 please remember to Zip and attach the Debug_Monitor.log file from your PF3\Logs folder. Thank you.

Post Reply   Page 1 of 1  [ 8 posts ]
Author Message
flycaptjon
Post subject: PF3 Full Installer v3.16.0 blocked due to UDS:Trojan.Win32.Delf
Posted: Thu Aug 04, 2022 5:40 pm
Offline
 
Posts: 2
Joined: Thu Aug 04, 2022 4:29 am
 
Good morning,

Yesterday I bought PF3 v3.16.0 and PFE to XPX to use with X-Plane 11.55.

After unzipping the download file and executing the PF3 Setup program, Kaspersky Internet Security blocked the start operation after finding a DNS Trojan.

There were no PF3 logs created as the setup was not far enough along to create anything. I cannot find further event logs, but if you direct me to something specific, I'll be glad to locate them and attach an update.

I have attached screen shots of all I have. 1) The event log from Kaspersky details the virus error and 2) the associated Windows 10 execution error warning. That is generated since Kaspersky is blocking execution.

It appears the UDS:Trojan.Win32.Delf is embedded in the PF3_Installation_Setup.exe//data0051 module.

After spending $60USD, I would appreciate a CLEAN install file so I can attempt to use the product. It is apparent that the download store/server has been severely compromised.

I have received the purchase validation email and license key. All I need is a clean setup package.

My windows system is as follows:

* Windows 10x64; MSI Gaming 7, LGA-3; Intel i7 5930K 3.9MHz; 64GB RAM DDR4 2133MHz;
* NVIDIA GeForce GTX1080 Ti 11GB DDR5 VRAM
* Samsung M.2 SSD850 500GB Windows 10 boot drive
* Samsung SSD840 500GB X-Plane 11 dedicated drive
* Samsung SSD85 1TB X-Plane 11 Custom Scenery drive mlinked to XP11

Please advise,

Best regards,

CaptJon

Attachments
[ attachment ]
PF3 v3.16.10 setup error DNS Trojan.Win32.Delf 0803 2022 Capture_3.JPG (39.3 KiB) Viewed 740 times
[ attachment ]
Windows error executing PF3_Installation_Setup.exez
PF3 v3.16.10 setup error DNS Trojan.Win32.Delf 0803 2022 Capture_2.JPG (30.39 KiB) Viewed 740 times
[ attachment ]
Kaspersky Event log
PF3 v3.16.10 setup error DNS Trojan.Win32.Delf 0803 2022 Capture.JPG (184.11 KiB) Viewed 740 times


Top
Profile Quote
Dave March
Post subject: Re: PF3 Full Installer v3.16.0 blocked due to UDS:Trojan.Win32.Delf
Posted: Thu Aug 04, 2022 6:01 pm
Site Admin
Offline
 
Posts: 6124
Joined: Mon May 18, 2009 6:22 pm
Location: Sawtry, Cambridgeshire. UK
Contact: Website
 
The installation file IS clean I can assure you. You're getting a false positive from Kasperky. I use the same AV as yourself and it drives mad most of the time.

_________________

Cheers

Dave March

Email: dmarch@oncourse-software.co.uk

I don't know if my memory is getting worse as I get older...
...I just can't remember how it used to be!

[ img ]


Top
Profile Quote
flycaptjon
Post subject: Re: PF3 Full Installer v3.16.0 blocked due to UDS:Trojan.Win32.Delf
Posted: Thu Aug 04, 2022 6:37 pm
Offline
 
Posts: 2
Joined: Thu Aug 04, 2022 4:29 am
 
Thank you for your quick reply.

I would really like to believe that, however I have NOT gotten any false positive, nor any other warnings of this nature in easily the past three plus years. And I use this system globally.

The one time I have allowed an exclusion, about 10 years ago -- I lost about a week rebuilding after the virus attached my FAT table.

I'm sure you can understand, I'm more than hesitant on this. If you cannot provide any further support than this, I am going to need a refund. I have never requested a refund for software, but I have gotten zero value and thus far zero support.

What warranty can you provide if my allowing this exception results in ransom ware or a DNS? If the answer is zero 'buyer assumes all risk', then I'll need a refund.

If you 'allow exceptions' when you get a Kaspersky warning by rote, then it is logical that this package is NOT secure, and you simply pass this Trojan to all global users. IF I was getting this 'false positive' downloading hundreds of files from global site such as xp.org, etc. with global users, I would buy into your logic.

Again, I'm not seeing what I can justify as a 'false positive'.

Again, I am requesting a clean install that will scan clean.

Regards,

CaptJon


Top
Profile Quote
johnhinson
Post subject: Re: PF3 Full Installer v3.16.0 blocked due to UDS:Trojan.Win32.Delf
Posted: Thu Aug 04, 2022 7:50 pm
Offline
 
Posts: 279
Joined: Fri Dec 03, 2010 2:54 pm
 
CaptJohn,

I assume that Kaspersky have a procedure (like most respectable AV providers) for submitting a suspected "false positive". They should check the file and update their definitions to allow it.

It may take a day or so but it is the way to be comfortable and, at the same time, help others.

I never take anybody's word that a file is safe. :)

John

_________________

My co-pilot is called Sid and he's a real Star!


Top
Profile Quote
pointy56
Post subject: Re: PF3 Full Installer v3.16.0 blocked due to UDS:Trojan.Win32.Delf
Posted: Thu Aug 04, 2022 9:19 pm
Offline
 
Posts: 317
Joined: Tue Feb 02, 2021 7:51 am
 
There is a significant problem with Kaspersky flagging some VB6 executables as false positives; I have recently been developing new PF3 code for Dave and Kaspersky has flagged the modules as Trojans on several occasions - I *know* that there is nothing bad with the code, yet it still happens.

I will be following this up with Kaspersky. To be honest I'm starting to reconsider whether I should be using their software, after a good few years, as I'm finding the latest updates very intrusive - I'm hitting similar 'false positive' issues with some of my C# code too.

Cheers,
Martin

_________________

[ img ]


Top
Profile Quote
Dave March
Post subject: Re: PF3 Full Installer v3.16.0 blocked due to UDS:Trojan.Win32.Delf
Posted: Fri Aug 05, 2022 1:13 pm
Site Admin
Offline
 
Posts: 6124
Joined: Mon May 18, 2009 6:22 pm
Location: Sawtry, Cambridgeshire. UK
Contact: Website
 
flycaptjon wrote: *  Thu Aug 04, 2022 6:37 pm
Thank you for your quick reply.

I would really like to believe that, however I have NOT gotten any false positive, nor any other warnings of this nature in easily the past three plus years. And I use this system globally.

The one time I have allowed an exclusion, about 10 years ago -- I lost about a week rebuilding after the virus attached my FAT table.

I'm sure you can understand, I'm more than hesitant on this. If you cannot provide any further support than this, I am going to need a refund. I have never requested a refund for software, but I have gotten zero value and thus far zero support.

What warranty can you provide if my allowing this exception results in ransom ware or a DNS? If the answer is zero 'buyer assumes all risk', then I'll need a refund.

If you 'allow exceptions' when you get a Kaspersky warning by rote, then it is logical that this package is NOT secure, and you simply pass this Trojan to all global users. IF I was getting this 'false positive' downloading hundreds of files from global site such as xp.org, etc. with global users, I would buy into your logic.

Again, I'm not seeing what I can justify as a 'false positive'.

Again, I am requesting a clean install that will scan clean.

Regards,

CaptJon
The way AV's detect trojans and such is they search for known footprints... our code is first compiled and then compressed, so there's always a chance a very similar footprint can be created during that process. That doesn't mean it's a trojan. As one of our other users suggested, please forward it to Kaspersky for checking.

We've been providing flight simulator software for nearly 30 years and can assure you we do not release virus ridden code. However, if you don't wish to have the file(s) checked by Kaspersky and/or don't wish to install the program, please email me direct and I'll gladly provide a full refund, despite that being against our general terms of not refunding digital media.

_________________

Cheers

Dave March

Email: dmarch@oncourse-software.co.uk

I don't know if my memory is getting worse as I get older...
...I just can't remember how it used to be!

[ img ]


Top
Profile Quote
pointy56
Post subject: Re: PF3 Full Installer v3.16.0 blocked due to UDS:Trojan.Win32.Delf
Posted: Fri Aug 05, 2022 2:39 pm
Offline
 
Posts: 317
Joined: Tue Feb 02, 2021 7:51 am
 
OK, while having a coffee I just submitted the file to the Kaspersky Threat Intelligence Portal https://opentip.kaspersky.com/ with the following result:

[ attachment ]
2022-08-05 14_34_01-Kaspersky Threat Intelligence Portal and 7 more pages - Personal - Microsoft​ Ed.png (50.02 KiB) Viewed 680 times

Yet I too get the software blocked by Kaspersky when I try to execute it on my machine. So it seems that their own software is inconsistent (you will notice that this piece of software has been checked previously on TIP). I have just submitted a Technical Support request to Kaspersky.

Martin

_________________

[ img ]


Top
Profile Quote
pointy56
Post subject: Re: PF3 Full Installer v3.16.0 blocked due to UDS:Trojan.Win32.Delf
Posted: Sun Aug 14, 2022 5:43 pm
Offline
 
Posts: 317
Joined: Tue Feb 02, 2021 7:51 am
 
I raised this issue with Kaspersky Technical Support and they have confirmed that it is a false positive - a fix will apparently be included in their next database update. (The screenshot that I included previously was for the Cumulative Update file which has been known to have similar issues, but I did actually raise the issue against the Full Installer - my mistake.)

Cheers,
Martin

_________________

[ img ]


Top
Profile Quote
Display: Sort by: Direction:
Post Reply   Page 1 of 1  [ 8 posts ]
Return to “PF3-ATC at its best”
Jump to: