Can someone help me understand why Kaspersky anti-virus identified and deleted a DLL within a recent Mission Planner update that is defined as a KeyLogger. I had to disable Kaspersky for the update to download; I was getting an update failed due to virus protection error; but my night time virus scan found this DLL with the Mission Planner directory and deleted it. Why is it there? Does it matter that it was deleted?Cheers!Pem
You need to be a member of diydrones to add comments!
Kaspersky advanced settings cause the malware affected files to be deleted directly without giving an option. Which is good for security measures but risky as it might delete certain program files. K7 Antivirus Customer Support can explain more on this topic. The firewall settings also perform certain access blockage.
This file is already present in previous versions of MP, but...
from version 1.3.15 of Mission Planner : the file is 241152 bytes long, and no malware detected (not a single).
from version 1.3.31 of Mission Planner : the file is 235008 bytes long, and malware detected by 15 antivirus.
The weird point is that both file are version 1.0.0.6 so they should be exactly the same.
It should be noted that this file is not developed by Michael Oborne, but by "Maxim Kartavenkov aka Sonic 2012". Who is probably someone reliable, but it's just to understand that it's a dll imported into the project, not a development from Michael so who knows what's really inside.
PS : I didn't compare to all versions of MP, but I had version 1.3.15 laying around, it could be interesting to compare with other versions too.
I am using MalwareBytes and Avast here and no report of infection have been found coming from the Mission Planner directories. Furthermore, I am using the latest version of the Mission Planner on my PC. As it has been mentioned previously, it must be a false positive.
Also, that .DLL file must have a certain line of code that is causing the AV to trigger it as a Trojan or Malware. If I were you, I would just report it to Kaspasky as a false positive.
NOTICE: Results are not 100% accurate and can be reported as a false positive by some scannerswhen and if malware is found. Please judge these results for yourself.
Replies
Kaspersky advanced settings cause the malware affected files to be deleted directly without giving an option. Which is good for security measures but risky as it might delete certain program files. K7 Antivirus Customer Support can explain more on this topic. The firewall settings also perform certain access blockage.
This file is already present in previous versions of MP, but...
from version 1.3.15 of Mission Planner : the file is 241152 bytes long, and no malware detected (not a single).
from version 1.3.31 of Mission Planner : the file is 235008 bytes long, and malware detected by 15 antivirus.
The weird point is that both file are version 1.0.0.6 so they should be exactly the same.
It should be noted that this file is not developed by Michael Oborne, but by "Maxim Kartavenkov aka Sonic 2012". Who is probably someone reliable, but it's just to understand that it's a dll imported into the project, not a development from Michael so who knows what's really inside.
PS : I didn't compare to all versions of MP, but I had version 1.3.15 laying around, it could be interesting to compare with other versions too.
I am using MalwareBytes and Avast here and no report of infection have been found coming from the Mission Planner directories. Furthermore, I am using the latest version of the Mission Planner on my PC. As it has been mentioned previously, it must be a false positive.
Also, that .DLL file must have a certain line of code that is causing the AV to trigger it as a Trojan or Malware. If I were you, I would just report it to Kaspasky as a false positive.
Hey Michael
This must be what is going on with the false alarm :)
http://www.torontosun.com/2015/08/14/antivirus-firm-kaspersky-faked...
This is what I got when I scan the BaseClassesNET.dll on www.virustotal.com
I have removed this dll from the current release of MP.
it is no longer part of the MSI, or the zip, and will not be downloaded as part of the update process either.
drivers are failing because of a Linux/windows line ending issue
the only reason you see that server is because you get beta update. release updates are md5 hashed and uploaded to http://firmware.diydrones.com
the source code
https://github.com/diydrones/MissionPlanner/tree/master/ExtLibs/Bas...
the library is for talking to windows directshow.
-
1
-
2
of 2 Next