Can someone help me understand why Kaspersky anti-virus identified and deleted a DLL within a recent Mission Planner update that is defined as a KeyLogger. I had to disable Kaspersky for the update to download; I was getting an update failed due to virus protection error; but my night time virus scan found this DLL with the Mission Planner directory and deleted it. Why is it there? Does it matter that it was deleted?Cheers!Pem
You need to be a member of diydrones to add comments!
Gary McCray > Michael OborneAugust 11, 2015 at 10:24am
Hi Michael,
Although I'm not currently using it, I have used Kaspersky in the past and it is a very popular anti virus program.
Way less obnoxious than Norton (what isn't) and even less of a pain than McAfee.
It comes free for a year on many Dell computers and there are hundreds of thousands of users.
Unfortunately, I think this means you can't ignore it and will either need to modify that module so it doesn't trigger Kaspersky's defenses or you will need to contact Kaspersky to get them to stop false triggering on it.
Obviously, some portion of the internal code bears a significant resemblance to the the "detected" virus and that is why they are deleting it.
It likely has nothing to do with it actually being the virus, but they are looking at machine code and it is entirely possible for a section of legitimate code to mimic a known evil chunk of code.
It would probably be simplest to just modify the order of elements in the DLL and recompile, there is a good chance that the code will be changed sufficiently to pass through Kaspersky without a false detection.
At worst you might need to move some of the elements to a separate DLL.
It is common for A/V software to detect false positives in new installations, thus the instructions usually suggest you disable your antivirus scanners during setup.
just FYI, Windows Defender is about the weakest/most allowing AV available, while Kaspersky is the opposite, and blocks just about anything new. So basically, windows defender isn't a good test of whether or not something will throw up a red flag.
there is no key logger inside mp, apart from shortcut keys.
Paul Miller > Michael OborneAugust 10, 2015 at 1:35pm
How will the deletion of the "BaseClassesNET.dll" file from the "C:/Program Files (x86)/Mission Planner/" sub-directory effect the performance of Mission Planner?
Paul Miller > Michael OborneAugust 10, 2015 at 1:31pm
As I said, I had to disable Kaspersky to get the update; with Kaspersky off, Mission Planner updated and ran fine. But during the night when Kaspersky performs a virus scan, it identified and deleted this file: BaseClassesNET.dll. According to Kaspersky, within this file is: Trojan-Spy.MSIL.KeyLogger.bzam.
Paul Miller > Michael OborneAugust 10, 2015 at 1:21pm
The deleted file is BaseClassNET.dll, shown in Mike Dobbs screensnap below.
Replies
Hi Michael,
Although I'm not currently using it, I have used Kaspersky in the past and it is a very popular anti virus program.
Way less obnoxious than Norton (what isn't) and even less of a pain than McAfee.
It comes free for a year on many Dell computers and there are hundreds of thousands of users.
Unfortunately, I think this means you can't ignore it and will either need to modify that module so it doesn't trigger Kaspersky's defenses or you will need to contact Kaspersky to get them to stop false triggering on it.
Obviously, some portion of the internal code bears a significant resemblance to the the "detected" virus and that is why they are deleting it.
It likely has nothing to do with it actually being the virus, but they are looking at machine code and it is entirely possible for a section of legitimate code to mimic a known evil chunk of code.
It would probably be simplest to just modify the order of elements in the DLL and recompile, there is a good chance that the code will be changed sufficiently to pass through Kaspersky without a false detection.
At worst you might need to move some of the elements to a separate DLL.
Just a thought.
Best Regards,
Gary
ive submitted it as a false alarm. only time will tell from here
http://newvirus.kaspersky.com/
It is common for A/V software to detect false positives in new installations, thus the instructions usually suggest you disable your antivirus scanners during setup.
just FYI, Windows Defender is about the weakest/most allowing AV available, while Kaspersky is the opposite, and blocks just about anything new.
So basically, windows defender isn't a good test of whether or not something will throw up a red flag.
what file did it delete?
there is no key logger inside mp, apart from shortcut keys.
How will the deletion of the "BaseClassesNET.dll" file from the "C:/Program Files (x86)/Mission Planner/" sub-directory effect the performance of Mission Planner?
As I said, I had to disable Kaspersky to get the update; with Kaspersky off, Mission Planner updated and ran fine. But during the night when Kaspersky performs a virus scan, it identified and deleted this file: BaseClassesNET.dll. According to Kaspersky, within this file is: Trojan-Spy.MSIL.KeyLogger.bzam.
-
1
-
2
of 2 Next