Jump to content
Sign in to follow this  
jcomm

Windows Defender Malware Alert - Win 10 ...

Recommended Posts

Today I tried to setup p3dv3.5 latest installer fetched from my LM account, on two different computers, both running win 10 professional 64 bit, nd got a succession of malware detection alerts by Windows Defender.

 

The trigger seems to be Setup.exe from the p3d v3 installer.

 

Has anyone experienced this ?

 

Thx for any info / hints...


Ok, just found this at the LM P3D forums:

 

http://www.prepar3d.com/forum/viewtopic.php?f=6322&t=119924


Main Simulation Rig:

Ryzen 5600x, 32GB RAM, Nvidia RTX 3060 Ti, 1 TB & 500 GB M.2 nvme drives, Win11.

Glider pilot since 1980...

Avid simmer since 1992...

Share this post


Link to post

Hi Jose,

 

As is recommended on AVSIM frequently and in the AVSIM CTD Guide, it is best to turn off UAC and any malware/anti-virus program when installing new software (this includes Microsoft Essentials).  I personally have exempted my malware program from scanning the directory where I have my flight sims installed.  If you do not know the Source of a program that you downloaded from the Internet, then you should definitely have your anti-virus or malware program enabled but we all know that Lockheed's P3D is from a trusted site.  The same goes when you download a software addon from FlightOne or Aerosoft.  They are not going to allow any viruses or malware with their software and it is all perfectly safe.  

 

Best regards,


Jim Young | AVSIM Online! - Simming's Premier Resource!

Member, AVSIM Board of Directors - Serving AVSIM since 2001

Submit News to AVSIM
Important other links: Basic FSX Configuration Guide | AVSIM CTD Guide | AVSIM Prepar3D Guide | Help with AVSIM Site | Signature Rules | Screen Shot Rule | AVSIM Terms of Service (ToS)

I7 8086K  5.0GHz | GTX 1080 TI OC Edition | Dell 34" and 24" Monitors | ASUS Maximus X Hero MB Z370 | Samsung M.2 NVMe 500GB and 1TB | Samsung SSD 500GB x2 | Toshiba HDD 1TB | WDC HDD 1TB | Corsair H115i Pro | 16GB DDR4 3600C17 | Windows 10 

 

Share this post


Link to post

Thx Jim!

 

Yes, the "Flight1 Malware" has long been known to me, although it's more than a decade since I install something from Flight1...

 

In this case, Defender was really "doing a great job", and even creating exclusions for folders and files didn't work. I actually had to temporarily stop Defender's Real-Time and Cloud-Based protections...


Main Simulation Rig:

Ryzen 5600x, 32GB RAM, Nvidia RTX 3060 Ti, 1 TB & 500 GB M.2 nvme drives, Win11.

Glider pilot since 1980...

Avid simmer since 1992...

Share this post


Link to post

ut2 will also get a hit from windows defender


 
 
 
 
14ppkc-6.png
  913456

Share this post


Link to post

It got worst after last week's Win 10 update.

 

At my office it also brought problems with NAS drives... More than 50 users affected....  Not saying with this that I don't like win 10 - quite on the contrary because so far it is my preferred Win OS ever, after good old XP...


Main Simulation Rig:

Ryzen 5600x, 32GB RAM, Nvidia RTX 3060 Ti, 1 TB & 500 GB M.2 nvme drives, Win11.

Glider pilot since 1980...

Avid simmer since 1992...

Share this post


Link to post

Thanks for posting Jose. 

 

This hits Ultimate Traffic 2 on a regular basis, You will see the following Error\Message below   "Please register this product before you try and use it"  

 

It see's the utii.dll file as a False Positive so it quarantines it (removes it to a safe and secure place within in your Anti virus set up) 

 
By going to your Quarantine area of your Anti virus Software and Restore it,   Then you should be back in business  
 
I was able to recreate this message by moving this file out of the folder,  I moved it back into the folder and the message went away  
 
 
27311354865_889f2465e8_o.png
 
 
The file in question is located here  Your Prepar3D location ► Prepar3D V3 ► Flight One Software ► Ultimate Traffic 2
 
After you restore it,  Confirm the file has been returned 
 
26705396453_dd85ac7c6e_o.png
  • Upvote 1

 

 

 

Share this post


Link to post

Thx Elaine - precious info!


Main Simulation Rig:

Ryzen 5600x, 32GB RAM, Nvidia RTX 3060 Ti, 1 TB & 500 GB M.2 nvme drives, Win11.

Glider pilot since 1980...

Avid simmer since 1992...

Share this post


Link to post

thats why  I got   my second  drive   that host all my  sim addons in my  exclude  from scanning


I7-800k,Corsair h1101 cooler ,Asus Strix Gaming Intel Z370 S11 motherboard, Corsair 32gb ramDD4,    2  ssd 500gb 970 drive, gtx 1080ti Card,  RM850 power supply

 

Peter kelberg

Share this post


Link to post

Hi Jose,

 

As is recommended on AVSIM frequently and in the AVSIM CTD Guide, it is best to turn off UAC and any malware/anti-virus program when installing new software (this includes Microsoft Essentials).  I personally have exempted my malware program from scanning the directory where I have my flight sims installed.  If you do not know the Source of a program that you downloaded from the Internet, then you should definitely have your anti-virus or malware program enabled but we all know that Lockheed's P3D is from a trusted site.  The same goes when you download a software addon from FlightOne or Aerosoft.  They are not going to allow any viruses or malware with their software and it is all perfectly safe.  

 

Best regards,

 

Agreed about the exceptions, definitely add your games folder to the exception list for your anti-virus. I do however never recommend shutting off the anti-virus for any reason regardless of whether you trust the site or not. Your download from Prepar3D, Aerosoft etc., which are in my opinion trusted sites and safe, but there is still internet/network connectivity going on other than just your download on your computer for as long as your connected. All it takes is someone malware to get on your system while your protection is off because you are downloading from a trusted site.

 

A situation like that would be rare, but not unheard of. I had no problem downloading Prepar3D while Windows Defender was active, it was just the install that got deleted after I tried to install it.

 

Since this post if from a couple of months ago and I have the same issue today, I can only assume there is no resolution from either Lockheed and/or Microsoft?

 

Either way, it's your computer and just my opinion.

Keep it safe guys!


Michael Lagow
Madness Software

Share this post


Link to post

 

 


All it takes is someone malware to get on your system while your protection is off because you are downloading from a trusted site.

 

I hope I did not recommend you turn off your anti-virus program, just exclude the FSX/P3D folders from being scanned.  Sorry for the poor communications.  I have never used an anti-virus program since at least 2000 and never been hit by a virus.  Malware, yes, but no virus.  Windows has a very reliable firewall and, if you ever turn that off, accidentally or on-purpose, you will most likely be hit with malware or a serious virus.  My sister living far, far away from me turned hers off even though I told her never to turn it off and she had a virus within 20 seconds and had to call in the geeks at BestBuy to fix it (uh, reinstall Windows).  Will an anti-virus program stop malware from hitting your computer?  No but the chances of getting a virus or malware will be drastically reduced.  What are you going to do about any new virus or malware that the developers of anti-virus programs do not even know about yet.  It will hit your system and maybe in a day or two later, you will be informed there's a new virus and you need to update your virus definition. 

 

So, keep your anti-virus, anti-malware programs and your Windows firewall enabled while cruising the Internet and downloading stuff.  When it comes time to install the product you just downloaded from Lockheed, make sure the folder where it will be installed, say, drive D, is excluded from scanning by your anti-virus or anti-malware program during the installation.  You can also disable the anti-virus program temporarily as you still have your firewall protecting you during the installation and you will not be on the Internet as long as you know the software you downloaded came from a trusted website (how do you disable your anti-virus program anyway?  I think they only have one method and that is to exclude the program or folder or drive from scanning)  I had one software program (i-fly 747) that did not install properly because I did not exclude my malware program from scanning during installation.  So it is all just a recommendation.

 

 

 


Since this post if from a couple of months ago and I have the same issue today, I can only assume there is no resolution from either Lockheed and/or Microsoft?

 

Didn't the OP post a link to the solution?  Just report the false positive to Microsoft and make sure you do not allow scanning of the install program or the installation folder during any installation.

 

Best regards,

 

Jim


Jim Young | AVSIM Online! - Simming's Premier Resource!

Member, AVSIM Board of Directors - Serving AVSIM since 2001

Submit News to AVSIM
Important other links: Basic FSX Configuration Guide | AVSIM CTD Guide | AVSIM Prepar3D Guide | Help with AVSIM Site | Signature Rules | Screen Shot Rule | AVSIM Terms of Service (ToS)

I7 8086K  5.0GHz | GTX 1080 TI OC Edition | Dell 34" and 24" Monitors | ASUS Maximus X Hero MB Z370 | Samsung M.2 NVMe 500GB and 1TB | Samsung SSD 500GB x2 | Toshiba HDD 1TB | WDC HDD 1TB | Corsair H115i Pro | 16GB DDR4 3600C17 | Windows 10 

 

Share this post


Link to post

 

 


Didn't the OP post a link to the solution? Just report the false positive to Microsoft and make sure you do not allow scanning of the install program or the installation folder during any installation.

Best regards,

Jim

 

Hi,

 

Thanks for the update. I didn't find any solution except to turn off Defender while installing, still not an option for me, however I think I got away with just installing the CLIENT, CONTENT, and SCENERY installs (in that order) without issue, even though the SETUP.EXE is missing. It is my understanding that you can install Prepar3D that way as well (I could be wrong). However for this experience I let Defender balk at the install while it was running. The install did not produce any errors and so far it's running ok. Time will tell ...

 

Thanks again for your support and insight.

Cheers!


Michael Lagow
Madness Software

Share this post


Link to post

 

 


I think I got away with just installing the CLIENT, CONTENT, and SCENERY installs (in that order) without issue, even though the SETUP.EXE is missing. It is my understanding that you can install Prepar3D that way as well (I could be wrong)

 

Yes in some cases your Anti virus Software will hide or Quarantine the Setup.exe.  

 

The Setup.exe is just an all-In-One Installer pulling Client, Content and Scenery together to Install as 1  But you can Install without the Seup.exe no Problem Once you Install the Client First  


 

 

 

Share this post


Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  
  • Tom Allensworth,
    Founder of AVSIM Online


  • Flight Simulation's Premier Resource!

    AVSIM is a free service to the flight simulation community. AVSIM is staffed completely by volunteers and all funds donated to AVSIM go directly back to supporting the community. Your donation here helps to pay our bandwidth costs, emergency funding, and other general costs that crop up from time to time. Thank you for your support!

    Click here for more information and to see all donations year to date.
×
×
  • Create New...