Jump to content
Sign in to follow this  
m54randy

GTN 750, bank screens, anti-virus false positive

Recommended Posts

For no apparent reason, my GTN 650 wouldn't come up in Xplane - the device is there, but totally black screen.  I tried reloading everything except X-Plane itself and still no luck.  I believe that the problem is caused by an update to the GTN Trainer, and it's incompatibility with the version of RealityXP that I have.  I downloaded the RealityXP update, but it won't run because of a Trojan Virus detected by Total Defense.  I looked through these threads, and it seems that all RealityXP can suggest is to ignore the warnings of antivirus, and, on faith of their word, let the software execute.

There have been multiple complaints about the virus issue here in these threads, it would seem that a reputable software manufacturer would investigate and eliminate the cause of their software triggering antivirus alerts.  Asking your customer to ignore anti-virus warnings doesn't seem like an acceptable solution. 

Does anyone have a solution for this problem, other than risking all of my personal information in order to be able to use this product?

Share this post


Link to post
Share on other sites

Hello...Would you be talking about this...

RealityXP XP11 updates   as of 06 February, 2021
http://reality-xp.com/appcast/rxp-software-updates.xml
http://reality-xp.com/support/updates/index.html

RealityXP Garmin GTN (X-Plane) ver. 2.5.28.0
released 09 Jan 2021 19:08:34 EST

This may be caused by the GTN update containing a normal and functional new binary that has triggered the anti-virus program due to a similarity within it's base "watch"list.
Once the developer has been notified, it can take a bit of time to address "the flagged code" with each anti-virus company, if that is the path taken.

IMHO, One always has options...

1] Cease use of the GTN650 until the matter is addressed. This could take some time.
2] Open/extract and verify contents in a sandbox prior to use. Install when confident.
3] Backup all your personal data. Do a harddrive clone and set it aside. Have one hand on the internet cable and a shot of wiskey ready...be bold and run it.
4] The update has been out for 1 month now. Have you been made aware of computer infections specifically due to this update...
5] Assume RXP is not trying to infect his customers...and whitelist the update in your anti-virus program. Download and extract the zipfile into "downloads". Then run the exe

Kidding aside, your call but generally when dealing with a regular vendor, there are times when trust is warranted. My GTN update was flagged by my antivirus program. I had a hunch that it was a "new binary being flagged" and I whitelisted it. The update works fine for generic installations. Note: regular backups and disc images are done for a reason.

Have a good day.

 

  • Like 1

Share this post


Link to post
Share on other sites

I searched the Reality XP website, and found no way to actually contact customer support.  The website has hours of operation, but no way to contact support within those hours. Support seems to be hiding in this forum somewhere.  The website says 'if you're not happy, we're not happy.'  I am not happy.  I bought this product, and I can't use it without taking the risk of installing software that is being flagged as having a Trojan Virus.  I paid for the software, but I can't use it.  I would like to have my money back if your technical support can't help me though this issue.  I have already invested a half a day in trying to find an answer in this forum, to no avail.  

  • Like 1

Share this post


Link to post
Share on other sites

First, welcome to Avsim.  This is a premier flight simulation site with an incredible number of other users and frequented by many developers.  You have reached the correct location.  The Reality XP developer visits this site and provides support.  There is also a great deal of user-to-user assistance here. 

The warning you are seeing is a long standing false positive.  It is based on an international database of signatures of potential virus used by most if not all AV software products. The warning you are seeing is returned by some AV software and not returned by others.  The file is OK for you to proceed with.  If you take a few minutes and scroll through several pages of topic titles here you will find that this has been responded to many many times.

Perhaps take some time to learn the layout of forums here.  In your half a day of searching here somehow you missed the third topic listed below in the RXP general forum.  See image below.

image.png.038bb4e06545df76d803d4a0792b4c85.png

 

 

Edited by fppilot
  • Like 1

Frank Patton
MasterCase Pro H500M; MSI Z490 WiFi MOB; i7 10700k 3.8 Ghz; Gigabyte RTX 3080 12gb OC; H100i Pro liquid cooler; 32GB DDR4 3600;  Gold RMX850X PSU;
ASUS 
VG289 4K 27" Monitor; Honeycomb Alpha & Bravo, Crosswind 3's w/dampener.  
Former USAF meteorologist & ground weather school instructor. AOPA Member #07379126
                       
"I will never put my name on a product that does not have in it the best that is in me." - John Deere

Share this post


Link to post
Share on other sites

FPPilot, thank you for responding - yes I did see the third item down, and many others, but this and other posts all resolve to "run the software in spite of the anti-virus warnings."  This is not an acceptable solution to me.  People should expect to be able to use an application without feeling like they are taking a Trojan Malware risk in doing it.  I spent a half a day trying to find a solution that doesn't require me to take this risk, and not finding one, I am requesting actual support from Reality XP, and perhaps a refund if they don't have an answer.  I have been using computers since the days of the TRS-80, and I have never encountered an application that expects the user to take a malware risk in using it.  These kind of issues should be resolved prior to release of the software, it is easy for the software developer to test and therefor know that their customers are going to experience this problem, IMHO.  Looking forward to someone from Reality XP getting in touch with me.

  • Like 1
  • Upvote 1

Share this post


Link to post
Share on other sites

Just in case it helps someone.  I removed the 2 plugins (rxpGTN and rxpGNS) and reinstalled the plugin again with the same installer.  For some reason, that fixed it for me.

Gregg

  • Like 1

Gregg Seipp

"A good landing is when you can walk away from the airplane.  A great landing is when you can reuse it."
i7-8700 32GB Ram, GTX-1070 8 Gig RAM

Share this post


Link to post
Share on other sites

I had this same problem which just started today, I have been running GTN750 no problem up to now.

When I tried deleting and reinstalling it, I got a virus warning, Windows defender is saying that rxpGtnSim32.dll is infected with Trojan virus.  This is worrying!

if I turn off virus protection, let the install happen, it works ok,  but as soon as virus protection is turned on, it quarantines the file.

Is it a real virus? where next?

Share this post


Link to post
Share on other sites
2 hours ago, uptimist1 said:

I had this same problem which just started today, I have been running GTN750 no problem up to now.

When I tried deleting and reinstalling it, I got a virus warning, Windows defender is saying that rxpGtnSim32.dll is infected with Trojan virus.  This is worrying!

if I turn off virus protection, let the install happen, it works ok,  but as soon as virus protection is turned on, it quarantines the file.

Is it a real virus? where next?

My suspicion is they didn't put the right signatures in the files to prevent this.  Nobody can make the decision for you, but, personally, I'd exclude them from the virus scan.

  • Like 1

Gregg Seipp

"A good landing is when you can walk away from the airplane.  A great landing is when you can reuse it."
i7-8700 32GB Ram, GTX-1070 8 Gig RAM

Share this post


Link to post
Share on other sites

Same problem here, been working flawlessly on multiple aircraft and suddenly this morning black screen and wont turn on. When I try reinstalling or updating, windows defender says a virus is blocked. Have tried multiple posted solutions with no luck......please help

Share this post


Link to post
Share on other sites

You are not alone.  Mine stopped working today as well, was fine yesterday.  I also deleted the two plugins mentioned by Gregg, and I was also inundated with virus warnings.  I made sure to allow the files in Norton so they wouldn't be quarantined, but the GTN still doesn't power up in Xplane. 

Share this post


Link to post
Share on other sites

Same for me.

Yesterday no issue, today black screen of pain. 

Tried a reinstall, virus warning,files locked etc.

Tried to allow but windows seems hellbent on saving my system.

Lets hope they fix the false positive soon.

Share this post


Link to post
Share on other sites

It's not loading because Windows Defender (or Norton, if you're using that) sees a threat in rxpGtnSim32.dll, which should be in C:\ProgramData\Reality XP\rxpGtnSim32.dll.

By re-installing RXP and explicitly allowing the "threat" to continue, it installed the file as expected.  Then I restarted X-Plane and re-launched the GTN 750, and it displayed as expected, too.

From rxpGtnSim.dll.log:

21/02/07 19:08:04.267 16416 -    ] # rxpGtnSim64.dll version 2.5.28.0
21/02/07 19:08:04.267 16416 INFO ] 
21/02/07 19:08:26.042 16416 INFO ] GTN 750.1 - TRAINER 6624
21/02/07 19:08:26.048 16416 WARN ] A component version required by the application conflicts with another component version already active., code: 000036b8
21/02/07 19:08:26.049 16416 WARN ] rxpGtnSim32.dll  v0.0.0.0 (32bits), v2.5.28.0 (64bits)
21/02/07 19:08:26.076 16416 ERROR] GTN 750.1 process not ready: The specified module could not be found., code: 0000007e
21/02/07 19:08:26.077 16416 ERROR]  check if file is missing or your antivirus: C:\ProgramData\Reality XP\rxpGtnSim32.dll
21/02/07 19:08:26.250 16416 INFO ] GTN 750.2 - TRAINER 6624
21/02/07 19:08:26.276 16416 ERROR] GTN 750.2 process not ready: The specified module could not be found., code: 0000007e
21/02/07 19:08:26.277 16416 ERROR]  check if file is missing or your antivirus: C:\ProgramData\Reality XP\rxpGtnSim32.dll

See this linked image for Windows Security's threat display for the file:

https://onedrive.live.com/?authkey=!AGASoFZWe4j-viM&cid=34AD34E93D66E069&id=34AD34E93D66E069!78433&parId=34AD34E93D66E069!214&o=OneUp

More on the nature of that threat:

https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=HackTool%3aWin32%2fAutoKMS!ml&threatid=2147748160

Edited by TangoWhiskey69
Documented that allowing the file to be installed fixed my problem.
  • Like 1

Share this post


Link to post
Share on other sites

Yesterday it worked perfectly. It did not turn on this morning. I found a RealityXP quarantined .dll in Windows Defender. Removed from quarantine, put the exclusion on the ProgramData/Reality XP folder and everything is back to workImmagine.png

  • Like 1

Share this post


Link to post
Share on other sites

Anyone experienced this?

Detected: Trojan:Win32/Wacatac.DE!ml
Affected Items:C:\ProgramData\Reality XP\rxpGtnSim32.dll


Torfi

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

  • Tom Allensworth,
    Founder of AVSIM Online


  • Flight Simulation's Premier Resource!

    AVSIM is a free service to the flight simulation community. AVSIM is staffed completely by volunteers and all funds donated to AVSIM go directly back to supporting the community. Your donation here helps to pay our bandwidth costs, emergency funding, and other general costs that crop up from time to time. Thank you for your support!

    Click here for more information and to see all donations year to date.
×
×
  • Create New...