AV Software removing .dlls?

Started by Hayhorse, August 13, 2015, 01:53:40 PM

Previous topic - Next topic

Hayhorse

Anyone have this problem where AV software will quarantine or just straight up delete AV software? the .dlls of mods.

Its annoying since I have to go into the software and tell it to restore it and ignore it from then on.. :-\

Mr.Cross

#1
So let me get this straight, you Av software is deleting your other Av software? or is it the same Av software deleting itself? Also I'm suppose I should mention that this should probably go in the Off topic portion.

Unless of course your second Av is supposed to be .dll in which case I don't know where it would go or how to help you.
Claims to know most things.

Hayhorse

Sorry, didn't really know where to post it, but my AV software for some reason see's the mod dll.'s as dangerous when they would need an executable for it to do anything.

Was wondering if anyone knows why this would be a thing. Also, no I only have one AV software installed. Gonna modify the OP.

Mr.Cross

Ah, I'm sorry I don't know how to help. As I don't really ever actively use my Av.
Claims to know most things.

Hayhorse

#4
An example, as soon as I extract the mod my AV software scans the .dll and says it isnt safe.
Heres what it says.

e:\rimworld a11d mods\rw_a2b_v0.11.2_\assembiles\a2b.dll
Removed

Edit:It only does this with EdB interface and Modorder along with A2B converybelt mods.

Devon_v

Your AV is overly sensitive.

Basically, because the mod DLLs are injected into the game and alter existing functions it's assuming that they are viruses. That tends to happen with DirextX wrappers and memory injectors as well because one program is "hacking" another. If your AV doesn't have a whitelist feature where you can tell it what isn't a virus, you're probably best off replacing it. I'd recommend Avast!, if only because it's never cried wolf on any sort of "unauthorized" game mod I've used.

Hayhorse

Sadly I cant access the white-list, but when it does remove it I can restore it and tell it to ignore the ID in the future.

harpo99999

hayhorse, could you name and shame the AV?
I also can suggest that avast does NOT have this issue even when it is set to MAX sensitivity and autovault any suspect

milon

This may be off topic, but I personally use MS Security Essentials (with sample submission etc turned off).  Reasons:
- It looks only for known viruses, no guess-work
- Lighter CPU/memory footprint
- False positives are virtually unheard of (haven't had a single one yet)

It may be a "lite" protection, but I don't need anything stronger since I don't go to sketchy websites or run unknown applications, etc.

Coenmcj

I had something similar with a bloat-ware AV program that was installed on my computer when I got it, Don't remember the name of it unfortunately as it would block anything and everything off the net and wouldn't let half my programs connect to the internet.
It was just sheer trash.

I'd recommend BitDefender actually, got a real light CPU/Memory Footprint (0.5 to 6 MB tops, 1% of CPU if anything) and doesn't really 'cry wolf' with false-positives.
Moderator on discord.gg/rimworld come join us! We don't bite

Hayhorse

Gonna name it, Norton. SHAME ME! It is always that damned ws.rep system it has!

harpo99999

my condolences for your DEAD computer that had the silly men tech virus. you might be able to resurrect it  by using safe mode and uninstalling the CRAPWARE, and then in normal mode downloading and installing another better antivirus like avast or bitdefender

Hayhorse

I know how to uninstall Norton and any left over files. (Bsides I have all my programs on a removable hard drive.) I am going to update to windows 10 soon anyways and might wipe my main hard drive in doing so.

Any good AV programs you guys use?

harpo99999

I use avast(free), but another good one is bitdefender (pay for)

isistoy

Would recommend either one of these two as well.

Bitdefender is nice, but, as stated, is not free.

Avast is on my dev computer and never complains about .net dlls flying around and it's free.
<Stay on the scene like a State machine>