7 Replies Latest reply: Apr 17, 2009 6:02 AM by Ex_Brit RSS

    McAfee is deleteing my exe file

      I bought a computer game, by the name of Battle of Britain. Then McAfee virusscan deleted the entire exe.file because it detected the generic.dx file which it calls a harmful trojan. however every time I install the game again, McAfee detects generic.dx in the
      software and deletes the whole exe.file immediately. The Manufacturer of the program states their is no trojan in their game which is in fact a classic game running for over 10 years now. Do anyone know the solution.
      Also I could switch off Security center and was able to install and play the game. Now I cannot even do that, I get a 0xc0000005 error (applicatio failed to initlize properly)
      I cannot locate the Generic.dx file to send to mcafee.
      thank you
        • 1. RE: McAfee is deleteing my exe file
          Ex_Brit
          You should go to the Restore tab in Security Center and make sure that it is forwarded to the Threat Center (Avert Laboratories) as, if it is harmless, it will then be excluded from the database automatically.

          To send it to the Threat Center outside of Security Center.....

          First disable VirusScan:

          To temporarily turn off VirusScan do the following:

          Double-click the taskbar icon to open Security Center
          Click Advanced Menu (bottom left)
          Click Configure (left)
          Click Computer & Files (top left)
          You can disable VirusScan in the right-hand module and tell it for how long.

          Then click the Restore button (left & assuming it was quarantined) & restore the item.

          Send the file to Avert for analysis:
          http://vil.nai.com/vil/submit-sample.aspx
          or
          https://www.webimmune.net/default.asp
          or
          Email file to: [EMAIL="virus_research@avertlabs.com"]virus_research@avertlabs.com
          When submitting samples via E-mail all samples must be packaged in a .ZIP file. When creating this .ZIP file, it is important to understand that the .ZIP can be no more than 3 megabytes in size and can contain no more than 30 files. Additionally, any .ZIP file created must be password-protected using the password "infected" (minus the ""). Failure to follow these guidelines will cause your submission to be rejected.
          • 2. RE: McAfee is deleteing my exe file
            I have also had a problem with the recent update of McAfee killing "Battle of Britain".

            I loaded "Battle of Britain" shortly after Christmas with McAfee antivirus running during the load. I have enjoyed playing the game many times since without incident, McAfee AV running. Mid to late last week the game would no longer load, GAME.EXE was missing. After some digging I have found that now McAfee recognises the GAME.EXE file as the GENERIC.DX trojan and immediately quarantines it. I uninstalled & deleted "Battle of Britain", scanned for malware, deleted everything McAfee had quarantined and reinstalled "Battle of Britain" with McAfee turned OFF. It would not let the game install from the CD if it was running. GAME.EXE was immediately quarantined even before I tried to load the game. I can restore the file from within the McAfee Security Center but it is immediately quarantined again. It is only after I turn McAfee OFF that I can run "Battle of Britain".

            I do not know of any changes to my PC in the past week except for automatic updates from McAfee and maybe Microsoft. I strongly suspect that an update from McAfee last week has lead to this problem.
            • 3. RE: McAfee is deleteing my exe file
              Ex_Brit
              Follow the instructions above. Hopefully they will send you an extra.dat to cover it.

              If they only reply without an extra.dat included, reply, keeping the header intact, asking for an extra/dat.
              • 4. RE: McAfee is deleteing my exe file
                Sorry Ex_Brit, I guess I'm just not smart enough to deal with McAfee. I did what you suggested and opened an account at "Avert(r) Labs WebImmune". I got all approved and everything, logged on, submitted a sample of the GAME.EXE file and waited for a reply.

                The reply came back to me on my "Account Page", told me nothing I didn't already now and did not include an "extra.dat". I tried to reply to them and request the file like you suggested but I can't find anyplace to REPLY to. When I hit the CONTACT US button I wind up on a corporate account page with a notation for "Home/Retail Users" to click here. This takes me to McAfee Sales trying to sell me more software and telling me that if I give McAfee enough money they will help me get rid of my virus.

                Sorry I am have so much trouble performing what I'm sure is a simple task. Us Engineers get that way some times.

                Here is what I got in my report:

                AVERT Labs - Beaverton
                Current Scan Engine Version:5300.2777
                Current DAT Version:5586.0000
                Thank you for your submission.

                Analysis ID: 5260210

                Name: game.exe
                Findings: current detection
                Detection: generic.dx
                Type: Trojan
                Extra: no
                *********************************

                Any more suggestions will be appreciated.
                • 5. RE: McAfee is deleteing my exe file
                  Ex_Brit
                  I have my dumb moments too you know. Come to think of it, it's most of the time lately....!

                  See my post above regarding emailing the file.

                   

                  Email file to: [EMAIL="virus_research@avertlabs.com"]virus_research@avertlabs.com
                  When submitting samples via E-mail all samples must be packaged in a .ZIP file. When creating this .ZIP file, it is important to understand that the .ZIP can be no more than 3 megabytes in size and can contain no more than 30 files. Additionally, any .ZIP file created must be password-protected using the password "infected" (minus the ""). Failure to follow these guidelines will cause your submission to be rejected.

                  • 6. RE: McAfee is deleteing my exe file
                    And if we keep trying it will work. LOL

                    I just ran "Battle of Britain" with McAfee up and running protecting me all the way.

                    I sent an e-mail to City Interactive S.A., the producers of Battle of Britain. Got a nice reply with an explanation, instructions and a patch to install that will handle McAfee until the problem is corrected. Good support effort.

                    For information here is what they had to say.

                    *********************************************
                    Here's explanation from our site:

                    "...City Interactive S.A. wishes to inform the users that some of the antivirus programs may erroneously identify the security system used in our software as a virus (most often TR/Crypt.XPACK, sometimes TR/Dropper) (...) The virus alert should be considered void and be ignored. We apologize for the difficulties caused by this issue and guarantee that our games undergo detailed testing aimed at detecting potentially harmful software.

                    City Interactive S.A. has contacted Avira, Dr. Web and other antivirus software developers. These companies have positively determined the files not to be infected and announced starting work on updating signature databases. This will help to avoid such problems in the future. Consequently, we encourage updating your antivirus software."

                    In attachment we send You a patch. All You have to do is to install game and when installator give You an error choose ignore option (You antivirus probably will block game file). After that install patch and run the game.
                    ******************************************************

                    The patch filename is 3pack_patch.zip (354KB)

                    grin Ex_Brit, thanks for the help.
                    • 7. RE: McAfee is deleteing my exe file
                      Ex_Brit
                      You're welcome and good luck.