506th IR Realism Unit

Recruiting => The Duty Desk => Topic started by: SPC (Ret) Wardlaw on November 21, 2015, 09:24:34 PM

Title: Kaspersky Antivirus Deleting ACE dlls
Post by: SPC (Ret) Wardlaw on November 21, 2015, 09:24:34 PM
Today a new kaspersky antivirus update detects ace_fcs.dll as Trojan-Dropper.Win32.Sysn.bgyq.   I believe this is a false-positive, however if you are finding you are getting the missing ace dll error and can't get on the servers do the following.

Open settings:
(https://lh5.googleusercontent.com/ZBEn_2vUmMegDt6kG3qI9WuK_PCGr07PSANWat_xXOL0ie_dgUM4v5QqJXObb7fyiEBo9Q=w1896-h911)

Select Additional:
(https://lh3.googleusercontent.com/_YRWsoHIPkNVGCJXODmfO5cOeN301KykA1GjlfXKlSJMd9lRNhZoXeOBjIyhmJ6i5e2HFg=w1896-h911)

Threats and Exclusions:
(https://lh6.googleusercontent.com/9Pg68bj3jrWM0co8g-kuWdKK3alJjya6YsnJsscMXSzgp4llHXTJu9MLEMe18wrw2ZoNdw=w1896-h911)

Configure Exclusions:
(https://lh4.googleusercontent.com/PFxjVL80KAxJF6qjm6EyKjODgo7Z8KclfnrW_6oeI5eMWwm5dLNgFpECpzwWO1OdCEfVVA=w1896-h911)

Add a new exclusion:
(https://lh3.googleusercontent.com/DJw2esRTgfTGENbMS5Vcb2-jA_IU0k8ERJMDSbAbhKKP-cF-0xG2KI2fJ11R9tXYVFRC3Q=w1896-h911)

Select the file you wish to exclude from antivirus scanning.  I chose my entire steam folder, you can just do the .dll that is causing the issue.  Ensure you have the object name set as Trojan-Dropper.Win32.Sysn.bgyq
(https://lh3.googleusercontent.com/Hbl2NfvXS-cFyIUxKxD6j8rEBg4UF0S1lfJlZrbw_b7PbQ5i3PY2mssWuhUNNEnuO7P9GA=w1896-h955)
Click add and you should be good to go.

Add the dll back to the @ACE folder, restart Kaspersky and you should be able to continue without having Kaspersky deleting the DLL.
Hope this helps
PFC Wardlaw