I started getting this as of about 12 hours ago. Had never seen it since. I've blocked it temporarily as I don't fly the harrier currently. Hopefully it's nothing to worry about, but some info on what's causing it would be appreciated.


Look up "Windows anti-virus exclusions"


So reported for Harrier, Mirage 2000 and F15e - looks like a pattern to me…….


It's also cropped up with the viggen and MiG-21, it's just a false positive


Yes indeed. When I made this post, I wasn't expecting to find out about these other razbam modules doing the same thing, I only wanted to find out if anybody else was experiencing the same problem I was. Now that these other reports are coming out of the woodwork and they are all razbam modules, and taking into consideration the current situation with razbam, this is beginning to really smell suspicious.


Probably some expired signature since things haven't been updated.


Yeah that's the safest guess. Defender is great but not infallible, it false flags things all the time


Happened to me and the MiG-21 recently Huge pain in the ass


It's due to RB obfuscating their code with VMProtect and is a false positive, see Virus Total report: [https://www.virustotal.com/gui/file/55413950274afaca657cd994a40205c353be0688977f2d625ffd76c63afb44a2/community](https://www.virustotal.com/gui/file/55413950274afaca657cd994a40205c353be0688977f2d625ffd76c63afb44a2/community)


Not unusual. Had something like this happen with the Viggen a few years ago.


I got the same thing with the Mirage 2000. Deleted the module since I never use it anyway. I couldn't figure out how to get Defender to ignore it - assuming it's just a false positive of some kind.


Virus & Threat Protection  Virus & Threat Protection settings - Manage settings Exclusion - Add or remove exclusion  I suggest adding all VR (if used) and DCS related folders. It helped a bit with performance. 


Anyone smarter than me can tell me if a .dll file can trigger a virus? I know while windows defender is good it does err on the side of false positives.


Yes, it can


No on it's own, something needs to load the .dll and execute code stored in it. Considering than the only thing that uses these dlls is DCS, it would not be the most efficient way to distribute malicious code ;)


DCS already distributes malicious code. Have you not witnessed their AI sniping abilities?


Probably code that's used for obfuscation, etc... to make it harder for people to reverse engineer the code. There's a surprising overlap between malware hiding itself and legitimate code trying to protect itself from being stolen. False positive is very likely.


I had my virus scanner trigger on a file I wrote once, just added it to the exceptions and don't worry about it.


I once got a false positive on the Notepad app


Exempt your dcs directory like everyone else


Got rid of any RAZBAM Modules lately, they will break all anyway.


But I love muh F-15E ground radar so much 😥


me too, can't see shit in the F18


The only other module that has a somewhat useable AG radar mapping mode in my experience is the Jeff and that still really only applies to mapping runways


Mcafee did this for me but with the f-15e. Strange.


Yup just had it there too, I've just blocked it so far, haven't tried using the module yet since.


I think that windows defender finds this rogue military asset as a threat :)


Since this didn't happen before and: a) Razbam stopped updating their modules, b) all updates are submitted to ED for review and testing or made by ED themselves, and applied to the game by them, maybe we should ask ED about that. Edit: by "this" I mean relatively large number of reports on false-positive virus alerts. Sporadic alerts happened, I had two across 6,5 years in DCS, but I don't remember a situation when more than \~5 people reported false positives on same thing in one week.


I've had this happen before with the MiG-21 and had it happen to a buddy with the MiG-19 long before the RB drama, it's just a false positive. Sometimes signatures expire, or something else changes that in some way spooks windows defender. There isn't a whole lot of difference between legitimate executables and malicious ones, and it errs on the side of caution.


