CrossOver Support - Community Forums

Important Information These are community forums and not official technical support. If you need official support: Contact Us

CrossOver Mac
Discussion about CrossOver Mac

The following comments are owned by whoever posted them. We are not responsible for them in any way.

Back to Threads Reply to Thread

Crossover 19 OSX 10.15 Catalina BitDefender delting files

Upgraded to Crossover 19 No sooner that the upgrade completed BitDefender started deliting files

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794681
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/net.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794643
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/rpcss.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794640
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/termsv.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794652
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/mshta.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794712
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/arp.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.42099556
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/cscript.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794700
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/attrib.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794700
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/attrib.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794707
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/xcopy.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794615
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/icacls.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794615
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/icacls.exe
We deleted the file to prevent malicious commands from being executed on your device.

An infected file attempted to run on your device.
Threat name: Trojan.GenericKD.32794610
Path: /Users/ianlangmead/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/msinfo32.exe
We deleted the file to prevent malicious commands from being executed on your device.

I have exactly the same messages and threats detected by BidDefender. Still running Mojave.

Nicola

I have the same issue, download it twice. BitDefender thinks the files have "Trojan.GenericKD.32794615"

im having a similar issue but i dont use any AV on my laptop

when i run an program i get

“winbox64.exe” cannot be opened because the developer cannot be verified.
macOS cannot verify that this app is free from malware.

and i only get the options Move To Bin or Cancel,

but click cancel and the app just runs anyways and the message disappears

Hi folks,

For any of you who missed it, Jeremy posted a general explanation of what is happening with CrossOver 19 and Mac antivirus software here: https://www.codeweavers.com/support/forums/general/?t=27;msg=222870

This thread seems to be mostly from folks with Bitdefender - unfortunately that is possibly the most damaging one because the program will delete the files after incorrectly flagging them without asking for permission.

We are working as hard as we can to come up with solutions for this issue.

Thanks,
Anna

I'm seeing a similar issue on MacOS Mojave with Avira A/V. It quarantines a bunch of exe's and dll's.

Don

Dec 11 21:33:05 Dons-iMac avguard.bin[357] <Info>: Virus alert for file "/Users/don/Library/Application Support/CrossOver/CrossOver 19.0.0.32195/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/ngen.exe": Details: DR/Delphi.Gen ; dropper ; Contains detection pattern of the dropper DR/Delphi.Gen
Dec 11 21:33:05 Dons-iMac avguard.bin[357] <Notice>: the alert in file /Users/don/Library/Application Support/CrossOver/CrossOver 19.0.0.32195/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/ngen.exe was handled. Action(s) taken: access denied, condition logged, file quarantined
Dec 11 21:33:05 Dons-iMac avqmd.bin[348] <Notice>: File /Users/don/Library/Application Support/CrossOver/CrossOver 19.0.0.32195/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/ngen.exe was quarantined
Dec 11 21:33:06 Dons-iMac avguard.bin[357] <Info>: Virus alert for file "/Users/don/Library/Application Support/CrossOver/CrossOver 19.0.0.32195/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/ngen.exe": Details: DR/Delphi.Gen ; dropper ; Contains detection pattern of the dropper DR/Delphi.Gen
Dec 11 21:33:06 Dons-iMac avguard.bin[357] <Warning>: Quarantine error for /Users/don/Library/Application Support/CrossOver/CrossOver 19.0.0.32195/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/ngen.exe: Unable to move file to quarantine (20)
Dec 11 21:33:06 Dons-iMac avguard.bin[357] <Notice>: the alert in file /Users/don/Library/Application Support/CrossOver/CrossOver 19.0.0.32195/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/ngen.exe was handled. Action(s) taken: access denied, condition logged
Dec 11 21:42:44 Dons-iMac avguard.bin[357] <Info>: Virus alert for file "/Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/plugplay.exe": Details: DR/Delphi.Gen ; dropper ; Contains detection pattern of the dropper DR/Delphi.Gen
Dec 11 21:42:44 Dons-iMac avguard.bin[357] <Notice>: the alert in file /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/plugplay.exe was handled. Action(s) taken: access denied, condition logged, file quarantined
Dec 11 21:42:44 Dons-iMac avqmd.bin[348] <Notice>: File /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/plugplay.exe was quarantined
Dec 11 21:42:44 Dons-iMac avguard.bin[357] <Info>: Virus alert for file "/Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/plugplay.exe": Details: DR/Delphi.Gen ; dropper ; Contains detection pattern of the dropper DR/Delphi.Gen
Dec 11 21:42:44 Dons-iMac avguard.bin[357] <Warning>: Quarantine error for /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/plugplay.exe: Unable to move file to quarantine (20)
Dec 11 21:42:44 Dons-iMac avguard.bin[357] <Notice>: the alert in file /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/plugplay.exe was handled. Action(s) taken: access denied, condition logged
Dec 11 21:42:44 Dons-iMac avguard.bin[357] <Info>: Virus alert for file "/Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/winedevice.exe": Details: DR/Delphi.Gen ; dropper ; Contains detection pattern of the dropper DR/Delphi.Gen
Dec 11 21:42:44 Dons-iMac avguard.bin[357] <Notice>: the alert in file /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/winedevice.exe was handled. Action(s) taken: access denied, condition logged, file quarantined
Dec 11 21:42:44 Dons-iMac avqmd.bin[348] <Notice>: File /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/winedevice.exe was quarantined
Dec 11 21:42:54 Dons-iMac avguard.bin[357] <Info>: Virus alert for file "/Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/rundll32.exe": Details: DR/Delphi.Gen ; dropper ; Contains detection pattern of the dropper DR/Delphi.Gen
Dec 11 21:42:54 Dons-iMac avguard.bin[357] <Notice>: the alert in file /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/rundll32.exe was handled. Action(s) taken: access denied, condition logged, file quarantined
Dec 11 21:42:54 Dons-iMac avqmd.bin[348] <Notice>: File /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/rundll32.exe was quarantined
Dec 11 21:42:54 Dons-iMac avguard.bin[357] <Info>: Virus alert for file "/Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/rundll32.exe": Details: DR/Delphi.Gen ; dropper ; Contains detection pattern of the dropper DR/Delphi.Gen
Dec 11 21:42:54 Dons-iMac avguard.bin[357] <Warning>: Quarantine error for /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/rundll32.exe: Unable to move file to quarantine (20)
Dec 11 21:42:54 Dons-iMac avguard.bin[357] <Notice>: the alert in file /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/rundll32.exe was handled. Action(s) taken: access denied, condition logged
Dec 11 21:44:37 Dons-iMac avguard.bin[357] <Info>: Virus alert for file "/Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/msimg32.dll": Details: DR/Delphi.Gen ; dropper ; Contains detection pattern of the dropper DR/Delphi.Gen
Dec 11 21:44:37 Dons-iMac avguard.bin[357] <Notice>: the alert in file /Users/don/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/msimg32.dll was handled. Action(s) taken: access denied, condition logged, file quarantined
Dec 11 21:44:37 Dons-iMac avqmd.bin[348] <Notice>: File /Users/don/Applications/CrossOver.app/Contents/SharedSupport/Cro

We are still working on a solution, but in the meantime I have written a tutorial detailing which exceptions to add to A/V software so that it will not flag/quarantine/delete CrossOver 19 files. My recommendation is to temporarily disable the antivirus software before downloading and installing CrossOver, adding the exceptions, and then turning the A/V software back on.

https://www.codeweavers.com/support/wiki/mac/mactutorial/bitdefender

Thanks,
Anna

Sorry for the "me too" post.

This issue is also happening with F-Secure for Mac. Unfortunately, F-Secure has no option to enable you to ignore files / folders. It either scans everything or you have to manually identify every folder to be scanned.

Have not been able to use Crossover 19 at all.

I would highly recommend reporting the files as incorrectly flagged if you have not already (or perhaps sending in a second report if you have :) Many of the major A/V options are no longer flagging CrossOver 19 files, and we are fairly certain that this is a result of users reporting the problem to the A/V software, not an active improvement on their side.

Please Note: This Forum is for non-application specific questions relating to installation/configuration of CrossOver. All application-specific posts to this Forum will be moved to their appropriate Compatibility Center Forum.

CrossOver Forums: the place to discuss running Windows applications on Mac and Linux

CodeWeavers or its third-party tools process personal data (e.g. browsing data or IP addresses) and use cookies or other identifiers, which are necessary for its functioning and required to achieve the purposes illustrated in our Privacy Policy. You accept the use of cookies or other identifiers by clicking the Acknowledge button.
Please Wait...
eyJjb3VudHJ5IjoiVVMiLCJsYW5nIjoiZW4iLCJjYXJ0IjowLCJ0enMiOi01LCJjZG4iOiJodHRwczpcL1wvbWVkaWEuY29kZXdlYXZlcnMuY29tXC9wdWJcL2Nyb3Nzb3Zlclwvd2Vic2l0ZSIsImNkbnRzIjoxNzA4NjEzODE4LCJjc3JmX3Rva2VuIjoicG5jeVhmRTJaZENSN3pOdyIsImdkcHIiOjB9