False positive by Bitdefender?

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • PcGuy34
    PCHF Member
    • Nov 2017
    • 96

    #1

    False positive by Bitdefender?

    My PC acquired a virus “Trojan.Ciusky.Gen.13” on December 9, 2017 after I clicked a friend’s facebook link. My paid BitDefender program found it not in C drive but another hard drive & I quarantined it. Virus was attached to two old files I had for years, that I scanned through numerous times without any alerts. One file is 7-Zip. Other file is RAR.
    Afterwards, I noticed every image file said .JPG at the end of the filename & every OpenOffice file said .odt at the end of the filename. I fixed that by clicking “Show hidden files, folders and drives” > “Hide extensions for known file types”. Then I scanned every drive with BitDefender & all was clean. On December 11, 2017 I scanned all drives with my paid Malwarebytes program & all was clean.
    Today, I went into BitDefender quarantine section. I saw they were files I want to keep so I restored them & quickly scanned the two individual files & the folders they are in with BitDefender twice. Results are clean. Scanned with Malwarebytes twice. Results are clean. Was it a false positive by Bitdefender?
  • system
    PCHF Owner
    • Jan 2015
    • 7634

    #2
    As we are yet to know the files in question there is a possibility that they may have been suspicious/false positives that the AV provider has since whitelisted. I would suggest you check the files concerned at VirusTotal.

    You also say that you have two paid for AV’s, with Bitdefender being one of the very best. I do hope you are not running both with realtime protection together IRRESPECTIVE of what the manufacturer of one says. Apart from the extra computer resources used running both AV’s the real problem comes when they both try to take control of a suspect file at the same time.

    Would recommend you run Bitdefender as your first line of defence as realtime protection, and turn Malwarebytes realtime protection off and use it strictly as a second opinion scanner.

    Comment

    • PcGuy34
      PCHF Member
      • Nov 2017
      • 96

      #3
      Gus, thank you for the VirusTotal site. Sorry for any confusion. BitDefender is my only anti-virus. Malwarebytes is for exploit protection, malware protection, & ransomware protection.

      Comment

      • system
        PCHF Owner
        • Jan 2015
        • 7634

        #4
        Originally posted by PcGuy34
        Malwarebytes is for exploit protection, malware protection, & ransomware protection.
        Pretty much what the paid version of Bitdefender does well

        I take it the files scanned clean at VirusTotal?

        Comment

        • PcGuy34
          PCHF Member
          • Nov 2017
          • 96

          #5
          Originally posted by gus
          Pretty much what the paid version of Bitdefender does well I take it the files scanned clean at VirusTotal?
          Oh, I thought BitDefender was antivirus only. VirusTotal didn’t say if it was clean or not. I don’t quite understand how it works there. They have an option for other people to vote yes or no, if it’s clean or not.

          Comment

          • system
            PCHF Owner
            • Jan 2015
            • 7634

            #6
            Try and follow this guide to check your files at VirusTotal. Both VirusTotal and Jotti provide online scanning using around 50 AV engines. Very handy sites

            Can you please got to VirusTotal and follow the instructions below.

            Click on Upload and Scan file.

            [MEDIA=imgur]hDDRsPz[/MEDIA]

            Using the dialogue box browse your computer to and locate your suspicious file.
            [ul]
            [li]Click on the file “xxxxx” which will place it in the Virustotal scan container.[/li][li]VirusTotal will then upload the file and start the scanning process.[/li][li]If VirusTotal gives a message that the file has been scanned before, choose to Reanalyse it.[/li][li]Wait till the scan completes, which may take a couple of minutes to finish, depending on the file size.[/li][/ul]

            [MEDIA=imgur]57O9gLi[/MEDIA]

            Can you please copy the Virustotal link from your browser address bar and paste in your next post?

            Repeat for the other file.

            Comment

            • PcGuy34
              PCHF Member
              • Nov 2017
              • 96

              #7
              Ah, VirusTotal updated their layout. Much easier to navigate & understand now. Results: Clean. VirusTotal

              Comment

              • system
                PCHF Owner
                • Jan 2015
                • 7634

                #8
                Sorry I just noticed that and updated the instructions above, can you repeat the steps for both files please? I can see why that file was looked on as suspicious, 3 extensions???

                Comment

                • PcGuy34
                  PCHF Member
                  • Nov 2017
                  • 96

                  #9
                  I deleted the other file. Here’s the scan for the file above
                  [MEDIA=imgur]sgoxzRk[/MEDIA]

                  Comment

                  • system
                    PCHF Owner
                    • Jan 2015
                    • 7634

                    #10
                    Any file with multiple extensions are commonly picked up by security apps, so yeh no problems here Suggest you rename the files with only one extension and they should not be picked up again?

                    Comment

                    • PcGuy34
                      PCHF Member
                      • Nov 2017
                      • 96

                      #11
                      Originally posted by gus
                      Any file with multiple extensions are commonly picked up by security apps, so yeh no problems here Suggest you rename the files with only one extension and they should not be picked up again?
                      Thank you. It’s part of a movie of 8 files. I joined all 8 files & deleted them all. Scanned the joined, complete movie & all is clean

                      Comment

                      • system
                        PCHF Owner
                        • Jan 2015
                        • 7634

                        #12
                        Wasn’t false positive, just suspicious due to multiple file extensions.

                        Looks like you are good to go, will close this thread, and should you require further help with this issue in the future please contact a staff member who will reopen it for you

                        Comment

                        Working...