Kindly be advised we cannot cancel subscriptions or issue refunds on the forum.
You may cancel your Bitdefender subscription from Bitdefender Central or by contacting Customer Support at: https://www.bitdefender.com/consumer/support/help/

Thank you for your understanding.

Three Scanners Found A Trojan In Avcheck.exe

Options

The Bitdefender AV Free file is AVCheck.exe. It is in the Install folder.


I have SAS Pro and during the installation of Bitdefender AV Free SAS Pro identified a trojan; i.e. Trojan Agent/Gen-Yoddos.Process in the AVcheck.exe file. SAS Pro quarantined the file. I then decided to upload AVcheck.exe to Virus Total and Jotti's Malware.


The Virus Total scan found one instance of malware in AVcheck.exe out of 44 AV scanners it uses. The once instannce was again SAS


Jotti's Malware sight. Out of 19 scans two found AVcheck.exe to contain a trojan The other 17 showed "Found nothing"


ClamAV detected PUA.Win32.Packer.WinrarSfx


CPsecure detected Troj.Downloader.W32.Aphex.020


For now I have left the file in SAS Pro quarantine and submitted a FP report to SAS.


Interesting that Bitdefender AV Free uninstalled Malwarebytes Pro during the Bitdefender AV Free installation. The installation process also disabled Windows Defender in W8 as it should. W8 had no problem with the forced disabling of Windows Defender. I doubled checked the Action Center and all was/is clear. My guess is that it was the code in AVcheck.exe that forced the uninstall of Malwarebytes and/or the disabling of Windows Defender that created the Malware warning in SAS Pro, ClamAV and CPsecure.


I was only trying out Malwarebytes Pro and had not yet paid for a license so no harm no foul on the forced uninstall.


OS - W8-Pro x64


Bitdefender AV Free appears to be working okay so far. B)

Comments

  • Nesivos
    Options
    The Bitdefender AV Free file is AVCheck.exe. It is in the Install folder.


    I have SAS Pro and during the installation of Bitdefender AV Free SAS Pro identified a trojan; i.e. Trojan Agent/Gen-Yoddos.Process in the AVcheck.exe file. SAS Pro quarantined the file. I then decided to upload AVcheck.exe to Virus Total and Jotti's Malware.


    The Virus Total scan found one instance of malware in AVcheck.exe out of 44 AV scanners it uses. The once instannce was again SAS


    Jotti's Malware sight. Out of 19 scans two found AVcheck.exe to contain a trojan The other 17 showed "Found nothing"


    ClamAV detected PUA.Win32.Packer.WinrarSfx


    CPsecure detected Troj.Downloader.W32.Aphex.020


    For now I have left the file in SAS Pro quarantine and submitted a FP report to SAS.


    Interesting that Bitdefender AV Free uninstalled Malwarebytes Pro during the Bitdefender AV Free installation. The installation process also disabled Windows Defender in W8 as it should. W8 had no problem with the forced disabling of Windows Defender. I doubled checked the Action Center and all was/is clear. My guess is that it was the code in AVcheck.exe that forced the uninstall of Malwarebytes and/or the disabling of Windows Defender that created the Malware warning in SAS Pro, ClamAV and CPsecure.


    I was only trying out Malwarebytes Pro and had not yet paid for a license so no harm no foul on the forced uninstall.


    OS - W8-Pro x64


    Bitdefender AV Free appears to be working okay so far. B)


    I re-installed Malwarebyes, restarted W8 and the Malwarebytes Tral version re-installed during the W8 restart. I entered the Bitdefender folder into the Malwarebytes ignore list. Ran severala Malwrebytes scans, Quick, Flash and Full. So far so good. I just need to test to see if the Malwarebytes real-time protection is working. Bitdefender AV Free updated and it says I am Protected. If all is good when my Trial version of Malwarebyes expries I will purchase two licenses, one each for each of my two W8 desktop computers.


    Thanks for the restart suggestion. It took only one W8 restart.

  • rootkit
    rootkit ✭✭✭
    Options

    Hello :)


    We have contacted that publisher and reported the False Alarm.


    I will let you know when it will be removed.


    Take care.

  • Nesivos
    Options
    Hello :)


    We have contacted that publisher and reported the False Alarm.


    I will let you know when it will be removed.


    Take care.


    SAS Pro is still identifying AVCHECK.EXE as a trojan