Kindly be advised we cannot cancel subscriptions or issue refunds on the forum.
You may cancel your Bitdefender subscription from Bitdefender Central or by contacting Customer Support at: https://www.bitdefender.com/consumer/support/help/

Thank you for your understanding.

Big False Positive

Options

BitDefender behavioral detect virus in my counter strike xD

Comments

  • rootkit
    Options

    Please upload the file(s) in an archive, protected with the password infected.


    Attach the archive in your next post here.

  • I can't. This file contains information about my account, install in your computer counter strike and test. But in virustotal 0 antivirus detect this. Its a false positive.

  • rootkit
    rootkit ✭✭✭
    edited September 2008
    Options

    Add the file to exclusion list.


    2777338376d499568d0cffaa835edba3.PNG

  • I added in the exclusions of behavioral, the scan cant detect this virus!

  • rootkit
    Options

    If you don't put here a sample, we can't guest if it's a virus or not.

  • andplus it doesn't mean its a false positive(could be) but maybe a virus infected your counterstrike file.

  • It's a false positive!!! In the critical or high mode behavioral have false positives.


    Bitdefender detects files of my windows whit a virus! (behavioral)

  • csalgau
    Options

    Dear sir.


    While we cannot force you reveal sensitive data, we cannot guess what version, build, mod or other variation of "Counter Strike" or Half Life you are using, nor can we guess what the detection name is. There is also a high probability that that situation arises only on your computer and your configuration of the detected file. No signature is intentionally included in definition updates if we might create false positives with it.


    If you do not want to upload your file directly on this topic(please note that the Malware Talk section and equivalents in other languages prohibit normal users from downloading; only moderators and analysts will be able to retrieve it) you can attach the file to a PM to me or another active Virus Analyst on the forum. We can also remove the file from the forum server once it has been checked.


    Thank you for understanding.

  • Di0g0
    edited September 2008
    Options
    semttulopd0.th.jpgthpix.gif
  • well none of the birdefender virus researchers can do anything about it until we get a copy of the exe

  • Sm3K3R
    Sm3K3R ✭✭✭
    edited September 2008
    Options

    I dont think there is any private info in that file Di0gO, so you can relax.If you are 100% sure that your game is original and its not a cracked exe and if you dont use any "free" cheats(with trojans included) you can consider it as a false positive for the behavioral.


    I also like the nice Quick Launch "green eyed icon" :).I hope you've uninstalled properly NOD 32 from your computer to avoid future conflicts.

  • My Game is the original version. <img class=" />


    i uninstalled nod, but i forget delete the icone. :blink:

  • rootkit
    Options

    The file is clean !


    http://www.virustotal.com/analisis/12a4954...e1a8e8520d34bac


    Just press Allow when BitDefender ask you to do it ;)

  • But is not possible remove for the definition file???

  • rootkit
    Options

    The aplication does not have a definition file. :)


    It' detected heuristically.


    http://www.thefreedictionary.com/heuristically


    BitDefender does an analisys of the application. (in this way you it can find new viruses without definitions). ;)

  • Ok, thanks

  • csalgau
    Options

    According to the team working on our behavioral engine the problem was already addressed and the file should not be detected as malicious. Was the product updated when the problem appeared?

  • The problem is not resolved :wacko:


    i sent the wrong file :S


    This is the correct file


    The password is: infected


    I wait for answer!!

    /applications/core/interface/file/attachment.php?id=3328" data-fileid="3328" rel="">hl.rar

    hl.rar 30.5K
  • Theoracle117
    edited September 2008
    Options

    You should be more careful.

  • csalgau
    csalgau ✭✭
    edited September 2008
    Options

    I misunderstood the answer.


    With the latest updates, the program should be white listed after "Allow"-ing it a few times.


    Please note that behavioral system updates are not included in signature updates but are featured as a product update.


    The problem itself will probably be addressed in a future update.


    In the meantime, you might try white listing the file yourself by adding it to the exception list if it is so bothersome.