Help - Search - Members - Calendar
Full Version: Root Kit And "backdoor.subsari.14.b" False Positives
BitDefender Forum > English > Old Forum Topics > Malware Talk > False positive reporting
szimm
I just ran a full scan and BitDefender came up with a what seems like a lot of false positives.

It came up with about 150 of these as "Rootkit-Hidden Items". These are all backup folders (yes hidden) installed by Lenovo's (IBM) "Restore and Recover" backup system.
C:\RRbackups\Documents and Settings\Steve\Application Data\Microsoft\SystemCertificates\My\CTLs

This was identified as "Backdoor.Subsari.14.B", but it's a simple printer test that I wrote myself. It was a test applet written in Delphi to identify the default printer on a local system.
C:\Test\dPrinterTest\DPrinterTst.exe

I sent this in via the "Quarantine" section in BitDefender.

I'd be happy to provide you with more information should you need it.
crysty2k5
Put the file in a zip or rar archive with the password infected and attach the file here . wink.gif
szimm
QUOTE (crysty2k5 @ Sep 14 2008, 06:13 AM) *
Put the file in a zip or rar archive with the password infected and attach the file here . wink.gif


Thanks, but they already took care of this. I sent it directly last week to BitDefender and it was fixed within hours. I'm impressed at their speed.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.