public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* Bitdefender detecting a file from cygwin as a trojan
@ 2021-11-25 19:32 Tyme LaDow
  2021-11-25 20:08 ` Csaba Raduly
  0 siblings, 1 reply; 2+ messages in thread
From: Tyme LaDow @ 2021-11-25 19:32 UTC (permalink / raw)
  To: cygwin

[-- Attachment #1: Type: text/plain, Size: 600 bytes --]

Hey,

I'm running Windows 10 Pro v. 10.0.19042 build 19042 and I installed cygwin
at least a year ago and haven't touched it since June 2020.  Today,
November 25th, 2021, I got a notification from Bitdefender that it had
detected a trojan and quarantined it.  The threat notification says "Item
was blocked. Threat name: Trojan.GenericKDZ.80660. Path:
C:\cygwin64\bin\dumper.exe."

Searching online gave results from 2014, 2015, and 2018, but nothing within
the timeframe of when I last installed/updated. Is this a false positive,
and is it safe to have Bitdefender restore the file and exclude it?

[-- Attachment #2: cygcheck.out --]
[-- Type: application/octet-stream, Size: 63246 bytes --]

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Bitdefender detecting a file from cygwin as a trojan
  2021-11-25 19:32 Bitdefender detecting a file from cygwin as a trojan Tyme LaDow
@ 2021-11-25 20:08 ` Csaba Raduly
  0 siblings, 0 replies; 2+ messages in thread
From: Csaba Raduly @ 2021-11-25 20:08 UTC (permalink / raw)
  To: Tyme LaDow; +Cc: cygwin list

Hi,

On Thu, 25 Nov 2021 at 20:33, Tyme LaDow via Cygwin  wrote:
>
> Hey,
>
> I'm running Windows 10 Pro v. 10.0.19042 build 19042 and I installed cygwin
> at least a year ago and haven't touched it since June 2020.  Today,
> November 25th, 2021, I got a notification from Bitdefender that it had
> detected a trojan and quarantined it.  The threat notification says "Item
> was blocked. Threat name: Trojan.GenericKDZ.80660. Path:
> C:\cygwin64\bin\dumper.exe."

That is almost certainly a false positive. Restore the file, and
submit it to virustotal.com
if you want to be safe.

Perhaps you could try upgrading too.

Csaba
-- 
You can get very substantial performance improvements
by not doing the right thing. - Scott Meyers, An Effective C++11/14 Sampler
So if you're looking for a completely portable, 100% standards-conformant way
to get the wrong information: this is what you want. - Scott Meyers (C++TDaWYK)

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2021-11-25 20:08 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-11-25 19:32 Bitdefender detecting a file from cygwin as a trojan Tyme LaDow
2021-11-25 20:08 ` Csaba Raduly

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).