Antivirus false positive
Posted: Sun Feb 16, 2020 10:51 am
FORScan uses binary compression and encryption to reduce the binary size and protect the code. This technique is often used by virus/malware (and often using the same compression/protection system), so some antivirus may throw a false positive if signature matched. We have created this thread to provide information on this issue.
At this moment we have this problem with FORScan v2.3.29 - several anti-virus software throw alerts for it, including Microsoft WIndows Defender. We have submitted the false positive to Microsoft and Bitdefender. Microsoft have already updated their database, so false positive should gone in the next update. They recommend to clear Defnder cache this way:
At this moment we have this problem with FORScan v2.3.29 - several anti-virus software throw alerts for it, including Microsoft WIndows Defender. We have submitted the false positive to Microsoft and Bitdefender. Microsoft have already updated their database, so false positive should gone in the next update. They recommend to clear Defnder cache this way:
Bitdefender promised to check the file and update DB in next 72 hours.We have removed the detection. Please follow the steps below to clear cached detection and obtain the latest malware definitions.
1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender
2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
3. Run "MpCmdRun.exe -SignatureUpdate"
Alternatively, the latest definition is available for download here: https://www.microsoft.com/en-us/wdsi/definitions