AD 28. juni kl. 7:52
Is this a false positive?
Hi all.

I just bought an external drive and just out of habit I uploaded the program that came with it to VirusTotal. It already existed there, but I'm paranoid so I redid the scan. Now one of the engines decided it was malware, calling it the following:
W32.AIDetectMalware

Since I just bought the thing and never done anything with it, I'm guessing it's a false positive?

Also, I haven't run the program or opened anything, I just scanned it with VirusTotal. Even if it was malware, it should be fine, right?

Either way, I'm just going to format the drive and get rid of everything in it. Was going to do that anyway, just wanted to see what was on it first.
Sidst redigeret af AD; 28. juni kl. 7:53
< >
Viser 1-8 af 8 kommentarer
1 of the engines and with a generic, non-descriptive term. Report them for a false positive and attention who****ring. You are absolutely safe. Remember to not eat everything you encounter on the internet.
emoticorpse 28. juni kl. 9:28 
I'd consider it safe if all these things checked out...

1. The drive was/is brand new bought from a store or something like that
2. The file in question wasn't oddly named like Seegate_toolz.exe or something
3. It was only detected by one engine AND it was a obscure one (Bkav Pro?)
HIVEmind 28. juni kl. 12:31 
I don't like virustotal. Its a bottom feeder that doesn't do its job. It detects. But that virus spreads.

Reinstall windows if I were you. And don't keep any files. Start again.

Sorry, this is my opinion.
I use win defender and Malwarebytes. I know what I'm doing. So this is what I do.
Sidst redigeret af HIVEmind; 28. juni kl. 12:33
A&A 28. juni kl. 12:35 
What is this program and by which manifacture?

And repartition the whole drive if you're paranoid.
Sidst redigeret af A&A; 28. juni kl. 12:36
AD 29. juni kl. 9:24 
Oprindeligt skrevet af emoticorpse:
I'd consider it safe if all these things checked out...

1. The drive was/is brand new bought from a store or something like that
2. The file in question wasn't oddly named like Seegate_toolz.exe or something
3. It was only detected by one engine AND it was a obscure one (Bkav Pro?)
I just got the drive. Brand new, right from the store, have not done anything with it at all. The first thing I did was literally to scan the content because I'm paranoid that way.

I expected buying a drive from a large store would be safe from malware, it's not like I bought it from a weird company (though I never heard of the brand name itself, so maybe it was a weird brand). The drive was many by a company called LACIE.

It had some name like "Start_here.exe". It was only detected by Bkav Pro. In fact, that was a recent thing. Someone had already scanned the file 12 days before me and nothing was detected back then, but when I clicked "reanalyze" it was detected.

Also, just to be clear, I didn't run the program.

Oprindeligt skrevet af HIVEmind:
I don't like virustotal. Its a bottom feeder that doesn't do its job. It detects. But that virus spreads.

Reinstall windows if I were you. And don't keep any files. Start again.

Sorry, this is my opinion.
I use win defender and Malwarebytes. I know what I'm doing. So this is what I do.
I don't use Windows on that device. I use Kubuntu. And I didn't run anything. Still, I logged out from everything I was logged into on that device, turned it off and reset the router. Not turning it back on until I have know it was a false positive or if I should reinstall.

I make backups for the stuff I care about (that was why I wanted an extra drive, to have one more backup location) so wiping the drive is just a bit inconvenient.

Oprindeligt skrevet af A&A:
What is this program and by which manifacture?

And repartition the whole drive if you're paranoid.
I already reformatted the drive itself. Had to do that because it was formatted as exfat and I want ext4. The suspicious program came with it. No downloads or anything. The manufacturer was LACIE, do you know of them?
Sidst redigeret af AD; 29. juni kl. 9:25
Lithurge 30. juni kl. 1:30 
Oprindeligt skrevet af AD:

I already reformatted the drive itself. Had to do that because it was formatted as exfat and I want ext4. The suspicious program came with it. No downloads or anything. The manufacturer was LACIE, do you know of them?
They've been around since the 80's and are now owned by Seagate. I've just uploaded the starthere exe from a Seagate drive I've got, what it reports is that it's suspicious because of a low ml (machine learning as far as I'm aware) score, not that it's detected a virus. Basically it's saying I don't really know anything about it so just in case. This was a different AV vendor I've never heard of than the one that detected your Lacie 'virus'.

The rule of thumb with being a PC user is caution not paranoia.

You should also be aware AV's these days use heuristic scanning, which basically means they guess based on existing data that something might be a virus because it kind of looks vaguely similar to known viruses. This is where a lot of false positives come from.

Ultimately if you're not sure about something then don't use it, when it comes to the tools supplied on external hard drives you don't really need them anyway.
Sidst redigeret af Lithurge; 30. juni kl. 1:31
Why worry about it; you want to do a 100% drive wipe anyways; don't need whatever software they provided.

Why buy an External anyways? Just buy an internal drive with better performance and better warranty; then make it external via a caddy or adapter.
A&A 30. juni kl. 4:00 
Oprindeligt skrevet af AD:
I already reformatted the drive itself. Had to do that because it was formatted as exfat and I want ext4. The suspicious program came with it. No downloads or anything. The manufacturer was LACIE, do you know of them?
Daughter company of Seagate.

Seems like they ship with a useless program for backups, mirrors and ect.
Sidst redigeret af A&A; 30. juni kl. 4:00
< >
Viser 1-8 af 8 kommentarer
Per side: 1530 50