Windows 10: WD bogus notification: malware detected and cleaned

Discus and support WD bogus notification: malware detected and cleaned in AntiVirus, Firewalls and System Security to solve the problem; Hello. I received a notification today from WD (at the notifications area) stating that "malware detected and is being cleaned". Funny enough I... Discussion in 'AntiVirus, Firewalls and System Security' started by eLPuSHeR, Jun 26, 2016.

  1. eLPuSHeR Win User

    WD bogus notification: malware detected and cleaned


    Hello.

    I received a notification today from WD (at the notifications area) stating that "malware detected and is being cleaned". Funny enough I checked WD history and nothing was found there. I clicked on the notification and nothing was shown there either.

    What gives? *Confused

    I have been scanning several folders (browsers cache, appdata and so on, as well as a quick test) with WD but my system seems to be pretty clean. Could it be that Steam was opened when I got that notification?

    :)
     
    eLPuSHeR, Jun 26, 2016
    #1
  2. Gymbos Win User

    where are quarantined files kept?

    "I turned off WD, compiled the file and will up load it then turn WD back on."

    I uploaded the file and the Microsoft Malware Protection Center has verified that it is not malware: "The submitted file is Clean.

    I hope this means that when I make another small change it won't get flagged as malware, time will tell.

    Jim
     
    Gymbos, Jun 26, 2016
    #2
  3. warc1 Win User
    WD Detects Trojan:Win32/Derbit.A But Cannot Remove Due to Error 0x80508023

    Two days ago, my main AV program, Malwarebytes Premium, continuously reported its blocking of hundreds of outbound attempts to connect to a malicious website using the process msiexec.exe. However, Malwarebyte's scan of my PC reported no threats. That evening,
    Windows Defender (WD) ran its daily scheduled scan and reported it detected and quarantined Trojan:Win32/Wammuras.C!cl. I chose to delete the virus in quarantine and then rebooted my PC.

    This put an end to Malwarebytes notifications of attempts to connect to a malicious website. However, I then got a Windows notification that malware had been detected and Windows Defender (WD) was removing it. When I opened WD, and looked under "All Detected
    Items", it listed a new detected item "Trojan:Win32/Derbit.A" with an action "Quarantined". However, below that was the message: "The following error occurred: Error code 0x80508023. The program could not find the malware and other potentially unwanted software
    on this computer." I did look under "Quarantined Items" and nothing was there.

    I now get the "Trojan:Win32/Derbit.A" detection everytime I start my computer followed by the 0x80508023 error code in WD. Running a subsequent full scan with WD always reports no threats detected. The same thing happens with any subsequent Malwarebytes
    scans. As a further precaution, I downloaded a trial copy of Kaspersky Premium and ran its full scan. Again, no threats were detected. Most recently, I discovered the offline scan capability of WD and ran that. It made no difference.

    I have not noted any unusual behavior with my PC since WD began reporting the Trojan Win32/Derbit.A. There has been no deterioration in gaming or browser performance and there has been no unwanted pop-ups or browser redirections. Am I potentially receiving
    false positives or am I dealing with a very sophisticated malware that can elude the removal attempts by WD? Any suggestions for next steps would be appreciated.
     
    warc1, Jun 26, 2016
    #3
  4. simrick Win User

    WD bogus notification: malware detected and cleaned

    Hi.
    I don't think Steam would cause that.
    I would run ADWCleaner just to be sure there's not something on the system that Defender is having trouble with. Please make sure all programs are closed as it will require a reboot if there is anything to "clean". If it does indeed find something, please post the log here for us to have a look. C:\AdwCleaner\AdwCleaner.txt
     
    simrick, Jun 26, 2016
    #4
  5. eLPuSHeR Win User
    I already ran AdwCleaner. Nothing found.

    Could it be that the notification system itself is wonky? Sometimes I get the "ding" sound from notification area but nothing is found there. I mean, sometimes Windows10 makes that sound without reason.

    But then again, the message "malware found and being cleaned" was clearly there in this case.
     
    eLPuSHeR, Jun 27, 2016
    #5
  6. simrick Win User
    Good!
    I've had that happen a couple of times myself. Not sure what it was all about either - no notifications anywhere.
    That is suspicious indeed. Have a look here and see if there's anything (this is supposed to be where Defender puts the quarantine):
    Code: C:\ProgramData\Microsoft\Windows Defender\LocalCopy[/quote]
     
    simrick, Jun 27, 2016
    #6
  7. Slartybart, Jun 27, 2016
    #7
  8. eLPuSHeR Win User

    WD bogus notification: malware detected and cleaned

    @Simrick

    The folder C:\ProgramData\Microsoft\Windows Defender\LocalCopy is empty.

    @Slartybart

    OK. I got it. WD mistakenly flagged ZHPCleaner as a trojan.

    It's a false positive. I think it's because most AV software tends to mistakenly flag all AutoIT software as trojan. It must be some heuristics issue.

    Marking thread as solved now.

    I really appreciate your help.

    Best regards.
     
    eLPuSHeR, Jun 27, 2016
    #8
  9. simrick Win User
    Sounds good. Glad you figured it out! *Smile
     
    simrick, Jun 27, 2016
    #9
  10. eLPuSHeR Win User
    To sum it up, I must say that those Powershell commands pointed me in the right direction.
     
    eLPuSHeR, Apr 5, 2018
    #10
Thema:

WD bogus notification: malware detected and cleaned

Loading...
  1. WD bogus notification: malware detected and cleaned - Similar Threads - bogus notification malware

  2. False malware detection

    in AntiVirus, Firewalls and System Security
    False malware detection: Good evening,My Windows 10 keeps identifying a perfectly legitimate program, Praat, as malware. Praat has been used by linguists and others that desire sonograms of human speech for decades. It is some of the best software available on any platform for acoustic analysis...
  3. False malware detection

    in Windows 10 Gaming
    False malware detection: Good evening,My Windows 10 keeps identifying a perfectly legitimate program, Praat, as malware. Praat has been used by linguists and others that desire sonograms of human speech for decades. It is some of the best software available on any platform for acoustic analysis...
  4. False malware detection

    in Windows 10 Software and Apps
    False malware detection: Good evening,My Windows 10 keeps identifying a perfectly legitimate program, Praat, as malware. Praat has been used by linguists and others that desire sonograms of human speech for decades. It is some of the best software available on any platform for acoustic analysis...
  5. Defender detected malware

    in AntiVirus, Firewalls and System Security
    Defender detected malware: Hi,in my environment the file 7zG.exe got deployed automatically to 100+ devices not manually or not from SCCM- not sure how it got deployed the defender has detected malware in it due to this, we have received 100+ alert generated for the same and still continuing.does this...
  6. Detection of Bogus Windows 10

    in Windows 10 Updates and Activation
    Detection of Bogus Windows 10: There are lots of tools offered by the internet where people can get bogus installer for Windows 10. https://answers.microsoft.com/en-us/windows/forum/all/detection-of-bogus-windows-10/8a6cf0f8-db33-4eb4-8f59-10564978920f
  7. WD Blue 10EZEX not detected in EUFI

    in Windows 10 Drivers and Hardware
    WD Blue 10EZEX not detected in EUFI: So I was trying to boot my PC through bootable USB and the UEFI says hard drive not detected. I don't hear any sound from hard drivePS i have new SATA cables and I'm using the same hard drive WD Blue 10EZEX I was using in a different case which used to be working fine...I...
  8. Windows Notification Malware Help

    in AntiVirus, Firewalls and System Security
    Windows Notification Malware Help: Hi everyone. The other day I was trying to download some PNGs of the windows mouse/pointer to use on a work graphic project. I (perhaps stupidly) downloaded them from a random website called pngio.com. Screenshot image attached. Since downloading them I keep getting these...
  9. Windows Notification Malware Help

    in Windows 10 Support
    Windows Notification Malware Help: Hi everyone. The other day I was trying to download some PNGs of the windows mouse/pointer to use on a work graphic project. I (perhaps stupidly) downloaded them from a random website called pngio.com. Screenshot image attached. Since downloading them I keep getting these...
  10. WD notification icon + WD User Interface ?

    in AntiVirus, Firewalls and System Security
    WD notification icon + WD User Interface ?: I am using Windows Defender. In task manager, I see both of these processes running. the two of them are also in startup. Is this normal? can and should I disable one of them in startup? 62204