Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Infected with Trojan.GenericKD.47061246 (?) #7

Closed
topfuel75 opened this issue Oct 28, 2023 · 3 comments
Closed

Infected with Trojan.GenericKD.47061246 (?) #7

topfuel75 opened this issue Oct 28, 2023 · 3 comments

Comments

@topfuel75
Copy link

If I try to download 'AbuseIPDB_Bulk_Checker.exe' Bitdefender automatically delete the file with the following message:
Feature: Antivirus
The file H:\Downloads\AbuseIPDB_Bulk_Checker.JjtXBI7O.exe.part is infected with Trojan.GenericKD.47061246 and was moved to quarantine.

If I download 'Source code (zip)' and test it at VirusTotal a lot of vendors flag it as malicious.
The report is at
https://www.virustotal.com/gui/file/840a800c675b7827929cd82db013d7596bba67acb29aec99ca1804db6ad38df5

Both of the downloads was made from https://github.com/AdmiralSYN-ACKbar/bulkcheck/releases/tag/1.0

@AdmiralSYN-ACKbar
Copy link
Owner

Hi Topfuel,

The EXE version is flagged as a "generic" Trojan because many antivirus engines flag all EXEs generated from PowerShell scripts using Powershell Pro Tools as malicious (regardless of if they actually are or not). You can read much more about the issue at (https://docs.poshtools.com/powershell-pro-tools-documentation/packaging/anti-virus).

I have removed the EXE from the link that you mentioned to avoid further confusion regarding this issue, as it has arisen before. The PS1 is now the only file being hosted - feel free to test that through VirusTotal to verify that it is malware-free. The next release should update the source code file that is hosted under the "Releases" page. Please let me know if you have any further questions on this.

@topfuel75
Copy link
Author

Thanks for the information.

Just to clarify, my post wasn't meant to be any critic. It was rather an observation and an informal notice.
I wasn't aware that a false positive trojan you linked to. It must be quite frustrating.

@AdmiralSYN-ACKbar
Copy link
Owner

Thanks topfuel, no worries! I'm glad you pointed this out, hopefully it will be resolved going forward.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants