loft

WD

11 posts in this topic

"note this is a conversation from another thread so to not hijack it"

okay so to try and re-create this problem happening, I have to exempt your program, now apparently I did it wrong. Hooray for me not looking up stuff and relying on Windows to tell me correct information.

 

Never exempted anything before and I went to the quarantined items, and hit restore. Apparently a very stupid idea. Now, as you can see from the picture

mshelp.PNG

 

it makes absolutely no mention whatsoever that it completely removes said item from any further Windows defender detection.  i had to look up that information myself after the program was not being registered as a threat. Yay

 

it just says it may continue to run after not being quarantined.

 

Go Microsoft for not tell me all the information I need to know, Would have did things a lot different if I had known that key bit of information

 

But whenever I go to the allowed list, so Windows defender protects against this program again. so I can try and re-create the problem I was having with your program.

mshelp1.PNG

It's not listed in the allowed programs list. In fact, no program is listed as being exempt.

 

So does this mean that blade and soul buddy is exempt from being seen by Windows defender?, or does it mean that Clavior.G!cl is exempt?.

 

Most importantly, where the hell do I go to get Windows defender to see this as a threat again. Especially if the real Clavior.G!cl is exempt from Windows defender. So I can try and re-create this problem.

frustrated with Windows 10 and Microsoft for not telling me key information

 

I know, this is not your problem, but I'm trying to get to where I can re-create what was happening with your program. And no, usually I'm not this stupid with computers, but this week has been something else.

 

would go to Microsoft's webpage for support. With this program and not bother you. But I don't know if it would be a wise idea to have my problem with your exe. splattered all over Microsoft support site

Edited by loft
0

Share this post


Link to post
Share on other sites

Is your av definition updated?

Mine is latest and does not detect BnS Buddy as a malware.

I even checked their support site. 

 

Fv1f7C.jpg

IU2x7p.jpg

 

 my conclusions would be that your pc has been infected. And the virus is binded to your most used .exe's, i have no other explanation.

0

Share this post


Link to post
Share on other sites

OK, just so that I can confirm this guy isn't going crazy, i'm getting this error on 3 PC's, seperated by different networks(2 on 1, another at another location)

 

As soon as i download BnSBuddy, Defender intercepts the download and it fails due to virus detected. It does appear in Windows Defender.

 

Although i am sure that the fault lies in Windows Defender, and not BnSBuddy, just thought i'd let you know, 100% reproduceable.

 

BTW, am running Windows 10 Pro(Insider Preview latest release) on my main rig. The other two(which also detect) are on the main release.

 

Done more testing, AV only positive on Windows Defender, Symantec(yuck!!) comes up clean.

 

Windows 10 Pro (insider preview) Windows Defender - Positive

Windows 10 Pro (latest release) Windows Defender - positive

Windows 7 Pro (latest updates) Windows Defender - positive

Windows 7 Pro (latest updates) Symantec Endpoint protection - No Virus found

Edited by kaigame
1

Share this post


Link to post
Share on other sites

Everyone, go on update tab of Windows Defender and update it.
Restart and scan again.

I'm on win10 enterprise
I'm still not having any issues.

Here, 
Windows Defender: Clean

BitDefender total security 2017: Clean

Iobit Malware fighter 4(beta): Clean

Malwarebytes: Clean

Edited by xEndless
0

Share this post


Link to post
Share on other sites
57 minutes ago, xEndless said:

Everyone, go on update tab of Windows Defender and update it.
Restart and scan again.

I'm on win10 enterprise
I'm still not having any issues.

Here, 
Windows Defender: Clean

BitDefender total security 2017: Clean

Iobit Malware fighter 4(beta): Clean

Malwarebytes: Clean

 

Updated, still can't download BnSBuddy, are your definitions showing the same as mine?

defender.jpg

0

Share this post


Link to post
Share on other sites
3 minutes ago, kaigame said:

 

Updated, still can't download BnSBuddy, are your definitions showing the same as mine?

 


Literally same.

xjBR07.jpg

Edited by xEndless
0

Share this post


Link to post
Share on other sites
5 minutes ago, xEndless said:

This is weird, again i don't think there is a virus here, but doesn't explain why the results are different.

 

Scanned using virustotal:

https://www.virustotal.com/en/file/47a0a3ec762c287eecc1433aa4f8e82c6ae3d761b7c6f89cb8722e431062335b/analysis/1487351796/

No Virus found

Edited by kaigame
1

Share this post


Link to post
Share on other sites

OK, something else strange, 

 

The BnSBuddy i have already on my system isn't detected as having a virus, but a new download is? I'm starting to get worried

 

To expand on that statement, the version i did the online check on was from a fresh download(with local AV disabled).

Edited by kaigame
0

Share this post


Link to post
Share on other sites
22 minutes ago, kaigame said:

OK, something else strange, 

 

The BnSBuddy i have already on my system isn't detected as having a virus, but a new download is? I'm starting to get worried

 

To expand on that statement, the version i did the online check on was from a fresh download(with local AV disabled).


I freshly downloaded the files to scan and local ones

nothing detected..

0

Share this post


Link to post
Share on other sites

Restoring a file from the Quarantine automatically registers a temporary path exclusion (in a "TemporaryPaths" registry key that’s invisible to the MSE interface). The restored file will no longer be monitored by MSE; and since MSE’s automatic exclusion for the restored file doesn’t show up in the “Excluded files and locations” settings or in the “Allowed items” list, there’s no easy way to immediately re-enable detection for the file – but when the automatic exclusion expires (after a couple of days), the ability to detect the file will be re-enabled, and running a Full Scan will return the file to the Quarantine.

 

 

Love how Microsoft leaves out important information, as it literally takes so much extra text space.

 

"This will also add a temporary allowance that Windows defender will not scan against this item, which will only last a couple days"

 

I mean hell, there's no room for that on the tooltip at all is there. Oh wait, there's plenty of room for this text on the restore tooltip. Lazy Microsoft

 

Key information there for someone that doesn't already know this. but hey, not enough worth writing about in Microsoft eyes. Nop I have spent the better part of a day trying to find information pertaining to this.

 

Just to learn, what takes up literally less than a freaking line of text.

 

Yes it's only useful information, used for rare occasions, but still.

 

Anyhow, later today. I will see if I can try and re-create what happened. With me using the normal client and your updater starting.

 

I've had Windows 10 drop drivers in the past. Reformatted and haven't had that problem since then.

 

but if your program works fine for everybody else and I'm the only person, that had this problem. I'm starting to think one of my antivirus programs during the night, At some point in time. Falsely identified some system file and just automatically deleted it. and i Wake up, see Windows defender found something, and took care of it. and thought to myself, oh that's nice. I went on with my day. Or Windows 10 is just not shutting some programs down whenever I tell it to, even though it didn't show up on any programs running list. Or some stupid system behavior like that.

if the program works, the way it works. There's something going on at my end

Thanks for the help

0

Share this post


Link to post
Share on other sites

I'm sorry for not being able to help you further than that :(
The tool is signed as a fulltrust application and does not allow any unsafe code...

So i'm pretty confused too..I hope it get's sorted on your end any time soon :/

Have a good day!

0

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!


Register a new account

Sign in

Already have an account? Sign in here.


Sign In Now

  • Recently Browsing   0 members

    No registered users viewing this page.