Skip to content

Trojan found in duelit update?

Forums Members Area Help Trojan found in duelit update?

  • Creator
    Topic
  • #47498
    KratosChestKratosChest
    Participant

    Hey

    When duelit did an autoupdate,  Windows Defender did pup up. Defender blocks duelit now and I don’t want to change anythining witthin Windos Defender.  

    Duelit was deleted from my PC and if I download it from the forum, I cant open it.

    I’ve checked  the downloaded duelit.rar with windows defender. Screenshot is in the attachment.

    Thank you

Viewing 10 replies - 1 through 10 (of 10 total)
  • Author
    Replies
  • #50340
    Duelit Forum BotDuelit Forum Bot
    Participant

    Hello KratosChest,

    Thank you for your request, we will try to solve your problem as soon as possible.

    In the meantime, please check out the tutorials section, nearly all common issues are answered there.
    When your problem still remains, try using the search function to make sure that a similar request wasn’t answered in another thread already.

    Keep in mind that we can only give support when you added screenshots (of NOX + Duelit) to your thread.

    This is an automated message, your request will be processed shortly.

    #50341
    GoofGoof
    Participant

    You’ll have to add duelit as an exception to your antivirus program, procedure varies between antivirus programs.

    #50342
    steilzsteilz
    Administrator

    Hello,

    This is a common issue with autoit scripts.
    Duelit connects to the Duelit server, autoupdates, writes files etc., some firewalls/antivirus are giving out false-positives. This has been like that since the beginning.

    Unfortunately in order to prevent that, we’d have to send every single Duelit update to every single security company in order to get checked and to prevent false-positives.
    This takes days and even weeks and since i am updating Duelit sometimes multiple times a day – impossible.

    You have to allow the .exe (in case of autoupdating maybe the whole folder) in your firewall / antivirus.

    #50343
    KratosChestKratosChest
    Participant

    So, I can ignore the Win32/Fuerboos.C!cl ? It isn’t dangerous or something? ’cause defender tells me it is an serious trojan

    #50344
    steilzsteilz
    Administrator

    It’s a false positive, which means that it’s being detected as something which it isn’t. Most likely after the next Windows Defender update it won’t be detected anymore, or maybe even as something else.

    #50345
    KratosChestKratosChest
    Participant
    steilz wrote:
    It’s a false positive, which means that it’s being detected as something which it isn’t. Most likely after the next Windows Defender update it won’t be detected anymore, or maybe even as something else.

    allright.                     Thanks for the help

    #50346
    steilzsteilz
    Administrator

    Uploading it to VirusTotal shows you that only 2 out of 66 engines detect it as a “malicious software”

    https://www.virustotal.com/#/file/ac3ca74ab449edccfdd99ae50c65f26071b3583f3517252a976dd94f43705bae/detection

    #50347
    KratosChestKratosChest
    Participant
    #50348
    steilzsteilz
    Administrator

    Yea, as you can see, Windows Defener might not be a reliable source ;)

    #50349
    GoofGoof
    Participant

    Windows Deafener, deafens the unsuspecting PC user with false positive notifications and HDD thrashing….

Viewing 10 replies - 1 through 10 (of 10 total)
  • You must be logged in to reply to this topic.