rcedit icon indicating copy to clipboard operation
rcedit copied to clipboard

Bitdefender is says that rcedit.exe is a virus

Open mcannon77 opened this issue 7 years ago • 5 comments

The message I get from Bitdefender is "Hyper Detect has detected a threat. There was no action taken on the file. ...\AppData\Roaming\npm\node_modules\electron-packager\node_modules\rcedit\bin\rcedit.exe is malware of type Gen:Illusion.ML.Miata.C.2.17.3010101. To take an action on the threat, please contact your system administrator.

Any clue as to why this is registering as such? I'm not particularly trusting Bitdefender's finding, however this is software my company just recently installed and now I'm encountering this issue.

Also another source: https://www.isthisfilesafe.com/sha1/7B566345D20980E117127013A4990251052EEB46_details.aspx

mcannon77 avatar May 14 '18 16:05 mcannon77

Considering the purpose of this project is to modify executables, I'm not surprised if it is flagged as malware by some anti virus softwares. The best way to fix this is to sign the executable, which I might do in future.

Currently if you are uncomfortable with the warning, I suggest building the project yourself.

zcbenz avatar May 15 '18 05:05 zcbenz

I'm not uncomfortable at all using it, I just think this may be a false positive.

mcannon77 avatar May 15 '18 20:05 mcannon77

I also got flagged by bit defender with an open source project I work on: https://github.com/DigitalRuby/IPBan, not sure of a way to contact them and let them know about this, any ideas?

jjxtra avatar May 26 '20 01:05 jjxtra

The 32-bit version is still falsely flagged as a virus by two AV providers, SecureAge APEX and eGambit.

  • rcedit-x64.exe: https://www.virustotal.com/gui/file/02e8e8c5d430d8b768980f517b62d7792d690982b9ba0f7e04163cbc1a6e7915/detection
  • rcedit-x86.exe: https://www.virustotal.com/gui/file/1733e4b7e532c99b6a4ddeca1b9fff7bb1c5fd0ba7dbeb5f3520b6da03a5284f/detection

I also got flagged by bit defender with an open source project I work on: https://github.com/DigitalRuby/IPBan, not sure of a way to contact them and let them know about this, any ideas?

You can submit false positives here: https://www.bitdefender.com/submit/

MarkTiedemann avatar Jul 01 '20 20:07 MarkTiedemann

Awesome, thanks for the link, I sent them a false-positive.

jjxtra avatar Jul 01 '20 20:07 jjxtra