Solved HELP!! 911--Windows Defender False Positive? Free Diagnostic Software Detected as Infected


Well Then LockHunter Stops Responding when i hit Delete it with Tamper Protection off and Controlled Folder Access was already off

((this is in my Extra OneDrive Download folder copy on My 4TB Storage drive))

OneDrive copy successfully deleted earlier



If nothing else works... you can use Autoruns to "stop" Defender from running.
Then delete the zip file then use Autoruns to start Defender again.

Set the "Options" like this...
Image1.png



UN-check the two items in the biggest RED box, and reboot.
Delete the zip file. Re-check those two boxes again and reboot again.

Image1.png
 
Last edited:

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦22631.3527 ♦♦♦♦♦♦♦23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 4702)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Internet Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Mouse
    Logitech Optical M-BT96a
    Keyboard
    Logitech Classic Keybooard 200
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 13 years?
What does Protection history show when you expand it?

1705015226408.png
 

My Computers

System One System Two

  • OS
    Win 11 Pro & 🐥.
    Computer type
    Laptop
    Manufacturer/Model
    ASUS VivoBook
    CPU
    AMD Ryzen 7 3700U with Radeon Vega Mobile Gfx
    Motherboard
    ASUSTeK COMPUTER INC. X509DA (FP5)
    Memory
    12GB
    Graphics Card(s)
    RX Vega 10 Graphics
    Monitor(s) Displays
    Generic PnP Monitor (1920x1080@60Hz)
    Screen Resolution
    1920x1080@60Hz
    Hard Drives
    Samsung SSD 970 EVO Plus 2TB NVMe 1.3
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
  • Operating System
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    ACER NITRO
    CPU
    AMD Ryzen 7 5800H / 3.2 GHz
    Motherboard
    CZ Scala_CAS (FP6)
    Memory
    32 GB DDR4 SDRAM 3200 MHz
    Graphics card(s)
    NVIDIA GeForce RTX 3060 6 GB GDDR6 SDRAM
    Sound Card
    Realtek Audio. NVIDIA High Definition Audio
    Monitor(s) Displays
    15.6" LED backlight 1920 x 1080 (Full HD) 144 Hz
    Screen Resolution
    1920 x 1080 (Full HD)
    Hard Drives
    Samsung 970 Evo Plus 2TB NVMe M.2
    PSU
    180 Watt, 19.5 V
    Mouse
    Lenovo Bluetooth
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
I've not used OneDrive in many years and wondered if it has something to do with it. Has it already synced and is already in the cloud backup? Worth logging in to your OneDrive account online to see if it's there and delete it there. Just guesswork though.
 

My Computers

System One System Two

  • OS
    Win 11 Pro & 🐥.
    Computer type
    Laptop
    Manufacturer/Model
    ASUS VivoBook
    CPU
    AMD Ryzen 7 3700U with Radeon Vega Mobile Gfx
    Motherboard
    ASUSTeK COMPUTER INC. X509DA (FP5)
    Memory
    12GB
    Graphics Card(s)
    RX Vega 10 Graphics
    Monitor(s) Displays
    Generic PnP Monitor (1920x1080@60Hz)
    Screen Resolution
    1920x1080@60Hz
    Hard Drives
    Samsung SSD 970 EVO Plus 2TB NVMe 1.3
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
  • Operating System
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    ACER NITRO
    CPU
    AMD Ryzen 7 5800H / 3.2 GHz
    Motherboard
    CZ Scala_CAS (FP6)
    Memory
    32 GB DDR4 SDRAM 3200 MHz
    Graphics card(s)
    NVIDIA GeForce RTX 3060 6 GB GDDR6 SDRAM
    Sound Card
    Realtek Audio. NVIDIA High Definition Audio
    Monitor(s) Displays
    15.6" LED backlight 1920 x 1080 (Full HD) 144 Hz
    Screen Resolution
    1920 x 1080 (Full HD)
    Hard Drives
    Samsung 970 Evo Plus 2TB NVMe M.2
    PSU
    180 Watt, 19.5 V
    Mouse
    Lenovo Bluetooth
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
Gone in OneDrive just checked Online there

Might end up having to use AutoRuns Option, and hopefully it deletes then, and system is all good lol

When i have issues, i really have issues sadly

Attachment is what Defender says in Protection History, been like this since 1:30PM Lol

Tried Remove (no luck)
Tried Quaratine seemed to do nothing

((don't wanna hit Allow on Device, but thought about it if would clear Defender lock on the said Zipped Files))

**Then i gotta check all the externals to make sure dummy me didn't save another copy**

**Extra Download Copy Folder was on local drive as i just finished a system recovery with Macrium reflect not long ago to fix Bluetooth issue**
 

Attachments

  • HELP Problem.png
    HELP Problem.png
    24.4 KB · Views: 1

My Computer

System One

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel I7 10700
    Motherboard
    Gigabyte B460M_DS3H Rev 1.0
    Memory
    32GB DDR4 2666mhz
    Graphics Card(s)
    EVGA Geforce 1660 Super
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    M.2 Samsung 970 Evo Plus 500GB Boot
    Samsung 860 Evo 1TB-Game SSD
    Western Digital Black 4TB Storage Drive

    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Western Digital My Book 8TB (Primary Backup drive)
    PSU
    EVGA G3 650 Watt
    Case
    Thermaltake V200 TG RGB
    Cooling
    Arctic Freezer 7X, 3 Front Intake Fans, 1 120 Exhaust in rear of case
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1000Mb/20 Upload
    Browser
    MS Edge Chromium
    Antivirus
    Windows Defender, Malwarebytes Free
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium 8 Home Edition
Gone in OneDrive just checked Online there

Might end up having to use AutoRuns Option, and hopefully it deletes then, and system is all good lol

When i have issues, i really have issues sadly

Attachment is what Defender says in Protection History, been like this since 1:30PM Lol

Tried Remove (no luck)
Tried Quaratine seemed to do nothing

((don't wanna hit Allow on Device, but thought about it if would clear Defender lock on the said Zipped Files))

**Then i gotta check all the externals to make sure dummy me didn't save another copy**

**Extra Download Copy Folder was on local drive as i just finished a system recovery with Macrium reflect not long ago to fix Bluetooth issue**

Wait... did you try deleting it from your 'downloads' folder ?
 

My Computer

System One

  • OS
    Windows 11 Intel i5 10400 HD630 graphics chip
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP
    CPU
    i5-10400
    Memory
    12 gb
    Graphics Card(s)
    HD630 chipset
    Monitor(s) Displays
    LG 24inch
    Hard Drives
    SSD, external usb drive 1tb for files/backups
    Keyboard
    wireless Logi
    Mouse
    ms 4000 wireless mouse
    Internet Speed
    10meg
    Browser
    Firefox
    Antivirus
    Defender
    Other Info
    Win11 Home 23H2 22631.3527 04/23/24
Yes i did, that is the folder that won't remove lol---once that is gone, things should be fine i hope
 

My Computer

System One

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel I7 10700
    Motherboard
    Gigabyte B460M_DS3H Rev 1.0
    Memory
    32GB DDR4 2666mhz
    Graphics Card(s)
    EVGA Geforce 1660 Super
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    M.2 Samsung 970 Evo Plus 500GB Boot
    Samsung 860 Evo 1TB-Game SSD
    Western Digital Black 4TB Storage Drive

    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Western Digital My Book 8TB (Primary Backup drive)
    PSU
    EVGA G3 650 Watt
    Case
    Thermaltake V200 TG RGB
    Cooling
    Arctic Freezer 7X, 3 Front Intake Fans, 1 120 Exhaust in rear of case
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1000Mb/20 Upload
    Browser
    MS Edge Chromium
    Antivirus
    Windows Defender, Malwarebytes Free
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium 8 Home Edition
Boot from windows installation media, troubleshoot > Cmd and then delete it via command. Then boot back to os
 

My Computer

System One

  • OS
    Windows 11 Pro
@dacrone
Will give that a shot in just a few minutes then, only thing i haven't tried yet

Tried safe Mode-didn't work
Tried from System Local Admin Account--No dice
Tried with LockHunter 3 times

Definitely not downloading anything i don't need anymore, definitely lesson learned for sure this time lol, plus just got Secondlife Game working perfect again and of course this happens

Extreme measure if all else fails i'll replace the entire 4TB storage drive lol, except not close to my birthday yet lol, so no card with funds available to purchase yet. Honestly the 4tB drive was originally suppose to be Backup drive, and would've kept my 1TB WD Black Internal inside desktop lol. ((I tend to download alot of junk with the available space to store it on with this 4TB lol))
 

My Computer

System One

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel I7 10700
    Motherboard
    Gigabyte B460M_DS3H Rev 1.0
    Memory
    32GB DDR4 2666mhz
    Graphics Card(s)
    EVGA Geforce 1660 Super
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    M.2 Samsung 970 Evo Plus 500GB Boot
    Samsung 860 Evo 1TB-Game SSD
    Western Digital Black 4TB Storage Drive

    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Western Digital My Book 8TB (Primary Backup drive)
    PSU
    EVGA G3 650 Watt
    Case
    Thermaltake V200 TG RGB
    Cooling
    Arctic Freezer 7X, 3 Front Intake Fans, 1 120 Exhaust in rear of case
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1000Mb/20 Upload
    Browser
    MS Edge Chromium
    Antivirus
    Windows Defender, Malwarebytes Free
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium 8 Home Edition
When running Cmd from boot media, the os is dormant. The ways you tried were from inside the os
 

My Computer

System One

  • OS
    Windows 11 Pro
Ok will give that a shot asap here then
 

My Computer

System One

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel I7 10700
    Motherboard
    Gigabyte B460M_DS3H Rev 1.0
    Memory
    32GB DDR4 2666mhz
    Graphics Card(s)
    EVGA Geforce 1660 Super
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    M.2 Samsung 970 Evo Plus 500GB Boot
    Samsung 860 Evo 1TB-Game SSD
    Western Digital Black 4TB Storage Drive

    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Western Digital My Book 8TB (Primary Backup drive)
    PSU
    EVGA G3 650 Watt
    Case
    Thermaltake V200 TG RGB
    Cooling
    Arctic Freezer 7X, 3 Front Intake Fans, 1 120 Exhaust in rear of case
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1000Mb/20 Upload
    Browser
    MS Edge Chromium
    Antivirus
    Windows Defender, Malwarebytes Free
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium 8 Home Edition
Update: File Finally Gone! used Cmd Force Delete file command

I assume Defenders Protection history will clear itself at some point correct?
 

My Computer

System One

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel I7 10700
    Motherboard
    Gigabyte B460M_DS3H Rev 1.0
    Memory
    32GB DDR4 2666mhz
    Graphics Card(s)
    EVGA Geforce 1660 Super
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    M.2 Samsung 970 Evo Plus 500GB Boot
    Samsung 860 Evo 1TB-Game SSD
    Western Digital Black 4TB Storage Drive

    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Western Digital My Book 8TB (Primary Backup drive)
    PSU
    EVGA G3 650 Watt
    Case
    Thermaltake V200 TG RGB
    Cooling
    Arctic Freezer 7X, 3 Front Intake Fans, 1 120 Exhaust in rear of case
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1000Mb/20 Upload
    Browser
    MS Edge Chromium
    Antivirus
    Windows Defender, Malwarebytes Free
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium 8 Home Edition
If not I’m sure there’s a way with the registry somehow somewhere
 

My Computer

System One

  • OS
    Windows 11 Pro
Update: File Finally Gone! used Cmd Force Delete file command

I assume Defenders Protection history will clear itself at some point correct?
Run a Manual Scan in Defender ?
 

My Computer

System One

  • OS
    Windows 11 Intel i5 10400 HD630 graphics chip
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP
    CPU
    i5-10400
    Memory
    12 gb
    Graphics Card(s)
    HD630 chipset
    Monitor(s) Displays
    LG 24inch
    Hard Drives
    SSD, external usb drive 1tb for files/backups
    Keyboard
    wireless Logi
    Mouse
    ms 4000 wireless mouse
    Internet Speed
    10meg
    Browser
    Firefox
    Antivirus
    Defender
    Other Info
    Win11 Home 23H2 22631.3527 04/23/24
Doing that now conducting Manual Full Scan, and should be all clear after that hopefully.

Been quite an afternoon flew lol, and still have to check the external drives to make sure no other copys of that zipped folder, but may do that tomorrow
 

My Computer

System One

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel I7 10700
    Motherboard
    Gigabyte B460M_DS3H Rev 1.0
    Memory
    32GB DDR4 2666mhz
    Graphics Card(s)
    EVGA Geforce 1660 Super
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    M.2 Samsung 970 Evo Plus 500GB Boot
    Samsung 860 Evo 1TB-Game SSD
    Western Digital Black 4TB Storage Drive

    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Western Digital My Book 8TB (Primary Backup drive)
    PSU
    EVGA G3 650 Watt
    Case
    Thermaltake V200 TG RGB
    Cooling
    Arctic Freezer 7X, 3 Front Intake Fans, 1 120 Exhaust in rear of case
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1000Mb/20 Upload
    Browser
    MS Edge Chromium
    Antivirus
    Windows Defender, Malwarebytes Free
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium 8 Home Edition
Thank you everyone for the help and suggestions in the matter, Protection History list still shows a huge list, but a New Scan showed No New Threats ((so guess maybe tomorrow Protection History will autoly clear hopefully--Guess i'll find out in coming days lol.

Deleted File Immediately off Gaming Laptop that im using now while i finish a few more scans on PC 1 just to be sure its really clean lol, though i didn't extract the above mentioned zip file at all, so really shouldn't be really infected i don't think, but just in case conducting Malwarebytes Full scan just to be safe

No downloading anything i don't need anymore

**Defender History now cleared with Help of Safe Mode and Accessing Scans, Service Folder then History--deleting all in there cleared the entire list, as some of the items in the history folder showed Redemption incomplete, googled that error, and solved it myself lol. Conducting 1 more full scan, and then gonna do a Malwarebytes scan!! then gonna relax after that lol.

Tomorrow i'll check the externals lol

Lessons Learned Today
1. Don't Download anything and everything just cause have the space
2. Don't store just anything on Onedrive file storage area
3. Only use good utilities, and not some off the wall utilities
4. Make sure System Image backups are up to date--updating that tomorrow, might delete old one with that file inside it lol as well
5. Very very Appreciative of all the Great Online Support!!
 
Last edited:

My Computer

System One

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel I7 10700
    Motherboard
    Gigabyte B460M_DS3H Rev 1.0
    Memory
    32GB DDR4 2666mhz
    Graphics Card(s)
    EVGA Geforce 1660 Super
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    M.2 Samsung 970 Evo Plus 500GB Boot
    Samsung 860 Evo 1TB-Game SSD
    Western Digital Black 4TB Storage Drive

    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Western Digital My Book 8TB (Primary Backup drive)
    PSU
    EVGA G3 650 Watt
    Case
    Thermaltake V200 TG RGB
    Cooling
    Arctic Freezer 7X, 3 Front Intake Fans, 1 120 Exhaust in rear of case
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1000Mb/20 Upload
    Browser
    MS Edge Chromium
    Antivirus
    Windows Defender, Malwarebytes Free
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium 8 Home Edition
4. Make sure System Image backups are up to date--updating that tomorrow, might delete old one with that file inside it lol as well
Are you absolutely sure that program hasn’t done anything suspect. If you backup your system now, you take whatever it may of done with you. Do you have an image pre downloading and running the file? Or is that what you mean when you say
might delete old one with that file inside it lol as well
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build: 22631.3374
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    4 x LG 23MP75 1 x 24" LG M38H 1 x 32" LF6300 TV Monitor 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    2 x WD something Something 8TB HDD's / 2 x WD something Something 4TB HDD's / 1 x EVO 1TB SSD / 2 x QVO 1TB SSD's / 1 x EVO 250 GB SSD / 2 x QVO 1TB (External Hub) / 1 x EVO 1TB (Portable Backup Case)
    PSU
    Silverstone 1500
    Case
    NZXT Full Tower
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    100/40Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 22621.2215
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Graphics processor is an Intel Iris Xe
    Sound Card
    optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Other Info
    …still on a horse.
Well i never extracted that Zip file at all, it was just sitting in OneDrive downloads folder, and also In Backup Copy of OneDrive Downloads on my 4TB Storage drive

Sadly i don't have an image pre downloading the file, wish i did, but drive only has so much space to backup 3 Systems, so it tends to not have Images too far back.

Backup drive is WD My Book 8TB

Systems backed up are
Main Desktop with M.2 Drive
Game SSD and 4TB storage drive

PC 2, Gaming Laptop
M.2 128GB Boot drive, and 1TB storage drive

PC 3, 1TB Sata SSD Boot drive

Are typically backed up monthly onto that drive

I'll do another scan with Malwarebytes (Full scan) soon as can here and make sure clean, and nothing wrong before i do another System Image.

Defender full scan and offline scan now show clean

Started Defender Scan at 12:30 for my weekly full scan, and it then detected that file as infected for the first time, file was on here since 12/4/2023

i'm sure the last backup image has the file in that backup

**If i do find anything wrong, then probably will do a complete clean install i suppose, not that really want to, but if its for the best if find anymore infected files, i swear i never extracted that 21GB Toolkit at all**
 
Last edited:

My Computer

System One

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel I7 10700
    Motherboard
    Gigabyte B460M_DS3H Rev 1.0
    Memory
    32GB DDR4 2666mhz
    Graphics Card(s)
    EVGA Geforce 1660 Super
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    M.2 Samsung 970 Evo Plus 500GB Boot
    Samsung 860 Evo 1TB-Game SSD
    Western Digital Black 4TB Storage Drive

    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Western Digital My Book 8TB (Primary Backup drive)
    PSU
    EVGA G3 650 Watt
    Case
    Thermaltake V200 TG RGB
    Cooling
    Arctic Freezer 7X, 3 Front Intake Fans, 1 120 Exhaust in rear of case
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1000Mb/20 Upload
    Browser
    MS Edge Chromium
    Antivirus
    Windows Defender, Malwarebytes Free
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium 8 Home Edition
@bikeman17



Unzipped it's 26GB... 5x bigger than Windows 11.
Inside the zip file... there's 502 password protected files.
64 files Bitdefender can't scan, and labeled threats.

It may be safe and someone is just serious about keeping their secrets safe.
To me though... it looks like a LOT of cracked software.


I could delete it completely.


For example... it had every backup software I've ever heard of. It had just about every software I've ever heard of that would help someone work on a computer.
Yes this sounds like some seriously BAD software
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2 (RP channel)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte
    CPU
    AMD Ryzen 5900X 12-core
    Motherboard
    X570 Aorus Xtreme
    Memory
    64GB Corsair Platinum RGB 3600MHz CL16
    Graphics Card(s)
    MSI Suprim X 3080 Ti
    Sound Card
    Soundblaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming VG289Q
    Screen Resolution
    3840x2160
    Hard Drives
    Samsung 990 Pro 2TB
    Samsung 980 Pro 2TB
    Samsung 970 Evo Plus 1TB
    Samsung 870 Evo 4TB
    Samsung T7 Touch 1TB
    PSU
    Asus ROG Strix 1000W
    Case
    Corsair D750 Airflow
    Cooling
    Noctua NH-D15S
    Keyboard
    Asus ROG Flare
    Mouse
    Logitech G903 with PowerPlay charger
    Internet Speed
    500Mb/sec
    Browser
    Microsoft Edge
    Antivirus
    Windows Defender
Is it best I just do a clean install anyways tomorrow? And just restore Music from external and Documents folder with game profiles.

Or if I run Malwarebytes scan soon and it's clean..then I should be good right?
 

My Computer

System One

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel I7 10700
    Motherboard
    Gigabyte B460M_DS3H Rev 1.0
    Memory
    32GB DDR4 2666mhz
    Graphics Card(s)
    EVGA Geforce 1660 Super
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    M.2 Samsung 970 Evo Plus 500GB Boot
    Samsung 860 Evo 1TB-Game SSD
    Western Digital Black 4TB Storage Drive

    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Western Digital My Book 8TB (Primary Backup drive)
    PSU
    EVGA G3 650 Watt
    Case
    Thermaltake V200 TG RGB
    Cooling
    Arctic Freezer 7X, 3 Front Intake Fans, 1 120 Exhaust in rear of case
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1000Mb/20 Upload
    Browser
    MS Edge Chromium
    Antivirus
    Windows Defender, Malwarebytes Free
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium 8 Home Edition
Yes this sounds like some seriously BAD software



I don't "know" whether it's good or bad.
But because I can't tell for sure... I would give it a pass.

As I said, Bitdefender found 502 passworded files, and it quarantined 64 items.
And... it seems that on your computer, Windows Defender didn't like it either.
WD didn't like it so much, it wouldn't let it go to be deleted.

For me... that's just more trouble than it's worth.



I've probably said it 1000 times.
The secret to NOT having software problems is... backup software.

Like tonight. I personally, didn't like that Medicat software. But I had a look at it and then deleted it.
But "because" it had 502 passworded files and 64 quarantined items... even after I deleted it...
I restored from a backup, too. Just to be on the safe side.

THAT is why I don't have software problems. If I don't "know" for sure... I restore from a "full" backup.



On purpose, I only have about 35GB on my C:\ drive. That way, my "full" backups and restores only take about 2 minutes each. And because of that... I can use my backups as a tool, like I did tonight.

I don't play around with backup software... I'm very serious about it... These are all "full" backups...

Image1.png



There's really only two ways to keep your software running well and un-infected.
Backups or clean installs.
 
Last edited:

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦22631.3527 ♦♦♦♦♦♦♦23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 4702)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Internet Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Mouse
    Logitech Optical M-BT96a
    Keyboard
    Logitech Classic Keybooard 200
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 13 years?

Latest Support Threads

Back
Top Bottom