BitDefender False Positive Nukes Office 2013

The Bitdefender logo: a white letter B on a red rounded square.

12/15/2015 a False Positive with the new Ransomware Vaccine nuked Office 2013 version 15.0.4875.1001, rendering it inoperable without a full online repair. The victim is the file below:

c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\office15\1033\msointl.dll

 

The signature that fired was Generic.Ransom.HiddenTear for the paticular DLL. File was last changed 9/20/2016 as installed, and was at version 15.0.4869.1000 which didn’t seem to have moved for a few months.

If you were unlucky enough to have that product combination, you may have had an issue. It’s always good to white list these locations, and check the Quarantine if you suspect an accidental infection. In this case, the configured events on the system did not notify of Malware Outbreak, even with the threshold ticked to 1%.

Share your thoughts, leave a comment

Your email address will not be published. Required fields are marked *

You may also like these

INFOSTRUCTION

You're about to become an infostruction VIP!

By subscribing, you’ll receive a monthly round-up of the latest news. There’ll be no spam, I promise :)