HVec

updated

5 years ago

H

HVec

1 Rookie

2 Posts

2

11880

March 2nd, 2022 09:00

Dell Update triggers CryptoStealBTC warning with Microsoft Antimalware

Is this a known false positive? This reddit page seems to indicate the problem is widespread.

i cant remove or put in quarantine "trojan:html/cryptostealbtc" : antivirus (reddit.com)

 

  • Brad L (retired)

    11 Legend

    2650 Posts

    2977

    2

    Posted March 4th, 2022 13:00

    As pointed out above, here is an update on this.

    Per the link: A recent update to Windows Defender has caused it to incorrectly identify SupportAssist as malware. Dell is working closely with Microsoft to resolve this issue and correct the false positive.

    * User with SupportAssist auto updates enabled should not be impacted
    * User with SupportAssist auto updates disabled should update Microsoft Defender virus definitions to version 1.359.1239.0 or higher

     


    Brad L (retired)

  • bossfan5050

    1 Rookie

    17 Posts

    7250

    3

    Posted March 2nd, 2022 10:00

    I got the crytosteal warning also and that Reddit thread has become pretty active with people asking about it.  Anyone from Dell can you post here to let us know if this is a false positive?

  • IgorGS

    1 Message

    7182

    2

    Posted March 2nd, 2022 11:00

    I got the same warning too, don't know if its a false positive or an actual threat yet, would love some clarification

  • giovap

    4 Posts

    7094

    2

    Posted March 2nd, 2022 12:00

    I have just got it on Dell Xps 15 9510, my dell is 3 days old and I didn't have time to download anything.

    If you start a complete scan you can quarantine it...

  • AidanCodes

    1 Message

    6842

    2

    Posted March 2nd, 2022 12:00

    I have a 9510 as well, about a month old running Windows 11. Mine should be up to date, as I run updates as soon as I can. I just received this notification a few minutes ago.

  • bossfan5050

    1 Rookie

    17 Posts

    7114

    3

    Posted March 2nd, 2022 12:00

    Windows Defender is flagging this so this might be a Microsoft issue vs. a Dell issue.

    When I got this notification I went into protection history and selected the action to remove the threat and it said that the remediation is incomplete and failed. Then I did a full scan, got the notification and when I selected the remove action protection history shows that the threat was removed. Another full scan now shows no threats detected.  So false positive with inconsistent removal results? 

  • DSGF

    13 Posts

    6280

    1

    Posted March 2nd, 2022 14:00

    Dell, where are you??

  • hamta_ball

    1 Message

    6214

    1

    Posted March 2nd, 2022 15:00

    Just received this notification on my work laptop: Dell Latitude 9420.

  • 6244

    1

    Posted March 2nd, 2022 15:00

    These sure appear to be false positives, but it would be great to get confirmation.

    As an aside, Dell hasn't done itself any favors with the apparent typo in the related executable name (note the missing "i" after the second "d" in "DellSupportAssistRemedationService.exe")

  • RoHe

    12 Elder

    45230 Posts

    172625 Points

    6078

    1

    Posted March 2nd, 2022 17:00

    I pinged my Dell contacts earlier today and provided the link to this thread and to the Reddit thread.

    Stay tuned...