Windows Seeing PBS Chunk File as Trojan

colin1234

New Member
Jan 3, 2024
3
0
1
I have PBS running on my Synology NAS and I have the backup share mounted to a Windows VM for cloud backups with Backblaze. I logged in today to check on status and it seems that Windows is seeing one of the PBS Chunk files as an "AgentTesla" Trojan. It reports it about once an hour. Windows doesn't have write permission to that drive so it's not actually removing it. How is this possible? The chunk files are just pieces of a VM aren't they? Even if one of the VMs did have a Trojan, Windows isn't able to discern that from a single ~2MB chunk file right?1000042521.png
 
1. Just exclude your Z-drive from Windows Defender, no need to cause CPU-overhead for something that is probably wrong and it can't fix anyway
2. Most AV-packages look for certain signatures to find if a virus/malware/trojan is there (not for a whole program/hash). It might just be that this chuck had a reported signature/set-of-ones-and-zeros inside it by chance, causing it to be triggered
 
  • Like
Reactions: UdoB

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!