Spybot Logo
Go Back   Safer-Networking Forums > Software > Spybot-S&D > False Positives
Register ProjectsBlogs FAQ Search Today's Posts Mark Forums Read Home Support Download Donate

Reply
 
Thread Tools Display Modes
Old 2007-05-23, 09:33   #1
lardboy
Junior Member
 
Join Date: May 2007
Posts: 11
Default banker.ceu ?

I keep getting the following detection -

Banker.ceu: Settings (Registry value, nothing done)
HKEY_USERS\S-1-5-21-1655073370-3743346858-1230028903-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\*\microsoft?????.exe


I have scanned with the following -

AVG Antispy - no results
spyware doctor SE - no results
AVG antivirus - no results
Kaspersky online antivirus - no results
Norton security scan - no results

I have no winx.log file in my windows directory and no services.exe in windows\system32\drivers\

I've checked with hijackthis, startup cpl & defender (network connected programs) and I can't find anything unexpected. I also have no unexpected tasks in my task manager.

Is this a false positive?
lardboy is offline   Reply With Quote
Old 2007-05-23, 12:20   #2
Yodama
Member of Team Spybot
 
Yodama's Avatar
 
Join Date: Oct 2005
Location: Buchenheim
Posts: 935
Blog Entries: 1
Rated LASSHes: 119
Default

hello,

this could be a false positive, this entry actually shows that a file named microsoft<followed_by_five_characters>.exe
for instance: microsoft12345.exe , microsoftserve.exe and so on,
has been executed.

It would be best if you could find the file in question and identify it or submit it for analysis. There are actually not that many files which do have microsoft in the filename.
__________________
born in the shadow to die in the shadow, that is the fate of the shinobi

Spybot S&D Downloads

Please help us improve Spybot and download our distributed testing client.
Yodama is offline   Reply With Quote
Old 2007-05-23, 14:09   #3
lardboy
Junior Member
 
Join Date: May 2007
Posts: 11
Default

Thanks for the feedback.

I searched for files named microsoft?????.exe (including hidden files & system files) and all I found was microsoft word.exe. I then searched for microsoft only and found nothing suspicious in the list. Also the only file in my prefetch with microsoft in the name is word again.

I've also checked that location in the registry and I can't find anything pointing to microsoft(5digits).exe as detailed.

I keep fixing this issue and it comes back.

Last edited by lardboy; 2007-05-23 at 14:19.
lardboy is offline   Reply With Quote
Old 2007-05-24, 07:34   #4
Yodama
Member of Team Spybot
 
Yodama's Avatar
 
Join Date: Oct 2005
Location: Buchenheim
Posts: 935
Blog Entries: 1
Rated LASSHes: 119
Default

hi,

it really does look like a false positive, it will be removed from detection with the next update.
You can have Spybot ignore this entry until the update is released.

thanks for reporting.
__________________
born in the shadow to die in the shadow, that is the fate of the shinobi

Spybot S&D Downloads

Please help us improve Spybot and download our distributed testing client.
Yodama is offline   Reply With Quote
Old 2007-05-25, 10:28   #5
lardboy
Junior Member
 
Join Date: May 2007
Posts: 11
Default

OK thanks
lardboy is offline   Reply With Quote
Old 2007-05-31, 09:53   #6
lardboy
Junior Member
 
Join Date: May 2007
Posts: 11
Default

latest update has "fixed" this problem.
lardboy is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 17:05.


Copyright © 2000-2010 Safer-Networking Limited. All rights reserved.