Results 1 to 6 of 6

Thread: banker.ceu ?

  1. #1
    Junior Member
    Join Date
    May 2007
    Posts
    11

    Default banker.ceu ?

    I keep getting the following detection -

    Banker.ceu: Settings (Registry value, nothing done)
    HKEY_USERS\S-1-5-21-1655073370-3743346858-1230028903-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\*\microsoft?????.exe


    I have scanned with the following -

    AVG Antispy - no results
    spyware doctor SE - no results
    AVG antivirus - no results
    Kaspersky online antivirus - no results
    Norton security scan - no results

    I have no winx.log file in my windows directory and no services.exe in windows\system32\drivers\

    I've checked with hijackthis, startup cpl & defender (network connected programs) and I can't find anything unexpected. I also have no unexpected tasks in my task manager.

    Is this a false positive?

  2. #2
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hello,

    this could be a false positive, this entry actually shows that a file named microsoft<followed_by_five_characters>.exe
    for instance: microsoft12345.exe , microsoftserve.exe and so on,
    has been executed.

    It would be best if you could find the file in question and identify it or submit it for analysis. There are actually not that many files which do have microsoft in the filename.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  3. #3
    Junior Member
    Join Date
    May 2007
    Posts
    11

    Default

    Thanks for the feedback.

    I searched for files named microsoft?????.exe (including hidden files & system files) and all I found was microsoft word.exe. I then searched for microsoft only and found nothing suspicious in the list. Also the only file in my prefetch with microsoft in the name is word again.

    I've also checked that location in the registry and I can't find anything pointing to microsoft(5digits).exe as detailed.

    I keep fixing this issue and it comes back.
    Last edited by lardboy; 2007-05-23 at 14:19.

  4. #4
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hi,

    it really does look like a false positive, it will be removed from detection with the next update.
    You can have Spybot ignore this entry until the update is released.

    thanks for reporting.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  5. #5
    Junior Member
    Join Date
    May 2007
    Posts
    11

    Default

    OK thanks

  6. #6
    Junior Member
    Join Date
    May 2007
    Posts
    11

    Default

    latest update has "fixed" this problem.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •