Hi,

I couldn't find any information about this thread on your website.

Win32.Fakealert.ttam: [SBI $CB1B5484] Class ID (Registrierungsdatenbank-Schlüssel, nothing done)
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}

I hope it's a false positive, because it is a registry entry of the - as I think - trustworthy program "phraseexpress.exe".

This program is a global autotext tool, which tracks the keyboard entries to find matching autotexts.

What does "Win32.Fakealert.ttam" mean?
Why is this entry detected as threat?


  • Operating System (Windows XP Media Center Edition)
  • Browser and Version (Internet Explorer 8, FireFox 3.5.1)
  • Version of Spybot S&D 1.6.2.46
  • Date of the latest update 29th July 2009
  • where did the false positive occur
    • Scan result


Thanks a lot.