Page 1 of 2 12 LastLast
Results 1 to 10 of 19

Thread: "Phoenix" False Positive

  1. #1
    Junior Member
    Join Date
    Nov 2005
    Posts
    7

    Exclamation "Phoenix" False Positive

    Since the 2005-11-25 update, Spybot identifies a file "C:\Windows\setup1.exe" on my computer as "Phoenix", but I'm reasonably sure that I don't have any keylogger on my system (as I scan daily with spybot, ad-aware and two antivirus apps). The file itself has a version information that says something like "Microsoft Visual Basic 6.0 Setup Toolkit" (Version 6.0.0.8171, Size 286.720 Bytes).

    After some searching around, I'm fairly sure now, that this is an false positive!
    Have a look at here, where they describe exactly the same file that was found on my computer.
    I also scanned it via virusscan.jotti.org and every scanner reported a clean file!

    What criteria is the Phoenix detection based upon?
    Are there any documents describing this keylogger?

  2. #2
    Junior Member the.basement's Avatar
    Join Date
    Nov 2005
    Posts
    2

    Default I want to know too....

    I deleted the file, but want to know the outcome of this topic.



    sorry for me English.
    it is not my mother language.
    :p

  3. #3
    Member of Team Spybot Buster's Avatar
    Join Date
    Oct 2005
    Location
    Bochum/Germany
    Posts
    389

    Default

    @ Elandril:
    Thanks for reporting this false positive. It will be fixed in the next update.

    @ the.basement:
    If you want to restore the file, you can do this by using Spybot´s recovery feature. Just run Spybot and select "recovery" on the left. Now open "Phoenix", select "setup1.exe" and click on "recover selected items".
    "The advantage of wisdom is that you can always act the fool. The opposite is quite tough."

    K. Tucholsky

    _______________________________________________________________

    Please help us improve Spybot and download our distributed testing client.

  4. #4
    Junior Member the.basement's Avatar
    Join Date
    Nov 2005
    Posts
    2

    Default thank you

    I know the way, but thank you for the support.
    the file is also clean and i will restore the file.

    I hope that the update restore the file by it self.
    Many people use this programm and don't know this "problem".

    sorry for me English.
    it is not my mother language.
    :p

  5. #5
    Junior Member GladToBeGrey's Avatar
    Join Date
    Dec 2005
    Location
    Dorset, England
    Posts
    4

    Question Me too ...

    I've hit this problem with the Shareware Earthwatch software (http://www.elanware.com/) installation. Again, I'm reasonably sure this software is clean.

    If this false positive is going to be fixed in the new release, when's that due out? (Currently running S&D 1.4). Been very happy with Spybot to date, and recommended it to others.

  6. #6
    Member of Team Spybot Buster's Avatar
    Join Date
    Oct 2005
    Location
    Bochum/Germany
    Posts
    389

    Default

    The next update will be available tomorrow!:D
    "The advantage of wisdom is that you can always act the fool. The opposite is quite tough."

    K. Tucholsky

    _______________________________________________________________

    Please help us improve Spybot and download our distributed testing client.

  7. #7
    Junior Member GladToBeGrey's Avatar
    Join Date
    Dec 2005
    Location
    Dorset, England
    Posts
    4

    Default

    Hi, I've updated SSD with today's update, run a (clean) scan, but I'm still getting the positive when I try to run the Earthwatch setup.exe. Error message below:



    :(

  8. #8
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    found and removed remaining entry in database, that made teatimer identify the visualbasic setup as phoenix,
    expect teatimer to not detect this false positive with the next update scheduled for the end for the week.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  9. #9
    Junior Member
    Join Date
    Dec 2005
    Location
    Salem, OR
    Posts
    4

    Default Phoenix False Positive

    We have a program called Phoenix - http://www.completesoft.com/vs-phoenix-pos.htm - and the update will remove the whole folder. This folder contains a database file that houses all of the financial data for the store running the program. Phoenix is a actually a Point Of Sale software. I'm not sure if there is another software called Phoenix that is a keylogger but this Point Of Sale software is not. It is a Video Point Of Sale Software. It tracks rentals and returns along with sales.

    Is there any way to remove Phoenix from the list or make it only remove it if it is actually a keylogger?

    Just wondering.

    Thanks for the help.

    Mike

  10. #10
    Member of Team Spybot Buster's Avatar
    Join Date
    Oct 2005
    Location
    Bochum/Germany
    Posts
    389

    Default

    @ Mike_F
    Does Spybot still flag the Phoenix directory with the latest detection updates dated on 2005-12-02 installed?
    "The advantage of wisdom is that you can always act the fool. The opposite is quite tough."

    K. Tucholsky

    _______________________________________________________________

    Please help us improve Spybot and download our distributed testing client.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •