Results 1 to 10 of 11

Thread: ...\Image File Execution Options\taskmgr.exe

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Senior Member
    Join Date
    May 2006
    Posts
    236

    Question ...\Image File Execution Options\taskmgr.exe

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

    Is this a false positive? I am using an old, updated Windows XP Pro. SP3 machine. I never had this one before. Attached a zip file with logs from its C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs\.

    Thank you in advance.

  2. #2
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hello,

    this is kind of a false positive.
    In your case this should not have been detected unless malicious exe files from Crypt.InfectRansom have been detected on your computer. And you would actually know it when your computer is taken for ransom.

    Image File Execution Options are usually not set. Some times a debugger is set there for legit operations but mostly it is used by malware to either block execution of files or to start malware when a file is started.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  3. #3
    Senior Member
    Join Date
    May 2006
    Posts
    236

    Default

    Quote Originally Posted by Yodama View Post
    hello,

    this is kind of a false positive.
    In your case this should not have been detected unless malicious exe files from Crypt.InfectRansom have been detected on your computer. And you would actually know it when your computer is taken for ransom.

    Image File Execution Options are usually not set. Some times a debugger is set there for legit operations but mostly it is used by malware to either block execution of files or to start malware when a file is started.
    Ah thanks. I let Spybot S&D remove it. So far, nothing weird/odd on the machine. I already rebooted too.

  4. #4
    Junior Member
    Join Date
    Oct 2006
    Location
    Casper, WY
    Posts
    5

    Default

    Yes, this is/can be a false positive.

    I have process explorer from sysinternals installed, and set to replace task manager on my machines, I have downloaded only from microsoft technet, and even old versions of process explorer are tripping the new "Crypt.InfectRansom++" detection.

    The installation (manual) directory I have used is: C:\Program Files\ProcessExplorer\ .

    I understand the severity of this, if it weren't a benign program, and PE for having a fast update track, would almost be impossible to avoid. So the mistaken identity is completely understood (I am the author of ZB Block, and I know all about false positives... headaches.)

    The question is, what can be done?

    Zap
    73 from AE7EC

  5. #5
    Senior Member
    Join Date
    May 2006
    Posts
    236

    Default

    Quote Originally Posted by zaphodb777 View Post
    Yes, this is/can be a false positive.

    I have process explorer from sysinternals installed, and set to replace task manager on my machines, I have downloaded only from microsoft technet, and even old versions of process explorer are tripping the new "Crypt.InfectRansom++" detection.

    The installation (manual) directory I have used is: C:\Program Files\ProcessExplorer\ .

    I understand the severity of this, if it weren't a benign program, and PE for having a fast update track, would almost be impossible to avoid. So the mistaken identity is completely understood (I am the author of ZB Block, and I know all about false positives... headaches.)

    The question is, what can be done?

    Zap
    Ahh! I used PE!

  6. #6
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    Thanks for the additional info.

    I forgot to tell you that the next detection update scheduled for Wednesday 2012-07-25 will fix this issue. I changed a dependency in the detection.
    Last edited by Yodama; 2012-07-20 at 12:34. Reason: added date
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •