Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: Zeno false positive

  1. #1
    Junior Member
    Join Date
    Dec 2005
    Location
    Portsmouth, UK
    Posts
    3

    Default FP in McAfee program files.

    I'm getting teatimer popups saying "s & D has encountered & terminated a process that is listed as malicious software" .... "Identified as Zeno".

    The files are mcafee.com\vso\mcmnhdlr.exe and ...com\agent\McDash.exe.
    As far as I can see, they haven't changed since 2005. And every anti-malware & av program I've run against them is happy.

    Installed new S & D definitions & beta definitions yesterday (01 July). Popups began last night (UK) with scheduled McAfee virus scan.

    Switched off teatimer, until new definitions arrive. (but WinPatrol's Scottie is guarding my Startup, so I feel reasonably safe)

    Mike

  2. #2
    Junior Member
    Join Date
    Dec 2005
    Location
    Portsmouth, UK
    Posts
    3

    Default mcafee fp. an update

    I've just learnt how to allow those mcafee tasks in teatimer. Haven't had to go there before, so I didn't know about it. Wonderful feature. S & D has gone up even higher in my estimation. So teatimer is back in action.

  3. #3
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    thanks for reporting,
    it is false positive in the beta detections and will be removed with the next update scheduled for the end of the week.
    this false positive also detects qttask.exe as zeno, so do not be alarmed if qttask gets detected by the teatimer.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  4. #4
    Junior Member
    Join Date
    Jul 2006
    Posts
    4

    Default Zeno false positive

    2006-07-03 05:10:09 Encountered and terminated Zeno in C:\WINDOWS\system32\nvsvc32.exe! from the log.

  5. #5
    Junior Member
    Join Date
    Jul 2006
    Posts
    2

    Default Zeno false positive

    Setacm.exe is for setting the speed of the maxtor Hard disks read heads, to make the seek quiet (but slower). I ran the file but got the warning...Zeno.
    File link included.

    http://maxtor.custhelp.com/cgi-bin/m...hph?setacm.exe

    Thanks Jon Graef

  6. #6
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hi, please tell us which detection rules you are using and where the warning occured: as scanresult or teatimer popup.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  7. #7
    Junior Member
    Join Date
    Jul 2006
    Posts
    1

    Default

    Hi,

    using latest beta detection rules (update: 1.7.06) teatimer creates following popups:

    Encountered and terminated Zeno in C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    -> Lenovo/IBM ThinkVantage Access Connection 4.12

    Encountered and terminated Zeno in D:\Microsoft ActiveSync\CEAppMgr.exe!
    -> Microsoft ActiveSync 3.8.0, Application Manager

    cu, biko

  8. #8
    Junior Member
    Join Date
    Jul 2006
    Posts
    2

    Default

    Zeno detection is corrupt as it seems to trigger on all sorts of perfectly correct software. To the list above I can add:

    * Encountered and terminated Zeno in C:\PROGRA~1\HEWLET~1\Toolbox\STATUS~1\STATUS~1.EXE!

    ...which is HP StatusClient to monitor printer status

    * Encountered and terminated Zeno in C:\Program Files\Dantz\Retrospect\Retrospect.exe!

    ...which is Backup software by DANTZ

    Re/F

  9. #9
    Junior Member
    Join Date
    Jul 2006
    Posts
    1

    Default

    Hi,
    Updated to detection-updates 01-07-2006 (incl. beta), teatimer found :

    "Encountered and terminated Zeno in C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe",

    ..., which is a legitimit file of "Acronis True Image"- backupsoftware.
    Disabled the "ZENO"-detection in the "beta.sbi"-checklist.

    CU, Wuschel

  10. #10
    Junior Member
    Join Date
    Dec 2005
    Location
    Portsmouth, UK
    Posts
    3

    Thumbs up FP in MAafee

    Quote Originally Posted by Yodama
    thanks for reporting,
    it is false positive in the beta detections and will be removed with the next update scheduled for the end of the week.
    Thanks for the info Yodama

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •