Results 1 to 10 of 11

Thread: ...\Image File Execution Options\taskmgr.exe

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Junior Member
    Join Date
    Oct 2006
    Location
    Casper, WY
    Posts
    5

    Default

    Yes, this is/can be a false positive.

    I have process explorer from sysinternals installed, and set to replace task manager on my machines, I have downloaded only from microsoft technet, and even old versions of process explorer are tripping the new "Crypt.InfectRansom++" detection.

    The installation (manual) directory I have used is: C:\Program Files\ProcessExplorer\ .

    I understand the severity of this, if it weren't a benign program, and PE for having a fast update track, would almost be impossible to avoid. So the mistaken identity is completely understood (I am the author of ZB Block, and I know all about false positives... headaches.)

    The question is, what can be done?

    Zap
    73 from AE7EC

  2. #2
    Senior Member
    Join Date
    May 2006
    Posts
    236

    Default

    Quote Originally Posted by zaphodb777 View Post
    Yes, this is/can be a false positive.

    I have process explorer from sysinternals installed, and set to replace task manager on my machines, I have downloaded only from microsoft technet, and even old versions of process explorer are tripping the new "Crypt.InfectRansom++" detection.

    The installation (manual) directory I have used is: C:\Program Files\ProcessExplorer\ .

    I understand the severity of this, if it weren't a benign program, and PE for having a fast update track, would almost be impossible to avoid. So the mistaken identity is completely understood (I am the author of ZB Block, and I know all about false positives... headaches.)

    The question is, what can be done?

    Zap
    Ahh! I used PE!

  3. #3
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    Thanks for the additional info.

    I forgot to tell you that the next detection update scheduled for Wednesday 2012-07-25 will fix this issue. I changed a dependency in the detection.
    Last edited by Yodama; 2012-07-20 at 12:34. Reason: added date
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  4. #4
    Senior Member
    Join Date
    May 2006
    Posts
    236

    Default

    Quote Originally Posted by Yodama View Post
    Thanks for the additional info.

    I forgot to tell you that the next detection update scheduled for Wednesday 2012-07-25 will fix this issue. I changed a dependency in the detection.
    Thanks! I have restore my quarantined registry key entry then.

  5. #5
    Junior Member
    Join Date
    Jul 2012
    Posts
    1

    Default

    i got that just a minute ago crypt.infectRansom

    exact same location

    I didnt have any problem with my computer and i installed a microsoft word program ealier so i think thats it.

    I also have procexp64

    no problems i could find.

  6. #6
    Junior Member
    Join Date
    Jul 2012
    Posts
    1

    Default confirmed from me also

    Hi!

    I confirm that false positive. Frightened me a lot.

    Looks like any change of that registry entry from Windows default cause that false positive.
    On last Sunday I've got that from installed Process Explorer mentioned and that ruin my free day.
    Today I tested ProcessHacker from http://processhacker.sourceforge.net/ which is "cousin" of PE and also enable "Replace Task Manager".
    And HEY, yes the same False Positive reappear.

    So SB team please narrow search of a Malware in that particular two registry keys.

    Regardless of above I give 10 of 10 point for Spybot.
    I use it for a very long time and hard to wait for a new version now in beta.

    Regards!

  7. #7
    Senior Member
    Join Date
    May 2006
    Posts
    236

    Default

    Quote Originally Posted by zdolar View Post
    Hi!

    I confirm that false positive. Frightened me a lot.

    Looks like any change of that registry entry from Windows default cause that false positive.
    On last Sunday I've got that from installed Process Explorer mentioned and that ruin my free day.
    Today I tested ProcessHacker from http://processhacker.sourceforge.net/ which is "cousin" of PE and also enable "Replace Task Manager".
    And HEY, yes the same False Positive reappear.

    So SB team please narrow search of a Malware in that particular two registry keys.

    Regardless of above I give 10 of 10 point for Spybot.
    I use it for a very long time and hard to wait for a new version now in beta.

    Regards!
    They said they fixed it for tomorrow's updates. Let's try again tomorrow!

  8. #8
    Senior Member
    Join Date
    May 2006
    Posts
    236

    Default

    Quote Originally Posted by Yodama View Post
    Thanks for the additional info.

    I forgot to tell you that the next detection update scheduled for Wednesday 2012-07-25 will fix this issue. I changed a dependency in the detection.
    Confirmed fixed with today's updates. Thanks!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •