Jump to content


Photo

False positive : Bill2's Process Manager


  • Please log in to reply
7 replies to this topic

#1 Herser

Herser

    New Member

  • Members
  • Pip
  • 7 posts

Posted 27 July 2009 - 03:30 PM

Hello

I'm French and my english is not sure
I help on french forum and newsgroup
And a user asks me for this line :

Fichier(s) infecté(s):
C:\Documents and Settings\Blmp\Bureau\ProcessManager.lnk (Rogue.Link)
-> No action taken

It's the program Bill2's Process Manager :
http://www.bill2-sof...processmanager/
And not a rogue

Thanks for MBAM

Herser

#2 TeMerc

TeMerc

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 1,990 posts
  • Gender:Male
  • Location:Phx. AZ. USA
  • Interests:Formula 1 Auto Racing, Computer Security, Entertainment, Sci-Fi, SuperHeroes

Posted 27 July 2009 - 05:20 PM

Hi and welcome to the forums.

Thanks for bringing this to our attention, please follow the directions in the link below to get us what we need:
http://www.malwareby...?showtopic=3228
Tom Mercado
Consumer Support Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3 Herser

Herser

    New Member

  • Members
  • Pip
  • 7 posts

Posted 28 July 2009 - 08:17 AM

View PostTeMerc, on Jul 28 2009, 12:20 AM, said:

Hi and welcome to the forums.

Thanks for bringing this to our attention, please follow the directions in the link below to get us what we need:
http://www.malwareby...?showtopic=3228

Yes i know
But it's not my computer.
I help a user
And he don't reply.
So i can't use "mbam.exe /developer" for him !!!

I wait a reply for him

Thank's

Herser

#4 Herser

Herser

    New Member

  • Members
  • Pip
  • 7 posts

Posted 28 July 2009 - 02:54 PM

Hi ! The log :


Malwarebytes' Anti-Malware 1.39
Version de la base de données: 2522
Windows 5.1.2600 Service Pack 3

28/07/2009 20:34:39
mbam-log-2009-07-28 (20-34-04).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 153835
Temps écoulé: 10 minute(s), 54 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 3
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. [5138494534363830414438586445483634456446343641424738615248395356345138614674688
38084807185615270688683748590013670798570839334798574557483868437748466677770478
0
857471903018130117]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. [5138494534363830414438586445483634456446343641424738615248395356345138614674688
38084807185615270688683748590013670798570839339748370886677773774846667777047808
5
7471903018130117]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. [5138494534363830414438586445483634456446343641424738615248395356345138614674688
38084807185615270688683748590013670798570839354816966857084377484666777704780857
4
71903018130117]

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Documents and Settings\Blmp\Bureau\ProcessManager.lnk (Rogue.Link) -> No action taken. [3857535134303627613780688678707985840166796901527085857479728461357778816135868
370668661498380687084844666796672708315777976]

#5 Herser

Herser

    New Member

  • Members
  • Pip
  • 7 posts

Posted 04 August 2009 - 08:16 AM

Hi !

It's the last line which is false positive :

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Documents and Settings\Blmp\Bureau\ProcessManager.lnk (Rogue.Link) -> No action taken. [3857535134303627613780688678707985840166796901527085857479728461357778816135868
370668661498380687084844666796672708315777976]

It's a french programme for priority to multiprocessor :
http://www.bill2-sof...processmanager/

It's not a rogue

Thank's

Herser

#6 nosirrah

nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,402 posts
  • Location:Northampton, MA USA

Posted 04 August 2009 - 08:43 AM

C:\Documents and Settings\Blmp\Bureau\ProcessManager.lnk <- this was fixed a while ago , I am unable to affect detection of this unless you update .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7 Falkra

Falkra

    Elite Member

  • Experts
  • PipPipPipPipPip
  • 544 posts
  • Gender:Male
  • Location:France
  • Interests:Languages : French, Spanish, English.

Posted 04 August 2009 - 09:03 AM

Hi, I get no detection with latest update 2557_1.40, even if I manually place a copy of the shortcut on desktop.

#8 Herser

Herser

    New Member

  • Members
  • Pip
  • 7 posts

Posted 04 August 2009 - 02:31 PM

Thank's nosirrah
Merci Falkra

I post to the user who asked me

Regards

Herser




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users