CnsMin False Positive

  • Thread starter Thread starter Cris McRae
  • Start date Start date
C

Cris McRae

I'm using the latest 5751 signatures and I'm getting a
false positive on CnsMin. It's flagging registry keys
associated with Yahoo! Messenger 7.5. All but two of the
registry values clearly say "Yahoo!" or "YPager".
 
Here are the registry keys it's detecting as related to "CnsMin":

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} ButtonText Yahoo!
Messenger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} clsid
{1FBA04EE-3024-11D2-8F1F-0000F87ABD16}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} MenuText Yahoo!
Messenger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} Default Visible
YES
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} Exec
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} Icon
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe,105
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} HotIcon
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe,105
 
Thanks Chris--I'll pass this on.

--

Cris McRae said:
Here are the registry keys it's detecting as related to "CnsMin":

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\Extensions\CmdMapping {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} ButtonText
Yahoo! Messenger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} clsid
{1FBA04EE-3024-11D2-8F1F-0000F87ABD16}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} MenuText Yahoo!
Messenger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} Default Visible
YES
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} Exec
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} Icon
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe,105
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} HotIcon
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe,105
 
Bill,

I also had this using 5751, and can confirm it has been corrected in 5755
(updated and finished scanning a few minutes ago).

Thanks,
Jason McKinnon
 
Thanks very much!

--

Jason McKinnon said:
Bill,

I also had this using 5751, and can confirm it has been corrected in 5755
(updated and finished scanning a few minutes ago).

Thanks,
Jason McKinnon
 
Just wanted to reiterate Jason's comments, Bill.

After receiving the same 'false positive' as Chris,
Spyware Definition Version: 5755 (13/09/2005 13:57:02)
corrected the issue.

The 'culprit' Spyware Definition Version in question, I
believe, was 5753.

-=JAZZ=-
 
Thanks!

--

Jazz said:
Just wanted to reiterate Jason's comments, Bill.

After receiving the same 'false positive' as Chris,
Spyware Definition Version: 5755 (13/09/2005 13:57:02)
corrected the issue.

The 'culprit' Spyware Definition Version in question, I
believe, was 5753.

-=JAZZ=-
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top