Start a Conversation

Unsolved

This post is more than 5 years old

16716

July 13th, 2014 09:00

Scan by Malwarebytes.

I ran Malwarebytes this morning and it detected this:

Registry Data: 2
Broken.OpenCommand, HKCR\piffile\shell\open\command, "C:\Program Files (x86)\Foolish IT\CryptoPrevent
\CryptoPreventFilterMod.exe" *"Good: ("Bad: ("C:\Program Files (x86)\Foolish IT\CryptoPrevent\CryptoPrevent
FilterMod.exe" *"%1" %*),Replaced,[ffffffffffffffffffffffffffffffff]" %*)" %*, %4, %5

Broken.OpenCommand, HKCR\scrfile\shell\open\command, "C:\Program Files (x86)\Foolish IT\CryptoPrevent
\CryptoPreventFilterMod.exe" "Good: ("Bad: ("C:\Program Files (x86)\Foolish IT\CryptoPrevent\CryptoPrevent
FilterMod.exe" "%1" /S %*),Replaced,[ffffffffffffffffffffffffffffffff]" /S)" /S %*, %4, %5

If I'm reading the notes correctly on CryptoPrevent, I believe this is a False Positive detection. I just want to make sure. Can I exclude this on my Malwarebytes scan? WinPatrol keeps coming up asking if its ok to allow this change. I check no. I need your opinion on this before I do anything. Thanks

1 Rookie

 • 

2.2K Posts

July 13th, 2014 10:00

I have both of those listed as exemptions, with no problems,

However, concerning CryptoPrevent, I have yet to update to 9 on the definitions, nor to version 6.1.0 on the application, untill I hear what results others have had.

3 Apprentice

 • 

15.2K Posts

July 13th, 2014 11:00

Evermore:

This has been discussed in great detail here:   http://en.community.dell.com/support-forums/virus-spyware/f/3522/t/19588207.aspx 

To summarize:   CryptoPrevent version 6.x introduced a new FILTER MODULE which runs in real time, and as a result, "anti-malware software [including MBAM and WinPatrol] may report several false positives related to CryptoPrevent’s [restriction of policy] settings".

Assuming you want to run both CryptoPrevent's Filter Module AND scan with MBAM, then yes, you need to tell MBAM to exclude these two registry items from future detection.  

If you allowed MBAM to quarantine these items, you need to restore them from quarantine.   Alternatively, you should be able to use CryptoPrevent to APPLY its PROTECTION again, which should re-instate them.

Then run the MBAM scan.   When the results appear, the default ACTION suggested is [probably] to quarantine.   Instead, use the drop-down ACTION menu to select ADD EXCLUSION.   Then click on APPLY ACTIONS.

If you then look under Settings, Malware Exclusions, you should now see the entries listed there.   Which means that they should no longer be detected in future scans.

 

3 Apprentice

 • 

15.2K Posts

July 13th, 2014 12:00

Dale wrote:  "However, concerning CryptoPrevent, I have yet to update to 9 on the definitions, nor to version 6.1.0 on the application, untill I hear what results others have had".

First off, let me stress that I am only using the "portable" (= NON-installed) version of CryptoPrevent, meaning I DON'T have its Filter Module running in real-time.    [I am NOT saying using the filter module is bad --- it certainly offers additional protection --- just that I have opted not to take advantage of it.]

As for 6.1, I think if you stick to the DEFAULT (NON-advanced) options, you should be okay.   The change-log mentions Improved Recycle Bin executable protection which certainly sounds good.   However, the remaining changes --- all of which are relegated to the Advance options --- are potentially dangerous; specifically:

1) Added feature to remove ALL software restriction policies (whether created by CryptoPrevent or not --- i.e., it will remove restrictions added by the user, or by other programs.)

2) feature to block %localappdata%\*, which may cause issues with legitimate apps; and so is generally not recommended even by the author.

3) the ability to "force" install or UNinstall --- which not 100% perfect, and so should only be used if absolutely necessary.

So do I think you should update?  Sure.   Just stick with the default options, and stay clear of the Advanced ones.

 

1 Rookie

 • 

2.2K Posts

July 13th, 2014 14:00

David....thanks for reviewing this subject again.

338 Posts

July 13th, 2014 19:00

Thanks  ky331 for the detailed answer to my question. I did as you suggested and everything seems to be ok. I probably shouldn't have updated CryptoPrevent to the latest version. I will stick to the default options. I will reread the link for the operation of CryptoPrevent as you posted at the start.

No Events found!

Top