Skip to content
This repository has been archived by the owner on Oct 19, 2019. It is now read-only.

Windows Defender false-positive against Termination-Checker.vbs #98

Open
putty182 opened this issue Sep 14, 2018 · 3 comments
Open

Windows Defender false-positive against Termination-Checker.vbs #98

putty182 opened this issue Sep 14, 2018 · 3 comments

Comments

@putty182
Copy link
Contributor

putty182 commented Sep 14, 2018

Bumped into this after booting up my rig today; Trojan:Script/Cloxer.A!cl

Clearly a false positive, logging it as a GH issue in case anyone else sees it and panics.

Category: Trojan

Description: This program is dangerous and executes commands from an attacker.

Recommended action: Remove this software immediately.

Items: 
containerfile:C:\cloudRIG\Termination-Checker.vbs
file:C:\cloudRIG\Termination-Checker.vbs->(UTF-16LE)
file:C:\Windows\System32\Tasks\CloudRIGTerminationChecker
process:pid:6924,ProcessStart:131813976001945618
regkey:HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D0A5740-1631-48F7-BA56-8870BBAFA866}
regkey:HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CloudRIGTerminationChecker
taskscheduler:C:\Windows\System32\Tasks\CloudRIGTerminationChecker

Get more information about this item online.

Want to back this issue? Post a bounty on it! We accept bounties via Bountysource.

@williamparry
Copy link
Owner

Great pick up - thanks :)

Any ideas how to get around it?

@AetherCollective
Copy link

You could always use my False Positive Reporter tool to request whitelisting from AV Vendors.
https://github.com/BetaLeaf/False-Positive-Reporter

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants