False Positive on VirusTotal (Yandex) for Process Explorer

blackice

Level 39
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Apr 1, 2019
2,853
16,878
3,769
USA
I downloaded Process Explorer from Microsoft's site (verified the certificate) and then verified the sigs on the processes. Interestingly Yandex on VT is showing a trojan. This has to be a FP right? It only shows for procexp.exe and not procexp64.exe.

213178
 
File: procexp.exe
File size: 2.58 MB
SHA1 checksum: 554B642E8DEE95010D2501D8B527BBEFCEFF3831
SHA256 checksum: 51C3BED87B9F8187DA6A3752C7EBA8766A0B7ECAB0E321BF2A6AD77ECC6A21D3
--
File: procexp64.exe
File size: 1.38 MB
SHA1 checksum: DCC36FEE51754F3171A161E5D66C7F2120A9D4C1
SHA256 checksum: C16DD2FB64F586A49EC58CE499C3C050C443A08E7282102DC7399C84C7B12E3B
--
https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer
 
Last edited:
Checksums match, no idea what's up with Yandex.

File: procexp.exe
File size: 2.58 MB
SHA1 checksum: 554B642E8DEE95010D2501D8B527BBEFCEFF3831
SHA256 checksum: 51C3BED87B9F8187DA6A3752C7EBA8766A0B7ECAB0E321BF2A6AD77ECC6A21D3
--
File: procexp64.exe
File size: 1.38 MB
SHA1 checksum: DCC36FEE51754F3171A161E5D66C7F2120A9D4C1
SHA256 checksum: C16DD2FB64F586A49EC58CE499C3C050C443A08E7282102DC7399C84C7B12E3B
--
https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer

By the way where did you get the checksum? I looked all over the page and couldn't find one it listed.
 
  • Like
Reactions: bjm_
  • Like
Reactions: blackice
  • Like
Reactions: bjm_
"Details" tabs offers more checksums.
--
https://www.virustotal.com/gui/file/51c3bed87b9f8187da6a3752c7eba8766a0b7ecab0e321bf2a6ad77ecc6a21d3/details
 
  • Like
Reactions: blackice
"Details" tabs offers more checksums.
--
https://www.virustotal.com/gui/file/51c3bed87b9f8187da6a3752c7eba8766a0b7ecab0e321bf2a6ad77ecc6a21d3/details

Thanks, I’ve never dug around VT much because I’ve never had it flag anything as malicious before.
 
  • Like
Reactions: bjm_