Jump to content

Kaspersky removal tool OS credential dumping


Go to solution Solved by Yury N.,

Recommended Posts

fabiodanzetta
Posted

Hello everyone,
I launched kaspersky removal tool on a windows machine with crowdstrike installed which at a certain point after 10 minutes from the start of the Kaspersky scan killed the kaspersky removal tool and triggered a critical detection with this wording: "A process appears to be accessing credentials and might be dumping passwords. If this is unexpected, review the process tree."
The killed process is identified as numeric.exe and in my case as "418ecc20.exe" which refers to Kaspersky Virus Removal Tool and which is located in Users\username\AppData\Local\Temp\{060a28d3-7b79-4b97-bfcb-6c1693af6922}
Can you please explain to me on a technical level why this happened?

Thanks everyone

harlan4096
Posted

Welcome to Kaspersky Community.

 

This is clearly a false positive of CrowdStrike...

 

Every time You run KVRT, a new random exe name is created, to avoid a possible malware in memory recognizes and kill it, for example.

  • Like 3
fabiodanzetta
Posted

Hi Harlan,
I had imagined this but I wanted to understand why kaspersky removal tool needs to dump credentials.

Thanks

  • Solution
Yury N.
Posted

Hello.

KVRT opens processes for query loaded libraries list. May be this triggers CrowdStrike. You should ask CrowdStrike what causes this alert.

  • Like 2
  • 2 weeks later...
fabiodanzetta
Posted

@Yury N. thank you very mutch for your explanation.

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...