NCrypt.exe deteced as RiskWare.BitCoinMiner

Hello to all,

In parallel with Norton 360, the MalwareBytes 4.4.3 program is also installed on my Windows 10. This program has now detected the file C:\Program Files\Norton Security\Engine\22.21.6.51\NCrypt.exe as a threat RiskWare.BitCoinMiner.
Does anyone have any idea if this is a false positive or if a threat has actually nested under Norton?

So far I have not detected any significant increase in computer performance due to possible mining
(on: Windows 10 Home; Intel Core i7-10700 CPU @ 2.90GHz; 32GB Memory)

Thanks for your help,
Markus

Saarlouis:

Is your Malwarebytes Premium (real-time) set up to Automatic Quarantine?  > YES, it is
Is your Malwarebytes Premium (real-time) registered to Windows Security Center? > YES, as far as I understand it (see attachment)

I was just curious ... how you run Norton 360 + Malwarebytes Premium.  

So you need to report this Malwarebytes detection as a false positive to Malwarebytes. > YES, I will do so. 

Malwarebytes "NCrypt.exe" detection should be fixed, now. 
https://forums.malwarebytes.com/topic/276813-riskwarebitcoinminer/

Do I need to close this thread again? Or when is it considered solved?

You may close this thread...you may mark Solution...when you're ready.  

An appreciation:
First and foremost, I would like to thank everyone involved (special to you "bjm_"), whether actively or indirectly, for their commitment!
Unusual, therefore special: I felt really taken seriously!

To your questions:
Is your Malwarebytes Premium (real-time) set up to Automatic Quarantine?  > YES, it is
Is your Malwarebytes Premium (real-time) registered to Windows Security Center? > YES, as far as I understand it (see attachment)

To your suggestion:
So you need to report this Malwarebytes detection as a false positive to Malwarebytes. > YES, I will do so.

Last question:
Do I need to close this thread again? Or when is it considered solved?
(sorry, but it is my first contact via such a community)

bjm_:

RiskWare.BitCoinMiner
https://forums.malwarebytes.com/topic/276813-riskwarebitcoinminer/

Thanks for reporting, this will be fixed in 10 minutes. 

https://forums.malwarebytes.com/topic/276813-riskwarebitcoinminer/?tab=comments#comment-1470528

This detection is for the new Norton Crypto feature in the latest version of 360 that is explained in this product announcement.   https://community.norton.com/en/blogs/product-service-announcements/norton-security-2221651-windows-now-available

It is not surprising that Malwarebytes or any other malware scanner might flag this file to protect users from unwanted apps from stealing your CPU cycles for crypto mining. So you need to report this Malwarebytes detection as a false positive to Malwarebytes.

The reason Malwarebytes cannot remove this detected file is the Norton Product Tamper Protection  feature protecting the valid Norton file.

 

Saarlouis:

In parallel with Norton 360, the MalwareBytes 4.4.3 program is also installed on my Windows 10. This program has now detected the file C:\Program Files\Norton Security\Engine\22.21.6.51\NCrypt.exe as a threat RiskWare.BitCoinMiner.

Is your Malwarebytes Premium (real-time) set up to Automatic Quarantine?  
Is your Malwarebytes Premium (real-time) registered to Windows Security Center?


Malwarebytes
-Log Details-
Scan Date: 7/21/21
Scan Time: 4:37 PM

-Software Information-
Version: 4.4.3.125
Components Version: 1.0.1387
Update Package Version: 1.0.43349

File: 1
RiskWare.BitCoinMiner, C:\PROGRAM FILES\NORTON SECURITY\ENGINE\22.21.6.51\NCRYPT.EXE, No Action By User, 917, 868256, 1.0.43349, 9D5E4754B893B8AF0DD2912D, dds, 01343013, AB3D8AA84421227F5E9C69AB8F62AA16, C68BEEE19034D32B2BAFF25B470E8617EA3139D0715B50C8D8C40D90636E6DC4


RiskWare.BitCoinMiner
https://forums.malwarebytes.com/topic/276813-riskwarebitcoinminer/

Saarlouis:

Sorry, just saw your question to late.
No, Malwarebytes could not solve it (see attachement)

Entfernung fehlgeschlagen
Removal failed
-
Okay....your NCrypt.exe icon looks stripped...  

...compared to my NCrypt.exe icon.

We'll need Malwarebytes user to confirm and report Malwarebytes detection. 
NCrypt.exe as a threat RiskWare.BitCoinMiner?


Filename: NCrypt.exe
Full Path: C:\Program Files\Norton Security\Engine\22.21.6.51\NCrypt.exe

Developers 
NortonLifeLock Inc.

Version 
1.0.0.33

Identified 
7/20/2021 at 10:16:11 AM

Last Used 
Not Available

Startup Item 
No

Few Users
Hundreds of users in the Norton Community have used this file.

Very New
This file was released less than 1 week  ago.

Good
Norton has given this file a favorable rating.

Source File:
NCrypt.exe

File Thumbprint - SHA:
c68beee19034d32b2baff25b470e8617ea3139d0715b50c8d8c40d90636e6dc4
File Thumbprint - MD5:
ab3d8aa84421227f5e9c69ab8f62aa16

Sorry, just saw your question to late.

No, Malwarebytes could not solve it (see attachement)

We'll need Malwarebytes user to report Malwarebytes detection. 

Um, did Malwarebytes act on it's detection? 
NCrypt.exe as a threat RiskWare.BitCoinMiner?

Datei nicht gefunden bzw. keine Informationen verfugbar fir dieses Dateiformat.
File not found or no information available for this file format.

@bjm

It seems to be a false positive message: file with same size and date/time compare with yours.

I will sleep a little easier now thanks to your help.
Close this item.
Thanks, have a good evening (22:00 in Germany) and stay healthy!

Markus

 

Um, did Malwarebytes act on it's detection? 
NCrypt.exe as a threat RiskWare.BitCoinMiner?

Datei nicht gefunden bzw. keine Informationen verfugbar fir dieses Dateiformat.
File not found or no information available for this file format.

Actually obvious, but I have not considered it. So thanks so far for 'side kick' on the exclusion topic:
"Malwarebytes for Windows antivirus exclusions list".


Thank you for the quick response!
Malwarebytes runs in real time, no exclusions.
Good idea to contact Malwarebytes as well. I'll go to Norton first, since this file can be found in an/the Norton folder.
My File Insight responses with an error (see attachment)

R U running Malwarebytes real-time or on-demand?
R U running Norton 360 + Malwarebytes mutual exclusions? 
https://support.malwarebytes.com/hc/en-us/articles/360038522974-Malwarebytes-for-Windows-antivirus-exclusions-list

Maybe, talk to Malwarebytes about Malwarebytes detections.
https://forums.malwarebytes.com/forum/122-false-positives/

 

 

https://www.virustotal.com/gui/file/c68beee19034d32b2baff25b470e8617ea3139d0715b50c8d8c40d90636e6dc4/detection