[Kaspersky/w11] OpenHuman.exe flagged as PDM:Trojan.Win32.Generic + IFEO Debugger entries #1946
DouglasOttoDavila
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I’m opening this as a possible false positive report. I am not claiming this is malicious behavior, but I wanted to share the details because Kaspersky triggered a high-severity behavioral detection shortly after installing/running OpenHuman on Windows.
Environment
C:\Program Files\OpenHuman\OpenHuman.exeC:\Users\<user>\AppData\Local\Programs\Ollama\ollama.exeKaspersky detections
Kaspersky reported the following detection for OpenHuman:
OpenHuman.exeC:\Program Files\OpenHumanPDM:Trojan.Win32.GenericKaspersky then reported actions such as:
OpenHuman.exeterminatedOpenHuman.lnkdeletedOpenHuman.exedeletedOllamaSetup.exescheduled for deletion after rebootIn another report, Kaspersky detected and disinfected multiple registry entries under:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\...\DebuggerDetection name:
HEUR:Trojan.Multi.Misslink.aAffected IFEO/Debugger targets included entries related to:
nordvpn.exenordvpn.diagnosticstool.exenordsecurity.nordvpn.diagnosticstool.application.exenvidia app.exesetup.exewondershare filmora launcher.exeCleanup performed
After uninstalling/removing OpenHuman and rebooting, I ran the following checks:
Both returned:
End of search: 0 match(es) found.I also removed:
Ollama appears to remain installed in the expected user-local path:
C:\Users\<user>\AppData\Local\Programs\Ollama\ollama.exeSHA256 of ollama.exe:
A820ECBC8A4B8654064E89EFDEB4340EF29E40EFBCBECBBC704019739F0286F3
Questions
Could the maintainers please clarify whether OpenHuman intentionally creates, modifies, or interacts with any Image File Execution Options...\Debugger registry entries on Windows?
Also, could you confirm whether the app or installer performs any behavior that might trigger Kaspersky’s behavioral detection, such as:
If this is expected behavior or a known false positive, it would be helpful to document it, ideally with:
I’m happy to provide the Kaspersky CSV reports privately if needed.
Thanks.
Beta Was this translation helpful? Give feedback.
All reactions