BleepingComputer.com: possible threat?

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

possible threat?

#1 User is offline   sniper8752 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 164
  • Joined: 15-August 11

Posted 11 February 2012 - 09:43 AM

I got this messsage, and wasn't sure what to do...
http://www.mediafire.com/imageview.php?quickkey=ezexi2moilxivmq
not sure what it means by "process name" for the first one. what does malwarebytes have to do with the printer .exe file?
also, the other ones have the process name as C:\WINDOWS\explorer.exe. And when i click on it (not opening it), or run a scan, it adds the same file. what is going on here???

could it be that some software (secunia or brother) is downloading and update, and installing it?

This post has been edited by sniper8752: 11 February 2012 - 09:46 AM


#2 User is online   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,805
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 11 February 2012 - 10:37 AM

Hello, where did you download MBAM from?
It may be an infected download if not from MBAM site or sponsored link.

It may also be... This is possibly a False positive. We should double check it before we take action.

Lets' upload this file for a second opinion on what it actually is..

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:
How to see hidden files in Windows

Please click this link-->Jotti

When the jotti page has finished loading, click the Browse button and navigate to the following file and click Submit.
<filepath>suspect.file

Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/


NOTE:
For submission to a specific anti-virus vendor see Submitting Virus Samples: How to Submit a Virus.
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#3 User is offline   sniper8752 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 164
  • Joined: 15-August 11

Posted 11 February 2012 - 02:17 PM

I actually bought it, from Circuit city. I know i got it from a safe site.

I had another post on here about i think it was, avast! calling intel bluetooth a threat... hahah weird!

i am getting this error for both when attempting to upload the .exe: http://www.mediafire.com/imageview.php?quickkey=l80v5uae6ebnhf4

This post has been edited by sniper8752: 11 February 2012 - 02:23 PM


#4 User is online   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,805
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 11 February 2012 - 04:30 PM

Hmm,what is the operating sytem?

Try to Take OWNERSHIP
Right click on the windows folder.

Goto properties.

Goto security

Goto advanced

Click on your username

Tick take ownership

Hit OK, if asked say all files and subfolders.
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#5 User is offline   sniper8752 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 164
  • Joined: 15-August 11

Posted 11 February 2012 - 07:45 PM

there is a problem. the file size is 142 MB.

it's windows 7 by the way.

This post has been edited by sniper8752: 11 February 2012 - 07:49 PM


#6 User is online   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,805
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 11 February 2012 - 08:16 PM

I find no info on those files. Why do you say MBAm is related to your printer?
as they are infection did you quaratine/delete/remove them?
If so does MBAM work after?
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#7 User is offline   sniper8752 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 164
  • Joined: 15-August 11

Posted 12 February 2012 - 05:36 PM

i use to click on properties for it, and avg would pop up. also, when i scanned it, it said it was malicious.
malwarebytes has always worked. not sure what was going on the the malwarebytes thing. i think i will just delete it, and hopefully that fixes the issue.

#8 User is online   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,805
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 12 February 2012 - 09:07 PM

Quarantine it if you have that option, It cannot hurt the PC from there.

1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel.
2. Restart your computer (very important).
3. Download and run this utility. Mbam clean
4. It will ask to restart your computer (please allow it to).
5. After the computer restarts, install the latest version from here. http://www.malwarebytes.org/mbam-download.php
Note: You will need to reactivate the program using the license you were sent.
Note: If using Free version, ignore the part about putting in your license key and activating.
Launch the program and set the Protection and Registration.
Then go to the UPDATE tab if not done during installation and check for updates.
Restart the computer again and verify that MBAM is in the task tray and run a Quick Scan and post that log.
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#9 User is offline   sniper8752 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 164
  • Joined: 15-August 11

Posted 12 February 2012 - 09:57 PM

i installed it right from the disk. it seems to run fine.

#10 User is online   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,805
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 12 February 2012 - 10:09 PM

Cool !! If there are no more problems or signs of infection, you should Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been backed up, renamed and saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Posted Image > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.

  • Then use Disk Cleanup to remove all but the most recently created Restore Point.
  • Go to Posted Image > Run... and type: Cleanmgr
  • Click "Ok". Disk Cleanup will scan your files for several minutes, then open.
  • Click the "More Options" tab, then click the "Clean up" button under System Restore.
  • Click Ok. You will be prompted with "Are you sure you want to delete all but the most recent restore point?"
  • Click Yes, then click Ok.
  • Click Yes again when prompted with "Are you sure you want to perform these actions?"
  • Disk Cleanup will remove the files and close automatically.

Vista and Windows 7 users can refer to these links:
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users