Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan.Downloader weird folder name but comes up clean when scanning on other PC


  • Please log in to reply
2 replies to this topic

#1 Anderath

Anderath

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:55 PM

Posted 24 December 2014 - 06:34 PM

Hello Bleepingcomputer,

 

I am working on this PC for this company, I've seen multiple instances of this same type of virus. I've uploaded it to Virustotal in the past and it's always came up clean. It seems harmless as it's just foldernames that Malwarebytes is catching but there are some just plain weird looking files that may be a for a legacy application they all use. See below for a screenshot of the files and folder paths:

 

https://imgur.com/q3r3DBv

 

Unfortunately, I no longer have access to the machine but I've been able to get the .quar files from Malwarebytes. I'm not sure how to extract them to re-upload to virustotal.

 

I'm just wondering if anyone has seen these folder paths before and/or could validate my concerns.

 

I know the guy had multiple toolbars installed on there but sometimes I've done a scan and the only thing that shows up on it is those folder paths.

Please let me know what you guys think.



BC AdBot (Login to Remove)

 


m

#2 buddy215

buddy215

  • BC Advisor
  • 12,608 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:55 PM

Posted 24 December 2014 - 06:58 PM

Were all those items deleted/ quarantined by MBAM? MBAM is a great program but you need to use others, too.

Suggest using the programs below if you get access to the computer. Of course, if you will never have access what is the purpose of

going further to find what some file is?

CCleaner - PC Optimization and Cleaning - Free Download

AdwCleaner Download

Junkware Removal Tool Download

Free Virus Scan | Online Virus Scanner from ESET


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#3 neneduty

neneduty

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 25 December 2014 - 01:09 PM

Never any disrespect intended. When you left that computer, are you sure it was clean?






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users