Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

C:\program file with file name warning on boot


  • Please log in to reply
1 reply to this topic

#1 ajg617

ajg617

  • Members
  • 68 posts
  • OFFLINE
  •  
  • Local time:06:20 AM

Posted 27 February 2016 - 08:38 AM

Windows 8.1 on a Toshiba Satellite P55t-A5118.  I'm not sure if the machine is infected but too many odd occurrences.

 

I broke one my own cardinal rules on Thursday the 25th by accessing the hotel wifi which was 9 digit pin protected, the pin being generated randomly when the key card was made. I did not notice any issues until I booted the laptop up last night and got the windows File Name Warning for a file names "C;\program".  I looked at the properties and everything was unknown but it was date/time stamped during my hotel stay.  Pop-up prevented Webroot from starting until I re-named or ignored the issue.

 

I have two accounts (one the original MS account which I never use).  I logged into the original account and did not get the same pop-up for File Name Warning which makes me think there might be something in the registry for the other login.  I ran a Webroot scan and a Malwarebytes scan both of which came up empty.  Some of the webroot features were not working which then made me a bit suspicious and in fact it only scanned about 7500 files which is way low. Also noticed that two hidden icons were present but the icons were not visible and could not be launched.

 

Re-logged in the primary account and received the pop-up again at which point I deleted the file in question.  Re-ran malwarebytes with nothing detected.  Windows Solve PC issues showed that all anti-virus was turned off and I then received a pop-up for requesting permission for WRSA.exe to modify the system (permission the webroot executable already had).  I can restore to an earlier point but would prefer to find out if there is anything else left over.  Any suggestions?

Thanks,

AJG

 

 



BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • BC Advisor
  • 12,883 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:20 AM

Posted 27 February 2016 - 12:54 PM

Please follow the instructions in the Malware Removal and Log Section Preparation Guide starting at Step 6.

  • If you cannot complete a step, then skip it and continue with the next.
  • In Step 6 there are instructions for downloading and running FRST which will create two logs.

When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team.

Start a new topic, give it a relevant title and post your log(s) along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. If you cannot produce any of the required logs...start the new topic anyway. Explain that you followed the Prep. Guide, were unable to create the logs, and describe what happened when you tried to create them. A member of the Malware Removal Team will walk you through, step by step, on how to clean your computer.

After doing this, please reply back in this thread with a link to the new topic so we can close this one.

 

DO NOT bump your new topic. Wait for a response from one of the Team Members.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users