A little scare

Status
Not open for further replies.

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
how_did_you_get_there.png



My Downloads folder is located on the D:\ drive, so I'm not sure how this got there... who knows? :mad:
 

Jack

Administrator
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
did you do the "nasty" in the past... :diablo:: ?...played with MDL on your system? :p
That yourbot.exe is usually a zeus trojan
 

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
:lol: I never play with MDL contents on my host.

Glad Avast caught it though, I was going to use NoVirusThanks Uploader to see what it was. :p
 

bogdan

Level 1
Jan 7, 2011
1,362
It got identified as a dropper so you should check if windows settings are ok, you can access TaskManager, regedit, Windows updates are still on, etc. Check autorun entries and hosts file. (more info).
 

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
I can access Task Manager, regedit and Windows Updates (just recently updated to SP1).

MBAM : clean
Avast : still scanning
Hitman Pro : Shows Explorer.exe : Malware (Medium Risk Malware) Prevx : Quarantine. -Edit: WPF replaced Explorer, I think it's because I used a custom start orb.

Could it be because I use Custom Themes and Start Orb?

Also before avast! detected the file, it was dated 15th Feb (from within Windows Explorer).
 

bogdan

Level 1
Jan 7, 2011
1,362
Could it be because I use Custom Themes and Start Orb?
It could be. That's why I hate them so much :p. You could try uploading the explorer.exe hitman detects to virustotal and check the results.
 

MetalShaun

Level 1
Mar 3, 2011
424
So did Avast catch it as it was downloaded or was it just sat there on your drive untill Avast had a Sig for it??
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Seems the file is suspicious as long avast detected and clean it no worries.
 

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
All is clear and fine. ;)
 

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Hey, just figured out how the file got there.

Since I use NoVirusThanks Uploader it downloads the file there before uploading it to their servers for scanning.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top