Jump to content

sUBs

Honorary Members
  • Posts

    10,157
  • Joined

  • Last visited

  • Days Won

    1

Posts posted by sUBs

  1. Hello. For false positives, we would require a developer's log.

    Kindly follow the instructions detailed here : http://forums.malwarebytes.org/index.php?showtopic=3228

    Also dequarantine the following files and zip/attach them to your next reply.

    C:\USERS\HEAVYOAK\APPDATA\ROAMING\RAINMETER\ADDONS\NIRCMD\NIRCMD.EXE

    C:\USERS\HEAVYOAK\APPDATA\ROAMING\RAINMETER\ADDONS\NIRCMD\NIRCMDC.EXE

  2. This is just my personal opinion. It depends on what the machine is used for.  If used for banking or for business purposes, once a machine has got infiltrated once, I will no longer trust it. For my own peace of mind, I will start afresh on a clean slate.

  3. @Krissen, this is a not a false positive. Those files in the folder labelled as 'Adobe' appears to be related to remote-admin software. You can compare some of the file names from here > http://www.shouldiremoveit.com/NetSupport-Manager-14804-program.aspx

     

    Best let mbam remove it for you. After doing that, I would advise you allow mbam to perform a full scan on the afflicted machine.

     

    Until such time that completes, I would also advise that you use another machine and change all your important passwords from there.

  4.  Is there any way of telling if they are false positives related to the CyberPowerDVD one, or if they are real?

     

    Modules: 1
    Trojan.Agent.ED, C:\Program Files (x86)\CyberLink\PowerDVD9\CLRCEngine3.dll, Delete-on-Reboot, [8b430b5c107a38fec3be0935b74bba46], 
     
    Registry Keys: 37
    Trojan.Agent.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D49CACC9-D3F0-46E6-AC91-66C5534EA367}, Quarantined, [8b430b5c107a38fec3be0935b74bba46], 
    Trojan.Agent.ED, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D49CACC9-D3F0-46E6-AC91-66C5534EA367}, Quarantined, [8b430b5c107a38fec3be0935b74bba46],

     

     

    See those numbers I highlighted in green? This means all 3 detections are related.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.