Jump to content

FP? 7dd7666.msi (Trojan.Agent.ED)


zongamin

Recommended Posts

This came up today in a quick scan, although nothing detected by hourly flash scans or realtime protection

 

Files Detected: 1
C:\Windows\Installer\7dd7666.msi (Trojan.Agent.ED) 
 
Only thing I had recently installed was a DuckDuckGo extension in Firefox (now removed)
 
Pretty sure this is an FP
Link to post
Share on other sites

Just had the same issue with C:\Program Files\FarStone\RestoreIT_XP\rescandisk.exe.

Scaning file with F_Secure shows no issue. Time stamp on file shows it has not been modified for a few years. Went ahead and removed. Below is mbam-log:

 

Malwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.org

Database version: v2014.01.12.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702


Protection: Enabled

1/12/2014 3:46:23 PM
mbam-log-2014-01-12 (15-46-23).txt

Scan type: Full scan (C:\|E:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 360338
Time elapsed: 1 hour(s), 23 minute(s), 35 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Program Files\FarStone\RestoreIT_XP\rescdisk.exe (Trojan.Agent.ED) -> Quarantined and deleted successfully.

(end)

Link to post
Share on other sites

can you please restore the file from quaritine and zip and attach it here?

Thanks.

Here is the log from running mbam.exe/developer:

 

 

Malwarebytes Anti-Malware (PRO) 1.75.0.1300

www.malwarebytes.org

Database version: v2014.01.12.06

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 8.0.6001.18702

Protection: Enabled

1/12/2014 9:55:48 PM

MBAM-log-2014-01-12 (23-33-09).txt

Scan type: Full scan (C:\|E:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 360698

Time elapsed: 1 hour(s), 36 minute(s), 10 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 2

C:\Documents and Settings\Dad\desktop\rescdisk.zip (Trojan.Agent.ED) -> No action taken. [ef57318392e8bd79ad051b5449b839c7]

C:\Program Files\FarStone\RestoreIT_XP\rescdisk.exe (Trojan.Agent.ED) -> No action taken. [a6a01e960f6b5ed8456dcba4ea1748b8]

(end)

 

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.