Jump to content

False Positive?


CrimsonMoon

Recommended Posts

Help! did a scan earlier on my system using malwarebytes and it detected C:\Users\torres\AppData\Local\Google\Chrome\User Data\Default\Preferences as a Pup.Optional.Terraclicks.shrtcln

was in a hurry so i didn't bother to clean it yet and just closed the scan and even forgot to export it, when i got back home I did a re-scan and it showed nothing, and did a scan on the file using virustotal and it was a negative. was it possible that it was a false positive and it just went away due to a more recent update? since today was the first time in at least a week that I logged on/turned on the pc due to being busy. 

Link to post
Share on other sites

  • Staff
14 minutes ago, CrimsonMoon said:

C:\Users\torres\AppData\Local\Google\Chrome\User Data\Default\Preferences

 

Hard to say without a copy of this file. If its no longer detected then though it probably wont show anything.

 

This is the google preferences file and it could of been a visit to a site that may have triggered it,

 

 

 

 

 

 

 

Link to post
Share on other sites

  • Staff

It was likely a URL within the Preferences file due to caching or DNS Prefetching (which helps speed up searches & loading of pages, etc). Typically caching/Prefetching is fairly limited so once a certain number of cached URLs have been reached, the older ones are "evicted" to make room for the new.

So if you visited a site that had an advert for terraclicks, because the browser still needs to resolve that URL (even though you didn't click it - it just does this so it can load quicker if you did) it will cache it along with the resolved info. (It does not care if it is an advert URL or a URL you might click every day from a specific web page)

You probably closed the browser at some point & re-opened it, visited some other sites which loaded some new URLs. This would have cleared the terraclicks one & therefore no more detection by MBAM.

In your case, it did not quarantine the URL within Preferences because you just closed the scan (without taking action). The URL was removed already when you ran the scan again.

Either way - no harm done. Chrome cleaned itself up just because of how it limits its cache. If you had let MBAM clean it, no harm would have been done either.

If you had the "full" infection of Terraclicks, your shortcuts would likely have been messed up causing advertisements to load every time you clicked your browser shortcut. (we can clean that too if it happened)

This page may help to explain how the caching/prefetching works in Preferences: (sorry, it is a bit teckky)

https://www.chromium.org/developers/design-documents/dns-prefetching

 

Hope that helps. :)

Link to post
Share on other sites

That's why! thank you for that info blended! It really cleared up my mind. so it does not matter if it was an advert which i didn't click correct and didn't even get infected.

At least it also re-assures me that MBAM detects almost anything even infected or possible malware advertisements! 

Link to post
Share on other sites

  • Staff

You're very welcome.

Nope - it doesn't really matter. The advert URL was simply on some web site you visited & your browser cached it. Because it was something you didn't bother to click or interact with, the browser just cleared that (and likely others) URL.

Indeed. We are pretty aggressive not only with true malware but also unwanted programs and other junk. We are aggressive against malvertising too by blocking URLs/IPs and so on that deliver this junk.

Link to post
Share on other sites

1 hour ago, blender said:

You're very welcome.

Nope - it doesn't really matter. The advert URL was simply on some web site you visited & your browser cached it. Because it was something you didn't bother to click or interact with, the browser just cleared that (and likely others) URL.

Indeed. We are pretty aggressive not only with true malware but also unwanted programs and other junk. We are aggressive against malvertising too by blocking URLs/IPs and so on that deliver this junk.

Thanks a bunch! this really cleared it up! must've been a hijacked ad on a legit website. 

Link to post
Share on other sites

  • Staff

If MBAM finds it again, be sure to exit the browser & let MBAM clean up. The cleanup goes through a few other routine checks and so on which works best if Chrome is closed. It may require a reboot to finish.

In any case, it isn't a false positive.

If you still have trouble after, please follow instructions at this page to get additional help to clean up any remains if any.

 

Link to post
Share on other sites

12 hours ago, blender said:

If MBAM finds it again, be sure to exit the browser & let MBAM clean up. The cleanup goes through a few other routine checks and so on which works best if Chrome is closed. It may require a reboot to finish.

In any case, it isn't a false positive.

If you still have trouble after, please follow instructions at this page to get additional help to clean up any remains if any.

 

Will post there thanks blender!

Link to post
Share on other sites

18 hours ago, blender said:

If MBAM finds it again, be sure to exit the browser & let MBAM clean up. The cleanup goes through a few other routine checks and so on which works best if Chrome is closed. It may require a reboot to finish.

In any case, it isn't a false positive.

If you still have trouble after, please follow instructions at this page to get additional help to clean up any remains if any.

 

I found a "cookie" regarding terraclicks.com.. maybe that's what's causing the detection? 

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.