Jump to content

BitCoinMiner found in Express VPN - False Pos?


topangajack

Recommended Posts

Today, MWB scans of two Win 7 PCs detected RiskWare.BitCoinMiner in Express VPN. The files were quarantined and the vpn no longer works. I contacted Express VPN and they claim this is a False Positive.

Scan log:

"Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 9/12/17
Scan Time: 11:30 AM
Log File: MWB Scan 9-12-17.txt
Administrator: Yes

-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.160
Update Package Version: 1.0.2786
License: Premium

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System

-Scan Summary-
Scan Type: Hyper Scan
Result: Completed
Objects Scanned: 2124
Threats Detected: 4
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 0 min, 59 sec

-Scan Options-
Memory: Enabled
Startup: Disabled
Filesystem: Disabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Disabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 1
RiskWare.BitCoinMiner, C:\PROGRAM FILES (X86)\EXPRESSVPN\BOOTSTRAP\AMD64\NSSM.EXE, No Action By User, [94], [434082],1.0.2786

Module: 1
RiskWare.BitCoinMiner, C:\PROGRAM FILES (X86)\EXPRESSVPN\BOOTSTRAP\AMD64\NSSM.EXE, No Action By User, [94], [434082],1.0.2786

Registry Key: 1
RiskWare.BitCoinMiner, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ExpressVpnService, No Action By User, [94], [434082],1.0.2786

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 1
RiskWare.BitCoinMiner, C:\PROGRAM FILES (X86)\EXPRESSVPN\BOOTSTRAP\AMD64\NSSM.EXE, No Action By User, [94], [434082],1.0.2786

Physical Sector: 0
(No malicious items detected)

(end)"

Can you confirm that this is a FP? Thanks

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.