Jump to content

Recommended Posts

Hi

Today I've found a process with the name Update.exe without Publisher name. Should I worried about it?

MalwareBytes Scan:

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 7/18/20
Scan Time: 12:02 PM
Log File: 6dc3eaf5-c8d5-11ea-bf92-0c9d92be85dd.json

-Software Information-
Version: 4.1.2.73
Components Version: 1.0.979
Update Package Version: 1.0.26981
License: Premium

-System Information-
OS: Windows 10 (Build 18362.959)
CPU: x64
File System: NTFS
User: DESKTOP-24EHERJ\Maxos

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 306559
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 2 min, 58 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

 

 

Capture.PNG

Addition.txt FRST.txt

Link to post
Share on other sites

Hello tokis and welcome to Malwarebytes,

The file you mention appears to be related to Microsoft Teams, if you want confirmation it is legitimate upload to VirusTotal, https://www.virustotal.com/gui/home/upload

Quote

HKLM-x32\...\Run: [TeamsMachineUninstallerLocalAppData] => C:\Users\Maxos\AppData\Local\Microsoft\Teams\Update.exe [2324624 2020-01-25] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKLM-x32\...\Run: [TeamsMachineUninstallerProgramData] => %ProgramData%\Microsoft\Teams\Update.exe --uninstall --msiUninstall --source=default

Let me know the outcome...

Thank you,

Kevin

Link to post
Share on other sites

3 minutes ago, kevinf80 said:

Hello tokis and welcome to Malwarebytes,

The file you mention appears to be related to Microsoft Teams, if you want confirmation it is legitimate upload to VirusTotal, https://www.virustotal.com/gui/home/upload

Let me know the outcome...

Thank you,

Kevin

Hi Kevin,

Thank you for your prompt reply.

It seems that the:

Quote

C:\Users\Maxos\AppData\Local\Microsoft\Teams\Update.exe

is legit , for the other one

Quote

%ProgramData%\Microsoft\Teams\Update.exe

the folder doesn't exist.

Thank you

Capture1.PNG

Link to post
Share on other sites

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Please review the following for Tips to help protect from infection

Thank you

 

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.