Jump to content

Malware.Heuristic.1008 found


precise

Recommended Posts

Malware.Heuristic.1008 found in 

C:\OEM\PRELOAD\APP\ACERUSEREXPERIENCEPROGRAMFRAMEWORK\5.00.3002\UEIPUWP\11F8477DC1034A749927CF5092491930.APPXBUNDLE

I believe I did have the agressive thing checkmarked. Here is the export log

I can't find anything related to this online, is it a false positive or something alarming? 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 6/22/22
Scan Time: 1:19 PM
Log File: 7e2d8620-f24f-11ec-80da-98eecbe9626c.json

-Software Information-
Version: 4.5.9.198
Components Version: 1.0.1699
Update Package Version: 1.0.56401
License: Premium

-System Information-
OS: Windows 10 (Build 19043.1766)
CPU: x64
File System: NTFS
User: DESKTOP-QAS4T68\maryp

-Scan Summary-
Scan Type: Custom Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 589283
Threats Detected: 1
Threats Quarantined: 1
Time Elapsed: 3 hr, 15 min, 42 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 1
Malware.Heuristic.1008, C:\OEM\PRELOAD\APP\ACERUSEREXPERIENCEPROGRAMFRAMEWORK\5.00.3002\UEIPUWP\11F8477DC1034A749927CF5092491930.APPXBUNDLE, Quarantined, 1000001, 0, 1.0.56401, 0000000000000000000003F0, dds, 01826540, D5B90CEDBBAB917A84F6CD59A7861E07, 1BE2DDA2D3DF20FC102E112FD45C3716EB1E68036161734E1EEAF592441377C6

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

Link to post
Share on other sites

16 minutes ago, Porthos said:

Please see here and turn off that non default setting to avoid these FP's

You can restore it from quarantine after.

 

Thank you Porthos, However, How can I be sure that the file is not infected or a type of malware? I do not want to restore or unquarantined unless I can be sure. I cant find anything related to the file online anywhere.

I am worried because Malwarebyte did pick up some PUPS.Trovi in the scan I ran before that, But I was using Malwarebytes browser guard extension, with adblocker plus, along with Malwarebytes Premium Pro so I dont think the PUP actually harmed the computer or browser because I didnt see anything unsual, no browser extension, toolbar or redirected home page.

 

Any thoughts?

Link to post
Share on other sites

2 minutes ago, precise said:

How can I be sure that the file is not infected or a type of malware?

It is part of ACER's preload junk. C:\OEM\PRELOAD\APP\ACERUSEREXPERIENCEPROGRAMFRAMEWORK

2 minutes ago, precise said:

And the PUPS were found in google chrome sync data

See the following to fix that. They usually comeback after cleaning when you open Chrome because of sync.

 

  • Like 1
Link to post
Share on other sites

39 minutes ago, Porthos said:

It is part of ACER's preload junk. C:\OEM\PRELOAD\APP\ACERUSEREXPERIENCEPROGRAMFRAMEWORK

See the following to fix that. They usually comeback after cleaning when you open Chrome because of sync.

 

Yea I deleted all sync data, and deleted cookies and then turned off sync. Should be okay now. Just hoping that Malwarebytes premium and browser guard was enough to prevent ant harm from the PUP.Trovi sitting in the sync files

  • Like 1
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.