anyone got any ideas on this

Discussion in 'Computer Security' started by greenbrucelee, Jun 29, 2009.

  1. greenbrucelee
    Highly Decorated Member Award

    greenbrucelee Zettabyte Poster

    14,292
    265
    329
    ESET flagged this up the other day and have quarantined it just incase.

    C:\system volume information\_restore{2ED75F99-A604-42A8-9CA5-859C54CCA3CE}\RP148\A0043867.exe probably a variant of Win32/Statik potentially unwanted application

    Anyone know anything about this?
     
    Certifications: A+, N+, MCDST, Security+, 70-270
    WIP: 70-620 or 70-680?
  2. zebulebu

    zebulebu Terabyte Poster

    3,748
    330
    187
    Probably a false positive. Check it with VirusChief - more than likely just some crappily packed executable.

    EDIT - my mistake, googling A0043867.exe shows a few HJT logs that seem to mark it as a munged name for a trojan. Have a look on ESET's forums to see whether its really a threat.
     
    Certifications: A few
    WIP: None - f*** 'em
  3. zimbo
    Honorary Member

    zimbo Petabyte Poster

    5,215
    99
    181
    turn off system restore and scan in safe mode then restart and turn system restore on... there could be a few more nasties on there..

    try http://www.virustotal.com/ they very good for malware analysis! :)
     
    Certifications: B.Sc, MCDST & MCSA
    WIP: M.Sc - Computer Forensics
  4. LukeP

    LukeP Gigabyte Poster

    1,194
    41
    90
    I never came accross anything that couldn't be removed by BitDefender online scanner, Malwarebytes Anti-Malware and SuperAntiSpyware combo. Some things left out by one were detected and sorted out by another.
     
    WIP: Uhmm... not sure
  5. greenbrucelee
    Highly Decorated Member Award

    greenbrucelee Zettabyte Poster

    14,292
    265
    329
    No threats found, although I ran Eset in safe mode and had a few unpack errors and a few damaged archive errors.

    I also ran the scanners linked by Zeb and Zimbo they found nothing either and I ran Trend Micro too.
     
    Certifications: A+, N+, MCDST, Security+, 70-270
    WIP: 70-620 or 70-680?
  6. zebulebu

    zebulebu Terabyte Poster

    3,748
    330
    187
    False positive it is then!

    As I've opined on here before - McAfee rules. I've never had it detect a False Positive on me before (in an environment where I can control the detections that is - i.e. under EPO)
     
    Certifications: A few
    WIP: None - f*** 'em
  7. greenbrucelee
    Highly Decorated Member Award

    greenbrucelee Zettabyte Poster

    14,292
    265
    329
    Never had eset do that to me before, I have submitted the file to their analasys team and let them know that it must be a false positive. Thanks for your help Zeb

    I wonder if this due to me changing from policy based mode to automatic.
     
    Certifications: A+, N+, MCDST, Security+, 70-270
    WIP: 70-620 or 70-680?

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.