Gizmos Freeware Reviews  

Go Back   Gizmo's Freeware Forum > Freeware Forum > General Computer Support

Reply
 
Thread Tools Display Modes
Old 12. Dec 2011, 04:05 PM   #1 (permalink)
Full Member
 
Join Date: Oct 2011
Posts: 88
Default trojan dropper file

hello, it's me .....again.

mbam has captured the following:

d:\i386\Apps\App07410\p2go\wmfdist.exe

the capture calls it: trojan dropper file. It wont let me quarantine it, not sure if i can or if i need to delete it "only" because im somewhat apprehensive as to what it may leave behind in little pieces. mse, msert, hmanpro,tdsskiller, all fail to catch it.

reasearch indicates to me, this or a version of this, has been around since early 2000, but i cant find solid information as to a prevention /removal tool.

i have reasonable suspicion it is located in an "options" file. my suspicion came soley from what i have read about it, hoping i wouldnt have to bother you'all but im stuck.

i actually know the site i picked this up at if it is of any help, prior to going there the site was listed as safe by a tool i cant mention by name here, but im begining to learn i need a good set of tools that would coincide with someone involved in a business with an investigative nature.

windows xp home, version 2002. by the nature of my profession this computer is only used by me, and extremely limited social networking, no e-mails,

thanks in advance
placou 1968 is online now   Reply With Quote
Old 12. Dec 2011, 05:00 PM   #2 (permalink)
Editor
 
4goTTen21's Avatar
 
Join Date: Oct 2011
Location: San Rafael, Argentina
Posts: 237
Default

Doesn't look like a threat. Folder p2go directory is created by Cyberlink's Power2Go burn utility as temporary path. wmfdist.exe is a part of Microsoft Windows Media Player. Try uploading file to virus total.
__________________
You call destiny to the future you can't control.
4goTTen21 is online now   Reply With Quote
Old 12. Dec 2011, 08:44 PM   #3 (permalink)
Editor
 
Join Date: May 2008
Posts: 303
Default

Might be a false positive and should have been corrected if it is. These are posts on it, though they are presumable found in different locations (WMP).
http://forums.malwarebytes.org/index...owtopic=101691
http://forums.malwarebytes.org/index...owtopic=101700

Try a re-scan after updating your MBAM.
mr6n8 is online now   Reply With Quote
Old 14. Dec 2011, 03:51 PM   #4 (permalink)
Full Member
 
Join Date: Oct 2011
Posts: 88
Default

thanks guys, i think i finally get it, based upon the links im gona disregard unless i see further, i downloaded emisisoft and it caught some thing and i havent had any further problems, once again you guys are awesome, thanks
placou 1968 is online now   Reply With Quote
Old 14. Dec 2011, 04:29 PM   #5 (permalink)
Editor
 
4goTTen21's Avatar
 
Join Date: Oct 2011
Location: San Rafael, Argentina
Posts: 237
Default

It's a pleasure
__________________
You call destiny to the future you can't control.
4goTTen21 is online now   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT +1. The time now is 11:39 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2