Jump to content

Malwarebytes

Is this program safe (After recent update)


3 replies to this topic

#1
Newb

    New Member

  • Members
  • Pip
  • 12 posts
  • Gender:Male
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fraps (Trojan.Backdoor.MRX) -> Quarantined and deleted successfully.
(Fraps - Safe)


Files Detected: 6
C:\Fraps\uninstall.exe (Trojan.Backdoor.MRX) -> Quarantined and deleted successfully.
(Fraps - Safe)

C:\Program Files\CCleaner\uninst.exe (Trojan.Backdoor.MRX) -> Quarantined and deleted successfully.
(CCleaner - Safe)

C:\Users\MBB\AppData\Local\Temp\is1598539481\zgInstaller.exe (Trojan.Backdoor.MRX) -> Quarantined and deleted successfully.
(What is this? Google doesn't show much. Does any legitimate program need this? This seems to be a redirecter?)

C:\Users\MBB\Downloads\ccsetup321.exe (Trojan.Backdoor.MRX) -> Quarantined and deleted successfully.
(CCleaner - Safe)

C:\Users\MBB\Downloads\npp.6.1.Installer.exe (Trojan.Backdoor.MRX) -> Quarantined and deleted successfully.
(Notepad++ - Safe)

C:\Users\MBB\Downloads\setup.exe (Trojan.Backdoor.MRX) -> Quarantined and deleted successfully.
(Fraps - Safe)

#2
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,992 posts
  • Gender:Male
  • Location:Tyneside, UK
We are aware of this and will have it resolved asap. My apologies for any inconvenience
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
Newb

    New Member

  • Members
  • Pip
  • 12 posts
  • Gender:Male
C:\Users\MBB\AppData\Local\Temp\is1598539481\zgInstaller.exe (Trojan.Backdoor.MRX) -> Quarantined and deleted successfully.
(What is this? Google doesn't show much. Does any legitimate program need this? This seems to be a redirecter?)

#4
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,690 posts
hard to say without the file but looks to be a legit part of an installer package.

Be sure to update the database so this is no longer detected.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us