Jump to content


Photo

Foo_Unpack.dll (False)


  • Please log in to reply
13 replies to this topic

#1 Conable

Conable

    New Member

  • Members
  • Pip
  • 9 posts

Posted 15 September 2009 - 05:57 PM

I'm not sure what you recommend for the whole "Developer Mode" since it wasn't the scan that caught it..it was the Protection client..

Anyway Foobar2000 is a media player application -- http://www.foobar2000.org/

When I opened an mp3 of mine the Protection put up a warning that said Foo_Unpack.dll which is intended to allow me to listen to music that's compressed in a .zip, .rar, .7z..etc..& called it a Worm(Auto) I believe it was..

I ignored it but I don't see it in the ignore list..& I played the same track several times & can't get the warning to reproduce..

#2 nosirrah

nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,402 posts
  • Location:Northampton, MA USA

Posted 15 September 2009 - 06:05 PM

Let me know if you can reproduce this , I fixed one earlier that could have been this so if it does not come back it was likely the same issue .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3 Conable

Conable

    New Member

  • Members
  • Pip
  • 9 posts

Posted 15 September 2009 - 07:01 PM

Well a little good news the error popped up again when I restarted my computer..this time I got a screen shot it so at least you know it's legitimate ;-)

Is there anything I can do to help more..I've ran scans before with 0 results..this has never occurred before since my database update to 2803 - 9.15.2009

It's the protection module catching it not the scans..

I've played this song before..on this machine..in Foobar..with Malwarebytes running..but I'll do what I can to help :-)

Posted Image

#4 nosirrah

nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,402 posts
  • Location:Northampton, MA USA

Posted 15 September 2009 - 08:09 PM

Please zip and attach a copy of the file being detected to your next post .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5 Conable

Conable

    New Member

  • Members
  • Pip
  • 9 posts

Posted 15 September 2009 - 08:23 PM

Huh well it won't let me post the file without some text in the post..so here's some text ^^

Attached Files



#6 Conable

Conable

    New Member

  • Members
  • Pip
  • 9 posts

Posted 15 September 2009 - 08:25 PM

I don't see an option to edit my post so..if it matter to you..it's a default plugin with Foobar too..not some custom 3P plugin

#7 e.s

e.s

    New Member

  • Members
  • Pip
  • 1 posts

Posted 16 September 2009 - 02:14 AM

Hi, after updating to the newest version I also am getting this foo unpack.dll autorun worm warning.

it wasnt the manual scanner that caught it, it was either the IP protection or the protection module.

it lists this IP as the outgoing IP 94.75.209.35

But as stated previously, foo_unpack.dll is part of the foobar media player software.

Maybe it is infected from the very start and its only now that we are able to pick it up, since I cant understand why its auto-running in the background when foo bar isnt even turned on, but there ya go.

I have put it in quarantine until I find out if its legit or not, I can send a copy of the file to you if you wish ?

#8 nosirrah

nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,402 posts
  • Location:Northampton, MA USA

Posted 16 September 2009 - 05:41 AM

This has already been corrected , make sure you update before rechecking .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9 yapaksa

yapaksa

    New Member

  • Members
  • Pip
  • 7 posts

Posted 20 September 2009 - 01:25 AM

 nosirrah, on Sep 16 2009, 11:41 AM, said:

This has already been corrected , make sure you update before rechecking .
Hi all, using
Database version : 2828 Date : 9/19/2009
and have the same alert with Foo_Unpack.dll

#10 nosirrah

nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,402 posts
  • Location:Northampton, MA USA

Posted 20 September 2009 - 01:29 AM

Zip and attach a copy of that file here please .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11 yapaksa

yapaksa

    New Member

  • Members
  • Pip
  • 7 posts

Posted 20 September 2009 - 01:32 AM

 nosirrah, on Sep 20 2009, 07:29 AM, said:

Zip and attach a copy of that file here please .
Here it is

Attached Files



#12 nosirrah

nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,402 posts
  • Location:Northampton, MA USA

Posted 20 September 2009 - 02:01 AM

I cant replicate this so there must be some sort of heuristic linking hitting here , what is the full path to that file on your system ?
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#13 yapaksa

yapaksa

    New Member

  • Members
  • Pip
  • 7 posts

Posted 20 September 2009 - 02:07 AM

C:\Applications\foobar2000\components

I had no problem with FOOBAR before.
The problem appeared since 2 days.

#14 yapaksa

yapaksa

    New Member

  • Members
  • Pip
  • 7 posts

Posted 20 September 2009 - 02:27 AM

OK,
With the Database version : 2829, all seems OK
Thank you nosirrah




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users