I've just updated my MBAM (free version) in my win XP sp3 when at the quick scan during euristic-extra scan I've found the backdoor.bot in sysprep.exe located in system32 folder.
I've quarantined the file but I'm wondering if it could be a false positive and the file should be therefore restored (I've known that sysprep.exe is a legitimate file of the system).
Thanks in advance for any suggestions.
#1
Posted 13 September 2008 - 10:07 AM
#2
Posted 13 September 2008 - 12:13 PM
Some additional info to help you in finding a solution to my problem:
1) a full scan before the quarantine confirmed the infection in sysprep.exe
2) if I'm not wrong the file sysprep.exe seems to have been added to my system with a recent installation of Visual c++ libraries
3) Superantispyware did not find anything; my Kaspersky internet security (my realtime protection) did not find anything either
4) with an on-line scan with VirusTotal 30 out of 31 products did not find anything; only the last one, webwasher guard (?) found something "suspicious"
Keep waiting for your suggestions
Cheers
1) a full scan before the quarantine confirmed the infection in sysprep.exe
2) if I'm not wrong the file sysprep.exe seems to have been added to my system with a recent installation of Visual c++ libraries
3) Superantispyware did not find anything; my Kaspersky internet security (my realtime protection) did not find anything either
4) with an on-line scan with VirusTotal 30 out of 31 products did not find anything; only the last one, webwasher guard (?) found something "suspicious"
Keep waiting for your suggestions
Cheers
#3
Posted 13 September 2008 - 01:25 PM
Will be corrected this morning .
#4
Posted 13 September 2008 - 01:40 PM
Please update and scan again , MBAM should now be able to tell the difference between the real and fake file .
#5
Posted 13 September 2008 - 03:15 PM
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account

Back to top










