Author Topic: Should I be concerned about this?  (Read 11703 times)

0 Members and 1 Guest are viewing this topic.

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Should I be concerned about this?
« on: March 02, 2013, 04:31:16 PM »
I got up this morning, went to the computer, and found an error message saying that a file had a problem and needed to be closed. What's strange is that it is a long file name containing a bunch of random letters. Here are the contents of the error report from "Problem Reports and Solutions":

"Problem Event Name:   BEX
Application Name:   067d4483-49e5-4d33-ab51-5d8d67b5e55d.exe
Application Version:   0.0.0.0
Application Timestamp:   5130c325
Fault Module Name:   StackHash_fd00
Fault Module Version:   0.0.0.0
Fault Module Timestamp:   00000000
Exception Offset:   00000000
Exception Code:   c0000005
Exception Data:   00000008
OS Version:   6.0.6002.2.2.0.768.3
Locale ID:   1033
Additional Information 1:   fd00
Additional Information 2:   ea6f5fe8924aaa756324d57f87834160
Additional Information 3:   fd00
Additional Information 4:   ea6f5fe8924aaa756324d57f87834160"


I opened Avast, and it showed that that file was the last thing that the Behavior shield scanned, but didn't find it suspicious. The file was in the Windows\Temp directory and is no longer there. I did a full Avast scan which didn't find anything either. If this isn't wasn't a virus or hacker attempt of some sort, what kind of normal program has an executable file name like that?

I am using Windows Vista Home Premium and the latest Avast.




Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Should I be concerned about this?
« Reply #1 on: March 02, 2013, 04:43:36 PM »
Did you just get a windows update or update another programme ?

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Should I be concerned about this?
« Reply #2 on: March 02, 2013, 04:49:26 PM »
Did you just get a windows update or update another programme ?

Not as far as I know. I just woke up and the file crash error was on the computer. As far as I know, I didn't get any new Windows updates today, unless it was some sort of stealth update.


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Should I be concerned about this?
« Reply #3 on: March 02, 2013, 04:57:04 PM »
BEX is a buffer overflow error and is part of windows DEP protection

How is the computer behaving anything untoward ?

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Should I be concerned about this?
« Reply #4 on: March 02, 2013, 05:10:15 PM »
The computer seems to be behaving fine.

I just checked the Event Viewer to see what Tasks may have been performed at the time of the crash, which was 6:50AM. At that time, there was an Avast emergency update due to a time trigger condition, but it also says that the task was completed.

I don't know if that is related or not.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Should I be concerned about this?
« Reply #5 on: March 02, 2013, 05:23:00 PM »
Hmm just looked through my logs and there were no untoward events

Do you have any minidumps at C:\windows\minidump ?

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Should I be concerned about this?
« Reply #6 on: March 02, 2013, 05:28:39 PM »
I just checked that directory and I see three dump files. It looks like 02/10/2012 is the most recent that these were modified.

I wonder if this was some buffer overflow exploit attempt that Microsoft hasn't patched yet.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Should I be concerned about this?
« Reply #7 on: March 02, 2013, 05:31:42 PM »
It may have been as it was DEP that stopped it

Could you upload the last two minidumps to a file sharing site for me to collect and look at

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Should I be concerned about this?
« Reply #8 on: March 02, 2013, 05:40:56 PM »
Would the minidumps have any new information? One says it was last modified on 02/10/2012, and the other says it was last modified on 02/03/2012. And there is a third that was last modified in 2011.

I've never had an issue like this in the almost five years I've been using Windows Vista.  But since switching from XP to Vista, since it is so security intensive, I've always relied on its own Firewall rather than installing a separate Firewall. Maybe it's time to install another Firewall.



Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Should I be concerned about this?
« Reply #9 on: March 02, 2013, 05:45:32 PM »
If you wish I can check the system out for you

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Should I be concerned about this?
« Reply #10 on: March 02, 2013, 05:53:27 PM »
Unfortunately I don't have Avast remote assistance installed, because I thought that it could be used as an exploit. If you need it, I could install it real quick.
« Last Edit: March 02, 2013, 05:57:14 PM by mbd35 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Should I be concerned about this?
« Reply #11 on: March 02, 2013, 05:58:22 PM »
We can do it via the forum just as easily

Download OTL  to your Desktop
Secondary link
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.


  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
winsock.*
/md5stop
CREATERESTOREPOINT


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Attach both logs

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Should I be concerned about this?
« Reply #12 on: March 02, 2013, 08:04:19 PM »
Here are the two log files. Thanks for the help!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Should I be concerned about this?
« Reply #13 on: March 02, 2013, 08:08:21 PM »
Both logs show clean with no anomalous software or registry entries at all.  Nor any critical errors on the event report 

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Should I be concerned about this?
« Reply #14 on: March 02, 2013, 08:17:33 PM »
Okay, thanks. It may have been nothing then. At least I can be fairly confident there is no malware.