Author Topic: Windows Files Alarms  (Read 1521 times)

0 Members and 1 Guest are viewing this topic.

kubolek01

  • Guest
Windows Files Alarms
« on: February 20, 2014, 11:27:41 AM »
i got alert when trying to install Windroy.

It blocked MPK.EXE,The Windows file

I got Reference Acer Aspire 5315 (only with installed XP Professional)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37561
  • Not a avast user
Re: Windows Files Alarms
« Reply #1 on: February 20, 2014, 11:40:19 AM »
Quote
i got alert when trying to install Windroy.
what is windroy?

Quote
It blocked MPK.EXE,The Windows file
what does the block message from avast say? ....you may attach a screenshot

have you tested the file (MPK.EXE) at www.virustotal.com   if tested before, click new scan
post link to scan result here


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Windows Files Alarms
« Reply #2 on: February 20, 2014, 12:36:52 PM »
Windroy: http://www.socketeq.com/


I've done a bit of Research. MPK.exe means MyPopUpKiller.exe (Just an abbreviation)

However, upon further review it appears to be a KeyLogger, Trojan or Worm. Some state from the KGB? I'd recommend you disable that program until further notice and until it can be confirmed as a Keylogger.

The "Windows" File you see should be located here:
Code: [Select]
C:\Windows\System32 or sometimes in a subfolder of the "My Files" folder.
 Therefore the technical security rating is 88% dangerous

**NOTE** The file is Hidden. Using regular tactics of find and searching will not reveal anything. I've attached a few pics in order to find the file.

You can find some of the info @ http://www.file.net/process/mpk.exe.html
« Last Edit: February 20, 2014, 12:52:28 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Windows Files Alarms
« Reply #3 on: February 20, 2014, 12:49:08 PM »
Windroy lets Android run on Windows systems.
Kinda like Wine that lets you run Windows applications on Linux.

mpk.exe is a filename that is used by several legitimate applications.
However, in most instances where that file is found it is not a legitimate file but malware.
The location of that file as well as the size is a start to see which one it is.

Since avast flags it, I strongly suggest to follow these instructions:
http://forum.avast.com/index.php?topic=53253.0