Author Topic: Suspicious Files Detected  (Read 5404 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Suspicious Files Detected
« on: December 03, 2018, 11:10:48 AM »
Hi, my first time posting here so apologies if I'm in the wrong area!
Avast has detected 54 suspicious files which "MAY" be harmful. 
I'm not sure whether I should delete them or not!
The threat name is: Rootkit: Hidden Process
All the files under under C:\Windows\Installer and all have the same name: MSIC5C7.tmp
What should I do?
thank you

edit:  I also have Malwarebytes installed.  I just ran a scan and it didn't detect anything!
« Last Edit: December 03, 2018, 11:51:17 AM by annew52 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Suspicious Files Detected
« Reply #1 on: December 03, 2018, 11:54:44 AM »
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Suspicious Files Detected
« Reply #2 on: December 03, 2018, 12:15:23 PM »
Files attached, thank you

REDACTED

  • Guest
Re: Suspicious Files Detected
« Reply #3 on: December 03, 2018, 12:28:55 PM »
Also a screen shot of the Avast message

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Suspicious Files Detected
« Reply #4 on: December 03, 2018, 12:30:17 PM »
was this a boot time scan?


REDACTED

  • Guest
Re: Suspicious Files Detected
« Reply #5 on: December 03, 2018, 12:33:24 PM »
Sorry, not quite sure which scan you mean.  The Avast message just popped up while I was writing an email, I assume it was running a scan in the background while I was working.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Suspicious Files Detected
« Reply #6 on: December 03, 2018, 12:38:08 PM »
Quote
Sorry, not quite sure which scan you mean.
https://support.avast.com/en-ww/article/Antivirus-Boot-time-Scan


Quote
The Avast message just popped up while I was writing an email, I assume it was running a scan in the background while I was working.
OK


it may take hours before the malware expert is online ...





REDACTED

  • Guest
Re: Suspicious Files Detected
« Reply #7 on: December 03, 2018, 12:41:52 PM »
Thanks Pondus, should I run this boot time scan?  I'm just worried if I close the current Avast message I may not find it again!  I can't see it listed in the notifications within the Avast software.  However I'm not very experienced at this kind of thing, if you hadn't already detected that! :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Suspicious Files Detected
« Reply #8 on: December 03, 2018, 12:47:35 PM »
@Sass Drake will check your logs when he is online


REDACTED

  • Guest
Re: Suspicious Files Detected
« Reply #9 on: December 03, 2018, 12:49:51 PM »
Great, thank you. Appreciate the comments.  Will wait to hear further! :)

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Suspicious Files Detected
« Reply #10 on: December 03, 2018, 08:03:10 PM »
Logs looks clean but we will check reported file.


  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
VirusTotal: C:\WINDOWS\Installer\MSIC5C7.tmp
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

REDACTED

  • Guest
Re: Suspicious Files Detected
« Reply #11 on: December 03, 2018, 09:50:07 PM »
Thanks for your help @Sass Drake.

Report attached as instructed.

Please note, I saved the file into Downloads rather than Desktop as that's where the FRST tool was located... I don't suppose the location affects the way it works, just mentioning in case it does!

The log suggests there are no issues.  Would you recommend allowing Avast to remove the suspicious files or not?
« Last Edit: December 03, 2018, 10:18:18 PM by annew52 »

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Suspicious Files Detected
« Reply #12 on: December 03, 2018, 11:15:22 PM »
Now I can only guess it is Avast false positive. Please let us know will it continue display alerts.

REDACTED

  • Guest
Re: Suspicious Files Detected
« Reply #13 on: December 04, 2018, 08:02:14 AM »
Hi, I ran a full scan through Avast this morning and it picked up the same files, but this time there are 70. 
This makes me think I should delete them!
Picture of the scan result attached.


REDACTED

  • Guest
Re: Suspicious Files Detected
« Reply #14 on: December 04, 2018, 08:32:00 AM »
I guess I should have waited for advice, but I clicked Resolve on the previous message.  Then ran another scan and now there are 72 files found  :-[

Not sure why I've got a different scan result screen this time, I think it may have been a quick scan rather than full scan like I ran this morning