Author Topic: 232mt8.exe  (Read 3705 times)

0 Members and 1 Guest are viewing this topic.

yawetage

  • Guest
232mt8.exe
« on: September 20, 2009, 11:39:16 PM »
Is 232mt8.exe associated with Dr. Web? It keeps popping up in my task manager.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: 232mt8.exe
« Reply #1 on: September 21, 2009, 12:28:58 AM »
Well if it were associated with DrWeb I would expect it to come up as such in a google search and it doesn't.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page.

Send a sample to avast if multiple detections at VT.
Send the sample to virus@avast.com zipped and password protected with the password in email body, a reference to this topic (give URL) and undetected malware in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.

If you haven't already got this software (freeware), download, install, update and run it and report the findings (it should product a log file).

Don't worry about reported tracking cookies they are a minor issue and not one of security, allow SAS to deal with them though. - See http://en.wikipedia.org/wiki/HTTP_cookie.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

CharleyO

  • Guest
Re: 232mt8.exe
« Reply #2 on: September 22, 2009, 09:31:31 PM »
***

It is not a Dr Web file according to their forum.

Hopefully, yawetage will use MBAM and return with a log.


***

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: 232mt8.exe
« Reply #3 on: September 22, 2009, 09:36:13 PM »
Hi yawetage,

The way the executable is named gives it a suspicious tinge i.m.o., so follow DavidR's suggestion and upload the file in question to virustotal.com. Curious what it is!

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

yawetage

  • Guest
Re: 232mt8.exe
« Reply #4 on: September 24, 2009, 09:32:22 PM »
It turns out Cureit has a different letter-number combination name depending on either what day it is downloaded or your location. So for example today when I did a fresh download it was ts827y6.exe and yesterday it was something else. And of course when this pops up in task manager it looks suspicious because I expect to see something like Drweb.exe running.   

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: 232mt8.exe
« Reply #5 on: September 24, 2009, 10:18:01 PM »
OK, mystery over, personally I would have uploaded it anyway.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

yawetage

  • Guest
Re: 232mt8.exe
« Reply #6 on: September 24, 2009, 11:36:59 PM »
I did upload it to VirusTotal pretty much first thing, but only Esafe and Comodo detected it as "suspicious".