Skip to main content
Solved

A threat has been eliminated


Asklepios
Community Leader
Good morning USA;)
Yesterday, when using my laptop, I have a WSA mesage: "this site is not secure".
Then I saw on the security bookmark: "1 threat has been elimanted".
Is it possible to see what was this threat?

Best answer by Rakanisheu Retired

Replied to the PM! The file is good and can be restored. The prevx information is out of date.
View original
Did this help you find an answer to your question?

31 replies

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 24, 2013
Hello Raka
Thanks:D

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 27, 2013
Hello Rakanisheu
I go on my "webconsole" and I find this:
 


 
I think that this is not a malware.
What do you think ?

JimM
  • Retired Webrooter
  • 1581 replies
  • June 27, 2013
I don't see Rakanisheu online this morning, but I might be able to help.
 
It's hard to say just based on the file name.  The file name alone doesn't tell us as much as the MD5 of the file would.  The MD5 is submitted automatically when you contact us via the support system, which is why we suggest using that system in all cases of false positives or infections.
 
That said, I'm leaning more towards it being an infection, based on this.  However, we won't really know for sure until we get a closer look, since file names alone can be misleading.  If you update your support case, we can provide a better answer since we'll have more data to go on.

Rakanisheu Retired
Looking at the file now (MD5:C8BB4B1F3E8B5AB8809B836119209188). What makes you think its good(it might be I am still investigating it)?

Rakanisheu Retired
Update: I have marked that file as good.
 
Thanks!

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 28, 2013
@ wrote:
Update: I have marked that file as good.
 
Thanks!

Hello Rakanisheu
I'm not sure, it was a guess because the file looked like to those of my professional software.

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 28, 2013
@ wrote:
I don't see Rakanisheu online this morning, but I might be able to help.
 
It's hard to say just based on the file name.  The file name alone doesn't tell us as much as the MD5 of the file would.  The MD5 is submitted automatically when you contact us via the support system, which is why we suggest using that system in all cases of false positives or infections.
 
That said, I'm leaning more towards it being an infection, based on this.  However, we won't really know for sure until we get a closer look, since file names alone can be misleading.  If you update your support case, we can provide a better answer since we'll have more data to go on.
Thanks Jim
This thread was on my old laptop and I cannot access to it before Saturday evening or Sunday.
 

Rakanisheu Retired
You wont need to submit logs, I found the file in our database and its now good. Saves you doing any work 🙂

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 28, 2013
@ wrote:
You wont need to submit logs, I found the file in our database and its now good. Saves you doing any work :)
Thanks Rakanisheu:D
But I don't understand the link given by Jim:@ :
http://www.prevx.com/filenames/X460799281356301372-X1/HDCTRLEX.DLL.html#nogo
Can you explain to me ?

Rakanisheu Retired
That page is out of date since I just changed the database entry for that file. I assume it will autoupdate soon enough.

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 28, 2013
Thanks Rakanisheu:D
Can you tell me if this file is really a file of my professional program ?

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 29, 2013
Hello Roy;)
I'm sorry to insist but I don't understand what I have to do.
Now I'm at home and I run my laptop, and I see that the suspicious file ("hdctrlex.dll") remains in the quarantine.
I don't know if I can restore it?
I'll send you a PM with the report of detection.

RetiredTripleHelix
Gold VIP
Forum|alt.badge.img+56
Hi Robert you can call him Roy if you like!
 
Daniel

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 29, 2013
@ wrote:
@ wrote:
You wont need to submit logs, I found the file in our database and its now good. Saves you doing any work :)
Thanks Rakanisheu:D
But I don't understand the link given by Jim:@ :
http://www.prevx.com/filenames/X460799281356301372-X1/HDCTRLEX.DLL.html#nogo
Can you explain to me ?
Another think that I don't understand is that the page above reports always that the file hdctrlex.dll is a "fraudulent security program".

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 29, 2013
@ wrote:
Hi Robert you can call him Roy if you like!
 
Daniel
Thanks Daniel for the info;)

Rakanisheu Retired
Replied to the PM! The file is good and can be restored. The prevx information is out of date.

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 30, 2013
Hi Roy,
Thanks for your help:D
I have restored the file, even if my laptop continued to works well without it.
Then I launched an analyse and the laptop is clean.
Good Sunday!
Robert

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • June 30, 2013
Hi Roy,
 
I think that's WSA-C have blocked another sure file on my home PC this time:
 
Automated Cleanup Engine Starting Cleanup at 30/06/2013 - 16:05:42 GMT Starting Routine> Removing c:users
obertdesktoplanguagepack_french.exe...#(PX5: - MD5: D2AFB7BBE8DDF4C4BD05537BD1598870)... Deleting File> c:users
obertdesktoplanguagepack_french.exe
 
Is it this a false positive ?

RetiredTripleHelix
Gold VIP
Forum|alt.badge.img+56
Hello Robert I can't tell for sure but to me it looks like an FP and I did a Search on VT using your MD5 Hash File D2AFB7BBE8DDF4C4BD05537BD1598870 as only Symantec came up with some kind of detection so it's best to wait for a conformation from Roy or another Threat Researcher. I wish Webroot was listed on VT as I made a suggestion maybe if a few more will Kudo it they will look at again as it's on Hold. http://community.webroot.com/t5/Ideas-Exchange/Adding-a-Webroot-SDK-to-VirusTotal/idi-p/7462#.UdBubW2DmJO  :D
 
HTH,
 
Daniel 😉

ProTruckDriver
Moderator
@ wrote:
I wish Webroot was listed on VT as I made a suggestion maybe if a few more will Kudo it they will look at again as it's on Hold.
I agree Daniel. If I could cheat and Triple Kudo it, I would. 😃

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • July 1, 2013
@ wrote:
Hello Robert I can't tell for sure but to me it looks like an FP and I did a Search on VT using your MD5 Hash File D2AFB7BBE8DDF4C4BD05537BD1598870 as only Symantec came up with some kind of detection so it's best to wait for a conformation from Roy or another Threat Researcher. I wish Webroot was listed on VT as I made a suggestion maybe if a few more will Kudo it they will look at again as it's on Hold. http://community.webroot.com/t5/Ideas-Exchange/Adding-a-Webroot-SDK-to-VirusTotal/idi-p/7462#.UdBubW2DmJO  :D
 
HTH,
 
Daniel ;)
Hi
Thanks Daniel!
Idea kudoed;)
Now I wait the Roy's answer.

Rakanisheu Retired
Not sure why that file was removed on your PC, its not bad in our database.  I have whitelisted the file in anycase, its not behaviour is not malicious and its associated files/processes are good. WSA not being on VT doesnt really bother me too much, VT is only a rough guide and should never be taken as gospel.

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • July 2, 2013
Hello Roy,
Thanks for whitelisting this file.
I don't know if this can help you but when I download this file with IE9 (Vista pro) I get the following error message and then WSA-C deleted the file:


 
I think it might be interesting to try to download "Sapnish pack" and "German pack";)

Rakanisheu Retired
That doesnt look like it was us that removed that! My french is rusty is that saying that the file was not downloaded to your PC as it may cause damage?

Asklepios
Community Leader
  • Author
  • Community Leader
  • 206 replies
  • July 2, 2013
No it says that this file was rarely downloaded and should be insecure.
The file was deleted by WSA-C after I have accepted to download it......

Reply