Hi Webrooters,
[u] c:usersjmsdesktop
edirectservice.exe [SHA256: B20608AA9A82D73E2541FBCAFB75623A24461273DF6AB7F07624B69248EFEC74] [MD5: 5AAC4998509C066B8ACFDCF461CEAAC9] [Flags: 00080001.3974]
[u] c:usersjmsdesktopoff1cc34dvnc3.exe [SHA256: C78739F397F2A982726394DB0557BA011C6A8724FDF0C11F22B25FE9788933DC] [MD5: 39FCDA73563DC640FF3F8F5B1D3DF6E5] [Flags: 00080001.3976]
My habit is to second opinion thru VirusTotal and WSA on-demand scan.
I recently had two samples that were not immediately known classified by WSA.
Both samples were not immediately classified on download nor classified with on-demand scan.
Both samples were well known detected thru VirusTotal.
Within a few minutes both downloaded executable samples were known detected thru WSA.
Automated Cleanup Engine
Starting Routine> Removing c:usersjmsdesktop
edirectservice.exe...#(PX5: 53F2855100B5D724B209006955521D001607D23E - MD5: 5AAC4998509C066B8ACFDCF461CEAAC9 - UniqueID: 07EB0E88)...
Deleting File> C:UsersjmsDesktopRedirectService.exe
Automated Cleanup Engine
Starting Routine> Removing c:usersjmsdesktopoff1cc34dvnc3.exe...#(PX5: 9333E9D67E13490F29320D0E2FAA4B009D1D1F3D - MD5: 39FCDA73563DC640FF3F8F5B1D3DF6E5 - UniqueID: 07EAF1F0)...
Deleting File> C:UsersjmsDesktopOff1cc34dvnc3.exe
Best practice for me is to scrutinize +.
FWIW ~ YMMV
Regards w Respect
Edit: add content
Solved
Delayed classification feedback
Best answer by TripleHelix
How did they get on your Desktop? Testing malware is testing whatever way YOU want to put it. So just follow the Community Rules! Go play at MT with your MT buddies! https://malwaretips.com/threads/how-wsa-works.11871/page-2#post-789035@ wrote:
@
1) I'm not testing known to me at the time malware.
2) I'm not testing malware.
3) I'm not soliciting malware testing discussion.
Do you want me to remove my "Delayed classification feedback" Topic.
Do you want me to remove my WebrootSA back-end praise and my daily rider end-user feedback.
Or, was your comment "@bjm_ you better read this" meant as "do not post this type of praise and feedback in future".
Regards w Respect
"Both samples were well known detected thru VirusTotal.
Within a few minutes both downloaded executable samples were known detected thru WSA."
[u] c:usersjmsdesktopredirectservice.exe [SHA256: B20608AA9A82D73E2541FBCAFB75623A24461273DF6AB7F07624B69248EFEC74] [MD5: 5AAC4998509C066B8ACFDCF461CEAAC9] [Flags: 00080001.3974]
[u] c:usersjmsdesktopoff1cc34dvnc3.exe [SHA256: C78739F397F2A982726394DB0557BA011C6A8724FDF0C11F22B25FE9788933DC] [MD5: 39FCDA73563DC640FF3F8F5B1D3DF6E5] [Flags: 00080001.3976]
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.

