View Full Version : Threat Alert
JVM
December 14th, 2008, 09:28 AM
Can someone explain what I am to do about this threat alert via email Module Real-time file system protection : C:\FRAPS\UNINSTALL.EXE contains Win32/Adware.Cinmus application.
I have Fraps installed on my computer and have had it for some time. Should I uninstall the program or?
ronjor
December 14th, 2008, 09:38 AM
Similar problem here. http://www.wilderssecurity.com/showthread.php?t=227849
JVM
December 14th, 2008, 09:47 AM
The log file said cleaned by deleting - quarantined. I see it in the quarantine section and does this mean I can't uninstall the program? I also see it in the Detected Threats section where it says cleaned by deleting -quarantined.
What should I do?
ronjor
December 14th, 2008, 10:04 AM
ESET will probably have to update the definitions to correct this. I would wait a bit before doing anything.
SuicidePunk
December 14th, 2008, 10:30 AM
Yes false positive, same problem with "C:\Program Files\Notepad++\uninstall.exe"
It seams to be the Nullsoft installer.
JVM
December 14th, 2008, 12:23 PM
Should I use the Restore function in Quarantine?
ronjor
December 14th, 2008, 12:32 PM
Sure.
es3ttor
December 14th, 2008, 12:35 PM
I encountered the same false hit while compiling a NSIS exe, the newest update fixes it. Update your definitions and scan it again, if it clears I'd say yes. Thanks Wilders. :>
JVM
December 14th, 2008, 01:07 PM
I didn't get this alert doing a scan. I got it via email as a Threat Alert: Module Real-time file system protection C:\FRAPS\UNINSTALL.EXE contains Win32/Adware.Cinmus application.
JVM
December 14th, 2008, 01:11 PM
I just read the information under Detected Threats: Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\SpeedFan\speedfan.exe. This is very confusing since I wasn't using Fraps.
JVM
December 14th, 2008, 07:21 PM
I restored it from quarantine and did an in-depth scan that revealed no threats. Since this was a real-time system protection thing, I don't know if that scan means anything. If this was a false positive real-time threat, then I hope it was solved with the signature update.
ronjor
December 14th, 2008, 07:27 PM
The definitions were corrected and you should be okay JVM.
JVM
December 14th, 2008, 08:01 PM
{QUOTE-> The definitions were corrected and you should be okay JVM. <-QUOTE}
Thanks!
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums