PDA

View Full Version : Threat Alert


JVM
December 14th, 2008, 09:28 AM
Can someone explain what I am to do about this threat alert via email Module Real-time file system protection : C:\FRAPS\UNINSTALL.EXE contains Win32/Adware.Cinmus application.

I have Fraps installed on my computer and have had it for some time. Should I uninstall the program or?

ronjor
December 14th, 2008, 09:38 AM
Similar problem here. http://www.wilderssecurity.com/showthread.php?t=227849

JVM
December 14th, 2008, 09:47 AM
The log file said cleaned by deleting - quarantined. I see it in the quarantine section and does this mean I can't uninstall the program? I also see it in the Detected Threats section where it says cleaned by deleting -quarantined.

What should I do?

ronjor
December 14th, 2008, 10:04 AM
ESET will probably have to update the definitions to correct this. I would wait a bit before doing anything.

SuicidePunk
December 14th, 2008, 10:30 AM
Yes false positive, same problem with "C:\Program Files\Notepad++\uninstall.exe"
It seams to be the Nullsoft installer.

JVM
December 14th, 2008, 12:23 PM
Should I use the Restore function in Quarantine?

ronjor
December 14th, 2008, 12:32 PM
Sure.

es3ttor
December 14th, 2008, 12:35 PM
I encountered the same false hit while compiling a NSIS exe, the newest update fixes it. Update your definitions and scan it again, if it clears I'd say yes. Thanks Wilders. :>

JVM
December 14th, 2008, 01:07 PM
I didn't get this alert doing a scan. I got it via email as a Threat Alert: Module Real-time file system protection C:\FRAPS\UNINSTALL.EXE contains Win32/Adware.Cinmus application.

JVM
December 14th, 2008, 01:11 PM
I just read the information under Detected Threats: Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\SpeedFan\speedfan.exe. This is very confusing since I wasn't using Fraps.

JVM
December 14th, 2008, 07:21 PM
I restored it from quarantine and did an in-depth scan that revealed no threats. Since this was a real-time system protection thing, I don't know if that scan means anything. If this was a false positive real-time threat, then I hope it was solved with the signature update.

ronjor
December 14th, 2008, 07:27 PM
The definitions were corrected and you should be okay JVM.

JVM
December 14th, 2008, 08:01 PM
{QUOTE-> The definitions were corrected and you should be okay JVM. <-QUOTE}

Thanks!