Legit or Malware?

Discussion in 'other software & services' started by khanyash, Jan 26, 2014.

Thread Status:
Not open for further replies.
  1. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,429
    Yesterday I was browsing & got the window. I cancelled it.
    Today too I was browsing & got the window. I cancelled it.
    I was browsing trusted sites & no shady sites.

    Is this legit or malware?
    Attached is the screenshot.

    Win 7 64 Bits
     

    Attached Files:

    • SCR.png
      SCR.png
      File size:
      45.7 KB
      Views:
      83
  2. JohnBurns

    JohnBurns Registered Member

    Joined:
    Jul 4, 2004
    Posts:
    778
    Location:
    Oklahoma City
    I also got this yesterday - and like you, I was not in "shady sites". I also had WinPatrol reject it and shortly later regretted it. My disk had errors and I couldn't fix them. Eventually, late last night, I had to restore from Macrium Backup in order to get back to where I was earlier in the day. I guess I screwed up something by rejecting the Windows Installer pop-up. I don't have a clue what it was or what it did to my pc.
     
  3. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,429
    I got & rejected it 2 times. No probs with the system yet.
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    If I double-click and manually run Msiexec.exe I get the same window. It looks like something is calling Msiexec.exe. It might be some installer calling that exe without parameters? Try to find out which process has run msiexec.exe to find out what's causing it. You can use Process Explorer to find parent process.

    hqsec
     
  5. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,429
    I never got this window.
    Couple of days I am running Bitdefender Free AV, could BD be the reason?
     
  6. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    Which window, the one from your first post?
    You can try and remove Bitdefender and you'll see if that was a problem.

    hqsec
     
  7. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,429
    Yes that window.
    I am not getting it often, as I mentioned in my previous post, got twice.
    When I rejected it, tried 2-3 restarts but it didn't appeared.
    Today too I rejected it & tried 2-3 restarts & it didn't appeared.
    So I guess uninstalling BD would be waste & BD is not the culprit here.
     
  8. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    To find culprit try suggestion in my first post. Something is executing msiexec.exe. Try to find out which process is running it and that might give you information where to look. Of course you will have to wait until it happens again.

    Another long shot question: do you use Chrome 32 and CCleaner with version lower than 4.09?

    hqsec
     
  9. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,429
    You mean when the window appears again, msiexec.exe will be there in the processes & I should check its properties to see whats calling it?
     
  10. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    Yes, but properties won't show you what's calling it. Use Process Explorer which will show you parent-child relationship for each process.

    hqsec
     
  11. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,429
    OK.
    Should I run chkdsk & sfc /scannow & check?
     
  12. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    I would first try to find out what's causing it. You might also want to check your Event viewer and see if there are any new records that might be connected to this problem.

    hqsec
     
  13. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,429
    EventViewer shows MsiInstaller which shows googletalkplugin update, guess this is the culprit?
    I guess when the window appears again, it would be safe to accept it, right?
     
    Last edited: Jan 26, 2014
  14. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    Might be that, yes. Accept it and you'll see if installation will continue.

    hqsec
     
  15. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,429
    It had appeared again & I had accepted it but nothing visible happened.
    Today it appeared again & I again accepted it & nothing visible happened.

    sfc /scannow didn't find any errors.
    chkdsk didn't find any errors.

    I think Google Update is the culprit for this window appearing coz when this window appears that times log in eventviewer is google update that mentions update failed, either its not installed or corrupted.

    I have Google Chrome, Picasa & Google Talk on my system Win 7 64.

    Under services, there are 3 services related to Google.

    Google Update Service (gupdate), Automatic (Delayed Start), Stopped
    Google Update Service (gupdatem), Manual, Stopped
    Google Update Service, Manual, Stopped

    Any of the above services Status & Startup Type is wrong & needs to be changed?
     
    Last edited: Jan 28, 2014
  16. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,429
    Removed all the google softwares, chrome, picasa, autobackup & google talk & remnants.
    Reinstalled chrome & picasa.
    Lets see if the window appears now or not.

    Google talk is discontinued?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.