Caution

Discussion in 'malware problems & news' started by Rico, May 10, 2017.

  1. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    2,287
    Location:
    Canada
    Yesterday, I meant to go to web site "frozencpu.xxx & instead typed "frozenpc.xxx" immediately, talked about they were M$ & do not close, as all my data would be lost etc.

    How can this be added to 'behavior blockers', or Trend Protect in the ASUS router etc? KIS did not block or protect. On scans MBAM, SAS, ADWcleaner, MBAM anti exploit all found nada.

    RougeKiller macrium.bin.exe, dbl extension why it was flagged most likely
    Eset on line found 3, but did not see what they were.
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Where did this file download to; AppData/Local/Temp?
     
  3. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    RougeKiller flags Marcrium Relect as a false positive and that is not good. They need to take care of that. Take a look at my post about it.
     
  4. plat1098

    plat1098 Guest

    Actually, starting with RogueKiller v. 12.10.7.0, you click "yes" to upload items to VirusTotal. RK was doing this to VoodooShield. I submitted an inquiry to Adlice and was told to allow the upload to VT in order to get whitelist. It did work for VS whitelisting though I cancelled the scan and restarted it to verify that it wouldn't be flagged again. Next time, try uploading the Macrium exe to VT and you won't see it flagged on subsequent scans (I hope), unless you delete the folders in C:\Program Data.

    Looks like some nasty scareware indeed. Here's an example and links to additional info if you didn't download/install anything, just navigated to a bad website by accident. Did you get the URL?

    https://www.microsoft.com/security/...ia/Entry.aspx?Name=SupportScam:JS/TechBrolo.A

    http://www.adlice.com/download/roguekiller/
     
  5. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    2,287
    Location:
    Canada
    It was: gkmnckokdopfmhohfmgoek\0.9\main.js yes it was appdata\local\temp
     
  6. plat1098

    plat1098 Guest

    If you haven't already, clear all your browsing data. You'll have to re-enter your passwords, etc.. Use CCleaner and purge your temporary files, unless you really need something in there.
     
  7. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    2,287
    Location:
    Canada
    Thanks! Done
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.