  tempnexus Premium join:1999-08-11 Boston, MA
| Expiro Malware. Boclean FP?
I just go this popup from Boclean on Expiro Malware, I was wondering if it's a FP since the properties of the file show a Genuine Microsoft file. Attached you will find the file and a screenshot of the detection.
03/16/2007 18:13:14: Trojan horse was found in memory. C:\WINDOWS\SYSTEM32\WUAUCLT.EXE contained the trojan. Active trojan horse WAS shut down. System now safe. Logged in user:
Cheers, |
|
  Cudni La Merma - Vigilado Premium,MVM join:2003-12-20 Someshire | sounds like fp here is the md5 hash of the unsecapp.exe file C7000F2DB2A5515C64C257478769A481
reported to their tech support?
Cudni |
|
  tempnexus Premium join:1999-08-11 Boston, MA | yeap reported few hours back can you also hash the wuauclt.exe |
|
  Cudni La Merma - Vigilado Premium,MVM join:2003-12-20 Someshire | reply to tempnexus sure EBF1AB7E4FC05CABF2F4680D2A45F827
Cudni |
|
  tempnexus Premium join:1999-08-11 Boston, MA | Wuauclt.exe and unsecapp.exe matches
I also have wuauclt1.exe with checksum CBD5FB89DBE85EBC9A50DB04AB514E87 |
|
  tempnexus Premium join:1999-08-11 Boston, MA | reply to Cudni Got reply from Kevin. It's all A-OK a FP in the defs, new defs will be out soon. |
|