Virus?

Started by Mark Rowe, June 22, 2015, 10:43:35 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Mark Rowe

One of my workstations started getting the pop "your system is infected" alerts.....ran 2 virus scans and nothing. Started poking around in processes running and found an odd entry which when google searched comes back with no entries. The file running is uhneweer.exe and it has 2 instances running...one at the user level and one at the system level. Anyone ever see or hear of it?  When ending task it seems to stay closed until a reboot.
Mark Rowe, CIC
Michaud, Rowe & Ruscak Insurance Associates, Inc.
North Andover, MA 01845
TAM 2014 R2, Etfile, 10 Users

Mark

I would find it and submit it if you can.
Mark Piontek, MBA
Director of Information Systems
BS in Information Systems Security

Mark

You could also try uploading it here: https://www.virustotal.com/
Mark Piontek, MBA
Director of Information Systems
BS in Information Systems Security

Bob

Some of the digging up I could find relates to .net 4.0 which I think latest TAM version went to.  Might be false positive with your Anti-virus.

Try excluding TAM folder and TAM network drive see what happens.   I had my AV after update suddenly think an exe in the tam print check routine was a virus.  Somehow the update erased my exclusions.

Jeff Golas

Virus...wipe and re-image (best way to get rid of that crap).
Jeff Golas
Johnson, Kendall & Johnson, Inc. :: Newtown, PA
Epic Online w/CSR24
http://www.jkj.com

Jeff Zylstra

There are so many "fake" viruses out there right now, that I'm curious what is generating the popup.  If it only happens in the web browser, I would say it's fairly certain that it is fake.  Btw, have you tried cleaning up the temp files yet?  A lot of evil hides in the temp files, but may not have burrowed into your operating system yet, and could be cleaned out by getting rid of temp files with CCLeaner or something like that. 

There are also several good online anti-virus websites that can check for malware that way.  Just Google them.
"We hang the petty thieves, and appoint the great ones to public office"  -  Aesop

Mark Rowe

Thanks for all the suggestions. Surprisingly my brain didn't go to malware (actually not surprisingly) but I'll run malwarebytes. Usually the first thing I do but my brain is struggling to leave the weekend behind.....Station is running fine now but I know there's an ant in there somewhere.
Mark Rowe, CIC
Michaud, Rowe & Ruscak Insurance Associates, Inc.
North Andover, MA 01845
TAM 2014 R2, Etfile, 10 Users

Jan Regnier

Also clear the browser history after cleaning......if it came from the browser
Jan Regnier
jan.regnier@meyersglaros.com
Meyers Glaros Group, Merrillville, IN 26 Users
EPIC 2020, Office 365, Indio

Mark Rowe

malwarebytes got rid of whatever it was.  Thanks again.
Mark Rowe, CIC
Michaud, Rowe & Ruscak Insurance Associates, Inc.
North Andover, MA 01845
TAM 2014 R2, Etfile, 10 Users