..\Macromed\Flash\testupdate.txt reported as malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by slappyfrogg, Oct 30, 2008.

  1. slappyfrogg

    slappyfrogg Private E-2

    Hello,

    Comodo Firewall Pro is reporting that Firefox is attempting to launch a file from windows\system32\macromed\flash\testupdate.txt when opening several tabs all at once so I was unable to identify which site was generating the issue.

    I have blocked this file and followed all the instructions at http://forums.majorgeeks.com/showthread.php?t=139313 and none of those tools reported a problem.

    I've done google searches and the only reference I can find is to certain malware creating and deleting this file (like this one: www.pcreview.co.uk/forums/thread-1709118.php).

    I've checked Adobe's support pages/forums, Comodo's support pages/forums, etc. and there is no clear indication of what this file is supposed to be doing and I am not seeing any of the other behaviors.

    Do you have any information on this file and what it is supposed to do? It seems odd that a legitimate Flash update would revolve around a .txt file.

    I have the logs if you'd like me to send them along. The only odd thing I could recognize was that combofix reported this:
    " /wow section - STAGE 32
    The requested operation cannot be performed on a file with a user-mapped section open." and rebooted my machine but continued to run fine after the reboot.

    Any thoughts would be greatly appreciated! Thanks in advance!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the requested logs.....it is possible that you are infected.
     
  3. slappyfrogg

    slappyfrogg Private E-2

    See attached for the first three.
     

    Attached Files:

  4. slappyfrogg

    slappyfrogg Private E-2

    And the fourth.

    Thank you for your earlier prompt response, greatly appreciated.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you done a search for that file? I am not seeing anything to suggest malware. You mention this happens in both IE and FireFox?

    Have you run any cleaning programs such as CCleaner of ATFCleaner?
     
  6. slappyfrogg

    slappyfrogg Private E-2

    Hi Tim,

    I ran CCleaner as part of the first steps recommended at this link: http://forums.majorgeeks.com/showthread.php?t=35407

    Here's what happened:
    I loaded a bunch of bookmarked blogs from Firefox's "open all in tabs" and Comodo fired referencing the testupdate.txt. Two things caused me to pause, the shortened spelling of Macromed and the fact it was trying to access a .txt file so I blocked it.

    I was curious so I searched Google for macromed\flash\testupdate.txt which referenced that file was added/deleted by some viruses but no references to what it actually did. I also checked Adobe's site and forums with no results as well as Comodo's forums and support.

    The fact that there did not appear to be any good references to the file also puzzled me and in my searching I found the malware removal forums here and proceeded to follow the steps of running cccleaner, etc. and then all the anti-malware tools that generated those logs.

    I did not try to run Internet Explorer, I rarely open it.

    I did a search for that file immediately after blocking it with Comodo Firewall with no results which added to my curiosity.

    As my normal protection package, I run: Comodo Firewall, AVG Anti-Virus, Lavasoft Ad-Aware and Watch, Spyware Blaster and weekly Spybot S&D immunizations and search and destroys.

    A few days prior to the message appearing, I did insert a CD from a friend, the CD had only images in .jpg format on it, I scanned it for viruses with nothing found, copied the files to my desktop and scanned the folder with nothing found.

    Frankly, I'm a bit paranoid about all this stuff, so figured I'd post and see what could be seen.

    :)
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I could not find any trustworthy info on that file either.....and you say it is in Firefox but you are not sure if it occurs in IE....

    And you have checked your bookmarks.....I would save your bookmarks to a disc or thumb drive and then delete them all and see if it still occurs.

    I do not think this is malware related......So I would suggest that you post in the software forum...maybe someone there has had this issue.
     
  8. slappyfrogg

    slappyfrogg Private E-2

    Thanks, I'll try the software forum.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Although I am not seeing any signs of files that could be associated with this ...please go HERE.

    Download the file and let me know what if anything it finds.
     
  10. slappyfrogg

    slappyfrogg Private E-2

    It found zero bad files. Log is attached.

    Thanks again for all your help!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I am stumped.....:(

    But as long as Comodo flags and stops it...I think you are safe. :)
     
  12. slappyfrogg

    slappyfrogg Private E-2

    That's my working theory but it was quite vexing to find so little information on it floating around on the internet. It's nice to have some confirmation.

    Thanks again for your help!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....let me know if you have any more problems.

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds