PDA

View Full Version : Need User Feedback: Wordpad.exe, infected by "Fraud.MySecurityEngine"?



Grand_Duc
2010-09-24, 11:13
Hello!

The title shows the main theme of my problem: I wanted to use Wordpad some minutes ago. My Spybot S&D thought that it would be useful to terminate the process, saying that "Fraud.MySecurityEngine" was found.

The corresponding log line reads:

24.09.2010 09:55:20 Encountered and terminated Fraud.MySecurityEngine in C:\Programme\Windows NT\Zubehör\wordpad.exe!


My system is build as follows

XP SP3,
latest updates of S S&D applied
Avira Antivirus Personal edition with the latest updates applied running.

As my Antivirus guard remained silent, I'm somewhat puzzled, especially since googling with
wordpad spybot "Fraud.MySecurityEngine" returned zero results. Has annybody a clue what happened here?

Greets, Grand-Duc

Gopher John
2010-09-24, 17:51
You might try submitting wordpad.exe to VirusTotal (http://www.virustotal.com/) where it will be scanned by multiple antivirus programs. Post the results link back here.

Were you attempting to load a downloaded document into Wordpad when you got the alert? Older versions of Wordpad had a vulnerability in which an infected document could cause problems.

Grand_Duc
2010-09-24, 18:30
Advice followed, here is the link (http://www.virustotal.com/file-scan/report.html?id=e00c7e85af8ce90d966f4aec3c072adc021e600d991d75fa0c5663482b74da89-1280513183#), there seems to be no positive result.

I wasn't trying to load/open a document into wordpad, I wanted a blank page to paste a text that I was about to post in a forum to preview it.

Thanks for help!

Grand-Duc

Gopher John
2010-09-24, 19:06
It's looking like a false positive. Does a Right Click scan of wordpad.exe with SpyBot S&D give the same result?

I'm running WinXP SP3 using SpyBot S&D 1.6.2.46 fully updated, and receive no alert with the right click scan. I have the English install of Windows, so that might be the reason. The wordpad.exe filesize and checksums are different.

tashi
2010-09-24, 19:15
Hi everyone,

Grand_Duc please follow instructions here: How to report Possible False Positives (http://forums.spybot.info/showthread.php?t=19117)

Best regards. :)

Grand_Duc
2010-09-24, 23:46
I hope that I understood correctly that you expect this report here. Well, here it comes:

- Win XP SP3, german, fully updated.
- Browsers: IE7, FF 3.6.6, Opera 10.61, I use Firefox as main browser (but is this important here? My browsers weren't affected, AFAIK)
- Spybot S&D 1.6.2.46, latest update from September 22nd, 2010

I do not have a context menu entry for scanning with Spybot (I'm wondering why, I'm recalling that I've seen it sometimes ago, but possibly previous to my system rebuild).

To "where did the event occur", well, as said above, I wanted to preview a text typed in a forum post editor, so I copied it, went to the accessories entry in the Start menu and clicked on Wordpad to past it there. At this moment, the resident wanted to block the process "Wordpad.exe", I've overruled this by allowing it manually, being confident that my antivirus would have reacted in case of a real danger.

Nevertheless, here are 2 logfiles:

5810, the resident log,
5811, the current search log (from a search finished some minutes ago).

Greets, Grand-Duc

Yodama
2010-09-28, 08:31
it appears that something is interfering with the TeaTimer which causes this false positive. Please make sure to only use one active background protection, if you use only the TeaTimer make sure to reboot after a Spybot S&D update or restart the TeaTimer.

If you wish to permanently disable the TeaTimer follow these steps:

start Spybot S&D
switch into advanced mode
navigate to Tools - Resident
disable the checkbox for Resident TeaTimer to shutdown the TeaTimer and remove it from system start