?
Solved

join.me.exe - quarantined on a windows 2008 server and a windows 2003 server

Posted on 2012-12-26
4
Medium Priority
?
1,166 Views
Last Modified: 2013-11-22
Two of the servers I work with, located as separate schools, which have our Managed Antivirus running, have detected a file called join.me.exe and quarantined it.  Here is the path of the file on one of the servers:

C:\users\administrator\appdata\local\apps\2.0\02D4YAAV.6BL\2Y6ZKXGR.0KX\join..tion_43a0dbe7f0f75062_0001.0000_9871fcdc8aa605d7\join.me.exe

Should I take any action to try and clean my system further, other than deleting this item out of quarantine.  Has anyone seen this file get picked up as a Trojan.win32.generic!bt

Any advice on further action, dealing with this infection?
0
Comment
Question by:redemption7
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 2

Assisted Solution

by:rmail
rmail earned 1000 total points
ID: 38721507
Remediation ideas:
1) Make sure your antivirus definitions are up to date,
2) Run a full scan on the suspect servers
3) Consider using another anti-virus or some anti-spyware for a second opinion, just make sure that you don't run the servers with two active antivirus products afterward. I scan my personal PCs with Malwarebytes (malwarebytes.org).

Prevention ideas:
1) Don't browse the internet as an administrator.
0
 
LVL 26

Accepted Solution

by:
Leon Fester earned 1000 total points
ID: 38723034
You always want to clean quarantined files.
The name itself indicates that this is a malicious file.

Generally the settings in Windows Explorer are to "Hide extension of known file types"
So this file when included in an email or seen in explorer will only show as "join.me" and the ".exe" is hidden, so people will click on the file.

If you cannot remove the file, then check if you can remove all permissions from this file.
This ensure that the file cannot be excuted by anybody including the system.

For more information on how to remove this trojan, I'd suggest that you view the manufacturers website of the AV software you're using.

Some tips from Symantec:
http://www.symantec.com/business/support/index?page=content&id=TECH122466
0
 

Expert Comment

by:ThreeShield
ID: 38725617
I believe this is a false positive in a recent VMware vCenter Protect (Shavlik) antivirus pattern update.  

Users who used the join.me service (same company as LogMeIn) show up in the quarantine with this file on December 22, 2012 (or subsequent antivirus scan) regardless of download date.  In all cases that we have tested, users downloaded the file directly from the Join.Me website. The parent directory contains other files from the same vendor.

This program is often used by vendors to provide remote support.  It's a well-known product that doesn't deserve a "high risk" rating from VMware/Shavlik. (although by definition, it does provide interactive access to a remote machine -- but only a the user's permission)
0
 

Author Closing Comment

by:redemption7
ID: 38740959
thank you
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A safe way to clean winsxs folder from your windows server 2008 R2 editions
For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question