join.me.exe - quarantined on a windows 2008 server and a windows 2003 server

Posted on 2012-12-26
Medium Priority
Last Modified: 2013-11-22
Two of the servers I work with, located as separate schools, which have our Managed Antivirus running, have detected a file called join.me.exe and quarantined it.  Here is the path of the file on one of the servers:


Should I take any action to try and clean my system further, other than deleting this item out of quarantine.  Has anyone seen this file get picked up as a Trojan.win32.generic!bt

Any advice on further action, dealing with this infection?
Question by:redemption7

Assisted Solution

rmail earned 1000 total points
ID: 38721507
Remediation ideas:
1) Make sure your antivirus definitions are up to date,
2) Run a full scan on the suspect servers
3) Consider using another anti-virus or some anti-spyware for a second opinion, just make sure that you don't run the servers with two active antivirus products afterward. I scan my personal PCs with Malwarebytes (malwarebytes.org).

Prevention ideas:
1) Don't browse the internet as an administrator.
LVL 26

Accepted Solution

Leon Fester earned 1000 total points
ID: 38723034
You always want to clean quarantined files.
The name itself indicates that this is a malicious file.

Generally the settings in Windows Explorer are to "Hide extension of known file types"
So this file when included in an email or seen in explorer will only show as "join.me" and the ".exe" is hidden, so people will click on the file.

If you cannot remove the file, then check if you can remove all permissions from this file.
This ensure that the file cannot be excuted by anybody including the system.

For more information on how to remove this trojan, I'd suggest that you view the manufacturers website of the AV software you're using.

Some tips from Symantec:

Expert Comment

ID: 38725617
I believe this is a false positive in a recent VMware vCenter Protect (Shavlik) antivirus pattern update.  

Users who used the join.me service (same company as LogMeIn) show up in the quarantine with this file on December 22, 2012 (or subsequent antivirus scan) regardless of download date.  In all cases that we have tested, users downloaded the file directly from the Join.Me website. The parent directory contains other files from the same vendor.

This program is often used by vendors to provide remote support.  It's a well-known product that doesn't deserve a "high risk" rating from VMware/Shavlik. (although by definition, it does provide interactive access to a remote machine -- but only a the user's permission)

Author Closing Comment

ID: 38740959
thank you

Featured Post

We Need Your Input!

WatchGuard is currently running a beta program for our new macOS Host Sensor for our Threat Detection and Response service. We're looking for more macOS users to help provide insight and feedback to help us make the product even better. Please sign up for our beta program today!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Understanding the various editions available is vital when you decide to purchase Windows Server 2012. You need to have a basic understanding of the features and limitations in each edition in order to make a well-informed decision that best suits …
This article explains how to install and use the NTBackup utility that comes with Windows Server.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question