Hi,
I just got done with my daily AV scan and the report says . . .
C:\WINNT\SoftwareDistribution\Download\S-1-5-18\579623779eb0192404c34bb7e7d3b632\BIT58.tmp could be a corrupted executable file
C:\WINNT\system32\MFC421.dll->(exefile) could be a corrupted executable file
C:\WINNT\system32\MFC421D.dll->(exefile) could be a corrupted executable file
What are these files for and do I need them? Can I just delete them?
If I can't delete them, is there a program that will fix them?
Thanks from Maine
I got new virus definitions yeterday, and this file also appeared
C:\WINNT\SoftwareDistribution\Download\S-1-5-18\579623779eb0192404c34bb7e7d3b632\BIT58.tmp
could be a corrupted executable file
General Tab
CreatedOct 16, 2005 4:43pm
Modified Oct 18 2005 5:53am
Accessed Oct 18 20057:32 am
Location: C:\WINNT\SoftwareDistribution\Download\S-1-5-18\579623779eb0192404c34bb7
Size 470 KB
Size on disk: 472 KB
Type of FileTMP file
Opens with: Unknown
Hidden
These 2 boxes are checked on Advanced Attributes
File is ready for archiving
For fast searching
C:\WINNT\system32\MFC421.dll->(exefile) could be a corrupted executable file
General Tab
Created Apr 10 2004
Modified June 20 2003
Accessed Oct 18 2005
Location: C:\WINNT/system32
Size 20.0KB
Size on disk: 24.0KB
Type of File Application Extension
Opens with: Unknown
Hidden
These 2 boxes are checked on Advanced Attributes
File is ready for archiving
For fast searching
C:\WINNT\system32\MFC421D.dll->(exefile) could be a corrupted executable file
General Tab
Created Apr 10 2004
Modified June 20 2003
Accessed Oct 18 2005
Location: C:\WINNT/system32
Size 20.0KB
Size on disk: 24.0KB
Type of File Application Extension
Opens with: Unknown
These 2 boxes are checked on Advanced Attributes
File is ready for archiving
For fast searching
Okay, here are the results of scan for each file sent to Online Malware scan.
For what it's worth I used FProt AV
Service load:
0% 100%
File: MFC421.dll
Status:
OK
MD5 88ba618de1765984cfc9f03911073119
Packers detected:
-
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found nothing
Last file scanned at least one scanner reported something about: 手机短信.exe, detected by:
Scanner Malware name
AntiVir X
ArcaVir X
Avast X
AVG Antivirus X
BitDefender X
ClamAV X
Dr.Web X
F-Prot Antivirus X
Fortinet X
Kaspersky Anti-Virus X
NOD32 X
Norman Virus Control X
UNA X
VBA32 Backdoor.Win32.Bifrose.ex
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Service load:
0% 100%
File: MFC421D.dll
Status:
OK (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 88ba618de1765984cfc9f03911073119
Packers detected:
-
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found nothing
Last file scanned at least one scanner reported something about: 手机短信.exe, detected by:
Scanner Malware name
AntiVir X
ArcaVir X
Avast X
AVG Antivirus X
BitDefender X
ClamAV X
Dr.Web X
F-Prot Antivirus X
Fortinet X
Kaspersky Anti-Virus X
NOD32 X
Norman Virus Control X
UNA X
VBA32 Backdoor.Win32.Bifrose.ex
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Ahh, but the final file . . . .
Service load:
0% 100%
File: BIT58.tmp
Status:
MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.)
MD5 43b68983992f3f17eb801fcf0498004d
Packers detected:
PE_PATCH
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found nothing
Scanner Malware name
AntiVir X
ArcaVir X
Avast X
AVG Antivirus X
BitDefender X
ClamAV X
Dr.Web X
F-Prot Antivirus X
Fortinet X
Kaspersky Anti-Virus X
NOD32 X
Norman Virus Control X
UNA X
VBA32 Backdoor.Win32.Bifrose.ex
Yet, Kaspersky did not recognise it when you run the Jotti scan.
Now…since none of the others detected any problem with it…that could indicate a false positive. However, a Google search for those two .dll's reveals nothing….that is a big red flag. Moreover…as the result said….when a scanner sticks on a file like that, that is also suspicious. Therefore, I don't want you to delete them right now…best to be sure about them. Anyway, it's given me a clue as to how to proceed:
Please download Ewido Security suite . Be sure to update Ewido to the latest definition files. To do that, open the program and on the main screen click Update–>Start Update.
After updating is 100% complete, run Ewido:
* Click on Scanner
* Click Settings and then under the 'What to Scan?' section at the bottom - check 'Scan every file'
* Click OK to retain those settings and close Ewido.
Now, navigate to C:\WINNT and right click on the System32 folder…in your shell you should now have 'Scan with Ewido' select that and let Ewido scan the whole folder. Save the Ewido log of that scan and post it up in your next post
I thought I posted a noted on this yesterday, but I don't see it so . . . .
Okay I have a dial up connection so it took me a while . . .
Here's the start-up and results of the Ewido scan📎Startup_report_20051019.txt.txt📎ewidoScan_report_20051019.txt
Hi there,
did you scan your whole system with Ewido then?
You do seem to be riddled whith spyware cookies. We can close that door….open Mozilla….Tools…Options….Prvacy….expand the field under 'Cookies'…check 'Allow sites to set cookies' but also check 'From originating vendor only'…click 'OK. 'That should should stop the spyware cookies.
Now, as for the files I don't believe thm to be dangerous. But, what I suggest you do is copy each to a zip file and password protect it. On your AV you should have a feature where it allows you to report a suspiscious file….clicking on that will give you instructions on how to do it…and send the zip file and the password off to them. Until they get back to you….you can use your AV to quarantine thiose files (don't delete them) until your AV people get back to you….if it's shown that the files are not a threat you can remove them from quarantine and we will then have a go at repairing them (since they are corrupted)
Big Smiles
HS
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI