The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    MSE and "allow" option

    Discussion in 'Security and Anti-Virus Software' started by hakira, May 13, 2011.

  1. hakira

    hakira <3 xkcd

    Reputations:
    957
    Messages:
    1,286
    Likes Received:
    0
    Trophy Points:
    55
    Had a friend download something fishy, and MSE detected it (2 exploit packs) right away - however he tells me that he clicked "allow" for both, I don't know why.

    Now, I'm sitting here with his computer, and sure enough MSE's history does say that 2 files were set to "allow" (Trojan:Mesdeh and a java exploit). However when I look at the logged location of the download, there is nothing to be found! He says he didn't delete anything, so where has this .zip package gone to? The MSE log also says it has been copied to mse's own quarantine zone (\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\), which I promptly deleted. But we can't figure out how the 2 files in question have been "allowed", yet the entire .zip archive that they were contained in is gone.

    I'm running a full scan with MSE on his comp as I type this but it will take a while; so now I'm wondering will MSE even detect something that A) apparently isn't even there anymore and B) has already been told to "allow"? I don't see an option to remove or quarantine anything that has been allowed within MSE.

    Did MSE just remove the entire archive even though it was told to allow files in the archive? Or is something else going on here?
     
  2. Hungry Man

    Hungry Man Notebook Virtuoso

    Reputations:
    661
    Messages:
    2,348
    Likes Received:
    0
    Trophy Points:
    55
    If you've deleted MSE's history it'll detect it again. It may have removed it... I'm not sure. I don't really understand >_> you sent your friend a virus or a fake virus?
     
  3. hakira

    hakira <3 xkcd

    Reputations:
    957
    Messages:
    1,286
    Likes Received:
    0
    Trophy Points:
    55
    Ah, didn't know about deleting the history will force a redetect. I don't know where he found the files, it was hosted on one of those rapidshare clone sites.

    I think it was an actual virus, but because I can't seem to find the files in question, I can't verify what it actually was...

    I'm still really confused as to how mse can "allow" files yet remove the archive which contains the files? That's what I'm leaning towards for an explanation right now and there's not much sense in that!
     
  4. Hungry Man

    Hungry Man Notebook Virtuoso

    Reputations:
    661
    Messages:
    2,348
    Likes Received:
    0
    Trophy Points:
    55
    If it was an actual virus it could simply have moved itself. I dono. MSE's detecting things for me before and when I allow them it just leaves them alone.