I have the following “potential malware” detected during a recent avast scan today
C:\WINDOWS\system32\wbem\proquota.exe
I put it in the chest. But I’m mixed on what to do after. Not sure to trash or keep. I’m not sure I deleate well, my pc could mess up really bad or not.
DONT DELETE it. Try running it through virus total. However that may require “re-infecting” your computer by restoring it, excluding it temporarly, and sending it to virus total. You may do that, but you will need to un-exclude the file and put it back in the chest.
First we have to establish whether it is real badware or a so-called false positive.
Description: proquota.exe is located in the folder C:\Windows\System32. Known file sizes on Windows XP are 50,176 bytes (50% of all occurrence), 45,056 bytes, 45,568 bytes.
There is an icon for this program on the taskbar next to the clock. The file is a Windows system file. The program has a visible window. The file is a Microsoft signed file. proquota.exe is able to record inputs, monitor applications, manipulate other programs. Therefore the technical security rating is 0% dangerous, however also read the users reviews.
Important: Some malware camouflage themselves as proquota.exe, particularly if they are located in c:\windows or c:\windows\system32 folder. Thus check the proquota.exe process on your pc whether it is pest. We recommend Security Task Manager for verifying your computer’s security. It is one of the Top Download Picks of 2005 of The Washington Post and PC World. The malware variant is being described here: http://www.prevx.com/filenames/814125165785198052-X1/PROQUOTA.EXE.html
So first check at virustotal.com
If malicious report here and we what further steps to take to secure your OS,