J.Sage
November 12, 2021, 2:49pm
1
Hi, I have this error 7214d8f8765e/211112.1431+0100
I’m a complete noob in pc security, do I need to be worried about this?
It’s about a “upgrade.ps1” file in my windows temp folder.
I keep getting this alert when I close it, and it keeps getting “quarantined”.
What can I do to solve this?
Appreciate your help
John
Asyn
November 13, 2021, 8:21am
2
Test the file at VT (https://www.virustotal.com ) and post the link to the result here.
J.Sage
November 13, 2021, 12:05pm
3
Hi! thanks for your answer. Basically it all shows “undetected” and some “unable to process file type”
Here are the details:
Basic Properties
MD5 984932d863a5a564215417a157903e02
SHA-1 50696f0ed8dd02acaa55b3fe946b3b1344e4f762
SHA-256 5832b099084db4aeb5f64f0b755a093fdf6672dfd278e7eaa7f517def7f3f477
Vhash 8d3d009cc256738588a79c98bfe7e82c
SSDEEP 96:rqDwulBnQSwpwUw4Ow9SwZqmAnAVAVA30HyzbLuiYz:rqHOF03Aqq3PLKz
TLSH T16D71011E7596813806B657699D0B906DFF27312B123920147BEEC1812FF7C2DE353AAD
File type Powershell
Magic ASCII English text, with CRLF line terminators
TrID file seems to be plain text/ASCII (0%)
File size 3.40 KB (3485 bytes)
History
First Submission 2021-11-13 12:03:30
Last Submission 2021-11-13 12:03:30
Last Analysis 2021-11-13 12:03:30
Names
upgrade.ps1
Powershell Info
Cmdlets
convertfrom-json
get-service
get-wmiobject
invoke-webrequest
new-object
resolve-path
set-location
start-process
start-sleep
stop-process
stop-service
where-object
Cmdlets Aliases
sc
.NET Calls
System.IO.Path
Functions
Get-MsiDatabaseVersion
stop-service
Variables
$erroractionpreference
$lastexitcode
$null
$psscriptroot
J.Sage
November 13, 2021, 12:06pm
4
Asyn
November 13, 2021, 1:21pm
5
You can report a suspected FP (File/Website) here: https://www.avast.com/false-positive-file-form.php