Is PBRem.exe in the temp folder malware?

windowsuser111

New member
Local time
8:19 PM
Messages
26
when i signed onto windows 7 a notice came up asking for permission for pbrem.exe to make changes to my computer. it was located in appdata\local\temp, i disallowed it, is it malware?
 

My Computer My Computer

OS
Windows 7 Home Premium x64 OEM
Hi,

What anti-malware software do you have installed on your system?

What size is that file? If its under 20MB, upload it to the online scanner VirusTotal. Post the results here.

Regards,
Golden
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
i have:
mse
avast
malwarebytes
spybot s&d

virustotal results:

Antivirus Version Last Update Result
AhnLab-V3 2011.04.03.01 2011.04.03 -
AntiVir 7.11.5.168 2011.04.01 -
Antiy-AVL 2.0.3.7 2011.04.02 -
Avast 4.8.1351.0 2011.04.02 -
Avast5 5.0.677.0 2011.04.02 -
AVG 10.0.0.1190 2011.04.02 -
BitDefender 7.2 2011.04.03 -
CAT-QuickHeal 11.00 2011.04.02 -
ClamAV 0.97.0.0 2011.04.01 -
Commtouch 5.2.11.5 2011.03.24 -
Comodo 8196 2011.04.02 -
DrWeb 5.0.2.03300 2011.04.03 -
eSafe 7.0.17.0 2011.04.01 -
eTrust-Vet 36.1.8248 2011.04.01 -
F-Prot 4.6.2.117 2011.04.02 -
F-Secure 9.0.16440.0 2011.04.02 -
Fortinet 4.2.254.0 2011.04.02 -
GData 22 2011.04.03 -
Ikarus T3.1.1.103.0 2011.04.02 -
Jiangmin 13.0.900 2011.03.31 -
K7AntiVirus 9.96.4280 2011.04.02 -
McAfee 5.400.0.1158 2011.04.02 -
McAfee-GW-Edition 2010.1C 2011.04.02 -
Microsoft 1.6702 2011.04.02 -
NOD32 6010 2011.04.03 -
Norman 6.07.03 2011.04.02 -
Panda 10.0.3.5 2011.04.02 -
PCTools 7.0.3.5 2011.04.01 -
Prevx 3.0 2011.04.03 -
Rising 23.51.05.05 2011.04.02 -
Sophos 4.64.0 2011.04.02 -
SUPERAntiSpyware 4.40.0.1006 2011.04.03 -
Symantec 20101.3.2.89 2011.04.03 -
TheHacker 6.7.0.1.164 2011.04.02 -
TrendMicro 9.200.0.1012 2011.04.02 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.03 -
VBA32 3.12.14.3 2011.04.01 -
VIPRE 8902 2011.04.03 -
ViRobot 2011.4.2.4390 2011.04.02 -
VirusBuster 13.6.284.0 2011.04.02 -

so i guess it's safe
i had deleted my temp and prefetch files before restarting so that might have something to do with it
 

My Computer My Computer

OS
Windows 7 Home Premium x64 OEM
Mmm...OK. I guess I'm suspicious since the first page of Google with pbrem.exe as the search expression causes WoT to flag every link as malicious.

Did you install any new software to your system recently?

Regards,
Golden
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
i just ran the executable and gave it permission, it said "might not have installed correctly", so i reinstalled it using the prompt option, and nothing has happened so far
i installed some software recently, but it's all innocuous - autograph is the only one i can think of
 

My Computer My Computer

OS
Windows 7 Home Premium x64 OEM
not out of the woods yet

I had the same probelm after install Autograph on my Windows 7 pc.
I have not given permissions to pbrem.exe from the temp folder to run, and Autographis working fine so far.

Have you have any recent problems with performance on your PC? other forums suggest that pbrem is worm that may cause performance issues.
 

My Computer My Computer

OS
Windows 7 Home Premium
It could depend on where you got the file from. If you d/l a file from a bad site that hosts a modified version, there could well be a virus in there. Some well known files can be modified to contain a virus. If I d/l anything, I try to get it from the source site instead of a general site hosting the file (if possible).
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
I downloaded the installation file directly from the source.
many other students have used the same download link (provided by the university) and have not had this problem.
It only seems to happen on windows 7 OS.
 

My Computer My Computer

OS
Windows 7 Home Premium
It could depend on where you got the file from. If you d/l a file from a bad site that hosts a modified version, there could well be a virus in there. Some well known files can be modified to contain a virus. If I d/l anything, I try to get it from the source site instead of a general site hosting the file (if possible).

+1 Me too! I have personally ran into that myself by downloading an executable of well known and popular software and it had been modified with a trojan. So stick with the site that the .exe or .zip is supposed to be from..Good advice!
 

My Computer My Computer

Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Ultimate x64
CPU
I7
Motherboard
GA-X58-USB3
Memory
6 x 1.5V DDR3 DIMM sockets supporting up to 24 GB of system
Graphics Card(s)
GeForce GTX 580
Sound Card
Realtek ALC892 codec 2/4/5.1/7.1-channel
Monitor(s) Displays
NEC Display Solutions E321 Black 32"
Screen Resolution
1366 x 768
Hard Drives
OCZ Colossus LT Series OCZSSD2-1CLSLT1T 3.5" 1TB SATA II MLC Internal Solid State Drive
PSU
XFX Black Edition XPS-850W-BES 850W ATX12V
Case
Antec
Cooling
Zalman
Keyboard
Microsoft
Mouse
Microsoft
Back
Top