SUSPICIOUS ACTIVITY DETECTED

  • 19 November 2017
  • 8 replies
  • 1657 views

Hello,
 
I am new to the forums however I keep getting this suspicious message whenever I turn my computer on, it is there.  https://
I am not sure what it means or if it is a real threat but I keep running scans and it is not finding any malware. Thank you to anyone who can be of assistance.

8 replies

Userlevel 7
Hi tonymontana19
 
Welcome to the Community Forums.
 
 
My initial reaction is that this is a scam caused by a PUA (Potentially Unwanted Application) or adware having gotten onto your compuetr.
 
But please provide as much of the detail of the message contents and exactly when it pops up, as that will help to confirm/disprove the veracity of the above.
 
If the message is anything like this:
 
"Windows Detected Security Error, Due to Suspicious Activity Found on your Computer. Contact our certified Live Window Technicians 1-888-711-5651 ", then it is without doubt a scam...but please provide the details requested as soon as possible and certainly do not take any action that the message may be requesting until we have determined the legitimacy or not of the message.
 
Regards, Baldrick
Okay yes I just got it again this is escatly what it says, sorry the picture didnt work.
 
Suspicious Activity Detected
SecureAnywhere has detected suspicious activity
System Folder Modified: /users/anthony/library/launchagents/.dat.nosync0173.Kbipbc
/Library/Printers/hp/Frameworks/HPDevieMonitoring.framework/Versions/1.0/Helpers/HP Device Monitor Manager.app/Contents/Library?loginItems/HP Device Monitor.app/Contents/MacOS/HP Device Monitor
To allow this app to make changes in the future press 'ignore'
 
the other one said:
 
System Folder Modified: /users/anthony/library/launchagents/com.hp.devicemonitor.plist/library/printers/hp/frameworks/HPDeviceMonitoring.framework/Versions/1.0/Helpers/HP Device Monitor Manager.app/Contents/Library/LoginItems/HP Device Monitor.app/Contents/MacOS/HP Device Monitor
To allow this app to make changes in the future press 'ignore'
 
 
Userlevel 7
Badge +22
Hello @
 
These types of messages appear when LaunchAgents/Daemons are created or modified on the system and when the Realtime shield setting "Monitor services running on the system" is enabled.
 
This setting is disabled by default because it can be chatty, even with applications that are good.
 
The messages you're listing show that the HP software is doing the modification. If you trust the HP software (personally, I would), you should be able to ignore this warning.
 
The formatting of the "System Folder Modified" might seem scary, but is not out of the ordinary for someone who has this shield setting enabled constantly and is used to seeing messages from it.
@ wrote:
Hello @
 
These types of messages appear when LaunchAgents/Daemons are created or modified on the system and when the Realtime shield setting "Monitor services running on the system" is enabled.
 
This setting is disabled by default because it can be chatty, even with applications that are good.
@please, where do I find the Realtime shield setting "Monitor services running on the system"
Is "Monitor services running on the system" a WebrootSA Home setting?
Userlevel 7
Badge +22
Yes, it is a WSA for Mac home setting. You will find it within the "Advanced Settings" > Realtime shield area. Advanced settings is in the top right corner of the WSA for Mac application.
@ wrote:
Yes, it is a WSA for Mac home setting. You will find it within the "Advanced Settings" > Realtime shield area. Advanced settings is in the top right corner of the WSA for Mac application.
Ahh, I should have specified WebrootSA Home for PC.
Thanks
Userlevel 7
Badge +22
This specific notification only happens with the WSA for Mac application.
@ wrote:
This specific notification only happens with the WSA for Mac application.
Okay.  [/Contents/MacOS/HP Device Monitor] Thanks

Reply