Possible infection?

Thanks. I'll use Hijack this to disable the dvpapi process later today.

Ad Aware was uninstalled yesterday.

Throughout this experience, Ad Aware, Norton 360, Windows Defender, Malwarebytes, and Super Anti spyware all found infections of varying severity. I am glad those have been removed.

 

I reinstalled Norton 360 last night, since last week it looked as though something on the computer might have partially disabled it. Interestingly, when it checked the computer for conflicts before installing, it said I needed to uninstall Windows Defender! I did so and the installation seemed to go smoothly.

 

One starts to wonder if the best thing when switching antivirus/antispyware products is a clean reinstall of Windows. They all seem to leave debris behind when they're uninstalled.

Just a follow up. After running scans with Malwarebytes, SUPER Anti Spyware, Windows Defender, and Norton 360, and using Hijack This, the computer appears to be clean of infections. YES!!! However it was still crashing, then giving me the messge that it had recovered from a serious error. When I sent in the error report and read Microsoft's results, it said this blue screen error could be due to a conflict with a driver or with some recently installed software or hardware, as well as a virus infection, or missing the latest Microsoft updates.

 

So I made sure to install all the latest updates. There were some non-critical ones that it seems don't install automatically. I still experienced crashes.

 

The last thing I tried, in response to the suggestion that it may be a hardware conflict, was remove the RAM I'd put in the computer and put the single stick of 128MB of RAM back in. Well I'll be darned but that stopped the crashing. I had the same type of RAM in the computer - two sticks of PC133 SDRAM (It is an old computer, I know, but it was quite usable for internet banking and paying bills), but they must not have been compatible.

 

Now with the original 128MB PC133 RAM stick in it, it's slow as molasses. I've removed Norton 360, and will be using another computer for my internet activities.

 

Thanks to all who helped as I was sorting this out - yogesh, Floating Red, Quads. You people are the greatest!

Message Edited by Zathrus on 02-04-2009 06:18 AM

Please send it to Symantec for testing

Threat Expert

Thanks Stu, uploaded it.

 

After a bit more reading I found a piece suggesting it comes with S.U.P.E.R, a video converting tool from eRightsoft.  Apparently it is involved in some kind of encryption but I never really understood what they meant.

 

I tried eRightsofts forum for answers but it appears to be down.

when I have googled something and it took me to the prevx site, I feel like they indicate almost everything as a baddie

Emmm, how do I set this thread back to unsolved?

 

http://www.threatexpert.com/report.aspx?md5=67f51b1a82fb11bbb9d486f7ce41cd35

 

  • Submission details:
    • Submission received: 4 June 2009, 07:43:30
    • Processing time: 6 min 22 sec
    • Submitted sample:
      • File MD5: 0x67F51B1A82FB11BBB9D486F7CE41CD35
      • File SHA-1: 0x47C3C04A031A21C118EF34E8C29DB8BEDDCD38F1
      • Filesize: 217,073 bytes
      • Alias & packer info:

 

 

 

Looks like I have some kind of infection but Norton doesn't recognise it.

 

Please try to submit to this one as well.

Malware Submission

Symantec will add the signature if found malware

Hi Stu,  I get this when clicking your link..

 

Secure Connection Failed  

An error occurred during a connection to submit.symantec.com.

Peer's Certificate has been revoked.

(Error code: sec_error_revoked_certificate)       

The page you are trying to view can not be shown because the authenticity of the

 received data could not be verified.

    *  Please contact the web site owners to inform them of this problem.      

Try this link instead ThreatExpert Submission as this is faster and the other link mentioned seems to have a certificate error today.  Thanks.

Is this link to upload to Symantec?  ^^^


JolietJake wrote:
Is this link to upload to Symantec?  ^^^

Yes. That's correct

OK, one (I sent three in) said it's a trojan.

 

Can I get help to remove it?

 

http://www.threatexpert.com/report.aspx?md5=67f51b1a82fb11bbb9d486f7ce41cd35

Symantec will make a signature for it . Where is the malware located?

You can submit the file to Symantec using your Norton product. If you are using a Norton 2009 product, then follow the steps in the Knowledge Base Article given below to submit that file.

 

http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&ssfromlink=true&sprt_cid=dcd3a500-72e0-4af2-bc9f-87acbce9e9e3&seg=hho&ct=us&lg=en&docurl=20080929131726EN

 

Vineeth--

It's a Win-Trojan/Xema.variant as per the Threat Expert and this means that it can be any one of the following threats:

Spyware.Ardakey

Trojan Horse

Backdoor.Tidserv

Infostealer.Gampass

Backdoor.IRC.Bot

 

 

It’s in C\WINDOWS.  How long for a signature?  Not too good if I have to wait some time with an infection.

JolietJake -

 

You can try MalwareBytes AntiMalware while you wait.  You can download it for free from this LINK .  Please choose the free version as this will not interfere with Norton' s scanners (the free version only has on demand scanning) .  Also, note that clicking on the Free Version will take you to another page for the actual download; not to worry this is expected and is not a hijacking or anything nasty.

 

Once you install the program, run it and update the definitions (on the Update tab) .  Then, reboot your machine into Safe Mode and run a Full Scan with MBAM.  Have the program fix / delete whatever it finds and save a log file.  Please post the contents of the log file in a post here for review.

 

To get to Safe Mode, restart your system and after the system powers up, start tapping the F8 key until the Windows Advanced Options menu appears.  Use the arrow keys to highlight Safe Mode (no network or command prompt) and press ENTER.

Thanks DB.  I have MB and did a scan of the actual files (right click and select 'scan with Malwarebytes) but it didn't find them to be malware.

 

I'll try the safe mode scan later.

Keep us informed and if anything comes up on this end, we'll post here.  Thanks.


JolietJake wrote:

Thanks DB.  I have MB and did a scan of the actual files (right click and select 'scan with Malwarebytes) but it didn't find them to be malware.

 

I'll try the safe mode scan later.


You might want to try to disable system restore.