Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 25, 2013, 02:19:51 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664070
Posts
70633
Topics
145263
Members
Latest Member:
freefirecauldron
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS! (Read 22462 times)
mntech
Comodo Member
Offline
Posts: 35
XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
on:
July 04, 2009, 11:34:06 PM »
Comodo Internet Security did an update today and asked for a reboot. After rebooting, when trying to play XMPlay.exe ver. 3.4.2.111, I am getting a popup with window title "ERROR!" and text "This file has been tampered with and MAY BE INFECTED BY A VIRUS!"
I have been running this program version fine for days and previous versions of this program for years. The program ran fine yesterday. I am not seeing this message so far when opening any other programs.
Various previous versions of the XMPlay executable were tried and come up with the same message. I unzipped XMPlay files to another directory -- this program does not require an install -- and I received the same message when trying to execute.
I have Windows Vista 64-bit Service Pack 2 with all updates and Comodo Internet Security, Product 3.10.102194.530, Virus Signature Database 1544.
A full scan and cleaning by Comodo Antivirus did not cure the issue, even after reboot. I followed sticky "What to do if you're infected - eXPerience Rev.3" and cleaned with Malwarebytes and Superantispyware programs. My issue persisted after each cleaning and a reboot.
A-Squared revealed the following detections, which I did not remove per the sticky advice:
Trace.Directory.FavSearch!A2
Trace.File.Ezula!A2
Trojan-Downloader.DelphiIK
Trojan.Generic!IK
HTML.Infected.WebPage!IK
Virus.Win32.Downloader.BV!IK
Trojan.ATRAPS!IK
Virus.JS.ScriptIP!IK
Cracker!IK
Trojan-Dropper.Agent!IK
Trojan-Proxy.Win32.Steredir!IK
Trojan-Spy.Win32.Agent.asf!IK
Riskware.Client-IRC.Win32.mIRC!IK
Trojan.Crypt!IK
Trojan.Dropper!IK
Email-Worm.VBS.Brit!IK
Trojan.BAT.Agent!IK
Trojan.Exploit.Dcomrpc.A!IK
Note: Trojan-Downloader.DelphiIK seems to be present at C:\Program Files\ (x86)\XMPlay\Plugins\dsp_vst.dll, though this may be a false positive and this plugin should not be engaged when running XMPlay from another directory. It is possible that this plugin would be engaged normally, however.
Then I ran HijackThis and I'm attaching the log.
Please help with removing my malware. Thank you!
[EDIT: I also run Spybot Search & Destroy. Yesterday before this problem appeared I know that I updated the program's malware database and did full immunization. I have found very little on the Internet about the exact error that I'm reporting; I don't know if it comes from Comodo, Vista, or elsewhere.]
hijackthis.txt
(8.18 KB - downloaded 7 times.)
«
Last Edit: July 04, 2009, 11:53:24 PM by mntech
»
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Rotty
Comodo's Hero
Offline
Posts: 903
http://www.venganza.org/ - Noodly Appendage
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #1 on:
July 05, 2009, 08:11:28 AM »
Could you post the name and directory of the files detected by A-Squared?
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
mntech
Comodo Member
Offline
Posts: 35
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #2 on:
July 05, 2009, 12:45:35 PM »
Quote from: Rotty on July 05, 2009, 08:11:28 AM
Could you post the name and directory of the files detected by A-Squared?
I've attached the scan text, with minor edits ([xxxxx]) for protecting identity.
a2scan_090704-203628.txt
(5.67 KB - downloaded 11 times.)
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
mntech
Comodo Member
Offline
Posts: 35
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #3 on:
July 05, 2009, 07:09:29 PM »
Update: After more research, it appears that code which generates this error is contained in another program written by the author of XMPlay, called Petite Packer. The code may also be contained somewhere in XMPlay.exe or a related file. I've contacted the author to inquire about this message, as he probably knows what is happening.
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
mntech
Comodo Member
Offline
Posts: 35
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #4 on:
July 06, 2009, 07:38:16 AM »
Update: Another person has reported this same problem with XMPlay after updating to Comodo version 3.10, but their problem was fixed by reverting to version 3.9. I can try to revert as well and confirm if Comodo version 3.10 is the culprit.
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Toggie
Guest
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #5 on:
July 06, 2009, 07:48:37 AM »
Curious! I just downloaded XMPlay and it works without problem. Strangely enough it must be on the Comodo safe list as I didn't receive an alert, but an entry has been added to D+
I don't believe 3.10 is the problem here, I guess we need to look elsewhere.
Logged
mntech
Comodo Member
Offline
Posts: 35
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #6 on:
July 06, 2009, 08:17:06 AM »
Well, I reverted to Comodo Internet Security 3.9 and all versions I have of the XMPlay executable now work!
Now what? And can someone advise me now how I should proceed with the detections found by A-Squared and HijackThis?
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Toggie
Guest
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #7 on:
July 06, 2009, 08:32:47 AM »
It's not unusual for an AV/AS application to misinterpret a 'packed' application as malicious. it's the way they work. Unfortunately CIS AV also, sometimes, gets the wrong idea.
Best I can do is suggest you forward your scan results and any files that may be suspect to the various vendors, then wait...
I've now tried XMP on the systems I have here, unfortunately no Vista, but XP and 7. It works...
I ran a scan with mbam, Spybot, hjt as well as CIS AV and nothing untoward was detected. I didn't try a-squared as i don't like it.
Logged
mntech
Comodo Member
Offline
Posts: 35
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #8 on:
July 06, 2009, 08:45:09 AM »
Quote from: Toggie on July 06, 2009, 08:32:47 AM
Best I can do is suggest you forward your scan results and any files that may be suspect to the various vendors, then wait...
According to the sticky in this forum:
"Here you can receive assistance by the thousands of other forum members in helping you clean your PC and getting it infection free! The type of support you get is irrelevant to if you use CAVS or not, this is for anybody who needs help in cleaning their PC of infections."
So I've submitted A-Squared and HijackThis results above and I'm asking for help HERE! Can someone advise on those?
It seems CIS version 3.10 has the same affect on XMPlay for at least two people, but the program appears virus and malware free. I'd think Comodo needs then to investigate the XMPlay issue. I've submitted my XMPlay executables to Comodo for analysis.
«
Last Edit: July 06, 2009, 09:04:55 AM by mntech
»
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Toggie
Guest
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #9 on:
July 06, 2009, 08:48:03 AM »
I can appreciate your concern and of course we will do what we can to help.
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16723
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #10 on:
July 07, 2009, 07:06:46 PM »
I just installed XMPlayer and had it scanned by a2, MBAM (database 2388) and CIS (database 1578) and it didn't find anything suspicious.
With regards to your HJT log. I ran it through
www.hijackthis.de
and these entries got flagged:
E:\PROGRAMS\TaskbarHide\TBhide.exe
E:\PROGRAMS\CoreFTP\coreftp.exe
O4 - Startup: TBhide.exe.lnk = E:\PROGRAMS\TaskbarHide\TBhide.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
What is taskbar hide? An application you know and use? I guess you have Core FTP installed. The AMD service misses a file and is innocuous because of that.
I have one question for now. From what source did you download the XMPlayer? May be got an infected version.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
mntech
Comodo Member
Offline
Posts: 35
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #11 on:
July 07, 2009, 07:43:24 PM »
Thanks for looking into this!
TBHide I'm aware of and have been using for years. It's a small proggie that just removes the single line of pixels at the bottom of the screen that still remains when putting Windows taskbar into auto-hide mode.
CoreFTP is installed, yes, but I'm pretty sure it's clean.
XMPlayer was downloaded from the author's ftp site. I get all the executables from the website or the author's ftp location.
Someone has suggested that maybe Comodo's Image Execution setting had something to do with the problem, though with version 3.9 of CIS all of my XMPlay executables work fine with either the Disabled or Normal settings.
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
mntech
Comodo Member
Offline
Posts: 35
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #12 on:
July 07, 2009, 10:47:28 PM »
Good news! CIS has updated today to version 3.10.102363.531. After uninstalling version 3.9, installing my previous version of 3.10 and then updating to 3.01.102363.531, I'm no longer having the trouble with XMPlay! It will run fine with Image Execution set to Disabled or Normal.
I did notice, however, that the trouble persisted when I first reinstalled 3.10, which was version 3.10.102194.530. Apparently some shortcomings in that version were fixed, or something got corrected on my system.
Anyone have further advice to give on my A-Squared log?
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16723
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #13 on:
July 08, 2009, 12:27:51 PM »
I tried to open the a2 log but it partially show Chinese. Can you post it again?
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
mntech
Comodo Member
Offline
Posts: 35
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #14 on:
July 08, 2009, 01:57:26 PM »
Quote from: EricJH on July 08, 2009, 12:27:51 PM
I tried to open the a2 log but it partially show Chinese. Can you post it again?
Thanks! Perhaps there was trouble reading the unicode text Attached is the same file, but encoded in ANSI text.
a2scan_090704-203628-ansi.txt
(2.83 KB - downloaded 5 times.)
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Tags:
XMPlay
comodo
vista
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.037 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com