Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 14, 2009, 08:41:07 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
334661
Posts
37000
Topics
83884
Members
Latest Member:
Carloslp369
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
« previous
next »
Pages:
[
1
]
Author
Topic: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS! (Read 2096 times)
mntech
Newbie
Offline
Posts: 20
XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
on:
July 04, 2009, 11:34:06 PM »
Comodo Internet Security did an update today and asked for a reboot. After rebooting, when trying to play XMPlay.exe ver. 3.4.2.111, I am getting a popup with window title "ERROR!" and text "This file has been tampered with and MAY BE INFECTED BY A VIRUS!"
I have been running this program version fine for days and previous versions of this program for years. The program ran fine yesterday. I am not seeing this message so far when opening any other programs.
Various previous versions of the XMPlay executable were tried and come up with the same message. I unzipped XMPlay files to another directory -- this program does not require an install -- and I received the same message when trying to execute.
I have Windows Vista 64-bit Service Pack 2 with all updates and Comodo Internet Security, Product 3.10.102194.530, Virus Signature Database 1544.
A full scan and cleaning by Comodo Antivirus did not cure the issue, even after reboot. I followed sticky "What to do if you're infected - eXPerience Rev.3" and cleaned with Malwarebytes and Superantispyware programs. My issue persisted after each cleaning and a reboot.
A-Squared revealed the following detections, which I did not remove per the sticky advice:
Trace.Directory.FavSearch!A2
Trace.File.Ezula!A2
Trojan-Downloader.DelphiIK
Trojan.Generic!IK
HTML.Infected.WebPage!IK
Virus.Win32.Downloader.BV!IK
Trojan.ATRAPS!IK
Virus.JS.ScriptIP!IK
Cracker!IK
Trojan-Dropper.Agent!IK
Trojan-Proxy.Win32.Steredir!IK
Trojan-Spy.Win32.Agent.asf!IK
Riskware.Client-IRC.Win32.mIRC!IK
Trojan.Crypt!IK
Trojan.Dropper!IK
Email-Worm.VBS.Brit!IK
Trojan.BAT.Agent!IK
Trojan.Exploit.Dcomrpc.A!IK
Note: Trojan-Downloader.DelphiIK seems to be present at C:\Program Files\ (x86)\XMPlay\Plugins\dsp_vst.dll, though this may be a false positive and this plugin should not be engaged when running XMPlay from another directory. It is possible that this plugin would be engaged normally, however.
Then I ran HijackThis and I'm attaching the log.
Please help with removing my malware. Thank you!
[EDIT: I also run Spybot Search & Destroy. Yesterday before this problem appeared I know that I updated the program's malware database and did full immunization. I have found very little on the Internet about the exact error that I'm reporting; I don't know if it comes from Comodo, Vista, or elsewhere.]
«
Last Edit: July 04, 2009, 11:53:24 PM by mntech
»
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 892
http://www.venganza.org/ - Noodly Appendage
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #1 on:
July 05, 2009, 08:11:28 AM »
Could you post the name and directory of the files detected by A-Squared?
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
mntech
Newbie
Offline
Posts: 20
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #2 on:
July 05, 2009, 12:45:35 PM »
Quote from: Rotty on July 05, 2009, 08:11:28 AM
Could you post the name and directory of the files detected by A-Squared?
I've attached the scan text, with minor edits ([xxxxx]) for protecting identity.
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
mntech
Newbie
Offline
Posts: 20
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #3 on:
July 05, 2009, 07:09:29 PM »
Update: After more research, it appears that code which generates this error is contained in another program written by the author of XMPlay, called Petite Packer. The code may also be contained somewhere in XMPlay.exe or a related file. I've contacted the author to inquire about this message, as he probably knows what is happening.
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
mntech
Newbie
Offline
Posts: 20
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #4 on:
July 06, 2009, 07:38:16 AM »
Update: Another person has reported this same problem with XMPlay after updating to Comodo version 3.10, but their problem was fixed by reverting to version 3.9. I can try to revert as well and confirm if Comodo version 3.10 is the culprit.
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2725
Follow the White Rabbit...
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #5 on:
July 06, 2009, 07:48:37 AM »
Curious! I just downloaded XMPlay and it works without problem. Strangely enough it must be on the Comodo safe list as I didn't receive an alert, but an entry has been added to D+
I don't believe 3.10 is the problem here, I guess we need to look elsewhere.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
mntech
Newbie
Offline
Posts: 20
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #6 on:
July 06, 2009, 08:17:06 AM »
Well, I reverted to Comodo Internet Security 3.9 and all versions I have of the XMPlay executable now work!
Now what? And can someone advise me now how I should proceed with the detections found by A-Squared and HijackThis?
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2725
Follow the White Rabbit...
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #7 on:
July 06, 2009, 08:32:47 AM »
It's not unusual for an AV/AS application to misinterpret a 'packed' application as malicious. it's the way they work. Unfortunately CIS AV also, sometimes, gets the wrong idea.
Best I can do is suggest you forward your scan results and any files that may be suspect to the various vendors, then wait...
I've now tried XMP on the systems I have here, unfortunately no Vista, but XP and 7. It works...
I ran a scan with mbam, Spybot, hjt as well as CIS AV and nothing untoward was detected. I didn't try a-squared as i don't like it.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
mntech
Newbie
Offline
Posts: 20
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #8 on:
July 06, 2009, 08:45:09 AM »
Quote from: Toggie on July 06, 2009, 08:32:47 AM
Best I can do is suggest you forward your scan results and any files that may be suspect to the various vendors, then wait...
According to the sticky in this forum:
"Here you can receive assistance by the thousands of other forum members in helping you clean your PC and getting it infection free! The type of support you get is irrelevant to if you use CAVS or not, this is for anybody who needs help in cleaning their PC of infections."
So I've submitted A-Squared and HijackThis results above and I'm asking for help HERE! Can someone advise on those?
It seems CIS version 3.10 has the same affect on XMPlay for at least two people, but the program appears virus and malware free. I'd think Comodo needs then to investigate the XMPlay issue. I've submitted my XMPlay executables to Comodo for analysis.
«
Last Edit: July 06, 2009, 09:04:55 AM by mntech
»
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2725
Follow the White Rabbit...
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #9 on:
July 06, 2009, 08:48:03 AM »
I can appreciate your concern and of course we will do what we can to help.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4137
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #10 on:
July 07, 2009, 07:06:46 PM »
I just installed XMPlayer and had it scanned by a2, MBAM (database 2388) and CIS (database 1578) and it didn't find anything suspicious.
With regards to your HJT log. I ran it through
www.hijackthis.de
and these entries got flagged:
E:\PROGRAMS\TaskbarHide\TBhide.exe
E:\PROGRAMS\CoreFTP\coreftp.exe
O4 - Startup: TBhide.exe.lnk = E:\PROGRAMS\TaskbarHide\TBhide.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
What is taskbar hide? An application you know and use? I guess you have Core FTP installed. The AMD service misses a file and is innocuous because of that.
I have one question for now. From what source did you download the XMPlayer? May be got an infected version.
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
mntech
Newbie
Offline
Posts: 20
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #11 on:
July 07, 2009, 07:43:24 PM »
Thanks for looking into this!
TBHide I'm aware of and have been using for years. It's a small proggie that just removes the single line of pixels at the bottom of the screen that still remains when putting Windows taskbar into auto-hide mode.
CoreFTP is installed, yes, but I'm pretty sure it's clean.
XMPlayer was downloaded from the author's ftp site. I get all the executables from the website or the author's ftp location.
Someone has suggested that maybe Comodo's Image Execution setting had something to do with the problem, though with version 3.9 of CIS all of my XMPlay executables work fine with either the Disabled or Normal settings.
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
mntech
Newbie
Offline
Posts: 20
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #12 on:
July 07, 2009, 10:47:28 PM »
Good news! CIS has updated today to version 3.10.102363.531. After uninstalling version 3.9, installing my previous version of 3.10 and then updating to 3.01.102363.531, I'm no longer having the trouble with XMPlay! It will run fine with Image Execution set to Disabled or Normal.
I did notice, however, that the trouble persisted when I first reinstalled 3.10, which was version 3.10.102194.530. Apparently some shortcomings in that version were fixed, or something got corrected on my system.
Anyone have further advice to give on my A-Squared log?
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4137
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #13 on:
July 08, 2009, 12:27:51 PM »
I tried to open the a2 log but it partially show Chinese. Can you post it again?
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
mntech
Newbie
Offline
Posts: 20
Re: XMPlay ERROR! This file has been tampered with and MAY BE INFECTED BY A VIRUS!
«
Reply #14 on:
July 08, 2009, 01:57:26 PM »
Quote from: EricJH on July 08, 2009, 12:27:51 PM
I tried to open the a2 log but it partially show Chinese. Can you post it again?
Thanks! Perhaps there was trouble reading the unicode text Attached is the same file, but encoded in ANSI text.
Logged
Crunch to solve AIDS and other diseases! Join
World Community Grid
.
Tags:
XMPlay
comodo
vista
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - Program Lineup
===> Comodo.TV - News and Announcements
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.046 seconds with 17 queries.
Powered by SMF 1.1.10
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com