Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 26th, 2010, 05:31 AM
shorinryu shorinryu is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Exclamation xcqbarm.dll reported as trojan

Hi guys,

The Basics:
Windows 7 Home Premium, 64-bit edition
ESET Smart Security v4.0.467.0
Virus Signature database: 5397 (20100825)
I've been a happy user of Eset since 2006 with Nod32, and when the opportunity rose to upgrade to ESS, I took it.

This morning, I saw an alert message:
Object: C:\Windows\system32\xcqbarm.dll
Threat: a variant of Win32/Spy.Hookit.A.trojan
Comment: Error while deleting. Please submit this object to ESET for analysis.
I've search google and bing for "xcqbarm.dll" verified the spelling a hundred times while doing so, and have come up with exactly zero results.

Does anyone else have this particular problem?
Should I be attempting to delete this file manually in safe mode, since ESS apparently can't?

Chad
  #2  
Old August 26th, 2010, 05:41 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,186
Default Re: xcqbarm.dll reported as trojan

Isn't the file deleted after the next computer restart?
  #3  
Old August 26th, 2010, 10:20 AM
shorinryu shorinryu is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default Re: xcqbarm.dll reported as trojan

No. I assume this is because Windows 7 has super-ultra locked down anything in the %windir% directories, though I could be wrong.

No, after a reboot, I get the same warning message, which is why I asked if I should attempt to delate the file manually.
  #4  
Old August 26th, 2010, 02:07 PM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Re: xcqbarm.dll reported as trojan

Have you tried scanning with other malware removal tools such a SUPERAntispyware or Malwarebytes? I can't find this file on any machine I have access to so I assume it isn't good.
  #5  
Old August 26th, 2010, 05:08 PM
shorinryu shorinryu is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default Re: xcqbarm.dll reported as trojan

No. But the mystery deepens... When I go look in that directory, the infected file is not there: I go from xcopy.exe to xinput1_1.dll.

When I do a custom scan of that folder, I get the following results:
Number of scanned objects: 29099
Number of infected objects: 0
Number of cleaned objects: 0
  #6  
Old August 27th, 2010, 09:58 PM
cool1007 cool1007 is offline
Regular Poster
 
Join Date: Oct 2009
Posts: 57
Default Re: xcqbarm.dll reported as trojan

Do a scan with Malwarebytes and see if it catches it.
  #7  
Old October 16th, 2010, 06:19 PM
shorinryu shorinryu is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default Re: xcqbarm.dll reported as trojan

Sadly, no dice there, either. Whenever I reboot, I'm getting the message that the threat was found in memory, which may explain why I can't actually find the file itself.

Any more suggestions? Is there a way I can purge the memory?
  #8  
Old October 17th, 2010, 12:43 AM
3GUSER 3GUSER is offline
Frequent Poster
 
Join Date: Jan 2010
Posts: 813
Default Re: xcqbarm.dll reported as trojan

Almost two months and you still haven't fixed the problem . WOW!?

Just use another products in order to clean the computer. The mistery you write about is because there may be something that is not detected by ESET.

If a file is in memory , it is on the hard disk , too - this is 100% true. Just not everything is detected by ESET.

I strongly suggest you run Hitman Pro (free multivendor cloud scanning application) . Download from http://www.surfright.nl/en/hitmanpro , start it and perform scan . Remember what and where it detects it (in order to let us know after that) , follow program's instructions , activate licence and remove the malware.
  #9  
Old October 17th, 2010, 01:52 AM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: xcqbarm.dll reported as trojan

You have the latest signatures?
You can check Operating Memory in "Custom Scan" from the ESET Security Window.

Is your file (C:\Windows\system32\xcqbarm.dll) on a NTFS filesystem?
Please check File/Folder access (File properties --> Security --> Advanced)
Check if you have sufficient administrative privileges, etc.

Last edited by toxinon12345 : October 17th, 2010 at 01:58 AM.
  #10  
Old October 17th, 2010, 03:32 AM
shorinryu shorinryu is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default Re: xcqbarm.dll reported as trojan

Scanned with HitMan Pro.

Apart from tracking cookies, this was the only item found:

<Item type="Malware" malwareName="Malware" score="106.0" status="Quarantiend">

<Scanners>
<Scanner id="Ikarus" name="Packed.Win32.Krap!IK"/>
</Scanners>
<File path="C:\Windows\Temp\TMPC253.tmp" hash="97043D1BCB5AF97682C6D5630C93BDB52C0A9535A8ED1D8688389D5FE7F3B573"/>
</Item>

Good catch, but after reboot, I'm still getting warnings about that pesky xcqbarm.dll.

Very strange... I can post the whole HitManPro xml if you like...
  #11  
Old October 17th, 2010, 08:35 AM
shorinryu shorinryu is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default Re: xcqbarm.dll reported as trojan

Quote:
Originally Posted by toxinon12345
You have the latest signatures?
You can check Operating Memory in "Custom Scan" from the ESET Security Window.

Done. Scan came away clean.

Quote:
Originally Posted by toxinon12345
Is your file (C:\Windows\system32\xcqbarm.dll) on a NTFS filesystem?

Yes.

Quote:
Originally Posted by toxinon12345
Please check File/Folder access (File properties --> Security --> Advanced)
Check if you have sufficient administrative privileges, etc.

Checked. I have everything except Full Control, Delete and Take Ownership. I SHOULD be able to see the file in question if it's there... it's just not showing up. I also have hidden and system files displayed...
  #12  
Old October 17th, 2010, 08:57 AM
Boyfriend Boyfriend is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Pakistan
Posts: 1,071
Default Re: xcqbarm.dll reported as trojan

run Chkdsk to eliminate possibilities of corrupt file system.
__________________
Windows 8 Pro x64 + Kaspersky Internet Security 2013 + Shadow Defender 1.2.0.376 + Sandboxie 3.76
  #13  
Old October 17th, 2010, 10:40 AM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: xcqbarm.dll reported as trojan

Quote:
I SHOULD be able to see the file in question if it's there... it's just not showing up

maybe these files are hidden by a rootkit, you tried run a Rescue Boot CD with antivirus? Rootkits are difficult to detect it when active.
  #14  
Old October 17th, 2010, 01:23 PM
Nerimash Nerimash is offline
Regular Poster
 
Join Date: Apr 2009
Location: Ukraine
Posts: 86
Default Re: xcqbarm.dll reported as trojan

Quote:
Originally Posted by shorinryu
Done. Scan came away clean.



Yes.



Checked. I have everything except Full Control, Delete and Take Ownership. I SHOULD be able to see the file in question if it's there... it's just not showing up. I also have hidden and system files displayed...
If you still experiencing problems with malware then you may run Kaspersky Virus Removal Tool. I think it will helps you eliminate malware.
__________________

There are three things for which it is possible to look eternally: How cities are burning, how people are drowning and how trojans are detecting.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:43 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums