Computer Virus

NAVIGATION
CATEGORIES
REFERRENCE
LINKS
  • xmltok.dll - malware?

    8 answers - 350 bytes - related search similar search Add To My Delicious Add To My Stumble Upon Add To My Google Mark Add To My Facebook Add To My Digg Add To My Reddit

    When I run McAfee AV, it shows xmltok as malware in my Eudora folder.
    However, Eudora runs fine. Also, I checked another PC with Eudora and
    it also has xmltok.dll in the folder - but McAfee doesn't identify it
    as malware. The two xmltok's are also the exact same size. Could
    someone clarify this for me? Thank you
  • No.1 | | 897 bytes | |

    From: "Nisko" <rmo555@cox.net>

    | When I run McAfee AV, it shows xmltok as malware in my Eudora folder.
    | However, Eudora runs fine. Also, I checked another PC with Eudora and
    | it also has xmltok.dll in the folder - but McAfee doesn't identify it
    | as malware. The two xmltok's are also the exact same size. Could
    | someone clarify this for me? Thank you

    Please submit a sample of the DLL to Virus Total --
    The submission will then be tested against many different AV vendor's scanners.
    That will give you an idea what it is and who recognizes it. In addition, unless told
    otherwise, Virus Total will provide the sample to all participating vendors.

    You can also submit a suspect, one at a time, via the following email URL
    mailto:scan@virustotal.com?subject=SCAN

    When you get the report, please post back the exact results.
  • No.2 | | 714 bytes | |


    "Nisko" <rmo555@cox.netwrote in message
    @4ax.com
    When I run McAfee AV, it shows xmltok as malware in my Eudora folder.
    However, Eudora runs fine. Also, I checked another PC with Eudora and
    it also has xmltok.dll in the folder - but McAfee doesn't identify it
    as malware. The two xmltok's are also the exact same size. Could
    someone clarify this for me? Thank you

    Here is some info I found simply by Googling the file name. It appears that
    the opinions are mixed as to whether or not it is part of an adware program.
    Perhaps it is a dll file used by more than one program, with at least one of
    them being the "Shop-At-Home" adware.

    pc doc

  • No.3 | | 620 bytes | |


    >Please submit a sample of the DLL to Virus Total --
    >
    >The submission will then be tested against many different AV vendor's scanners.
    >That will give you an idea what it is and who recognizes it. In addition, unless told
    >otherwise, Virus Total will provide the sample to all participating vendors.
    >
    >You can also submit a suspect, one at a time, via the following email URL
    >mailto:scan@virustotal.com?subject=SCAN
    >
    >When you get the report, please post back the exact results.


    Thanks, Dave - will do.
  • No.4 | | 416 bytes | |

    >
    >Here is some info I found simply by Googling the file name. It appears that
    >the opinions are mixed as to whether or not it is part of an adware program.
    >Perhaps it is a dll file used by more than one program, with at least one of
    >them being the "Shop-At-Home" adware.
    >
    >
    >
    >
    >
    >pc doc
    >

    Thank you
  • No.5 | | 1220 bytes | |

    From: "Nisko" <rmo555@cox.net>

    >>

    >Here is some info I found simply by Googling the file name. It appears that
    >the opinions are mixed as to whether or not it is part of an adware program.
    >Perhaps it is a dll file used by more than one program, with at least one of
    >them being the "Shop-At-Home" adware.
    >
    >
    >
    >
    >>

    >pc doc
    >>

    | Thank you

    Please realize that any file can be named anything. It is often the case where malware will
    use the name of legitmate files names to obfuscate their malicious intent.

    That is why I asked to send it to Virus Total for analysis by multiple AV scanners. This
    why we are not merely going by a name but by actual analysis of the sample.

    This could have easily been the file; SVCHST.EXE and if you just Google it, you'll find
    many references saying it is legitimate. However, I can provide *numerous* examples of
    malwarde using that name or slight variations of it.

    I mention all this because I did NT see a Virus Total report as requested.
  • No.6 | | 1303 bytes | |

    David H. Lipman wrote:
    From: "Nisko" <rmo555@cox.net>

    Here is some info I found simply by Googling the file name. It
    appears that the opinions are mixed as to whether or not it is part
    of an adware program. Perhaps it is a dll file used by more than
    one program, with at least one of them being the "Shop-At-Home"
    adware.

    pc doc

    >Thank you
    >

    Please realize that any file can be named anything. It is often the
    case where malware will use the name of legitmate files names to
    obfuscate their malicious intent.

    That is why I asked to send it to Virus Total for analysis by
    multiple AV scanners. This why we are not merely going by a name but
    by actual analysis of the sample.

    This could have easily been the file; SVCHST.EXE and if you just
    Google it, you'll find many references saying it is legitimate.
    However, I can provide *numerous* examples of malwarde using that
    name or slight variations of it.

    I mention all this because I did NT see a Virus Total report as
    requested.

    I agree. Especially since there are differing opinions in the Google search.
    It would be wise to send in a sample to VirusTotal as David suggested.

    pc doc

  • No.7 | | 1430 bytes | |


    >>

    >Please realize that any file can be named anything. It is often the
    >case where malware will use the name of legitmate files names to
    >obfuscate their malicious intent.
    >>

    >That is why I asked to send it to Virus Total for analysis by
    >multiple AV scanners. This why we are not merely going by a name but
    >by actual analysis of the sample.
    >>

    >This could have easily been the file; SVCHST.EXE and if you just
    >Google it, you'll find many references saying it is legitimate.
    >However, I can provide *numerous* examples of malwarde using that
    >name or slight variations of it.
    >>

    >I mention all this because I did NT see a Virus Total report as
    >requested.
    >
    >I agree. Especially since there are differing opinions in the Google search.
    >It would be wise to send in a sample to VirusTotal as David suggested.
    >
    >pc doc
    >

    I intend to - haven't been feeling well last couple of days. Also,
    when McAfee called out the file, it was on my wife's networked PC. I
    placed a copy of the file on my PC and ran McAfee again on both her
    version of xmltok and mine. This time, neither one was called out.
    Very strange
  • No.8 | | 451 bytes | |

    From: "Nisko" <rmo555@cox.net>

    | I intend to - haven't been feeling well last couple of days. Also,
    | when McAfee called out the file, it was on my wife's networked PC. I
    | placed a copy of the file on my PC and ran McAfee again on both her
    | version of xmltok and mine. This time, neither one was called out.
    | Very strange

    I understand you are ill and you have my symapthies and my wishes for better health.

Re: xmltok.dll - malware?


max 4000 letters.
Your nickname that display:
In order to stop the spam: 1 + 0 =
QUESTION ON "Computer Virus"

EMSDN.COM