Register  |  Login




Advertisement

Start Your Own Q&A Site

Create your own Q&A site easily, allowing you to quickly grow a new community around any subject matter or generate new organic traffic for your existing website.

Question

Status: Closed Points: 75 Time: 04:21 - Oct 02, 2007  

greta177

my antivirus program dont except DivoCodec

my antivirus program dont except divocodec

Categories

Answer Discussion
Tutorials

 

oracleofDelphi

Date:: Oct 02, 2007

Time:: 10:39

As well it shouldn't. The Divo/3wplayer codec isn't a codec at all, it's malware.
The program that worked for me was something from wildman productions. it was a little app downloaded from http://wildman-productions.org/ (I have nothing to do with the site, nor am I trying to endorse it) Note that the file downloaded that displayed the divo codec is NEVER the intended file.
Anyway, I'm not sure if it was the binary or the installer (nothing to install really, it's just an exe file) but the links were swapped last time, anyway, one of the two links contains a rar file which has a very simple executable that decompresses 3w files into their playable counterparts.
Since the divo codec isn't a codec at all, you want to remove it just as any other app. since it is a piece of $#%! malware ridden application, our friends at symantec have documented it's removal
http://www.symantec.com/en/uk/norton/sec...
hope this helps

jmrnoras

Date:: Nov 20, 2007

Time:: 15:38

I have tried to install the divo codec, but during the process my anti-virus alerted me to the fact that this was malware. Then with the antivirus I erased the all the installed files. But I'm not sure if I'm still infected since I've noticed there have changed in a shell file. How can i fix this?

oracleofDelphi

Date:: Nov 20, 2007

Time:: 21:23

3w player does the following:

C:\Documents and Settings\All Users\Start Menu\Programs\3wPlayer\Uninstall 3wPlayer.lnk
%ProgramFiles%\3wPlayer\settings.ini
%ProgramFiles%\3wPlayer\settings.stp
%ProgramFiles%\3wPlayer\SkinCrafterDll.dll
%ProgramFiles%\3wPlayer\skins\Stylish.skf
%ProgramFiles%\3wPlayer\test.gif
%ProgramFiles%\3wPlayer\unins000.dat
%ProgramFiles%\3wPlayer\unins000.exe
C:\Documents and Settings\All Users\Start Menu\Programs\3wPlayer\3wPlayer.lnk
%ProgramFiles%\3wPlayer\3wPlayer.exe
%ProgramFiles%\3wPlayer\minime.exe


Next, the program creates the following registry subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\3wPlayer
_is1
HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Sta
rt Menu\Programs\3wPlayer
HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Sta
rt Menu2\Programs\3wPlayer

these files in turn install adware.lop which does the following:

oracleofDelphi

Date:: Nov 20, 2007

Time:: 21:25

May create the file %UserProfile%\Application Data\[RANDOM CHARACTERS].dll.
May create multiple copies of the following file:
%ProgramFiles%\[RANDOM FOLDER NAME]\[RANDOM FILE NAME]
Note:
[RANDOM FOLDER NAME] and [RANDOM FILE NAME] are composed of random English words, such as the following:
team pure
bolt date book
OozeBind
Hold way amok
KEEP AXIS
Adds the .dll file as a Browser Helper Object in the registry.
May create multiple copies of the following files:
%Windir%\[RANDOM FILE NAME].htm
%Windir%\[RANDOM FILE NAME].gif
May create the following files:
%Temp%\Delete.me\Xpp.idx
%Temp%\Delete.me\Tbt.idx
Adds a toolbar and search button to Internet Explorer.
Adds one of the values:
"(Default)" = "%ProgramFiles%\[RANDOM FOLDER NAME]\[RANDOM FILE NAME]"
"(Default)" = "%UserProfile%\Application Data\[RANDOM CHARACTERS].dll"
to one of the following registry subkeys:
HKEY_CLASSES_ROOT\CLSID\[RANDOM CLSID]\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\[RANDOM CLSID]\InprocServer32

oracleofDelphi

Date:: Nov 20, 2007

Time:: 21:34

lastly, you need to check your registry under
hklm->software->microsoft->winnt->winlogon->notify
for random generated dll file subkeys. do not delete anything unless you really know what you're doing. just note the dll files listed.
once you've identified the dll files that shouldn't be there, boot your computer into the recovery console (safe mode won't work) mode using your windows XP disk and rename the previously mentionded dll files. restart the computer normally. if everything is working then go ahead and delete the problem registry keys, if they come back, you're still infected. You'll know if everything is working almost immediately because if you've renamed a file you shouldn't have, you won't be able to boot properly.

admin

Date:: Mar 04, 2009

Time:: 09:58

The question looks to be abandoned by the user who asked it. If no action is taken within 2 days, a Quomon Moderator will consider closing the question and distributing the points.

The Quomon Team

admin

Date:: Mar 10, 2009

Time:: 13:40

The question has been closed.

The Quomon Team

jessonh

Date:: Dec 25, 2010

Time:: 08:08

Hey, are you bothered with the slow internet connection, here is an easy to solve your problem, to install a PC protector or cleaning, according to my personal experience, Tuneup360 is good choice, and your computer takes only 30 sec to start up if you have it!!!

Question Answered

This question has been closed, and points have been rewarded to the following experts:


oracleofDelphi: 75

You're welcome however to comment or give additional information or if you wish, you have the ability to write a Tutorial in the Tutorial Area.

Answer this Question

New User

Email:

Upon submission of this form, you will automatically be registered as a Quomon user and we will send your login information to this address

Registered User

Username:

Password:

Forgot Your Password?

No tutorials have been submitted yet. Want to be the first?

Answer this Question

New User

Email:

Upon submission of this form, you will automatically be registered as a Quomon user and we will send your login information to this address

Registered User

Username:

Password:

Forgot Your Password?

Ask a Question

Have a new question? Ask!

You have 100 characters to use



Top Experts

View More

Rank

Expert

Points

1.

nidhi

10354

2.

oracleofDelphi

6493

3.

rcastagna

5596

4.

LAGM

4848

5.

PeterNZ

3487

6.

gonzalo

2840

7.

Mason

2770

8.

jgivoni

2303

9.

xarcus

1820

10.

Anpanman

917

Become an Expert

Register today to share your knowledge with the community and be recognized and rewarded for your contributions.


Register Here




"Psst, Quomon is a great site. Pass it on."     Tell a Friend  |   Link To Us  |   Save to Delicious  |   Digg! Digg it



Language Options

English:

www.quomon.com

Español:

www.quomon.es