Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Do i have a virus?


  • Please log in to reply
4 replies to this topic

#1 sizzlefrizzle

sizzlefrizzle

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Location:Cleveland Ohio
  • Local time:08:51 PM

Posted 14 April 2013 - 06:59 PM

I used a program called Hitman Pro on my 2 computers, one is running windows 7 the other is Vista.
On both Hitman detected SFARKL.DLL installed at the same time 9/25/12.
This is what hitman said
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
Name    SFARKL.DLL
Location    C:\Windows\SysWOW64
Size    66.5 KB
Time    201.1 days ago (2012-09-25 07:46:45)
Entropy    5.7
SHA-256    0AE709F95F35429EB06340830A20A848EE9271379BD9C6FA3D0467F25E7476C2
Should i get rid of this?
Thanks in advance

Edit: Moved topic from Windows 7 to the more appropriate forum. ~ Animal

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:08:51 PM

Posted 14 April 2013 - 07:55 PM

Hello, there is vague info on this ,so I think we should get a second opinion.

 

Please go to: VirusTotal
On the page you'll find a "Choose File" button.
Click on the Choose File button.
In the Choose File to Upload window which opens, copy and paste this into the File Name box.


The Full actual path.. something like this. 
C:\Windows\SysWOW64..........SFARKL.DLL

 
Next, click the Open button.
Then click the "Scan It!" button just below.
This will scan the file. Please be patient.
If you get a message saying File has already been analyzed: click Reanalyze file now
Once scanned, copy and paste the link to the results page in your next reply.


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 sizzlefrizzle

sizzlefrizzle
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Location:Cleveland Ohio
  • Local time:08:51 PM

Posted 14 April 2013 - 08:36 PM

https://www.virustotal.com/en/file/0ae709f95f35429eb06340830a20a848ee9271379bd9c6fa3d0467f25e7476c2/analysis/1365989219/



#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:08:51 PM

Posted 14 April 2013 - 08:51 PM

Well,if those 40 + antivirus' say it's clean ,, I concur.... Keep the file. and chalk it up to another Hitman False Positive.


Edited by boopme, 14 April 2013 - 08:52 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 sizzlefrizzle

sizzlefrizzle
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Location:Cleveland Ohio
  • Local time:08:51 PM

Posted 14 April 2013 - 09:04 PM

Ok thank you for your time it is greatly appreciated!!






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users