Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Virus: Downloader.FXW

Dec 21, 2005 9:51AM PST

I use Norton Internet Security 2005. A couple of hours ago, I had a pop up from Norton that a virus has been found but Norton has been unable to clean it - since it did not have access. The file reference was p9hEPQkbj.exe. It classified the risk as high.

Since Norton said that it was unable to clean, I went to Panda and did a scan. Sure enough, it identified and cleaned a virus. The report suggested that the virus identified and cleaned was DOWNLOADER.FXW. Technical information said that this is a virus which enables hackers to access information including Screen shots.

I have been worried. I ran the Panda a second time and no viruses cropped up.

What I need to know is:

a) Is the p9hEPQkbj.exe the same as DOWNLOADER.FXW ?
b) How do I know that my machine is clean ?
c) Clearly,having paid for Norton Internet Security, why does Norton not detect (?) or clean such viruses ?

I use Windows XP with Service Pack 2.

Can anyone help here

Discussion is locked

- Collapse -
Hi! I Couldn't Find Any Info on the Norton Ref #....
Dec 22, 2005 3:28PM PST

probably it's strictly internal to them. Norton probably couldn't clean because the program was active at time or it has a copy hidden in System Restore files which are designed to be unalterable . You could run the Norton again in "Safe Mode" (will take longer) as that MAY be enough to stop activity & allow cleaning. Instructions here:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam
When you get these kind of findings, it's very important to write down exactly what the warning says especially the path(location) (C:windows\system32\program files\ etc.). Did the phrase "in system volume" appear in warning??
The Panda info you already have.
From Pandas description, if not a false positive, it sounds like you have more than just a keylogger. Sounds more like you have a full blown "Nanny Program" such as some parents use to inspect kids net travels. This kind of program is also used by some companies to monitor employee use of company computers. Basically, it records ALL you see on your screen in snapshots. Do either of these situations apply to you ???
If such a program is not listed in your Control Panels' add/delete programs icon, it can be hard to identify and remove or disable. Some of these hide themselves by not adding anything to toolbar or may be listed as a seemingly harmless in programs files.
Even if you identify the malicious program name, I may require a password you don't know, to disable or remove. Such a password could have been entered by a person installing the program locally (access to the computer) or included in a download trojan from the net.
For more peace of mind you could do another online scan with "housecalls" (active-X: US) or if you have Sun Java installed you would be better off using the Java Scan from Housecalls Europe (links for both below) & you could also try scanning with a trojan specialist like Ewido SS using instructions below courtesy of Roddy32.
HOUSECALLS EU:http://uk.trendmicro-europe.com/enterprise/products/housecall_launch.php
US:http://www.trendmicro.com/spyware-scan/
Ewido SS:
Ewido SS, You might not need the log but it might be useful to save it.

Dowload link http://www.ewido.net/en/


* Install ewido security suite
* When installing, under ''Additional Options'' uncheck ''Install
background guard'' and ''Install scan via context menu''.
* Launch ewido, there should be an icon on your desktop double-click it.
* The program will now go to the main screen

You will need to update ewido to the latest definition files.

* On the left hand side of the main screen click Update
* Then click on Start Update

The update will start and a progress bar will show the updates being
installed.
If you are having problems with the updater, you can use this link to
manually update ewido.
http://www.ewido.net/en/download/updates/

Once the updates are installed do the following:
* Click on scanner
* Click on Complete System Scan and the scan will begin.
* While the scan is in progress you will be prompted to clean files,
click OK
* When it asks if you want to clean the first file, put a check in the
lower left corner of the box that says ''Perform action on all
infections'' then choose clean and click OK.
* Once the scan has completed, there will be a button located on the
bottom of the screen named Save report
* Click Save report.
* Save the report .txt file to your desktop.

Now close ewido security suite.
If you find all results are clean after Norton (safe), Housecalls & Ewido SS (free 14 day trial and can also be run in "safe mode") I suspect you are clean. If results are finding things, tell programs to clean, and re-run a couple again for good measure. Watch for "system volume" mentioned. With all but "House calls", you should be disconnected from net during installs & scans.
Please re-post back to us with results. If all unstatisfactory, there are further things to try.
Hope this gets it for you! Happy

- Collapse -
Thank you
Dec 23, 2005 6:18AM PST

Thank you for your help. I used EWIDO and Housecall. Some points which might help others as well:

a) I think EWIDO is great. However, it kept hanging. At first I thought that it was a Windows XP problem. However, I noticed that it was hanging when it was scanning the Cookies or the Temporary Internet files folder. So I went in and deleted these manually before restarting. Strangely, it hung again when it was scanning the Recycle bin. So I had to delete the contents of the recycle bin. It worked alright. EWIDO did find a number of malware. Not sure if all of them were harmful, but good to know it had cleared.

b) Read about EWIDO. Noticed that EWIDO actually supplements various Anti Virus. Tried to actually buy it, but the online purchase is not easy - tried 2-3 times and could buy it. Really surprised at this - I would have expected that this would be the easiest thing to do.

c) Anyway, I went to Housecall as well. It picked out a number of adwares. Surprise since I thought Ewido would have picked them up. Of course my children were playing inbetween and these could have popped up during this time. Housecall cleaned it all except One which it could not clean. This is ADW_SE.75679. This one still remains.

d) The one thing about both these - EWIDO and Housecall is that both of them first complete the scanning and then do the cleaning. So if it hangs while scanning, as it happened to me when using EWIDO several times, you have to do the scanning all over again. Wonder if there is a reason for this.

e) The other conclusion is that none of these are comprehensive completely. It seems that you need to keep trying more than one to get some satisfaction that your machine is reasonably safe.

f) However, it does appear that even with something like Norton Anti Virus Security Suite, you need a specialist malware supplement like EWIDO

Not easy at all.

Thank you for your help on this.

- Collapse -
Glad You are Pretty Clean. You're Probably Right.....
Dec 23, 2005 1:40PM PST

about new one coming down during kid interlude. I am going to suggest you go to the link below and get & install Spybot & AdawareSE (both free), Update & scan in safe mode. Let fix all. Everything on linked page is trustworthy and safe to use. Suggest you keep & scan regularly. Update about every 8-10 days. More & more the kids sites are downloading spyware because of the lowered security required. Hope this gets it all. Grin
http://reviews.cnet.com/5208-6132-0.html?forumID=32&threadID=114259&messageID=1298628

- Collapse -
Amost Forgot To Mention: You Might Want to Remember.....
Dec 23, 2005 1:53PM PST

this episode when Norton starts flashing renewal demands at you (if not sooner). On same page are several good AVs & firewalls (all free). Enjoy & Happy Holidays! Grin

- Collapse -
p9h etc.
Jan 1, 2006 2:55AM PST

Hi!
I have the same problem. I'm not english, I speak only a few words english, but I hope you can understand me.
The virus p9hEPQkbj.exe is in my computer, in a file exe and I cannot cancel it, because the system says the program is in use. I use norton too, but the antivirus did not find this virus, in apparence the PC is clean, but if I go to the task manager I see the file and if I cancel it from the task manager, the virus creates itself again. Another strange file is present, SERVICES.exe, and this file creates itself again in the register if I try to cancel the key in the register.
I have understand you was able to clean your computer, but perhaps I have no understand. Can you help me?
And if you can help me, can you write simply, very simply the passage to remove the virus so I can understand all?
Thank you!

- Collapse -
Try This
Jan 1, 2006 3:29AM PST

1. Download trial version:
Ewido: http://www.ewido.net/en/download/

2. Install.

3. See ''Additional Options'' uncheck these:
''Install background guard''
''Install scan via context menu''.

4. Run Ewido from icon on Desktop.

5. Update > Start Update

6. Update Finished > Start Computer in SAFEMODE
(Turn on the computer.
Immediately begin tapping the F8 key (or F5 on some computers)
Use the arrow keys to highlight Safe Mode and press the Enter key.)

7. Click on Ewido>Scanner

8. SETTINGS > Scan Every File > Complete System Scan > OK

9. Scan can take a long time.

10. Clean> ''Perform Action on All Infections'' > OK

Also: Do an online virus scan:
http://housecall.trendmicro.com/
(Trend Micro Housecall Scan for Internet Explorer)

- Collapse -
EWIDO is very good
Jan 1, 2006 6:40AM PST

As Bugbatter says EWIDO is a useful software for removing the files.

- Collapse -
p9hEPQ etc.
Jan 2, 2006 5:09PM PST

Thank you for help. I followed the instructions and I was able to remove p9hEPQ.... Now I will watch in my computer if is it all clean and a friend says to me to use HijackThis. I find this little program very interesting and helpful, so I say to you. You will sure know it, but I say you also that you can find it on www.Merijn.org
Thank you.

- Collapse -
You are correct canedipezza that
Jan 2, 2006 9:29PM PST