BackDoor.Blarul virus? Anyone know anything?

J3anyus

Platinum Member
Mar 30, 2001
2,774
0
76
So the other day I was just doing my normal thing on my computer when all of a sudden AVG popped up a warning telling me that C:\System Volume Information\_restore{A1CE9995-9866-4EA2-A9ED-29AE9B90E174}\RP98\A0005563.exe was infected with Trojan horse BackDoor.Blarul.A. I immediately cleared all system restore points to get rid of whatever it was, and then ran a virus scan and found nothing. I Googled around and found almost no information on the virus, other than most companies started adding protection for it between Oct. 31 and Nov. 2 of this year. I checked Symantec's Virus Encyclopedia and found nothing, and even checked AVG's encyclopedia without finding anything. I figured whatever it was it must not be anything important, so I forgot about it.

Skip ahead to today. I'm sitting here talking to people on IRC, when suddenly I notice a jump in my timestamps. All my timestamps moved backwards about a minute and a half, meaning the Windows clock changed. I have all time-synchronization stuff in XP disabled, and I don't run any other software for keeping my time right. The only explanation for why my time would've changed is if I had manually changed it or something else had changed it. So, I began examining things. Nothing in the registry's startup that looked odd, and nothing under the standard Windows startup menu. I then looked at my services, and found a service named "Lictsvfpa" with no description. I checked it out, and it has no dependencies, and doesn't show anything for the path to executable. It's set to startup manually, and it's currently not running. Windows' Event Log shows that this service has never started, and doesn't show anything weird. I also haven't seen anything out of the normal on my firewall. Google turns up nothing when I search for the name of that mystery service.

I don't use P2P programs or do anything like that that would invite viruses onto my machine. I keep both Windows and my AV software up to date, and I don't run any of the standard vulnerable software like IE or Outlook. I'm using Windows XP SP1 with all critical updates installed. I'm just simply trying to figure out exactly what's going on, and why I'm getting weird behavior like my time changing and such. I'm currently running a virus scan through Panda Activescan since if I am infected with something, it would probably disable AVG. I've run Spybot S&D and it hasn't found anything on my machine.

If anyone could offer me any help at all, I'd really appreciate it. Thanks so much.
 

Miramonti

Lifer
Aug 26, 2000
28,651
100
91
Is lictsvfpa located in any conspicuous place or folder? (via a search for it)

It may be created and started in memory each time by something else thats starting up automatically with windows or an app.

Make sure you scan all of your partitions too.
 

capybara

Senior member
Jan 18, 2001
630
0
0
id disable lictsvfpa, not leave it set to manual startup.
and you dont have to DL mp3s , or run outlook express , to get a virus
or worm or backdoor or whatever.
some come in using DCOM. your should disable DCOM if your not using it.
some come in on svchost. the only solution to that is not use IE, use an alternate browser
instead ( hint: firebird).
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |