About: Spyware.Destart.A

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
User avatar
ProeliatorX
New Member
Posts: 2
Joined: Mon Jan 07, 2008 6:21 am

About: Spyware.Destart.A

Post by ProeliatorX »

It recently came into my attention when doing a Full System Scan on my computer with BitDefender Internet Security 2008;

The Was a detection labeled "Spyware.Destart.A" in the following directory,

"C:\WINDOWS\system32\Tools\" and the filename was "Restart.exe"

I did some research as to what other users had posted on several sites which were also threaded discussions. Most came to the same conclusion that it must be malicious in one way or another. I decided to investigate and post my own analysis into that subject.

It turns out that that file is associated to a group of other files which I believe is for installation of a device or devices. I confirmed this by some gut feeling that that stuff came from my nForce3-A MotherBoard Setup CD.
I changed the view file options to "View all hidden files and folders" and discovered that indeed that folder named "Tools" was indeed part of the CD along with all of the other associated files!!!

So I did the following:

Erased the "Tools" folder from the directory of "C:\WINDOWS\system32\"
and then restarted My Windows Xp Pro System.

There where no issues or consequences thereafter. I also ran a registry scan for any entries associated with either files or directory and nothing came up.

I hope this helps or even clears some of the confusion I've seen out there through a more solid thread!

All comments, suggestions, other findings are welcomed!

Thanks for reading,

ProeliatorX


P.S.

I posted my other partial analysis on my website, it contains the file names of the other associated files and some other probably useful info.

*Also I couldn't find any information on BitDefender's website as to how it was classified or details about the detection!!!

I am removing the link to my site for now...

I am going to be working on the actual site content...

Peace out.

http://www.proeliatorx.4t.com/

Thanks! :rockin:
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

Post by mnosteele52 »

You should submit the files to Bit Defender so they know it's a false positive.

:)
User avatar
ProeliatorX
New Member
Posts: 2
Joined: Mon Jan 07, 2008 6:21 am

Post by ProeliatorX »

Well do! Thanks. I just took care of that right now! I am awaiting a response.
Post Reply