1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

What is HwInfoD.vxd ?

Discussion in 'General Malware And Security' started by Warren, Mar 8, 2008.

  1. Warren

    Warren Guest

    One of my spyware scanners keeps identifying this file in Windows\System as
    a worm. I quaranteen the file but it keeps coming back.

    Is this a false positive or have I got a serious problem ? If a serious
    problem where is it coming from ?
     
  2. Malke

    Malke Guest

    Warren wrote:
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    > One of my spyware scanners keeps identifying this file in WindowsSystem
    > as
    > a worm. I quaranteen the file but it keeps coming back.
    >
    > Is this a false positive or have I got a serious problem ? If a serious
    > problem where is it coming from ?<!--colorc--><!--/colorc-->

    A quick Google tells me that hwinfod.vxd is one of the driver files created
    by Microsoft System Information Tools.



    However, since you didn't tell us what spyware scanner identifies the file
    as a worm and because malware can call itself anything, you may want to
    upload the file to Virus Total for identification. Virus Total will submit
    the file to numerous antivirus companies and send you a report.



    Additionally, you may wish to perform more thorough scans for viruses and
    malware with other tools:



    Malke
    --
    MS-MVP
    Elephant Boy Computers

    Don't Panic!
     
  3. Warren

    Warren Guest

    Thanks Malke, I've give thaat site a try. The tool that I'm using was
    XoftSpySE, which seems to tend to give false positives. I have to be very
    careful with it. The fact that it keeps coming back has me a little
    suspicious that it is a system file & not a worm.


    "Malke" <malke@invalid.invalid> wrote in message
    news:OD$ggsUgIHA.3352@TK2MSFTNGP04.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Warren wrote:
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    > > One of my spyware scanners keeps identifying this file in WindowsSystem
    > > as
    > > a worm. I quaranteen the file but it keeps coming back.
    > >
    > > Is this a false positive or have I got a serious problem ? If a serious
    > > problem where is it coming from ?<!--colorc--><!--/colorc-->
    >
    > A quick Google tells me that hwinfod.vxd is one of the driver files<!--colorc--><!--/colorc-->
    created<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > by Microsoft System Information Tools.
    >
    >
    >
    > However, since you didn't tell us what spyware scanner identifies the file
    > as a worm and because malware can call itself anything, you may want to
    > upload the file to Virus Total for identification. Virus Total will submit
    > the file to numerous antivirus companies and send you a report.
    >
    >

    >
    > Additionally, you may wish to perform more thorough scans for viruses and
    > malware with other tools:
    >
    >

    >
    > Malke
    > --
    > MS-MVP
    > Elephant Boy Computers
    >

    > Don't Panic!<!--colorc--><!--/colorc-->
     
  4. From: "Warren" <nospam@nospam.com>

    | Thanks Malke, I've give thaat site a try. The tool that I'm using was
    | XoftSpySE, which seems to tend to give false positives. I have to be very
    | careful with it. The fact that it keeps coming back has me a little
    | suspicious that it is a system file & not a worm.
    |

    It is JUNK. It had been listed as a Rogue on SpyWare warrior but was de-listed.
    However based upon new information, it should be re-listed. Unfortunately Spyware Warrior's
    Rogue list is out-of-date.

    Remove XoftSpy!

    --
    Dave

    Multi-AV -
     
  5. Warren

    Warren Guest

    Well Virus Total came out negative so I think it's safe to say it's okay.

    "Warren" <nospam@nospam.com> wrote in message
    news:ugOTRKYgIHA.2004@TK2MSFTNGP05.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Thanks Malke, I've give thaat site a try. The tool that I'm using was
    > XoftSpySE, which seems to tend to give false positives. I have to be very
    > careful with it. The fact that it keeps coming back has me a little
    > suspicious that it is a system file & not a worm.
    >
    >
    > "Malke" <malke@invalid.invalid> wrote in message
    > news:OD$ggsUgIHA.3352@TK2MSFTNGP04.phx.gbl...<!--coloro:green--><span style="color:green <!--/coloro-->
    > > Warren wrote:
    > ><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    > > > One of my spyware scanners keeps identifying this file in<!--colorc--><!--/colorc--><!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
    Windows\System<!--coloro:blue--><span style="color:blue <!--/coloro--><!--coloro:green--><span style="color:green <!--/coloro--><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    > > > as
    > > > a worm. I quaranteen the file but it keeps coming back.
    > > >
    > > > Is this a false positive or have I got a serious problem ? If a<!--colorc--><!--/colorc--><!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
    serious<!--coloro:blue--><span style="color:blue <!--/coloro--><!--coloro:green--><span style="color:green <!--/coloro--><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    > > > problem where is it coming from ?<!--colorc--><!--/colorc-->
    > >
    > > A quick Google tells me that hwinfod.vxd is one of the driver files<!--colorc--><!--/colorc-->
    > created<!--coloro:green--><span style="color:green <!--/coloro-->
    > > by Microsoft System Information Tools.
    > >
    > >
    > >
    > > However, since you didn't tell us what spyware scanner identifies the<!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
    file<!--coloro:blue--><span style="color:blue <!--/coloro--><!--coloro:green--><span style="color:green <!--/coloro-->
    > > as a worm and because malware can call itself anything, you may want to
    > > upload the file to Virus Total for identification. Virus Total will<!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
    submit<!--coloro:blue--><span style="color:blue <!--/coloro--><!--coloro:green--><span style="color:green <!--/coloro-->
    > > the file to numerous antivirus companies and send you a report.
    > >
    > >

    > >
    > > Additionally, you may wish to perform more thorough scans for viruses<!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
    and<!--coloro:blue--><span style="color:blue <!--/coloro--><!--coloro:green--><span style="color:green <!--/coloro-->
    > > malware with other tools:
    > >
    > >

    > >
    > > Malke
    > > --
    > > MS-MVP
    > > Elephant Boy Computers
    > >

    > > Don't Panic!<!--colorc--><!--/colorc-->
    >
    ><!--colorc--><!--/colorc-->
     
  6. Warren

    Warren Guest

    Yes I've heard some very negative comments, like yours. Do you know of any
    specific reference material I can read ? Other antispyware engines don't
    flag it as a potential problem.

    "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
    news:eZ2SXNYgIHA.3940@TK2MSFTNGP05.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > From: "Warren" <nospam@nospam.com>
    >
    > | Thanks Malke, I've give thaat site a try. The tool that I'm using was
    > | XoftSpySE, which seems to tend to give false positives. I have to be<!--colorc--><!--/colorc-->
    very<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > | careful with it. The fact that it keeps coming back has me a little
    > | suspicious that it is a system file & not a worm.
    > |
    >
    > It is JUNK. It had been listed as a Rogue on SpyWare warrior but was<!--colorc--><!--/colorc-->
    de-listed.<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > However based upon new information, it should be re-listed. Unfortunately<!--colorc--><!--/colorc-->
    Spyware Warrior's<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Rogue list is out-of-date.
    >
    > Remove XoftSpy!
    >
    > --
    > Dave
    >
    > Multi-AV -

    >
    ><!--colorc--><!--/colorc-->
     
  7. From: "Warren" <nospam@nospam.com>

    | Yes I've heard some very negative comments, like yours. Do you know of any
    | specific reference material I can read ? Other antispyware engines don't
    | flag it as a potential problem.
    |

    The only public information is that on SpyWare Warrior.


    I don't have any other public data.

    --
    Dave

    Multi-AV -
     
  8. From: "Warren" <nospam@nospam.com>

    | Well Virus Total came out negative so I think it's safe to say it's okay.
    |

    Yes !


    --
    Dave

    Multi-AV -
     
  9. Warren

    Warren Guest

    Good read thanks David. And thank you for all the helpful information.

    "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
    news:u2pnbyYgIHA.2540@TK2MSFTNGP05.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > From: "Warren" <nospam@nospam.com>
    >
    > | Yes I've heard some very negative comments, like yours. Do you know of<!--colorc--><!--/colorc-->
    any<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > | specific reference material I can read ? Other antispyware engines<!--colorc--><!--/colorc-->
    don't<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > | flag it as a potential problem.
    > |
    >
    > The only public information is that on SpyWare Warrior.
    >
    >
    > I don't have any other public data.
    >
    > --
    > Dave
    >

    > Multi-AV -

    >
    ><!--colorc--><!--/colorc-->
     
  10. From: "Warren" <nospam@nospam.com>

    | Good read thanks David. And thank you for all the helpful information.
    |

    YW

    As I noted, SpyWare Warrior is unfortunately out-of-date.
    There are *many* rogues not listed. :-(


    --
    Dave

    Multi-AV -
     
  11. C.B.

    C.B. Guest

    Warren,

    I wouldn't even consider using XoftSpySE as it is provided by the same
    company that provides RegCure. There's no way in hell I would ever use a
    product from ParetoLogic. Actually, ParetoLogic has used the "delisting" of
    its software as a rogue as an excuse that it is legitimate. I read and
    responded to the thread from one of ParetoLogic's representatives but I
    can't seem to remember which discussion group it was in and I can't seem to
    locate it.
    However, don't let me influence your purchasing decisions. My opinion
    of ParetoLogic is mine alone.

    C.B.


    --
    It is the responsibility and duty of everyone to help the underprivileged
    and unfortunate among us.

    "Warren" <nospam@nospam.com> wrote in message
    news:ugOTRKYgIHA.2004@TK2MSFTNGP05.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Thanks Malke, I've give thaat site a try. The tool that I'm using was
    > XoftSpySE, which seems to tend to give false positives. I have to be very
    > careful with it. The fact that it keeps coming back has me a little
    > suspicious that it is a system file & not a worm.
    >
    >
    > "Malke" <malke@invalid.invalid> wrote in message
    > news:OD$ggsUgIHA.3352@TK2MSFTNGP04.phx.gbl...<!--coloro:green--><span style="color:green <!--/coloro-->
    >> Warren wrote:
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >> > One of my spyware scanners keeps identifying this file in
    >> > WindowsSystem
    >> > as
    >> > a worm. I quaranteen the file but it keeps coming back.
    >> >
    >> > Is this a false positive or have I got a serious problem ? If a
    >> > serious
    >> > problem where is it coming from ?<!--colorc--><!--/colorc-->
    >>
    >> A quick Google tells me that hwinfod.vxd is one of the driver files<!--colorc--><!--/colorc-->
    > created<!--coloro:green--><span style="color:green <!--/coloro-->
    >> by Microsoft System Information Tools.
    >>
    >>
    >>
    >> However, since you didn't tell us what spyware scanner identifies the
    >> file
    >> as a worm and because malware can call itself anything, you may want to
    >> upload the file to Virus Total for identification. Virus Total will
    >> submit
    >> the file to numerous antivirus companies and send you a report.
    >>
    >>

    >>
    >> Additionally, you may wish to perform more thorough scans for viruses and
    >> malware with other tools:
    >>
    >>

    >>
    >> Malke
    >> --
    >> MS-MVP
    >> Elephant Boy Computers
    >>

    >> Don't Panic!<!--colorc--><!--/colorc-->
    >
    > <!--colorc--><!--/colorc-->
     

Share This Page