<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Recurring Malware</title><link>https://community.sophos.com/sophos-labs/f/discussions/98855/recurring-malware</link><description>I&amp;#39;m having a recurring malware problem when I start or restart my Windows 10 PC. A malware by the name Hpmal-kovter/d (close spelling) keeps appearing and Sophos states that it has blocked it and removed it, but it keeps coming back. What can I do to</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Recurring Malware</title><link>https://community.sophos.com/thread/359074?ContentTypeID=1</link><pubDate>Wed, 13 Dec 2017 16:55:58 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1a703b20-1219-4687-ae43-6173cfd7b51e</guid><dc:creator>PeterM</dc:creator><description>&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;We can see the detection is on the legit regsvr32.exe file:&lt;/p&gt;
&lt;p&gt;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&lt;/p&gt;
&lt;p&gt;That file isn&amp;#39;t the problem it is just being used by Kovter. Kovter is what we call a fileless malware meaning once it has infected your machine it wont be us any malicious files physically stored on your machine, instead it will be running in the memory and using the Windows Registry to load itself after a reboot. We need to find where it is hiding itself in the registry and doing that is complicated.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I will send you a private message with some instructions.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Recurring Malware</title><link>https://community.sophos.com/thread/359069?ContentTypeID=1</link><pubDate>Wed, 13 Dec 2017 16:29:33 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f1dabe45-f1b8-48a5-b296-3bc4f2426de7</guid><dc:creator>BeejTee</dc:creator><description>&lt;p&gt;I&amp;#39;m replying online as I&amp;#39;m not sure my first email reply was sent to you.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I am using the personal version (I am on a Windows 64 bit PC).&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I will insert a copy of the log below:&lt;/p&gt;
&lt;p&gt;20171210 150514&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340704 items.&lt;br /&gt;20171210 150514&amp;nbsp;User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.&lt;br /&gt;20171210 150541&amp;nbsp;The automatic sending of file data and samples for Sophos Live Protection is enabled.&lt;br /&gt;20171210 150650&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; started.&lt;br /&gt;20171210 153105&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; aborted.&lt;br /&gt;20171210 153105&amp;nbsp;Summary of results for scan &amp;#39;Scan my computer&amp;#39;:&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items scanned: 53&lt;br /&gt;&amp;nbsp;&amp;nbsp;Errors: 0&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items quarantined: 0&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items dealt with: 0&lt;br /&gt;20171210 153350&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; started.&lt;br /&gt;20171210 155846&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; aborted.&lt;br /&gt;20171210 155846&amp;nbsp;Summary of results for scan &amp;#39;Scan my computer&amp;#39;:&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items scanned: 73&lt;br /&gt;&amp;nbsp;&amp;nbsp;Errors: 0&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items quarantined: 0&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items dealt with: 0&lt;br /&gt;20171210 155851&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; started.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 163037&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 174841&amp;nbsp;File &amp;quot;I:\Downloads Bkup\Downloads\DriverUpdate-setup.exe&amp;quot; belongs to adware or PUA &amp;#39;DriverUpdate - Slimware Util&amp;#39; (of type Adware).&lt;br /&gt;20171210 185602&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 185602&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 185602&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 185602&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 185602&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171210 192945&amp;nbsp;Adware or PUA &amp;#39;DriverUpdate - Slimware Util&amp;#39; has been detected.&lt;br /&gt;20171210 192945&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; completed.&lt;br /&gt;20171210 192946&amp;nbsp;Summary of results for scan &amp;#39;Scan my computer&amp;#39;:&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items scanned: 372461&lt;br /&gt;&amp;nbsp;&amp;nbsp;Errors: 24&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items quarantined: 1&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items dealt with: 0&lt;br /&gt;20171210 194007&amp;nbsp;File &amp;quot;I:\Downloads Bkup\Downloads\DriverUpdate-setup.exe&amp;quot; belongs to adware or PUA &amp;#39;DriverUpdate - Slimware Util&amp;#39; (of type Adware).&lt;br /&gt;20171210 194013&amp;nbsp;File &amp;quot;I:\Downloads Bkup\Downloads\DriverUpdate-setup.exe&amp;quot; has been cleaned up.&lt;br /&gt;20171210 194013&amp;nbsp;Adware or PUA &amp;#39;DriverUpdate - Slimware Util&amp;#39; has been removed.&lt;br /&gt;20171210 201455&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340707 items.&lt;br /&gt;20171210 231337&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340710 items.&lt;br /&gt;20171211 025819&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;: Process killed.&lt;br /&gt;20171211 025826&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;.&lt;br /&gt;20171211 025828&amp;nbsp;Virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39; has been removed.&lt;br /&gt;20171211 133727&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;: Process killed.&lt;br /&gt;20171211 133734&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;.&lt;br /&gt;20171211 133740&amp;nbsp;Virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39; has been removed.&lt;br /&gt;20171211 150014&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340716 items.&lt;br /&gt;20171211 182831&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; started.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 190039&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 210308&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340746 items.&lt;br /&gt;20171211 211051&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 211051&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 211051&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 211051&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 211051&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171211 213757&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; completed.&lt;br /&gt;20171211 213757&amp;nbsp;Summary of results for scan &amp;#39;Scan my computer&amp;#39;:&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items scanned: 370355&lt;br /&gt;&amp;nbsp;&amp;nbsp;Errors: 24&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items quarantined: 0&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items dealt with: 0&lt;br /&gt;20171212 132424&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;: Process killed.&lt;br /&gt;20171212 132431&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;.&lt;br /&gt;20171212 132433&amp;nbsp;Virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39; has been removed.&lt;br /&gt;20171212 132646&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; started.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 140404&amp;nbsp;Scanning &amp;quot;C:\OEM\Preload\Autorun\APP\Best Buy Software Installer R2\Setup.exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 141835&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340798 items.&lt;br /&gt;20171212 162119&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 162119&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 162119&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 162119&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 162119&amp;nbsp;Scanning &amp;quot;I:\FileHistory\BJT\LENOVO\Data\C\Users\BJT\Downloads\flash_setup (2015_08_18 15_36_57 UTC).exe&amp;quot; returned SAV Interface error 0xa0040212: The file is encrypted.&lt;br /&gt;20171212 164802&amp;nbsp;Scan &amp;#39;Scan my computer&amp;#39; completed.&lt;br /&gt;20171212 164802&amp;nbsp;Summary of results for scan &amp;#39;Scan my computer&amp;#39;:&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items scanned: 370804&lt;br /&gt;&amp;nbsp;&amp;nbsp;Errors: 24&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items quarantined: 0&lt;br /&gt;&amp;nbsp;&amp;nbsp;Items dealt with: 0&lt;br /&gt;20171213 021810&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340822 items.&lt;br /&gt;20171213 132753&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;: Process killed.&lt;br /&gt;20171213 132800&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;.&lt;br /&gt;20171213 132802&amp;nbsp;Virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39; has been removed.&lt;br /&gt;20171213 140928&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340847 items.&lt;br /&gt;20171213 162045&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340847 items.&lt;br /&gt;20171213 162046&amp;nbsp;User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.&lt;br /&gt;20171213 162526&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;: Process killed.&lt;br /&gt;20171213 162532&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;.&lt;br /&gt;20171213 162536&amp;nbsp;Virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39; has been removed.&lt;br /&gt;20171213 162931&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340847 items.&lt;br /&gt;20171213 162932&amp;nbsp;User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.&lt;br /&gt;20171213 163120&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;: Process killed.&lt;br /&gt;20171213 163127&amp;nbsp;File &amp;quot;C:\Windows\SysWOW64\regsvr32.exe&amp;quot; belongs to virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39;.&lt;br /&gt;20171213 163130&amp;nbsp;Virus/spyware &amp;#39;HPmal/Kovter-D&amp;#39; has been removed.&lt;br /&gt;20171213 193318&amp;nbsp;Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15340869 items.&lt;br /&gt;20171213 204345&amp;nbsp;Scanning &amp;quot;Boot record, drive F:&amp;quot; returned SAV Interface error 0xa0040210: The file could not be accessed.&lt;br /&gt;20171213 204439&amp;nbsp;Scanning &amp;quot;Boot record, drive F:&amp;quot; returned SAV Interface error 0xa0040210: The file could not be accessed.&lt;br /&gt;20171213 204556&amp;nbsp;Scanning &amp;quot;Boot record, drive J:&amp;quot; returned SAV Interface error 0xa0040210: The file could not be accessed.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Recurring Malware</title><link>https://community.sophos.com/thread/359060?ContentTypeID=1</link><pubDate>Wed, 13 Dec 2017 14:57:10 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d5c7c02d-dbe8-4078-bbdf-dced7cd3a389</guid><dc:creator>PeterM</dc:creator><description>&lt;p&gt;Hi BeejTee,&lt;/p&gt;
&lt;p&gt;Kovter is a nasty piece of malware, among other things it will attempt to steal user details (passwords etc), and a HPmal detection means we detected it running in memory. The fact that we have blocked and removed it is mainly referring to us killing it running in memory, you are quite right to want to know why it is coming back. There is likely something else hiding on the machine that is doing it.&lt;/p&gt;
&lt;p&gt;What Sophos product are you using?&lt;/p&gt;
&lt;p&gt;Can you confirm the exact detection you are getting and what file/process is being detected, assuming you are on a Windows 64bit machine you should be able to look at the log file here:&amp;nbsp;C:\ProgramData\Sophos\Sophos Anti-Virus\logs\SAV.txt&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;that txt file will have the detections of the Kovter detection.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>