Innocent Devil Posted December 9, 2007 Posted December 9, 2007 (edited) whever i open cmd.exeavast! warns thats the files namedscrsys16_061230.scrwinsys16_061230.dll are infected by Win32:hupigon-BQO [Trj]andwinsys32_061230.dll infected by Win32:Delf-ECW [Trj]then i press move to chestthis appears everytime cmd is openedi tried boot time scannin and deleted these files but it reappears wen cmd opensalso tries microsoft malicious software removal toolam using xp sp2 rtm with avast! 4.7 Home editionEDIT:It is a trojan sorry, i mis typd the trojan name, now its corrected Edited December 9, 2007 by Innocent Devil
PC_LOAD_LETTER Posted December 9, 2007 Posted December 9, 2007 Id try a different Antivirus if that one isnt working (avg is free)also, i was unable to find any information on 'Win32:hupogon-BQO' if you need help with this virus, it might help us to know what exactly its called
Innocent Devil Posted December 9, 2007 Author Posted December 9, 2007 the trojan name is mis-typedit actuallyWin32:hupigon-BQO
nitroshift Posted December 9, 2007 Posted December 9, 2007 It is safe to delete those files as they are not needed...
Tarun Posted December 9, 2007 Posted December 9, 2007 It sounds like they're getting restored from the dllcache folder. So you may want to try going into the command prompt and running sfc /purgecache then scanning your Windows directory for viruses.
Innocent Devil Posted December 10, 2007 Author Posted December 10, 2007 previousla i did thatfirst run sfc /purgecachethen sfc /cachesize=0still it resurfaces wen i open cmd
Tarun Posted December 11, 2007 Posted December 11, 2007 Boot into Safe Mode and scan the Windows directory.
Innocent Devil Posted December 12, 2007 Author Posted December 12, 2007 As I said, i tried boot time scanning, found nothingif iput it ignore in avast (clicking Noaction button)another problem happens, sme process opens iexplore.exe and it consumes memory, there is lot of iexplore.exeprocess in taskmgrlet me check once more with boot time scanning .....
eidenk Posted December 12, 2007 Posted December 12, 2007 Once you'll have cleaned those very visible things, get interested in the several invisible and stable rootkits your system is likely to be infected with.
PC_LOAD_LETTER Posted December 12, 2007 Posted December 12, 2007 (edited) just get Icesword and look in the process list for items in RED. those are items that are not visible to the OS directly(aka rootkits).there are other ways to fond 'em but IceSword has never let me down Edited December 12, 2007 by geek
Innocent Devil Posted December 13, 2007 Author Posted December 13, 2007 cmd.exe problem solved its due to some autorun entry in HKLM\software\Cicrosoft\Command Processor{thanx to Sysinternals autoruns}its loads 2 memory by userinit {HKLM\Software\Microsoft\windows NT\CurrentVersion\winlogon}userinit=C:\WINDOWS\system32\userinit.exe,rundll32.exe userinit.exe,rundll32.exe,rundll32.exe start,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll starti deleted it and put justC:\WINDOWS\system32\userinit.exewat is supposed to be default uerinit value ??Now, problem is from winlogon and iexplore.exeafter loading desktopiexplore.exe runs in background, by checking with unlocker it is locked by winlogon.exehow to prevent this? ,why winlogon starting it ??The root of the Trojan is still hidden (ans i cant make un hide folders, it just resets)and can be seen in list of screensaves as scrsys16_061230
eidenk Posted December 18, 2007 Posted December 18, 2007 (edited) Now, problem is from winlogon and iexplore.exeafter loading desktopiexplore.exe runs in background, by checking with unlocker it is locked by winlogon.exehow to prevent this? ,why winlogon starting it ??My guess is you have a kernel mode rootkit installed which is responsable for that. It is very likely that your iexplore.exe process is the genuine Internet Explorer that has been launched by it, has been injected with so-called FWB code by it and serves as a backdoor server. Well, it is a possible explanation.You should look at your system with IceSword recommended above IMO. Edited December 18, 2007 by eidenk
Innocent Devil Posted December 18, 2007 Author Posted December 18, 2007 checked with IceSword found nothing in redbtw iexplore.exe problem too solvedits bcoz ,i havnt configured the Phone and Modem options in CPafter setting region and code and all, rebooted there after no iexplore.exe process initiated by winlogon.exe(i dunno y i should set this as i use cable internet connecting directly 2 the lan card )to conclude that I hope the problem is ALMOST solved.still the presence of scrsys16_061230.scr in Sreensaver list is a prob.wen i select it, avast detects and moves to chest (i afraid even that triggers the reactivation of the trojan)Another problem to add is that i cant unhide folders (it resets back to hide folders)in registry i found that HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hiddenis a REG_SZ value, is it actually a REG_DWORD?maually making it a DWORD fails, as it automaically revert back to REG_SZ
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now