December 9, 200718 yr whever i open cmd.exeavast! warns thats the files namedscrsys16_061230.scrwinsys16_061230.dll are infected by Win32:hupigon-BQO [Trj]andwinsys32_061230.dll infected by Win32:Delf-ECW [Trj]then i press move to chestthis appears everytime cmd is openedi tried boot time scannin and deleted these files but it reappears wen cmd opensalso tries microsoft malicious software removal toolam using xp sp2 rtm with avast! 4.7 Home editionEDIT:It is a trojan sorry, i mis typd the trojan name, now its corrected Edited December 9, 200718 yr by Innocent Devil
December 9, 200718 yr Id try a different Antivirus if that one isnt working (avg is free)also, i was unable to find any information on 'Win32:hupogon-BQO' if you need help with this virus, it might help us to know what exactly its called
December 9, 200718 yr It sounds like they're getting restored from the dllcache folder. So you may want to try going into the command prompt and running sfc /purgecache then scanning your Windows directory for viruses.
December 10, 200718 yr Author previousla i did thatfirst run sfc /purgecachethen sfc /cachesize=0still it resurfaces wen i open cmd
December 12, 200718 yr Author As I said, i tried boot time scanning, found nothingif iput it ignore in avast (clicking Noaction button)another problem happens, sme process opens iexplore.exe and it consumes memory, there is lot of iexplore.exeprocess in taskmgrlet me check once more with boot time scanning .....
December 12, 200718 yr Once you'll have cleaned those very visible things, get interested in the several invisible and stable rootkits your system is likely to be infected with.
December 12, 200718 yr just get Icesword and look in the process list for items in RED. those are items that are not visible to the OS directly(aka rootkits).there are other ways to fond 'em but IceSword has never let me down Edited December 12, 200718 yr by geek
December 13, 200718 yr Author cmd.exe problem solved its due to some autorun entry in HKLM\software\Cicrosoft\Command Processor{thanx to Sysinternals autoruns}its loads 2 memory by userinit {HKLM\Software\Microsoft\windows NT\CurrentVersion\winlogon}userinit=C:\WINDOWS\system32\userinit.exe,rundll32.exe userinit.exe,rundll32.exe,rundll32.exe start,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll starti deleted it and put justC:\WINDOWS\system32\userinit.exewat is supposed to be default uerinit value ??Now, problem is from winlogon and iexplore.exeafter loading desktopiexplore.exe runs in background, by checking with unlocker it is locked by winlogon.exehow to prevent this? ,why winlogon starting it ??The root of the Trojan is still hidden (ans i cant make un hide folders, it just resets)and can be seen in list of screensaves as scrsys16_061230
December 18, 200718 yr Now, problem is from winlogon and iexplore.exeafter loading desktopiexplore.exe runs in background, by checking with unlocker it is locked by winlogon.exehow to prevent this? ,why winlogon starting it ??My guess is you have a kernel mode rootkit installed which is responsable for that. It is very likely that your iexplore.exe process is the genuine Internet Explorer that has been launched by it, has been injected with so-called FWB code by it and serves as a backdoor server. Well, it is a possible explanation.You should look at your system with IceSword recommended above IMO. Edited December 18, 200718 yr by eidenk
December 18, 200718 yr Author checked with IceSword found nothing in redbtw iexplore.exe problem too solvedits bcoz ,i havnt configured the Phone and Modem options in CPafter setting region and code and all, rebooted there after no iexplore.exe process initiated by winlogon.exe(i dunno y i should set this as i use cable internet connecting directly 2 the lan card )to conclude that I hope the problem is ALMOST solved.still the presence of scrsys16_061230.scr in Sreensaver list is a prob.wen i select it, avast detects and moves to chest (i afraid even that triggers the reactivation of the trojan)Another problem to add is that i cant unhide folders (it resets back to hide folders)in registry i found that HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hiddenis a REG_SZ value, is it actually a REG_DWORD?maually making it a DWORD fails, as it automaically revert back to REG_SZ
Create an account or sign in to comment