Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Does anyone know of a malware that does this?  (Read 2040 times)

0 Members and 1 Guest are viewing this topic.

BaRR

  • Guest
Does anyone know of a malware that does this?
« on: September 12, 2008, 11:15:37 PM »
As of now, I removed it... But there was a DLL file in my system32 folder trying to write the same file in the same place continually, and failing every time. I found it with process monitor because I was wondering why my computer was running slowly. When I forcefully deleted the DLL (It was in use, naturally...) it BSoD'd the computer. On reboot everything was fine.

I can't remember the name of the DLL, but I google'd it before I deleted it and it came up with 0 results, so I don't think that the name of it would matter much. I do remember that the name was 8 letters, all caps, began with DF, and was in use by firefox, explorer, msn messenger, and winlogon. Unfortunately when Firefox crashes, recent searches aren't saved.

Apparently Trend Micro didn't catch it, so either its a new one or Trend Micro missed it. Although I would like to note that Trend Micro was writing something to its log every few seconds, but when I checked, that particular log was not in the Trend Micro logs folder, which is all the more annoying. Trend micro is also not writing a huge number of logs now, like it was before.

Oddly, even an undelete utility didn't find it! Despite the fact it found my data-shredded passwords from 3 months ago, anyway.  >:(

It's like just gone  :o

In any case, the reason I am posting this topic is because I want to know if there is any other malware out there that does this sort of action, in case I happen to get it again, I'll know what to look for. Even if it's not known, I'd like to know what it was trying to accomplish by writing the same file over and over, if anybody out there might have an explanation. Thanks.

~ BaRR

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 489
  • Experience: Familiar
  • OS: Windows 10
Re: Does anyone know of a malware that does this?
« Reply #1 on: September 12, 2008, 11:35:03 PM »
Welcome to CH.

Sounds like the Vundo trojan or a variant of it. With these when you find one, there are usually multiple more that you don't see/find.

Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

BaRR

  • Guest
Re: Does anyone know of a malware that does this?
« Reply #2 on: September 13, 2008, 07:04:40 PM »
You were right, there were these:

C:\WINDOWS\system32\fccaBSJY.dll
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\winio.vxd
C:\WINDOWS\system32\x64

Ironically, I had disabled these a few weeks ago because I suspected them, but left them in place because I didn't know if they were harmful or not. I guess I missed one file, and I found the name finally: EFCDSLEX.DLL

I've never had a problem with viruses/malware before yesterday, so I didn't know the procedures to deal with it.

Guess I need to do a bit more programming on my Suspicious File Detector. It missed one. Well no program is perfect, hence the name "bug."

~ BaRR

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 489
  • Experience: Familiar
  • OS: Windows 10
Re: Does anyone know of a malware that does this?
« Reply #3 on: September 13, 2008, 07:11:15 PM »
Quote
I've never had a problem with viruses/malware before yesterday, so I didn't know the procedures to deal with it.

And I do.....

If you don't post the combofix log I can't help.

C:\combofix.txt

iamtonsoffun247



    Apprentice

    Thanked: 7
    Re: Does anyone know of a malware that does this?
    « Reply #4 on: September 13, 2008, 07:16:05 PM »
    lol evilfantasy I know this is random, but I just noticed that it says ur experience is "beginner" lol i thik ur a little bit better than that ;)

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 489
    • Experience: Familiar
    • OS: Windows 10
    Re: Does anyone know of a malware that does this?
    « Reply #5 on: September 13, 2008, 07:22:36 PM »
    The more you learn, the less you know...

    iamtonsoffun247



      Apprentice

      Thanked: 7
      Re: Does anyone know of a malware that does this?
      « Reply #6 on: September 13, 2008, 07:23:35 PM »
      The more you learn, the less you know...

      LOL WHAT?! You just had me sitting here for like a minute trying to make sense of that haha lol ok ill leave now......  :-X

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 489
      • Experience: Familiar
      • OS: Windows 10
      Re: Does anyone know of a malware that does this?
      « Reply #7 on: September 13, 2008, 07:26:43 PM »


      Don't leave without meeee

      BaRR

      • Guest
      Re: Does anyone know of a malware that does this?
      « Reply #8 on: September 13, 2008, 09:18:49 PM »
      I write software and there's private stuff on that log, but don't worry, everything's running fine now.

      Quote
      The more you learn, the less you know...

      The more you learn about a subject, the more you realize you don't know about it. I write software, but don't know how to remove viruses, for instance, haha. I completely thought that one DLL was the only file, since it was the only one running, to be honest.

      ~ BaRR

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 489
      • Experience: Familiar
      • OS: Windows 10
      Re: Does anyone know of a malware that does this?
      « Reply #9 on: September 13, 2008, 09:27:54 PM »
      Quote
      I write software and there's private stuff on that log

      Nobody can see your code that you have written. Nothing in the log is harmful to you. That would defeat the purpose of what the malware forum is all about.

      Unless you remove it from the registry you are still infected. Removing dlls isn't enough.

      Your choice though.

      BaRR

      • Guest
      Re: Does anyone know of a malware that does this?
      « Reply #10 on: September 13, 2008, 09:43:19 PM »
      Quote
      Removing dlls isn't enough

      Aye, I read on the internet how to remove everything. You were a big help, thanks. I wouldn't have known there was more left if you hadn't pointed it out.