Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

Virus/Malware Most srs virus case in LYN?, Qhost Trojan is just the beginning.

views
     
TSMiracles
post Sep 28 2009, 09:59 PM, updated 17y ago

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
QUOTE
Just few days ago, I was afk and when I come back, I saw this virus notification. It keep popping up every 2 secs as we are speaking.
I did scanned in safe mode using Malwarebytes' Anti-Malware. Yes, there are 2 detected and cleaned.

But this Qhost trojan keep coming in after reboot. I have no clue. :sigh:

edited : yes, my AVs detected the Qhost Trojan. But after deleting it, it keeps coming back. Very persistent virus.

user posted image
then someone asked me to use HostXpert. And it solved the qhost problem.
Pls refer to my older thread.

http://forum.lowyat.net/topic/1173846


My system restore is disabled after the virus attack. I was not able to turn it on back.
I tried every solutions i can find on Google. They failed.



So, i rescanned my laptop.




MBAM log in safe mode



» Click to show Spoiler - click again to hide... «






The ones in blue, they just keep coming back even though it was quarantined and cleaned. Everytime I scan, those 3 must be present.



------------------------------------------------------




MBAM log in normal mode (scanned mins after rebooting from safe mode)

» Click to show Spoiler - click again to hide... «



Added on September 28, 2009, 10:00 pm------------------------------------------

My Random's System Information Tool

log.txt
» Click to show Spoiler - click again to hide... «




info.txt

post too long. so i attach it here.

[attachmentid=1221008]


After that I did a scan run using Kaspersky Online Scanner.

my log.
[attachmentid=1221014]



And finally, my fresh my HJT log

[attachmentid=1221016]


Someone told me that my pc is infected with serious backdoor and trojans. I need help. sad.gif

This post has been edited by Miracles: Sep 28 2009, 10:10 PM
TSMiracles
post Sep 28 2009, 10:44 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
QUOTE(gyver @ Sep 28 2009, 10:23 PM)
Hi again,

It seems you have got a variant of qhost. Somebody just modified the code straint so standard AV can't delete all trojan files.

Please check back my posting about the qhost manual remove. It seems that you have skip a step.

Just do what I did since year 2000 before malware was even given a name. You should do a search by time or sort files in system32  and check the dates. Suspected backdoor files should be the latest dates. Delete all suspected files.

BTW the backdoor bot C:\WINDOWS\system32\secupdat.dat created here, is it the same file name or auto generated with random names everytime after you cleanup. If it is the same just do a search in registry of that entry and delete it.

I hope you are comfortable enough to mess around in system32 and registry files manually smile.gif
*
rclxub.gif I dont really understand the qhost manual remove. im not good in computers.


C:\WINDOWS\system32\secupdat.dat <-- is it the same file name everything. how do i search in registry?

Backdoorfiles, even they are quarantined, they will come back with random names. sad.gif

This post has been edited by Miracles: Sep 28 2009, 10:50 PM
TSMiracles
post Sep 30 2009, 09:40 AM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
Hey.. Below are the logs that you requested.

OTM
[attachmentid=1223212]


Gmer
[attachmentid=1223215]

RSIT
[attachmentid=1223213]
TSMiracles
post Nov 14 2009, 02:29 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
opps sorry for not noticing. yeap, no more malicious items detected. thankiu so much!

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0186sec    0.70    6 queries    GZIP Disabled
Time is now: 14th December 2025 - 11:44 AM