I saw these in my NOD32 AV Threat log. The ones I saw at first were the 8/30/2007 ones. I thought the infection had been contained and eliminated, but then I later received the 8/31/2007 ones and saw that ZoneAlarm was asking me for authorization for alot of programs it should have had authororized before such as both my Seamonkey and IE web browsers, even NOD was asking for permission to connect. I denied all but didn't tick the always remember option so I'd see when it would ask again. I tried to run the NOD standalone scanner on my system and it said "NOD32 Checking CRC of NOD32.EXE: file is corrupted, possibly due to infection." Now I was getting VERY nervous. I hadn't downloaded anything recently, I mainly use the system to check emails and play an online game. So I confronted my friend that had been over earlier and he said that he had downloaded a file via bittorrent and the the AV windows had popped up, but since it said quarantined/deleted he thought nothing of it and kept on going.
After some Google searches I came accross this forum and I'm hoping I can find some help here. I've downloaded DSS.exe already aswell as done the PandaAV scan, but NEITHER can finish it's scanning, they crash towards the end and I receive no logs . However DSS did download HijackThis and I ran it and did get a successful log there. I did find one line in particular that caught my attention due to the fact that it had such a weird name.
O20 - Winlogon Notify: ljjifgg - C:\WINDOWS\SYSTEM32\ljjifgg.dll
I believe that is one of the culprits and I'm hoping to find a way to get my system up and running again. I'll attach the HijackThis log. Please let me know if I should just add that file as a post since it seems rather small and I've seen other posts with the HijackThis logfile fully posted.
I also notice that the CPU usage of the nod32krn.exe process shoots WAY up to 97% or so alot of time and am worried that it is infecting other .exe's I also found the files my friend had downloaded and can zip those up and provide them if they need to be dissected.
All help would be greatly appreciated.
Time Module Object Name Threat Action User Information
8/31/2007 01:02:50 AMON file C:\TEMP\VRR632.tmp probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/31/2007 01:02:49 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\05NYGZBT\dl[1].exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/31/2007 01:02:48 AMON file C:\TEMP\VRR631.tmp a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/31/2007 01:02:44 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I1C76VNC\adv735[1].exe a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:54:00 AMON file C:\TEMP\VRR3.tmp probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:54:00 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\5W55GNJ4\dl[1].exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:53:58 AMON file C:\TEMP\VRR2.tmp a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:53:58 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\05NYGZBT\adv735[1].exe a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:42:55 AMON file C:\TEMP\VRR2.tmp probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:42:52 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I1C76VNC\dl[1].exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:42:45 AMON file C:\TEMP\VRR1.tmp a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:42:44 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\5W55GNJ4\adv735[1].exe a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:33:00 AMON file C:\TEMP\VRR1E40.tmp probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:32:58 AMON file C:\Documents and Settings\Enrique\Local Settings\Temporary Internet Files\Content.IE5\R411JK6D\dl[1].exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:32:55 AMON file C:\TEMP\VRR1E3F.tmp a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:32:51 AMON file C:\Documents and Settings\Enrique\Local Settings\Temporary Internet Files\Content.IE5\WLFQ23D9\adv735[1].exe a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:32:40 AMON file C:\TEMP_E\GUQF296\wr.exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted Event occurred on a new file created by the application: C:\TEMP_E\GUQF296\subst.exe. The file was moved to quarantine. You may close this window.
After some Google searches I came accross this forum and I'm hoping I can find some help here. I've downloaded DSS.exe already aswell as done the PandaAV scan, but NEITHER can finish it's scanning, they crash towards the end and I receive no logs . However DSS did download HijackThis and I ran it and did get a successful log there. I did find one line in particular that caught my attention due to the fact that it had such a weird name.
O20 - Winlogon Notify: ljjifgg - C:\WINDOWS\SYSTEM32\ljjifgg.dll
I believe that is one of the culprits and I'm hoping to find a way to get my system up and running again. I'll attach the HijackThis log. Please let me know if I should just add that file as a post since it seems rather small and I've seen other posts with the HijackThis logfile fully posted.
I also notice that the CPU usage of the nod32krn.exe process shoots WAY up to 97% or so alot of time and am worried that it is infecting other .exe's I also found the files my friend had downloaded and can zip those up and provide them if they need to be dissected.
All help would be greatly appreciated.
Time Module Object Name Threat Action User Information
8/31/2007 01:02:50 AMON file C:\TEMP\VRR632.tmp probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/31/2007 01:02:49 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\05NYGZBT\dl[1].exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/31/2007 01:02:48 AMON file C:\TEMP\VRR631.tmp a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/31/2007 01:02:44 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I1C76VNC\adv735[1].exe a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:54:00 AMON file C:\TEMP\VRR3.tmp probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:54:00 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\5W55GNJ4\dl[1].exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:53:58 AMON file C:\TEMP\VRR2.tmp a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:53:58 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\05NYGZBT\adv735[1].exe a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:42:55 AMON file C:\TEMP\VRR2.tmp probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:42:52 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I1C76VNC\dl[1].exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:42:45 AMON file C:\TEMP\VRR1.tmp a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 23:42:44 AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\5W55GNJ4\adv735[1].exe a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:33:00 AMON file C:\TEMP\VRR1E40.tmp probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:32:58 AMON file C:\Documents and Settings\Enrique\Local Settings\Temporary Internet Files\Content.IE5\R411JK6D\dl[1].exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:32:55 AMON file C:\TEMP\VRR1E3F.tmp a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:32:51 AMON file C:\Documents and Settings\Enrique\Local Settings\Temporary Internet Files\Content.IE5\WLFQ23D9\adv735[1].exe a variant of Win32/TrojanDownloader.Small.NRS trojan quarantined - deleted NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: \??\C:\WINDOWS\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
8/30/2007 21:32:40 AMON file C:\TEMP_E\GUQF296\wr.exe probably a variant of Win32/TrojanDownloader.Small.EQN trojan quarantined - deleted Event occurred on a new file created by the application: C:\TEMP_E\GUQF296\subst.exe. The file was moved to quarantine. You may close this window.