Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Questionable sys file


  • Please log in to reply
2 replies to this topic

#1 Jeff-b

Jeff-b

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:57 PM

Posted 11 December 2010 - 10:19 AM

Hello,

After reviewing Process Explorer I have located an unsigned sys file loaded under System qlhc.sys. I cannot find the file through explorer or through gmer(thinking it might be hidden via rootkit).

Process explorer says its being run from system32\drivers\ -- And Autoruns doesnt show it at all.

I googled the file name but could not come up with anything...which made me think it might be malicious.

If the file is not being masked by a rootkit and is not found through explorer under that folder where is it loading from? And is it legit?

I've run TDSSKiller and that came up clean. Malwarebyes full scan came up clean. Hijackthis does not show anything out of the ordinary.

This windows XP Home SP3

Thanks in advance for the help.

Edited by hamluis, 11 December 2010 - 04:29 PM.
Moved from XP to AII ~ Hamluis.


BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,738 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:08:57 PM

Posted 11 December 2010 - 01:59 PM

With the information you have provided I believe you will need help from the malware removal team. I would like you to start a new thread and post a DDS log HERE and include a link to this thread. Please make sure that you read the information about getting started before you start your thread.

It would be helpful if you post a note here once you have completed the steps in the guide and have started your topic in malware removal. Good luck and be patient. Help is on the way!

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#3 hamluis

hamluis

    Moderator


  • Moderator
  • 56,299 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:10:57 PM

Posted 11 December 2010 - 04:28 PM

Moved to Am I Infected.

Louis




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users