Author Topic: New sys file XP Pro SP3  (Read 11030 times)

0 Members and 1 Guest are viewing this topic.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5710
  • Spartan Warrior
New sys file XP Pro SP3
« on: February 10, 2013, 12:37:09 PM »
File name:  Ixbcgwrb.sys or lxbcgwrb.sys

File listed as autorun allowed Online Armor.  See attached below.  Currently have autorun blocked.

Google shows no results.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76033
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: New sys file XP Pro SP3
« Reply #1 on: February 10, 2013, 12:40:26 PM »
The file date is more than suspicious..!!
Any VT results..??
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89280
  • No support PMs thanks
Re: New sys file XP Pro SP3
« Reply #2 on: February 10, 2013, 01:11:52 PM »
Not to mention the services name which, like the file name appear to be randomly generated. This is probably why you find no information on the google search.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5710
  • Spartan Warrior
Re: New sys file XP Pro SP3
« Reply #3 on: February 10, 2013, 01:59:02 PM »
Recommendation? 

Agree file date is anomalous, as is the file name.  Have run autoruns, used that to check the registry, no current entries found.  OA has same feature using the File Information box and right-clicking that option within to go search for exact location in registry.  Nothing there either.

Thanks for the feedback.

Have the autorun set to block for now.

Can't VT as cannot find the file; not registered in the registry either.  Have searched with all options enabled.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89280
  • No support PMs thanks
Re: New sys file XP Pro SP3
« Reply #4 on: February 10, 2013, 02:03:07 PM »
So it isn't in the drivers folder as in the first image you posted ?

Could be time to go down the analysis scans path, OTL, etc.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5710
  • Spartan Warrior
Re: New sys file XP Pro SP3
« Reply #5 on: February 10, 2013, 02:22:59 PM »
Yes, I'm thinking that also.

Next replies will have all logs posted, except for Malwarebytes, which I will update and run now.  AdwCleaner, OTL, and aswMBR.exe will be posted sometime tomorrow.

Note the time it took for a quick scan.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5710
  • Spartan Warrior
Re: New sys file XP Pro SP3
« Reply #6 on: February 11, 2013, 11:06:51 AM »
Ok.  I've run the normal requested scans.  OTL was run as not on quick scan, so took a bit of time to finish.  Do want to point out that there are various Norton drivers left over on the system as I once had Norton's System Utilities, as well as the a/v, they both have been removed for some years now.

Attached logs are below:

All scans run with the usual start up programs running and active; also connected to the internet whilst these scans were running.

Now I wait.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89280
  • No support PMs thanks
Re: New sys file XP Pro SP3
« Reply #7 on: February 11, 2013, 01:23:13 PM »
A malware removal specialist has been informed of your topic.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New sys file XP Pro SP3
« Reply #8 on: February 11, 2013, 02:45:42 PM »
Hmm that is showing in control set 3 I would like to run Combofix as I can see no triggers for that service

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5710
  • Spartan Warrior
Re: New sys file XP Pro SP3
« Reply #9 on: February 11, 2013, 08:50:02 PM »
Well, Combofix has been run with avast!, OA, and WD disabled.  Some files were deleted, including a windows.ini file.  Reboot was automatic, run took only 6 minutes, and the attached windows error message popped up on logon to admin. 

I've set OA to allow the executable from Comobofix.

No Combofix txt can be found anywhere, so nothing to attach.  Have run Combofix once before, but that was under your supervision, date was August 29, 2012, but that log would not apply?  [EDIT:]  Have a file 377 bytes in size, but not what I expected.  Attached below.
« Last Edit: February 11, 2013, 08:57:33 PM by mchain »
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New sys file XP Pro SP3
« Reply #10 on: February 11, 2013, 08:57:05 PM »
OK that is OA blocking combofix on restart so that it was unable to generate a log

Could you re-run Combofix but not let  OA block that on start

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5710
  • Spartan Warrior
Re: New sys file XP Pro SP3
« Reply #11 on: February 11, 2013, 08:58:26 PM »
Done.  Will post the resulting log on next reply.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5710
  • Spartan Warrior
Re: New sys file XP Pro SP3
« Reply #12 on: February 11, 2013, 09:34:59 PM »
Successfully run Comobfix to completion, as it was OA on reboot that blocked Combofix. 

Note the second attachment; do not know what to make of this?  [EDIT:]  This process popped up whilst Combofix was still running.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New sys file XP Pro SP3
« Reply #13 on: February 11, 2013, 09:52:18 PM »
That was Combofix releasing your registry

Is OA still finding this start up ?

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5710
  • Spartan Warrior
Re: New sys file XP Pro SP3
« Reply #14 on: February 11, 2013, 10:42:30 PM »
Thank you for that.
That was Combofix releasing your registry

Is OA still finding this start up ?

Yes, OA still shows the same autorun as present but blocked.

Attached find registry search for autorun entry.  Same result as before; no entry found.

If need be, can we clean this computer up a bit?  I like tidy, but do not know how to do this safely.  Additional note:  Norton Ghost 10 is installed, so...  (See replies #1, 3, and 7).

[EDIT:] It's not reply 7, it is 6.
« Last Edit: February 11, 2013, 10:45:07 PM by mchain »
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803