This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] "System infected ' Wallpaper

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI

This afternoon while browzing the net, i got the message suddenly that the 'system is infected' and 'SPyware activity is detected'…

When i googled, i saw this very useful link. I followed the steps given in that. It appears that the spyware is now deleted. My taks manager, speakers were not workign before and now it has started working. Also, i dont get the pop ups that spyware activity is detected and i need to update my security tool.

While all these are gone, i am still stuck with my Wall paper. It still says that my system is infected and i am unable to change the wall paper settings. Is there a way to change it?

Thanks a zillion for this solution link. ANy help on removing the wallpaper would be GREATLY appreaciated.

I am posting my logs below

exehelper log

*****************************
exeHelper by Raktor
Build 20091122
Run at 05:34:08 on 11/29/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Killed process winupdate86.exe
Checking for bad files…
Deleting file C:\WINDOWS\system32\41.exe
Deleting file C:\WINDOWS\system32\critical_warning.html
Deleting file C:\WINDOWS\Temp\_ex-08.exe
Deleting file C:\WINDOWS\system32\winupdate86.exe
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

*******************************************************************
DDS log

exeHelper by Raktor
Build 20091122
Run at 05:34:08 on 11/29/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Killed process winupdate86.exe
Checking for bad files…
Deleting file C:\WINDOWS\system32\41.exe
Deleting file C:\WINDOWS\system32\critical_warning.html
Deleting file C:\WINDOWS\Temp\_ex-08.exe
Deleting file C:\WINDOWS\system32\winupdate86.exe
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

**************************************************************
Attached log


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-11-29.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/25/2009 5:03:08 PM
System Uptime: 11/29/2009 4:06:13 AM (1 hours ago)

Motherboard: Dell Inc. | | 0NF743
Processor: Intel® Core™2 CPU T5500 @ 1.66GHz | Microprocessor | 980/166mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 24 GiB total, 12.957 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 50 GiB total, 38.604 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA

==== System Restore Points ===================

RP1: 11/29/2009 2:54:31 AM - System Checkpoint

==== Installed Programs ======================

32 Bit HP BiDi Channel Components Installer
Adobe Acrobat Connect Add-in
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.9
ALPS Touch Pad Driver
Broadcom 440x 10/100 Integrated Controller
Citrix Presentation Server Client
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Dell Resource CD
Dell Wireless WLAN Card
DVD Suite
EMC VPN Client 5.0.01.0600
Google Chrome
High Definition Audio Driver Package - KB835221
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software
J2SE Development Kit 5.0 Update 7
J2SE Runtime Environment 5.0 Update 7
Java™ 6 Update 17
LG ODD Auto Firmware Update
LiveUpdate 3.1 (Symantec Corporation)
mCore
mDriver
mDrWiFi
mHlpDell
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Communicator 2007
Microsoft Office Project Standard 2003
Microsoft Office Standard Edition 2003
Microsoft Office Visio Standard 2003
Microsoft redistributable runtime DLLs VS2005(x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
mIWA
mLogView
mMHouse
mPfMgr
mPfWiz
mProSafe
MSN
mSSO
MSXML 6.0 Parser (KB927977)
mWlsSafe
mWMI
mXML
mZConfig
OZ776 SCR CardBus V1.1.3.6
OZ776 SCR CardBus Windows Driver
PowerDVD
PowerProducer
RealPlayer
SAP Front-End
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB950582)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB960714)
SigmaTel Audio
Symantec AntiVirus
Update for Windows XP (KB951072-v2)
WebEx
WebFldrs XP
Windows Communication Foundation
Windows Imaging Component
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinRAR archiver
WinZip
XML Paper Specification Shared Components Pack 1.0

==== Event Viewer Messages From Past Week ========

11/26/2009 6:42:59 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Bluetooth Support Service service to connect.
11/26/2009 6:42:59 AM, error: Service Control Manager [7000] - The Bluetooth Support Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/26/2009 6:41:48 AM, error: DCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
11/26/2009 6:41:30 AM, error: NETLOGON [5719] - No Domain Controller is available for domain HCLTECH due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
11/26/2009 4:32:45 AM, error: Dhcp [1002] - The IP address lease 10.7.72.133 for the Network Card with network address 001C26AC9D9E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
11/26/2009 12:38:50 AM, error: Dhcp [1002] - The IP address lease 192.168.1.145 for the Network Card with network address 001C26AC9D9E has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).

==== End Of File ===========================

********************************************************************************
************************

GMER log

GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-11-29 06:16:50
Windows 5.1.2600 Service Pack 3, v.3264
Running: gmer.exe; Driver: C:\DOCUME~1\Bhaskara\LOCALS~1\Temp\awldiuob.sys


—- System - GMER 1.0.15 —-

SSDT 86292A78 ZwAlertResumeThread
SSDT 86290A78 ZwAlertThread
SSDT 85BB7828 ZwAllocateVirtualMemory
SSDT 86228A78 ZwConnectPort
SSDT 86207A78 ZwCreateMutant
SSDT 86291DB8 ZwCreateThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAAC17350]
SSDT 86243CB8 ZwFreeVirtualMemory
SSDT 86201A78 ZwImpersonateAnonymousToken
SSDT 8623CA78 ZwImpersonateThread
SSDT 861FAD70 ZwMapViewOfSection
SSDT 8645F958 ZwOpenEvent
SSDT 8629FAC8 ZwOpenProcessToken
SSDT 86281AC8 ZwOpenThreadToken
SSDT 8625BFC0 ZwQueryValueKey
SSDT 86289AA0 ZwResumeThread
SSDT 86281A90 ZwSetContextThread
SSDT 86281CA0 ZwSetInformationProcess
SSDT 86280BF0 ZwSetInformationThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAAC17580]
SSDT 8623AA78 ZwSuspendProcess
SSDT 8628AA78 ZwSuspendThread
SSDT 8628BE60 ZwTerminateProcess
SSDT 86280A78 ZwTerminateThread
SSDT 86217DC0 ZwUnmapViewOfSection
SSDT 86073A98 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [8654F6F2] atapi.sys[.reloc]
Device \Driver\atapi \Device\Ide\IdePort0 [8654F6F2] atapi.sys[.reloc]
Device \Driver\atapi \Device\Ide\IdePort1 [8654F6F2] atapi.sys[.reloc]
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [8654F6F2] atapi.sys[.reloc]

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\BTHUSB \Device\00000097 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000099 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)

—- Processes - GMER 1.0.15 —-

Process C:\WINDOWS\system32\wuaclt.exe (*** hidden *** ) 3616

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001a6bc4394a
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001a6bc4394a (not active ControlSet)

—- EOF - GMER 1.0.15 —-
Hi I thought the problem was solved but for the wall paper issue. Now i have a new issue. Since morning, i am getting an alert that the system is infected by 'w32.spybot.worm'. My Symantec antivirus recognized it and it cleaned it by deletion. It prompts me to reboot and when i reboot, again the worm pops up. it looks like that it needs to be deleted permanently from somewhere, maybe registry.I am not sure and i am not a computer nerd. So, in addition to removing the 'Wall paper; issue, can somebody help me in removing this w32.spybot.worm permanently. Thanks
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
[external image: Posted Image]
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
Hi I have done the steps suggested and my system looks a lot better now. The wallpaper is gone now and after rebooting, i have not got any 'spybot' pop ups. I am attaching the malware log file. I have note attached 'HijackThis' log as indicated as it was very clearly mentioned not to use HijacThis tool without proper supervision. as i am not a computer nerd, i did nto do it as suggested. Now pl. take a look at the log file and let me know if i need to do anything next. Thanks a million for your help. Its much appreciated. Log of Malware ************************************************************* Malwarebytes' Anti-Malware 1.41 Database version: 3264 Windows 5.1.2600 Service Pack 3, v.3264 12/1/2009 6:31:04 AM mbam-log-2009-12-01 (06-31-04).txt Scan type: Quick Scan Objects scanned: 118645 Time elapsed: 6 minute(s), 11 second(s) Memory Processes Infected: 6 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 8 Registry Data Items Infected: 4 Folders Infected: 0 Files Infected: 13 Memory Processes Infected: C:\WINDOWS\system32\photo_id.exe (Malware.Packer) -> Unloaded process successfully. C:\WINDOWS\system32\av_md.exe (Trojan.Inject) -> Unloaded process successfully. C:\Documents and Settings\Bhaskara\photo_id.exe (Malware.Packer) -> Unloaded process successfully. C:\Documents and Settings\Bhaskara\av_md.exe (Trojan.Inject) -> Unloaded process successfully. C:\skami.exe (Trojan.Inject) -> Unloaded process successfully. C:\skami.exe (Trojan.Inject) -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\photo_id (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\photo_id (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\av_md (Trojan.Inject) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\av_md (Trojan.Inject) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Microsoft Driver Setup (Worm.Palevo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Driver Setup (Worm.Palevo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn (Hijack.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Bhaskara\photo_id.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\photo_id.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\av_md.exe (Trojan.Inject) -> Quarantined and deleted successfully. C:\Documents and Settings\Bhaskara\av_md.exe (Trojan.Inject) -> Quarantined and deleted successfully. C:\skami.exe (Trojan.Inject) -> Quarantined and deleted successfully. C:\start.exe (Trojan.Inject) -> Quarantined and deleted successfully. C:\WINDOWS\system32\winlogon86.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Documents and Settings\Bhaskara\Local Settings\Temp\l (Malware.Packer) -> Quarantined and deleted successfully. C:\Documents and Settings\Bhaskara\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\wind7upd.exe (Worm.Palevo) -> Delete on reboot. C:\WINDOWS\system32\AVR10.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\winhelper86.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\937.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
hi In the earlier post, it was mentioned not to run COmbofix without any supervision and it may lead to sytem inoperability. I am a bit apprehensive as i am not a computer expert and worried. Can i run combofix? Also, it seems that my system is normal now. I am not getting any pop ups and i ran full scan of symantec antivirus and it did not detect anything. Pl. confirm if i still need to carry out the combofix run. Again, thank a lot for your help
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI