This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan SPM/LX, Worm.win32.Netsky, avr10.exe

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Win XP Pro, suddenly Avast identified that it wanted to put avr10.exe in quarantine chest, and at about that time the desktop wallpaper disappeared and the background is now just a plain shade of green, with a box in the center (behind the icons) which says "Your System is Infected!" in bold red letters. A window pops up periodically titled "Warning" "Attention!. System has detected a potential hazard (Trojan SPM/LX) on your computer that may infect executable files. You private information and PC safety is at risk. To get rid of unwanted spyware and keep your computer safe you need update your current security software. Click OK to download official intrusion detection system (IDS software). The bad English tells me that message is fishy so I have declined that offer each time the window pops up. Another message pops out of the systray periodically which says "Click here to protect your computer from spyware! Your computer is infected! Windows has detected an infection of spyware! It is recommended to use special antispyware tools to prevent data loss. Windows will now download and install the most up-to-date antispyware for you." I have declined that as well. I started the process outlined in "How to Get Help", and downloaded and ran ERUNT, and saved the file. I downloaded DDS, but when I run it, very briefly a window with white text on a black background (like an old DOS window) appears for a second or so and then disappears, and another window appears in the center of the desktop which is titled "Warning". "Application cannot be executed. The file is infected. Please activate your antivirus software" I never see DDS.txt, and attach.txt never opens. I downloaded rootrepeal and ran it, but after checking the checkboxes for drivers, processes etc and clicking OK, I am NOT given a checkbox for the main system drive, but rather the program runs for a few seconds and the scan is finished. The report is very short, and it follows: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/12/10 21:23 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_iaStor.sys Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys Address: 0x946C1000 Size: 815104 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0x90E2A000 Size: 49152 File Visible: No Signed: - Status: - SSDT ——————- #: 025 Function Name: NtClose Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480b6b8 #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480b574 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480ba52 #: 068 Function Name: NtDuplicateObject Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480b14c #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480b64e #: 122 Function Name: NtOpenProcess Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480b08c #: 128 Function Name: NtOpenThread Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480b0f0 #: 177 Function Name: NtQueryValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480b76e #: 204 Function Name: NtRestoreKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480b72e #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0x9480b8ae ==EOF== As I mentioned, there is no data from DDS to include. I look forward to hearing your response and I will be ready to follow up on any suggestions you have in the morning. Thanks, Jon
Hi JonHK, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the bold text into the window under Custom Scan
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Thanks
Things went from bad to worse. Following my last post, I couldn't even get to a Desktop, even in Safe Mode. I had disconnected that computer from the network, and I needed to remove at least some of the data from that drive, so I removed the hard drive from the machine. I connected the drive via an external power cable and a SATA data cable adapter to my laptop, and the laptop recognized the drive as just some external drive (F). I copied the data files I needed to retrieve to another external hard drive (E), and when I ran an AVG scan on (E), there appeared to be no problems. I am thinking I will install a brand-new hard drive (had been thinking about increasing capacity anyway) on the machine which had the problem, install Windows 7 (which I had been planning to do anyway), and then put my data which is now on (E) back on the new drive running Windows 7, and re-install all of the programs from scratch. Do you see any problems with this plan? I headed in this direction because in reading many of the threads, a common comment was that "if it's any worse or if this doesn't work, you may have to re-format the drive", and I knew that to go from XP to 7 I was going to either re-format the drive, or install a brand-new drive anyway. Is there anything I could do now that the original drive is out and on the bench to be able to make certain there is nothing bad left on it, but more importantly, what programs would be best to try to avoid these rootkits and worms in the future? I appreciate very much all of your help. Thanks, Jon
Hi

Nothing wrong with your plan as far as an upgrade goes. If you were going to reformat it anyway, now is as a good time as any.

If there are any programs you want off it, I'd suggest that you run an online scan on the HD. Since you are able to connect it to another computer you will be able to scan just that drive. This way you will be able to see if any of the programs are infected.

Depending on the amount and type of data it could take awhile, but well worth the time if it prevents you from reinstalling an infecion.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on whichever drive letter the HD is currently seen as under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

what programs would be best to try to avoid these rootkits and worms in the future?

A very good resource for information and programs can be found HERE .
I ran Kaspersky and asked it to scan the hard drive of my laptop © and the external drive (E) to which I had copied the files I needed from the known-infected drive. I was surprised to find that the report shows some files on the laptop infected. Attached is the Kaspersky report.
Hi JonHK, Those detections are in the Inbox in your Thunderbird mail account. There isn't any way of telling which email it detected. You will need to open the inbox and delete any unsolicited email. The bad ones usually have an attachment. Other than that, it would seem you are in the clear. Good plan scanning the laptop as well. Good luck with the new install.
When I ran the Kaspersky scan the first time, it did not scan the E drive, the one where the potentially-infected files might be. As you can see from the attached log, it's a good thing I re-ran the scan. See attached scan of E
Hi jonHK,

E:\DATA FROM JONS COMPUTER\Documents and Settings\JON\Local Settings\Temp\{112B31E3-59A5-3FC1-CABB-6447C0E9F93A}-winupdate86.exe Infected: Trojan.Win32.Vilsel.ocj 1
E:\DATA FROM JONS COMPUTER\Documents and Settings\JON\Local Settings\Temp\{734C2473-9334-52B6-56B3-626F67BA32E0}-winupdate86.exe Infected: Trojan.Win32.Vilsel.ocj 1
E:\DATA FROM JONS COMPUTER\Documents and Settings\JON\Local Settings\Temp\{BFE54FF9-5A36-725E-2FD6-4C2999B03761}-winupdate86.exe Infected: Trojan.Win32.Vilsel.ocj

We can remove these without any problems as they are in a temporary folder and won't effect your data.

In windows explorer, navigate to this folder E:\DATA FROM JONS COMPUTER\Documents and Settings\JON\Local Settings\Temp
  • The right hand panel should now list the contents
  • At the top of windows explorer, click Edit, click Select All, this will highlight all the files in the right panel
  • Click File, click delete
  • Click yes to confirm
Empty the Recycle Bin.

We can't use a tool to remove the infected emails as we would in most likelyhood corrupt the entire database and make it unaccessable.

While we can't identify the idividual email that was detected we can identify the folder it was detected in.

2 detections were in the Sent folder. You should be able to empty those folder.

E:\Thunderbird Files\Mail\Local Folders\Personal Folders.sbd\Sent
E:\DATA FROM JONS COMPUTER\Documents and Settings\JON\Application Data\Thunderbird\Profiles\JonYale\Mail\Local Folders\Personal Folders.sbd\Sent

Once you do that, empty the deleted Items (or whatever Thunderbird calls that folder)

With these ones, delete any unknown, old, or unsolicited emails. I put a notation in bold as to how many detections were made in each folder.

E:\Thunderbird Files\Mail\127.0.0-1.1\ 1
E:\Thunderbird Files\Mail\127.0.0-3.1\ 15
E:\Thunderbird Files\Mail\127.0.0-3.1\Inbox 1

E:\DATA FROM JONS COMPUTER\Documents and Settings\JON\Application Data\Thunderbird\Profiles\JonYale\Mail\127.0.0-3.1\Inbox 1

On your laptop

C:\Documents and Settings\Administrator\Application Data\Thunderbird\Profiles\Jon Panasonic Laptop\Mail\Local Folders\Inbox 2

Kaspersky does give you the option to just scan a folder. This will be much faster than scanning the entire HD.

After you have deleted what you can, run Kaspersky again on just certain folders. After the database has loaded
  • In the Scan section, click Folder
  • A browse box will open, use it to browse to the following folder
  • C:\Documents and Settings\Administrator\Application Data\Thunderbird\Profiles\Jon Panasonic Laptop\Mail\Local Folders\Inbox
  • Uncheck the box Scan Subfolders
  • Click Scan
  • When the scan is complete save the report
  • Repeat the same steps for these folders
  • E:\Thunderbird Files\Mail\127.0.0-1.1
  • E:\Thunderbird Files\Mail\127.0.0-3.1
  • E:\Thunderbird Files\Mail\127.0.0-3.1\Inbox
  • E:\DATA FROM JONS COMPUTER\Documents and Settings\JON\Application Data\Thunderbird\Profiles\JonYale\Mail\127.0.0-3.1\Inbox
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI