This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Unknown Infection-Need Removal

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has recently contracted an infection and I am trying to discern the cause of it.

This infection also prevents access to the Kaspersky website, the Malware bytes website and the Microsoft website. I am unable to download any updates through other sites for Kaspersky, Malware Bytes or for Microsoft.

A common message that pops up is that my computer is infected and that I need to scan it immediately. If I click yes, a phoney virus scan occurs and then I get three porn icons on my desktop. Each time I use malwarebytes to delete the infection, it returns as soon as I restart. If you need any further information, please let me know.

Also, I am running Windows XP.


I ran hijackthis, will provide log results below:







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:49:08 PM, on 4/5/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [rmosnq] RUNDLL32.EXE C:\WINDOWS\system32\msyblkya.dll,w
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [uxvefl] RUNDLL32.EXE C:\WINDOWS\system32\mssapsmr.dll,w
O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe" /SCB
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Common Files\Logishrd\eReg\Common\eReg.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://mail.daum.net/hanmail-ax/DaumActive…cab?ver=2,0,0,8
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15111/CTPID.cab
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 4493 bytes





I also ran malware bytes and saved that log. The log results are below:



Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3945

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

4/5/2010 6:02:34 PM
mbam-log-2010-04-05 (18-02-34).txt

Scan type: Full scan (C:\|)
Objects scanned: 242336
Time elapsed: 1 hour(s), 3 minute(s), 44 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 2
Registry Values Infected: 11
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 52

Memory Processes Infected:
C:\WINDOWS\Temp\VRT5.tmp (Spyware.OnlineGames) -> No action taken.

Memory Modules Infected:
c:\WINDOWS\system32\BtwSvc.dll (Backdoor.Bot) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwsvc (Backdoor.Bot) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\buildw (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\firstinstallflag (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ulrn (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\update (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\updatenew (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mbt (Backdoor.Bot) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udpe (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mpe (Malware.Trace) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Protection System (Rogue.ProtectionSystem) -> No action taken.

Files Infected:
C:\WINDOWS\Temp\VRT5.tmp (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\4LK3QR8P\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\4LK3QR8P\w[2].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\4LK3QR8P\w[3].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\4LK3QR8P\w[4].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\4LK3QR8P\w[5].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\4LK3QR8P\w[6].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KFSB4BUN\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KFSB4BUN\w[2].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KFSB4BUN\w[3].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KFSB4BUN\w[4].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KJ83SNC5\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KJ83SNC5\w[2].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KJ83SNC5\w[3].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KJ83SNC5\w[4].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KJ83SNC5\w[5].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\KJ83SNC5\w[6].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\O94F6RCT\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\O94F6RCT\w[2].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\O94F6RCT\w[3].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\O94F6RCT\w[4].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\O94F6RCT\w[5].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\O94F6RCT\w[6].bin (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP2\A0000288.dll (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP2\A0000165.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP2\A0000166.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP2\A0000167.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP2\A0000289.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP3\A0000326.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP3\A0000327.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP3\A0000329.dll (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP3\A0000330.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP4\A0000333.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP4\A0000334.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP4\A0000337.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP4\A0000340.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{9BD975E3-0A3D-4F51-88B7-0BAB20C01050}\RP4\A0000543.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\SC.INS (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\w.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\PowerDes.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\so.bin (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\d.bin (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\opear.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\Temp\tmp0_402805369841.bk.old (Backdoor.Bot) -> No action taken.
C:\WINDOWS\Temp\tmp0_742474765719.bk.old (Backdoor.Bot) -> No action taken.
C:\WINDOWS\Temp\VRTA5.tmp (Spyware.OnlineGames) -> No action taken.
C:\WINDOWS\Temp\t4m0_24929548197.bk.old (Backdoor.Bot) -> No action taken.
C:\WINDOWS\Temp\t4m0_80775311138.bk.old (Backdoor.Bot) -> No action taken.
C:\WINDOWS\Temp\t4m0_8264249571.bk.old (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\BtwSvc.dll (Backdoor.Bot) -> No action taken.
C:\WINDOWS\sc.exe (Trojan.FakeAlert) -> No action taken.
Hello Kp_soldier and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back as soon as possible with instructions.
Kp_Soldier,

🖼Click to load external image (Posted Image) You are infected with a trojan know to sometimes have backdoor properties. Backdoor Trojans are very dangerous because they use advanced techniques (backdoors) to bypass security mechanisms and steal sensitive information which they send back to the hacker. If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately limit your online activity until your system is cleaned. All passwords should be changed immediately using a different computer and banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

🖼Click to load external image (Posted Image) P2P - I see you have P2P software (uTorrent, BTDNA, BitTorrent, Limewire) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to malware infections. Malware authors use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at WTT are complete.

🖼Click to load external image (Posted Image) Please run HijackThis and follow these instructions:
  • Click the Do a system scan only button to produce a log.
  • Place a check mark beside each one of the following items:
O4 - HKLM\..\Run: [rmosnq] RUNDLL32.EXE C:\WINDOWS\system32\msyblkya.dll,w
O4 - HKLM\..\Run: [uxvefl] RUNDLL32.EXE C:\WINDOWS\system32\mssapsmr.dll,w

  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the Fix checked button.
  • Close the HijackThis window.
🖼Click to load external image (Posted Image) Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time.
🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please include the following in your next post:
  • OTL Scan and Extras logs
  • GMER log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI