This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Horse Backdoor.Generic15.IKV virus [Solved]

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok I ran this and it found files for AVG and also a product called Cyberdefender. I have never heard of Cyberdefender and have not installed it or any other Antivirus product on this computer, have only ever had AVG. So I ran a file search but it found nothing containing this name. I allowed the remover to remove both these detections. Looking in my C:/Program Files I can still see all of the entries for AVG with 20 odd data files of around 200kb. So it has not removed these. Whilst I could remove them manually, how will I know there are not others or that all data has been removed from my system? bar457
What I'm planning to do now is to search all the possible folders and files associated with AVG as well as Cyberdefender. So what I'd like you to do for me is to delete the existing copy of ComboFix and download a fresh one using the link given earlier. Don't run ComboFix yet as we need to determine the locations of the folders.

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :folderfind
    *AVG*
    *Cyberdefender*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
The Cyberdefender result is a bit odd, but it looks like it has located the AVG files. SystemLook 30.07.11 by jpshortstuff Log created at 17:29 on 11/03/2012 by Owner Administrator - Elevation successful ========== folderfind ========== Searching for "*AVG*" C:\Documents and Settings\All Users\Application Data\AVG2012 d—— [19:30 10/03/2012] C:\Documents and Settings\Owner\Application Data\AVG2012 d—— [19:34 10/03/2012] C:\Program Files\AVG d—— [11:28 19/06/2011] C:\Program Files\AVG\AVG10 d—— [11:28 19/06/2011] C:\Program Files\AVG\AVG2012 d—— [13:40 26/01/2012] Searching for "*Cyberdefender*" No folders found. -= EOF =-
It's ok, we will go from here.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

Folder::
C:\Documents and Settings\All Users\Application Data\AVG2012
C:\Documents and Settings\Owner\Application Data\AVG2012
C:\Program Files\AVG


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

When finished, it shall produce a log for you. Please post that log, C:\ComboFix.txt, in your next reply.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]
Ok that seems to have removed the files, I cannot see them anymore.
Was the Cyberdefender detection a false reading then, or is there something harmless somewhere in the system with that name?

report:-

ComboFix 12-03-10.02 - Owner 12/03/2012 16:22:04.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2047.1498 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\AVG2012
c:\documents and settings\All Users\Application Data\AVG2012\fet\407c36d17c36c208.dat
c:\documents and settings\Owner\Application Data\AVG2012
c:\documents and settings\Owner\Application Data\AVG2012\cfgall\userawacs.cfg
c:\documents and settings\Owner\Application Data\AVG2012\cfgall\usergui.cfg
c:\program files\AVG
c:\program files\AVG\AVG10\js.dat
c:\program files\AVG\AVG10\mfacz.lns
c:\program files\AVG\AVG10\mfada.lns
c:\program files\AVG\AVG10\mfaes.lns
c:\program files\AVG\AVG10\mfafr.lns
c:\program files\AVG\AVG10\mfage.lns
c:\program files\AVG\AVG10\mfahu.lns
c:\program files\AVG\AVG10\mfaid.lns
c:\program files\AVG\AVG10\mfain.lns
c:\program files\AVG\AVG10\mfait.lns
c:\program files\AVG\AVG10\mfajp.lns
c:\program files\AVG\AVG10\mfako.lns
c:\program files\AVG\AVG10\mfams.lns
c:\program files\AVG\AVG10\mfanl.lns
c:\program files\AVG\AVG10\mfapb.lns
c:\program files\AVG\AVG10\mfapl.lns
c:\program files\AVG\AVG10\mfapt.lns
c:\program files\AVG\AVG10\mfaru.lns
c:\program files\AVG\AVG10\mfasc.lns
c:\program files\AVG\AVG10\mfask.lns
c:\program files\AVG\AVG10\mfasp.lns
c:\program files\AVG\AVG10\mfatr.lns
c:\program files\AVG\AVG10\mfavera.txt
c:\program files\AVG\AVG10\mfazh.lns
c:\program files\AVG\AVG10\mfazt.lns
c:\program files\AVG\AVG2012\awacs\dav\component\content.dat
c:\program files\AVG\AVG2012\awacs\dav\component\image.bmp
c:\program files\AVG\AVG2012\awacs\dav\sign.bin
c:\program files\AVG\AVG2012\awacs\fas\component\content.dat
c:\program files\AVG\AVG2012\awacs\fas\component\image.bmp
c:\program files\AVG\AVG2012\awacs\fas\sign.bin
c:\program files\AVG\AVG2012\awacs\obx\component\content.dat
c:\program files\AVG\AVG2012\awacs\obx\component\image.bmp
c:\program files\AVG\AVG2012\awacs\obx\sign.bin
c:\program files\AVG\AVG2012\awacs\pct\component\content.dat
c:\program files\AVG\AVG2012\awacs\pct\component\image.bmp
c:\program files\AVG\AVG2012\awacs\pct\sign.bin
c:\program files\AVG\AVG2012\awacs\rules.cat
c:\program files\AVG\AVG2012\awacs\rules.js
c:\program files\AVG\AVG2012\awacs\speedtest\component\content.dat
c:\program files\AVG\AVG2012\awacs\speedtest\component\speedtest.bmp
c:\program files\AVG\AVG2012\awacs\speedtest\sign.bin
c:\program files\AVG\AVG2012\awacs\techbuddy\component\content.dat
c:\program files\AVG\AVG2012\awacs\techbuddy\component\techbuddy.mht
c:\program files\AVG\AVG2012\awacs\techbuddy\sign.bin
.
.
((((((((((((((((((((((((( Files Created from 2012-02-12 to 2012-03-12 )))))))))))))))))))))))))))))))
.
.
2012-03-09 19:48 . 2012-03-09 19:48 ——– d—–w- c:\documents and settings\Administrator
2012-02-28 15:40 . 2012-02-28 15:40 ——– d—–w- c:\documents and settings\Owner\Application Data\PeaZip
2012-02-26 22:34 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2012-02-26 22:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-24 18:01 . 2011-05-18 12:25 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-12 16:53 . 2006-02-28 12:00 1859968 —-a-w- c:\windows\system32\win32k.sys
2011-12-17 19:46 . 2006-02-28 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2006-02-28 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2006-02-28 12:00 385024 —-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-29_21.49.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-03-10 20:06 . 2012-03-10 20:06 16384 c:\windows\Temp\Perflib_Perfdata_670.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 11:58 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
.
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"POP Peeper"="c:\program files\POP Peeper\POPPeeper.exe" [2011-11-16 1613824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-13 88209]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-21 1155122]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
.
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [03/05/2004 16:26 80384]
S4 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [01/10/2010 15:25 4064]
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: {{5D40A133-FB02-4405-BE17-A3FC8749DF4E} - c:\program files\FreshDevices\FreshDownload\fd.exe
TCP: DhcpNameServer = 192.168.1.254
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-12 16:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2012-03-12 16:34:10
ComboFix-quarantined-files.txt 2012-03-12 16:33
ComboFix2.txt 2012-03-01 18:38
ComboFix3.txt 2012-02-29 21:55
.
Pre-Run: 100,615,675,904 bytes free
Post-Run: 100,636,790,784 bytes free
.
- - End Of File - - 482F90FE02F3EB831B2565AEFFC43635
I would need you to run SystemLook for me again.
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *tifm21*
    *gtipci21*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
SystemLook 30.07.11 by jpshortstuff Log created at 13:44 on 13/03/2012 by Owner Administrator - Elevation successful ========== filefind ========== Searching for "*tifm21*" C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\5TS6R47M\tifm21.sys[1].htm –a—- 18433 bytes [13:38 13/03/2012] [13:38 13/03/2012] DF7786627238DBEC1BBAF07C5EEFFB91 C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\7FE7205M\tifm21sys[1].html –a—- 172488 bytes [13:36 13/03/2012] [13:36 13/03/2012] D96CB4A665A885FDAC5966DF2F89EC4E C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UZM8LAHM\tifm21.sys[1].htm –a—- 12100 bytes [13:31 13/03/2012] [13:31 13/03/2012] 98C4634E4BF7A17EC3FC14AF1BA823FC C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UZM8LAHM\tifm21.sys[1].html –a—- 32045 bytes [13:34 13/03/2012] [13:34 13/03/2012] EC97B16EB769160AE5827E049F099A13 C:\SwSetup\Misc3\tifm21.cat –a—- 7918 bytes [16:45 14/09/2010] [14:01 13/02/2005] 3E5E62BA0AF4C600D124F941AE7E483D C:\SwSetup\Misc3\tifm21.inf –a—- 3020 bytes [16:45 14/09/2010] [00:51 11/02/2005] AE0EF7F2FCCA394DF0AB1752D927A831 C:\SwSetup\Misc3\tifm21.PNF –a—- 7352 bytes [16:45 14/09/2010] [18:06 31/05/2007] C58C22702C808F27D1ED45A83324DD6A C:\SwSetup\Misc3\tifm21.sys –a—- 157056 bytes [16:45 14/09/2010] [00:52 11/02/2005] 8778A553003A3D37A550A1F9CFF6BE28 C:\SwSetup\TIbus\Windows\tiinst\tifm21.cat –a—- 7918 bytes [16:40 14/09/2010] [14:01 13/02/2005] 3E5E62BA0AF4C600D124F941AE7E483D C:\SwSetup\TIbus\Windows\tiinst\tifm21.inf –a—- 3020 bytes [16:40 14/09/2010] [00:51 11/02/2005] AE0EF7F2FCCA394DF0AB1752D927A831 C:\SwSetup\TIbus\Windows\tiinst\tifm21.sys –a—- 157056 bytes [16:40 14/09/2010] [00:52 11/02/2005] 8778A553003A3D37A550A1F9CFF6BE28 C:\WINDOWS\system32\drivers\tifm21.sys –a—- 157056 bytes [00:52 11/02/2005] [00:52 11/02/2005] 8778A553003A3D37A550A1F9CFF6BE28 Searching for "*gtipci21*" C:\SwSetup\Misc3\gtipci21.cat –a—- 10656 bytes [16:45 14/09/2010] [15:54 15/06/2004] 7B1BC2FFA59A77262ED648088B687BC0 C:\SwSetup\Misc3\gtipci21.inf –a—- 3080 bytes [16:45 14/09/2010] [08:26 04/05/2004] 73B1B3F45E6E6B4F62E75CAAB30B29A6 C:\SwSetup\Misc3\gtipci21.PNF –a—- 7860 bytes [16:45 14/09/2010] [18:06 31/05/2007] 47B3010C2DBBCA7131A2305B7D5E04FD C:\SwSetup\Misc3\gtipci21.sys –a—- 80384 bytes [16:45 14/09/2010] [16:26 03/05/2004] 7D074058804AD398F93CA0A08AF83FF2 C:\SwSetup\TIbus\Windows\tiinst\gtipci21.cat –a—- 10656 bytes [16:40 14/09/2010] [15:54 15/06/2004] 7B1BC2FFA59A77262ED648088B687BC0 C:\SwSetup\TIbus\Windows\tiinst\gtipci21.inf –a—- 3080 bytes [16:40 14/09/2010] [08:26 04/05/2004] 73B1B3F45E6E6B4F62E75CAAB30B29A6 C:\SwSetup\TIbus\Windows\tiinst\gtipci21.sys –a—- 80384 bytes [16:40 14/09/2010] [16:26 03/05/2004] 7D074058804AD398F93CA0A08AF83FF2 C:\WINDOWS\system32\drivers\gtipci21.sys –a—- 80384 bytes [16:26 03/05/2004] [16:26 03/05/2004] 7D074058804AD398F93CA0A08AF83FF2 -= EOF =-
I need you to uninstall Texas Instrument related applications temporarily as a test to see if it's corrupted or something. In the mean time please run FSS for me. Thanks.

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Not sure if I have any Texas Instruments related applications? report: Farbar Service Scanner Version: 01-03-2012 Ran by [removed] (administrator) on 13-03-2012 at 15:22:41 Running from "C:\Documents and Settings\Owner\Desktop" Microsoft Windows XP Professional Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Attempt to access Google IP returned error: Google IP is offline Yahoo IP is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit C:\WINDOWS\system32\netman.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\srsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit C:\WINDOWS\system32\wscsvc.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\wuauserv.dll => MD5 is legit C:\WINDOWS\system32\qmgr.dll => MD5 is legit C:\WINDOWS\system32\es.dll => MD5 is legit C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= Gpc(4) IPSec(6) irda(3) NetBT(7) PSched(8) RFCOMM(10) Tcpip(5) 0x0C000000060000000100000002000000030000000400000005000000090000000B0000000C0000 0007000000080000000A000000 IpSec Tag value is correct. **** End of log ****
Disregard the Texas Instrument thing. My dumb mistake.

If this doesn't work, I might have to direct you to our Windows forum to get better support.

SFC – System File Checker Workaround

Please try this workaround (you will need your Windows® XP SP2 CD).

(In the event that you do not have a Windows® XP CD with SP2, you will need to 'borrow' one from a friend or colleague, as the manufacturer's "Recovery Discs" will not work in this instance.)

Insert the Windows® XP CD in your drive. (Hold down the Shift Key to prevent it from starting.)

Go Start > Run …in the box type in sfc /scannow …please take note of the space between the sfc and the /.

This is the System File Checker…it will scan all the Windows® core system files to ensure that they are in their respective correct places, and if not replace them from the CD.

During the scan you may be asked to Insert the CD, if this happens just go retry and let it do its thing.

One important point:
While sfc is running, it is not advisable to do any other work, or have any browsers/programs running on the computer, until the scan is complete. (This process will generally take around 45-65 minutes to complete).
Well I borrowed an XP disk from a friend as mine was an OEM loaded system. Ran the scan, but it said it was the wrong disk entered each time it tried to access it (I guess about 10 times). So it could do any updating. regards

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI