This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Odd situation. Persistent Malware.

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I downloaded a file .avi (a sex movie I admit, damned when I did it…) and since then the computer doesn't work properly, being very slow, freezing if I try to delete that file (saying the file is already in use). I can't even check the .avi file properties whithout causing the computer to freeze.
I have run many antivirus/scan programs: everytime they find new malware that seems to be deleted at first but when I reboot here we are again.
At the moment I can't use any online scan (though I have lowered the protection to allow the activeX) , as the procedure always shows an error or simply .

I have followed the prepost steps: after updating each program, here is what I have done so far:


-run spy-bot
(found and deleted Avenue A inc., Blue Stark, Double Click, Fast Click, Trade Doubler, Web Trends Live)
-run ad-aware (nothing found)
-reboot in safe mode
- run AVG (nothing found)
-reboot in normal mode
- run ATF cleaner
- restart
-hjt

I have submitted my log at HiJackThis! Log auto analyzer V2 that pointed out the line:

Unknown file in Winsock LSP: c:\windows\system32\mwtsp.dll
as Winsock Hijacker.

I would really appreciate your help, as I don't know what to do.
Sorry for my english, I write from Italy and I hope you can understand me.
Thanks in advance.


Logfile of HijackThis v1.99.1
Scan saved at 14.01.18, on 06/11/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\atievxx.exe
C:\download\AVG Anti-Spyware 7.5\guard.exe
C:\download\eScan\TRAYSSER.EXE
C:\download\eScan\avpm.exe
C:\Programmi\File comuni\MicroWorld\Agent\MWASER.EXE
C:\Programmi\File comuni\MicroWorld\Agent\MWAgent.exe
C:\Programmi\Acer\Powerkey\Powerkey.exe
C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\Ahead\InCD\InCD.exe
C:\download\eScan\TRAYICOS.EXE
C:\download\eScan\AVPMWrap.EXE
C:\download\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmi\Messenger\msmsgs.exe
C:\download\eScan\AvpM.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\download\hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O1 - Hosts: 192.9.200.200 lanificio
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AcerPowerkey] "C:\Programmi\Acer\Powerkey\Powerkey.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [InCD] C:\Programmi\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MailScan Dispatcher] "C:\download\eScan\LAUNCH.EXE"
O4 - HKLM\..\Run: [eScan Updater] C:\download\eScan\TRAYICOS.EXE /App
O4 - HKLM\..\Run: [eScan Monitor] C:\download\eScan\AVPMWrap.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\download\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - Global Startup: EPSON Controllo in background.lnk = C:\ESM2\STMS.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\mwtsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\mwtsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\mwtsp.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6814A9EF-FBF1-46B2-A46E-56B401079C26} - http://212.39.24.3/cab/xu101.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162386724111
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O21 - SSODL: TapiSrv - {F3EB075D-B99B-5EE0-995C-A06C81361E5F} - C:\WINDOWS\help\newfeat4.hlp
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\download\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: eScan Server-Updater (eScan-trayicos) - MicroWorld Technologies Inc. - C:\download\eScan\TRAYSSER.EXE
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
O23 - Service: eScan Monitor Service (KAVMonitorService) - Kaspersky Labs. - C:\download\eScan\avpm.exe
O23 - Service: MWAgent - MicroWorld Technologies Inc. - C:\Programmi\File comuni\MicroWorld\Agent\MWASER.EXE
gibi :D

Welcome to Tom Coyote I live in the USA but my Nunno and Nunna are from Piacenza. :thumbup:

Unknown file in Winsock LSP: c:\windows\system32\mwtsp.dll
<– This is legitimate..DO NOT REMOVE IT It's related to MicroWorld Technologies Inc.

Download the Stand Alone Version of CWShredder to your desktop.
  • Open CWShredder
  • Check for Updates
  • Close out the program. <– Dont run it yet

    Boot into Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard

    Open CWShredder
  • Double-click on CWShredder.exe.
  • Click Fix and click OK at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click Next and then Exit .


Reboot normally
, open HJT Scan Only, close your browser and all open windows, check these and click on Fix Checked.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O16 - DPF: {6814A9EF-FBF1-46B2-A46E-56B401079C26} - http://212.39.24.3/cab/xu101.exe




Run this system cleaner.


Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

Post a new log please
This topic is being closed due to lack of response, if you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI