Hi -
I have the same symptoms and infection now in my Laptop.
1) System Alert with Yellow Exclamation Icon in the System Tray
2) The Red X icon with System Intrusion Detected in System Tray
3) A spyware alert which claims that my system is infected with Worm.Win32.NetBooster.
4) SystemDefender (which I don't remember having installed) claiming that there are dangerous spywares in my system and wants me to buy the Spware cleaner.
5) IE shows "AntiSpywareMaster" website with a list of VIRUSes and Spyware
Spybot scan shows - Smitfraud-C. entries and disableSystemRestore and disableTaskManager entries.
Here's my HiJackThis log. Can anyone help in removing this? The laptop is slow and very sluggish and am not able to do a System Restore nor kill any processes.
----------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:37:46 PM, on 4/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\ibmpms
vc.exe
C:\WINDOWS\System32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\eTSrv.
exe
C:\Program Files\AT&T Global Network Client\NetCfgSv.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\PROT_S
RV.EXE
C:\WINDOWS\system32\pagent
s.exe
C:\WINDOWS\system32\PSTART
SR.EXE
C:\WINDOWS\System32\QCONSV
C.EXE
C:\WINDOWS\System32\RegSrv
c.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\TpKmpS
VC.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
C:\WINDOWS\TEMP\LJ36B.EXE
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\vVX3000.exe
C:\Program Files\Pointsec\P95tray.exe
C:\WINDOWS\system32\eTCrtM
ng.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\ixqjgt
kd.exe
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - (no file)
O1 - Hosts: 172.21.6.209 e-scape
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4
C09146192C
A} - C:\Program Files\Real\RealPlayer\rpbr
owserrecor
dplugin.dl
l
O2 - BHO: DVA Storm - {52676F4A-D830-4513-BE81-3
A0C28B32C2
F} - C:\WINDOWS\lgmxvpatkmb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\system32\dla\tf
swshx.dll
O2 - BHO: Explorer - {7348D74C-731B-DECE-9F8A-A
37D8214708
E} - C:\WINDOWS\system32\wlcstp
32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
E66B5AD205
D} - C:\Program Files\Google\GoogleToolbar
Notifier\2
.1.615.585
8\swg.dll
O2 - BHO: (no name) - {F3AEF888-A3E2-44EB-BD85-F
0C85BA7673
F} - C:\WINDOWS\system32\vtUonk
lK.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: qtvglped - {C8F0EE32-3AF7-4730-9D8C-9
EB9D031529
0} - C:\WINDOWS\qtvglped.dll
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [Protect Tray] "C:\Program Files\Pointsec\P95tray.exe
"
O4 - HKLM\..\Run: [eTCertManger] C:\WINDOWS\system32\eTCrtM
ng.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKCU\..\Run: [NetSP - restore settings on power failure] "C:\Program Files\AT&T Global Network Client\NetSP.exe" -show
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\Yah
ooMessenge
r.exe" -quiet
O4 - HKCU\..\Run: [tvnazgzo] C:\WINDOWS\system32\ixqjgt
kd.exe
O4 - HKLM\..\Policies\Explorer\
Run: [MN3Corsnlw] C:\Documents and Settings\All Users\Application Data\kdurqvoh\ihkfalil.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\IBM\Java141\jre\bin\
NPJPI141.d
ll
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\IBM\Java141\jre\bin\
NPJPI141.d
ll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {00134F72-5284-44F7-95A8-5
2A619F7075
1} (ObjWinNTCheck Class) -
https://172.21.6.10/officescan/console/ClientInstall/WinNTChk.cabO16 - DPF: {08D75BC1-D2B5-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) -
https://172.21.6.10/officescan/console/html/ClientInstall/setup.cabO16 - DPF: {30528230-99f7-4bb4-88d8-f
a1d4f56a2a
b} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsth
elper.dll
O16 - DPF: {35C3D91E-401A-4E45-88A5-F
3B32CD72DF
4} (Encrypt Class) -
https://172.21.6.10/officescan/console/html/root/AtxEnc.cabO16 - DPF: {474F00F5-3853-492C-AC3A-4
76512BBC33
6} (UploadListView Class) -
http://picasaweb.google.co.uk/s/v/25.25/uploader2.cabO16 - DPF: {5EFE8CB1-D095-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) -
https://172.21.6.10/officescan/console/ClientInstall/RemoveCtrl.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
830C7DD7F5
D} - C:\PROGRA~1\COMMON~1\Skype
\SKYPE4~1.
DLL
O20 - Winlogon Notify: vtUonklK - C:\WINDOWS\SYSTEM32\vtUonk
lK.dll
O21 - SSODL: CheckAlrt - {46d5d815-ebda-4192-9d43-c
80888aafd6
2} - C:\WINDOWS\Resources\Check
Alrt.dll
O21 - SSODL: pmsoarbf - {81E1779B-D7C8-4355-A1DA-1
29D246A4C4
1} - C:\WINDOWS\pmsoarbf.dll
O21 - SSODL: omlbpkaw - {968A2DDA-9B04-455A-9E29-1
F6416C8C71
F} - C:\WINDOWS\omlbpkaw.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2ev
xx.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: eToken Notification Service (ETOKSRV) - Aladdin Knowledge Systems, Ltd. - C:\WINDOWS\system32\eTSrv.
exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpms
vc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\Program Files\AT&T Global Network Client\NetCfgSv.EXE
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: Pointsec - Unknown owner - C:\WINDOWS\system32\PROT_S
RV.EXE
O23 - Service: Pointsec update agent (Pointsec_agent) - Unknown owner - C:\WINDOWS\system32\pagent
s.exe
O23 - Service: Pointsec service start (Pointsec_start) - Unknown owner - C:\WINDOWS\system32\PSTART
SR.EXE
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSV
C.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrv
c.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvM
on.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpS
VC.exe
--------------------------
----------
---End of Log -----------------------
Thanks.
ORIGINAL RELATED QUESTION
==========================
======
A "System Alert: Spyware Detected" box of text pops up from a little yellow yield sign in the tray. The yellow icon has an exclamation point on it. The text reads:
System Alert: Spyware Detected
System has detected 4 active spyware applications that may cause you computer to crash and restart, slow it to a crawl
(its gone away currently so I cant continue to type it out. But you get the gist.)
Also a System Intrusion Detected" box of text pops up from the tray. The icon for it is a red circle with a white x through it. The icon alternates between the red circle to the Windows update logo. The text reads:
System Instrusion Detected! (notice typo on Intrusion)
The system will now download and install most efficient antimalware program to prevent data loss and you private information theft. Click here to protect you computer from the biggest malware threats.
A browser popup reads:
Security Configuration
Attention? Win32.HS.m2 Spyware has just overcome default security software on Your PC. Your personal information and pc safety is in critical danger. To clear Your PC and get rid of dangerous virus you need paid security system patch called AD-PROJECT". By clicking Continue You will be taken to official developers page, where you may download the patch.
SpywareStrike loads itself.
An HTML link to SpySherrif loads when the yellow yield sign is clicked.
Other popups include porn and casino ads.
Here is the HJT log:
<< HiJackLog from Orig post removed to avoid any confusion >>
Any help with this would be greatly appreciated.
Thanks,
DD
Start Free Trial