I am trying to remove a virus/spyware that pop up Fake System Alert with yellow icon and give diferent messages. the process seems to be runing in hidden mode. It had e-trust AV and have tried trendMicro AV plus antyspyware with full scan and it seems it can't fix this problem.
it also turn system restore to only one point which is today even though system restore is on.
the problem starts when enabling network connection it then start poping up warnings and copy 2 shortcuts to the desktop and start menu, they are: "online security guide" and "life safety center" they point to a website: kukkakreck.com but when it is not enabled it doesn't pop up msgs or copy these shortcuts.
It also has a security toolbar on IE7 with dll file: okbykurp.dll
here is hijackthis log:
--------------------------
--
StartupList version: 1.52.2
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16544)
* Using default options
==========================
==========
==========
====
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\CA\SharedComponents\
CA_LIC\lic
98rmt.exe
C:\Program Files\CA\SharedComponents\
CA_LIC\Log
WatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OmniDrive USB Pro\OmniUSBServ.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WISPTI
S.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon
.exe
C:\Documents and Settings\admin\Desktop\Hij
ackThis.ex
e
C:\WINDOWS\system32\rundll
32.exe
C:\WINDOWS\system32\wuaucl
t.exe
C:\WINDOWS\system32\notepa
d.exe
--------------------------
----------
----------
----
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\W
indows NT\CurrentVersion\Winlogon
]
UserInit = C:\WINDOWS\system32\userin
it.exe,
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run
ctfmon.exe = C:\WINDOWS\system32\ctfmon
.exe
--------------------------
----------
----------
----
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------
----------
----------
----
Enumerating Task Scheduler jobs:
AdwareAlert Scheduled Scan.job
--------------------------
----------
----------
----
Enumerating ShellServiceObjectDelayLoa
d items:
PostBootReminder: C:\WINDOWS\system32\SHELL3
2.dll
CDBurn: C:\WINDOWS\system32\SHELL3
2.dll
WebCheck: C:\WINDOWS\system32\webche
ck.dll
SysTray: C:\WINDOWS\system32\stobje
ct.dll
--------------------------
----------
----------
----
End of report, 3,248 bytes