Automatically Deleted File Causing Popup At Startup

I just installed Avast today and about 3 minutes later I got a popup saying a trojan was detected and deleted. Now, everytime I start up my laptop I get an error message popup saying “there was a problem starting c:\Users\xxxxx\AppData\Local\BthcfgLite\nsPathapi.dll - The specified module could not be found”, which was the file that was deleted by Avast.

Any idea what this was, or how I can stop this message from popping up every time I boot? I’ve searched for this file to try and find the program it’s associated with but my search turns up zero results. Thanks!


Welcome to the forums, mpkeith :slight_smile:

If I am not mistaken, that dll belongs to Java. Try reinstalling Java. Make sure you get the newest version.


EDIT : The information given at the below link is a little different. In the post at the link below, you say that avast quarantined the file. If that is true, then the file would still be in the Virus Chest and might be restored. Is it still there?
http://www.bleepingcomputer.com/forums/topic368760.html


Thanks Charley. Yes, it is still there. I installed Avast for the first time yesterday and ran a manual scan, which returned 2 results for trojans… the file in question as well as msocfg32.exe. I quarantined them both and the popup started @ bootup, so I did a system restore and reinstalled Avast earlier today. That’s when I got the taskbar popup that said the file was (detected/quarantined) and deleted.

EDIT: If I restore this file, that should solve the problem, but won’t it just get quarantined again the next time it tries to run? Also, I think it may possibly be part of a browser hijacker I’ve been having problems with in Firefox. I believe the notification of quarantine occurred when I was doing a Google search, and the hijacker would take me to pages that weren’t the page my search results said they were. If that’s the case, I’d like to delete whatever it is that the file is associated with as well so I don’t have the hijacker and I don’t get the “failure to start” popup either.

POSTEDIT: When I search Google for “BthcfgLite” with the quotes, this page and the page you mentioned of my other post are the only 2 results that come up. Is it possible if I delete this folder that contains the nsPathapi.dll file that might stop the popup I’m getting? It seems to me if I’m the only person on the Internet that’s mentioned this folder it can’t be something that belongs to any legit programs. Or could it be autogenerated by a legit program?


OK, let’s do this :

You could check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner ( http://www.virustotal.com/ ) and report the findings here the URL in the Address bar of the VT results page. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive. Now exclude that folder in the File System Shield, Expert Settings, Exclusions, Add, type (or copy and paste) C:\Suspect*
That will stop the File System Shield scanning any file you put in that folder.

If only GData and avast detect it - GData uses avast as one of its two scanners so counts as 1 detection and almost certainly an FP.
Send the sample to avast as a False Positive:
Open the chest and right click on the file and select ‘Submit to virus lab…’ complete the form and submit, the file will be uploaded during the next update.

Borrowed from DavidR


Here is the VT link: http://www.virustotal.com/file-scan/report.html?id=f6e1c5bb3c46f7b3cca4501695a1ef8f58d4c73bb7b40a87cfb419fbd1ce20a0-1293011449

There are 6/43 possitives on this… 4/43 if you count Avast, Avast5 and Gdata as one. What do you think?

I did not find anything in Google.
Seems a false positive (and companies mimic the others detection on VT). But, it’s difficult to say as I can’t find any legit program that uses that BthcfgLite folder…
Maybe someone with more experience could help us.

Well, the folder name alone is highly suspicious…!!!
Run free Mbam to get a second opinon…! http://www.malwarebytes.org/mbam.php
Update it before scanning and post the log here afterwards.
asyn

Ikarus (and Emsisoft with its Ikarus engine) and COMODO and avast! says that it is a trojan named sefnit. So I would say all three detections are the same. So I think that isn’t a false positive.

I would suggest what Asyn said…
Download MBAM and run a full scan.

Give us a feedback when it’s done.

I’ve ran mbam a few times already over the past week or so and it hasn’t found any malicious files… this was even before I quarantined the file in question. I can restore the file to it’s original location and give it another shot though. I’ll do a manual update of mbam first.

There is probably a run key related to that file - Do you use bluetooth ?

Below are the results of a full scan with mbam… I forgot to restore the file to it’s original location, but then I realized it’s still in C:\Suspect folder so it should have caught it there. Again, nothing malicious.

No, I don’t use bluetooth, but that doesn’t mean my laptop didn’t come with bluetooth software.

Malwarebytes’ Anti-Malware 1.50
www.malwarebytes.org

Database version: 5351

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

12/22/2010 3:47:32 PM
mbam-log-2010-12-22 (15-47-32).txt

Scan type: Full scan (C:|)
Objects scanned: 224499
Time elapsed: 1 hour(s), 0 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

If it is in the vault then MBAM will not be able to detect it

If you could run an OTL log for me I could look at the run key location and then determine whether or not it is a legitimate file

Download OTL to your Desktop

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select All Users
[*]Under the Custom Scan box paste this in

[b]netsvcs
%SYSTEMDRIVE%*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%*. /mp /s
CREATERESTOREPOINT

[/b]

[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

I restored the file to it’s original location before I ran mbam but it’s still showing up in the vault. I tried again to make sure it went through and was told the file already existed, so it is there. I also ran mbam a few times before I installed Avast and it came back negative then as well.

Here are my OTL logs… I had to host them on one of my domains as they were too large to post here:

http://gylbo.com/myfiles/OTL.Txt
http://gylbo.com/myfiles/Extras.Txt

The folder seems to have been created the night I installed Flip Video (though a few hours later), which is a software program that edits video taken from Flip camcorders. I wonder if it is a part of that program… or possibly a file converter I downloaded to change my mp4 files to flash video files.

http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan%3AWin32%2FSefnit.E

Any of those files or folder present.

BTW,I see a lot of Norton Internet Security entry’s in your log. How did you removed Norton. And did you use their removal tool.
http://us.norton.com/support/kb/web_view.jsp?wv_type=public_web&docurl=20080710133834EN

None of those files are on my computer.

As far as Norton, it’s still on my computer just disabled.

btpcfg.dll - Process Information

This component is part of BlueSoleil Bluetooth Plug and Play Module

Component Name: btpcfg.dll

Description of : BlueSoleil Bluetooth Plug and Play Module, from IVT Corporation, is an application used by systems to form networks wirelessly.

Recommendation for :
NA

Trusted: Yes
Trojan: No
Chronic: No
Adware: No
Carrier: No
Browser Hijacker: No
Dialer: No
Commercial Keylogger: No
Remote Administration Tool: No
Suspected: No

Company Name: IVT Corporation
Platforms Affected:
Methods of Distribution: NA
Variants/Versions:
Release Date: NA

btpcfg.dll does look a lot like it’s related to BthcfgLite. Definitely looks like a bluetooth name after seeing that. BthcfgLite = bluetooth config lite?

The only thing that puzzles me is that it was created only a few weeks ago and I never installed any bluetooth related software. ???

It may not be particularly relevant to this particular problem (then again, it might be) but simply disabling one AV while running another is not adequate.

Norton has to be uninstalled, and then the removal tool run, before anything either installed AV reports can be taken seriously.

Conflicts are almost certain, even with one disabled, sooner or later.

Following up on the previous posts:

Running two AV on the same computer can create all kind of mysterious windows errors and false detections.

Clash Of The Antivirus Apps:
http://www.smartcomputing.com/editorial/article.asp?article=articles/2003/s1407/38s07/38s07.asp

Why you should never run more than one AV (see reply from quietman7):
http://www.bleepingcomputer.com/forums/index.php?s=49db784baecf17e7b189c833aafb624d&showtopic=260844&view=findpost&p=1441638

You need to uninstall Norton/Symantec with their uninstaller tool:
http://us.norton.com/support/kb/web_view.jsp?wv_type=public_web&docurl=20080710133834EN, then reboot.

After this, you may need to do an Avast Repair since you had 2 AV’s on your machine:

  • Go to Control Panel > Add/Remove programs > Avast Antivirus.
  • Scroll down and choose Repair function in the pop-up window.
  • Reboot.

If Avast still is giving you FP’s or not working correctly, you may need to uninstall and do a clean install using the Avast Uninstaller Utility tool to uninstall: http://www.avast.com/uninstall-utility.

Please let us know if you have any questions. Thank you.