What kind of virus is xpdt.sys? Need advice to get it out.

Hello, everbody, after long time :wink: Here is long description of problem, with dynamic story :smiley:

Monday afternoon: I downloaded some selfextracting file, and make avast-on-demand scan. Nothing found. Then…click…and chaos! Avast have poping every minute a warnings, troyan infection :(. I deleted every time, but it was some kind that replicate self. So, it was happening all the time, only solution was to let me kill some processes in task manager. I found some unknown of them and replication stopped.

Incident + 2h: Everything seems quite, and I starting full system thorough scan. Avast found 3 troyans:

Win32:Agent-GSA
Win32:Delf-CDI
Win32:Small-gen2

It clean them with success.

After 2 hours of scanning, system get crushed!!! First time I saw BSOD under XP SP2. Explanation, some error in file xpdt.sys

Monday, late night. I beginning new scan… after 2 hours, again crush. Same explanation.
Tuesday, morning: I begun scan in safe mode. After few hours, same thing. BSOD blaming xpdt.sys
Tuesday, afternoon. I searching for xpdt.sys on internet. I find software prevx1, they saying xpdt.sys is malware that they can fix. Downloading program… Scanning… Prevx1 have next results.

Malware that have been found and blocked to run:

FCABAX.DLL
GOS1C.TMP
MOVEE.EXE
OPLS.DLL.HOOK
WIN24.TMP.EXE
WINTFJ32(2).DLL

After that, it seems everything is OK, again. But 30 minutes ago, my comp had another crush.
IMPORTANT: I searched for xpdt.sys in safe mode to delete it manually, but I couldn’t find it in system32, altough it was reported there.
And I never succeed to have avast to complete it scanning. Every time computer crushed when avast was scanning in directory C:Windows.
After infection, my Ashampoo firewall was damaged (.exe file). I had to reinstall it.

Computer: Pentium IV 1.7 GHz, RAM 512 MB, hmmm… is that important… System XP Pro SP2.

Hi kojta,

xpdt.sys is undesirable, resides in C:\Windows\System32\xpdt.sys and is added by Troj/Rustok-Q
confirmed here:
http://research.sunbelt-software.com/threatdisplay.aspx?name=Backdoor.Rustock&threatid=45547

pozdravi,

polonus

check out this link
http://www.sophos.com/security/analyses/trojrustokq.html
there is some registry entry u can remove

and do avast boot-time scan to remove the virus…
[right click on avast simple user interface and select boot time scan].

Ok, thanks guys. Finally, I found a basstard. I used Sophos anti-rootkit, and clean that xpdt.sys. Now I will see if that resolved a problem. But havent find that troyan rustokq yet. Hey, maybe ppl from avast should reconsider that.

It is quite interesting why, when infection occured, troyans destroyed my firewall program. I havent noticed any other programm that was corrupted.

Pozdrav.

Hi kojta,

Run the removal tool here to confirm the rootkit is gone:

http://www.geekstogo.com/forum/How-to-Remove-Rustock-b-pe386-lzx32-msguard-infections-t140682.html

Then run a scan with avast! and AVG Anti-Spyware, which may well find and remove more stuff now the rootkit element is gone.