Hello,
5-6 days ago my Macafee virus protestion ran out. I have had this fro 3-4 years but was lax in renewing my subscription. I tirned on the computer one morning and signed into yahooo to check my email and I got hit with a virus. Typical add propaganda saying I was infected and must click here to remove virus. I tried to click on Macafee icon to renew subscription but I was thrown back to new visue infected messages. I tried to run malwaresbytes but got same error. I tried to go to internet to download Spybot but interenet will not work now. ( but I can connect to the internet with other computers through my wirelesee router- so it is my computer messed up not the actaul internet)
I booted into safe mode and was able to run malewarebytes. It found 6 duff trojans- on was backdor.bot and stole.date if that means anything. It said it removed the files. But once I rebooted I still can not get to the internet.
I loaded a trail version of Norton. It to found viruses and removed them but still no internet.
I am attaching DDS diles as advised. Any help is much appreacited!
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Owner at 10:22:56.62 on Wed 04/20/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1308 [GMT -4:00]
.
AV: Norton AntiVirus *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ehome\RMSvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe
C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
K:\Hackers\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mDefault_Page_URL = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:47392
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\17.8.0.5\IPSBHO.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\windows\system32\BAE.dll
BHO: {F0626A63-410B-45E2-99A1-3F2475B2D695} - No File
BHO: Fast Browser Search Toolbar Helper: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\fast browser search\ie\FBStoolbar.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - No File
TB: Fast Browser Search Toolbar: {1bb22d38-a411-4b13-a746-c2a4f4ec7344} - c:\program files\fast browser search\ie\FBStoolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - No File
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
c:\documents and settings\owner\local settings\temp\de1.tmp\temp00
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: Translate this web page with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Action.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Filter: text/html - {7ed929a6-11d5-4a82-9bd6-ecfabeed3b8c} -
Notify: igfxcui - igfxdev.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Notification Packages = scecli
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nav\1108000.005\symds.sys [2011-4-19 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1108000.005\symefa.sys [2011-4-19 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\bashdefs\20110419.001\BHDrvx86.sys [2011-4-19 802936]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1108000.005\cchpx86.sys [2011-4-19 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nav\1108000.005\ironx86.sys [2011-4-19 116784]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-3-1 374152]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-4-4 47640]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\McrdSvc.exe [2005-10-20 96256]
R2 NAV;Norton AntiVirus;c:\program files\norton antivirus\engine\17.8.0.5\ccsvchst.exe [2011-4-19 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-4-19 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\ipsdefs\20110419.002\IDSXpx86.sys [2011-4-19 341944]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\virusdefs\20110419.034\NAVENG.SYS [2011-4-20 86136]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\virusdefs\20110419.034\NAVEX15.SYS [2011-4-20 1393144]
S2 0259741303160339mcinstcleanup;McAfee Application Installer Cleanup (0259741303160339);c:\docume~1\owner\locals~1\temp\025974~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\owner\locals~1\temp\025974~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-9-17 12856]
S3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\drivers\activhidsermini.sys [2009-5-5 55936]
S3 cpuz132;cpuz132;\??\c:\docume~1\owner\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\owner\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2006-10-18 29744]
S3 meddmrr;meddmrr;c:\windows\system32\drivers\meddmrr.sys --> c:\windows\system32\drivers\meddmrr.sys [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-11-16 88544]
S3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-11-16 88544]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-4-10 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-4-10 40552]
S3 MSI_DVD_010507;MSI_DVD_010507;c:\program files\msi\live update 5\DVDSYS32_100507.sys [2011-2-8 22328]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files\msi\live update 5\msibios32_100507.sys [2011-2-8 25912]
S3 MSI_VGASYS_010507;MSI_VGASYS_010507;c:\program files\msi\live update 5\VGASYS32_100507.sys [2011-2-8 16696]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files\msi\live update 5\NTIOLib.sys [2011-2-8 7680]
S3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\drivers\activmouse.sys --> c:\windows\system32\drivers\activmouse.sys [?]
S3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-12-14 551680]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== Created Last 30 ================
.
2011-04-19 21:09:35 43696 ----a-w- c:\windows\system32\drivers\nav\1108000.005\srtspx.sys
2011-04-19 21:09:35 361904 ----a-w- c:\windows\system32\drivers\nav\1108000.005\symtdi.sys
2011-04-19 21:09:35 339504 ----a-w- c:\windows\system32\drivers\nav\1108000.005\symtdiv.sys
2011-04-19 21:09:35 328752 ----a-r- c:\windows\system32\drivers\nav\1108000.005\symds.sys
2011-04-19 21:09:35 173104 ----a-w- c:\windows\system32\drivers\nav\1108000.005\symefa.sys
2011-04-19 21:09:34 501888 ----a-w- c:\windows\system32\drivers\nav\1108000.005\cchpx86.sys
2011-04-19 21:09:34 325680 ----a-w- c:\windows\system32\drivers\nav\1108000.005\srtsp.sys
2011-04-19 21:09:34 116784 ----a-w- c:\windows\system32\drivers\nav\1108000.005\ironx86.sys
2011-04-19 21:09:21 -------- d-----w- c:\windows\system32\drivers\nav\1108000.005
2011-04-19 06:35:53 -------- d-----w- C:\NBRT
2011-04-19 02:45:12 -------- d-----w- c:\docume~1\owner\applic~1\Tific
2011-04-19 02:45:11 -------- d-----w- c:\docume~1\owner\locals~1\applic~1\Symantec
2011-04-18 21:42:06 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2011-04-18 21:42:06 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-04-18 21:42:05 -------- d-----w- c:\program files\Symantec
2011-04-18 21:36:44 -------- d-----w- c:\windows\system32\drivers\NAV
2011-04-18 21:36:39 -------- d-----w- c:\program files\Norton AntiVirus
2011-04-18 20:56:09 -------- d-----w- c:\program files\NortonInstaller
2011-04-18 20:52:44 -------- d-----w- c:\program files\trend micro
2011-04-05 01:41:43 -------- d-----w- c:\docume~1\owner\locals~1\applic~1\LogMeIn
2011-04-05 01:41:38 53632 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2011-04-05 01:41:37 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-04-05 01:41:37 47640 ----a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2011-04-05 01:41:37 29568 ----a-w- c:\windows\system32\LMIport.dll
2011-04-05 01:41:27 87424 ----a-w- c:\windows\system32\LMIinit.dll
2011-04-05 01:41:20 -------- d-----w- c:\docume~1\alluse~1\applic~1\LogMeIn
2011-04-05 01:41:04 -------- d-----w- c:\program files\LogMeIn
2011-04-05 01:39:07 -------- d-----w- c:\docume~1\owner\locals~1\applic~1\Deployment
2011-03-23 22:55:04 -------- d-----w- c:\docume~1\owner\applic~1\.minecraft
.
==================== Find3M ====================
.
2011-04-16 13:50:27 5104 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41:59 385024 ----a-w- c:\windows\system32\html.iec
2011-02-18 21:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-04 22:48:32 456192 ----a-w- c:\windows\system32\encdec.dll
2011-02-04 22:48:30 291840 ----a-w- c:\windows\system32\sbe.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
.
============= FINISH: 10:23:59.50 ===============
Edit
Previous thread for different computer: http://forums.spybot.info/showthread.php?t=61858