Hi
This is my first post so please pardon any errors on my part. I need some help with a virus or malware (I think its a root kit). I thought I found and cleaned the system, however the system is unstable. It seems lethargic and hangs or freezes often. The original infection caused pop up windows alerting me to a "bad Image" with almost every service attempting to run. so initially i ran a scan with Norton 360 and then with malwarebytes. both indicated a Trojan of some sort and cleaned the system. as a precaution I did an online with Eset however the scan froze about 75% through. It seemed to hang on file C:\i386\lang\imjpdte.ch_ so the scan was never completed. I have included the required DDS scan log. Any help you can provide would be greatly appreciated.
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by Shawn at 8:24:28 on 2011-05-27
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.421 [GMT -4:00]
.
AV: Norton 360 *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe
C:\Program Files\WSED\WSED.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\OA012Mon.exe
C:\Program Files\CapsLKNotify\CapsLKNotify.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Battery Meter\BTMeter.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
C:\Documents and Settings\Shawn\Desktop\dds.scr
C:\WINDOWS\system32\WSCRIPT.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.msn.com
uSearch Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.3.0.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.3.0.5\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\shawn\application data\mozilla\firefox\profiles\a7jv023c.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\coffplgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\IPSFFPlgn
FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\coFFPlgn
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2011-05-26 17:11:17 -------- d-----w- c:\windows\pss
2011-05-26 14:27:23 19528 ----a-w- c:\windows\cscmondump.bin
2011-05-26 13:33:43 -------- d-----w- c:\program files\ESET
2011-05-26 13:05:52 -------- d-----w- c:\program files\COMODO
2011-05-26 13:05:41 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-05-26 13:05:41 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2011-05-26 13:05:41 1060864 ----a-w- c:\windows\system32\mfc71.dll
2011-05-25 14:50:58 -------- d-----w- c:\documents and settings\shawn\application data\PCDr
2011-05-25 05:37:40 6075904 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-05-25 05:37:40 52224 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-05-25 05:37:40 468480 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-05-25 05:37:40 380928 -c----w- c:\windows\system32\dllcache\ieapfltr.dll
2011-05-25 05:37:40 268288 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-05-25 05:37:40 2452872 -c----w- c:\windows\system32\dllcache\ieapfltr.dat
2011-05-25 05:37:40 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2011-05-25 05:37:39 63488 -c----w- c:\windows\system32\dllcache\icardie.dll
2011-05-25 03:47:16 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-25 03:05:33 -------- d-----w- c:\windows\ServicePackFiles
2011-05-25 01:55:27 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2011-05-25 01:55:27 1071088 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2011-05-25 01:55:26 -------- d-----w- c:\program files\SpywareBlaster
2011-05-25 01:31:32 -------- d-----w- c:\program files\CCleaner
2011-05-24 16:33:14 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2011-05-24 16:33:14 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-05-24 16:33:13 978944 -c----w- c:\windows\system32\dllcache\mfc42.dll
2011-05-24 16:32:44 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-05-24 16:29:01 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2011-05-24 16:28:50 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-05-24 16:22:06 -------- d-----w- c:\documents and settings\shawn\application data\Malwarebytes
2011-05-24 16:21:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-24 16:21:28 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-05-24 16:21:23 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-24 16:21:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-24 16:09:32 -------- d-----w- c:\program files\VS Revo Group
2011-05-24 16:05:23 45568 -c----w- c:\windows\system32\dllcache\wab.exe
.
==================== Find3M ====================
.
2011-03-11 14:10:38 471552 ----a-w- c:\windows\apppatch\aclayers.dll
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45:07 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:27:43 1866880 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 8:25:50.62 ===============
This is my first post so please pardon any errors on my part. I need some help with a virus or malware (I think its a root kit). I thought I found and cleaned the system, however the system is unstable. It seems lethargic and hangs or freezes often. The original infection caused pop up windows alerting me to a "bad Image" with almost every service attempting to run. so initially i ran a scan with Norton 360 and then with malwarebytes. both indicated a Trojan of some sort and cleaned the system. as a precaution I did an online with Eset however the scan froze about 75% through. It seemed to hang on file C:\i386\lang\imjpdte.ch_ so the scan was never completed. I have included the required DDS scan log. Any help you can provide would be greatly appreciated.
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by Shawn at 8:24:28 on 2011-05-27
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.421 [GMT -4:00]
.
AV: Norton 360 *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe
C:\Program Files\WSED\WSED.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\OA012Mon.exe
C:\Program Files\CapsLKNotify\CapsLKNotify.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Battery Meter\BTMeter.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
C:\Documents and Settings\Shawn\Desktop\dds.scr
C:\WINDOWS\system32\WSCRIPT.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.msn.com
uSearch Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.3.0.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.3.0.5\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
c:\docume~1\shawn\locals~1\temp\nsg38.tmp\temp00
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\shawn\application data\mozilla\firefox\profiles\a7jv023c.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\coffplgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\IPSFFPlgn
FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\coFFPlgn
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2011-05-26 17:11:17 -------- d-----w- c:\windows\pss
2011-05-26 14:27:23 19528 ----a-w- c:\windows\cscmondump.bin
2011-05-26 13:33:43 -------- d-----w- c:\program files\ESET
2011-05-26 13:05:52 -------- d-----w- c:\program files\COMODO
2011-05-26 13:05:41 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-05-26 13:05:41 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2011-05-26 13:05:41 1060864 ----a-w- c:\windows\system32\mfc71.dll
2011-05-25 14:50:58 -------- d-----w- c:\documents and settings\shawn\application data\PCDr
2011-05-25 05:37:40 6075904 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-05-25 05:37:40 52224 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-05-25 05:37:40 468480 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-05-25 05:37:40 380928 -c----w- c:\windows\system32\dllcache\ieapfltr.dll
2011-05-25 05:37:40 268288 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-05-25 05:37:40 2452872 -c----w- c:\windows\system32\dllcache\ieapfltr.dat
2011-05-25 05:37:40 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2011-05-25 05:37:39 63488 -c----w- c:\windows\system32\dllcache\icardie.dll
2011-05-25 03:47:16 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-25 03:05:33 -------- d-----w- c:\windows\ServicePackFiles
2011-05-25 01:55:27 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2011-05-25 01:55:27 1071088 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2011-05-25 01:55:26 -------- d-----w- c:\program files\SpywareBlaster
2011-05-25 01:31:32 -------- d-----w- c:\program files\CCleaner
2011-05-24 16:33:14 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2011-05-24 16:33:14 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-05-24 16:33:13 978944 -c----w- c:\windows\system32\dllcache\mfc42.dll
2011-05-24 16:32:44 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-05-24 16:29:01 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2011-05-24 16:28:50 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-05-24 16:22:06 -------- d-----w- c:\documents and settings\shawn\application data\Malwarebytes
2011-05-24 16:21:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-24 16:21:28 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-05-24 16:21:23 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-24 16:21:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-24 16:09:32 -------- d-----w- c:\program files\VS Revo Group
2011-05-24 16:05:23 45568 -c----w- c:\windows\system32\dllcache\wab.exe
.
==================== Find3M ====================
.
2011-03-11 14:10:38 471552 ----a-w- c:\windows\apppatch\aclayers.dll
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45:07 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:27:43 1866880 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 8:25:50.62 ===============