I have a Dell Dimension running Windows XP that was seriously attacked. The computer would not run well (not even in safe mode) so I performed the procedure below in an attempt to remove the infestation and repair myself. I know I should have contacted you earlier; but better late than never.
Edit: http://forums.spybot.info/showthread.php?p=404974#post404974
1. Removed the hard drive and installed in another computer.
2. Utilized Spybot and Malwarebytes anti malware programs to clean the disk from the other computer.
3. Reinstalled the disk into the Dell and system would not boot.
4. Utilized the XP Recovery console to restore the master boot record.
5. Now the computer can boot, but many errors and can not run most programs.
6. Used the XP installation disk to do a system restore/repair.
7. System still has significant issues; but am now able to run the pre post procedures.
8. backed up the Registry with ERUNT
9. Ran DDS see below and attached
10. Spybot is still detecting errors as follows:
Virtumonde.prx
Fraud.DesktopSecurity2010
Fraud.HDDDefragmenter
FraudInternetSecurity2011
MicrosoftWindows.AppFirewallBypass
MircosoftWindowsSecurityCenter.FirewallBypass
Win32.FraudLoader.edt
Thanks so much!!!
Roger
---------------------- DDS Log -------------------------------------------
DDS (Ver_2011-06-12.02) - NTFSx86
Internet Explorer: 6.0.2800.1106
Run by Christara at 2:11:03 on 2011-06-23
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.511.227 [GMT -7:00]
.
AV: Microsoft Security Essentials *Disabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe -k itlsvc
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\NewTech Infosystems\Backup Now EZ\BackupNowEZSvr.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\rundll32.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: {868cdff6-81ae-451f-a89e-7ae501bbfab9} - c:\windows\system32\dpnhupn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: ShopAtHomeIEHelper Class: {e8daaa30-6caa-4b58-9603-8e54238219e2} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: ShopAtHome.com Toolbar: {98279c38-de4b-4bcf-93c9-8ec26069d6f4} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [ToolBoxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum
n /alerts
n /notifications
n /systrayIcon
n /fl
n /fr
n /appData
n
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1
mRun: [ladarujaz] Rundll32.exe "c:\windows\system32\mutipuyu.dll",a
mRun: [BackupNowEZtray] "c:\program files\newtech infosystems\backup now ez\BackupNowEZtray.exe" -k
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SelectRebates] c:\program files\selectrebates\SelectRebates.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [SRFirstRun] rundll32 srclient.dll,CreateFirstRunRp
mRun: [DXDllRegExe] c:\windows\registeredpackages\{44bba855-cc51-11cf-aafa-00aa00b6015c}\dxdllreg.exe
mRun: [SchedulingAgent] mstinit.exe /firstlogon
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [R8388QA8U8] c:\windows\temp\Sth.exe
dRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
dRun: [5GUTNY6MFK] c:\windows\temp\Stg.exe
dRunOnce: [RunNarrator] Narrator.exe
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\paypal~1.lnk - c:\program files\paypal\payment wizard\outlook express\OEHook.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snsicon.lnk - c:\program files\second nature\Snsicon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winkey.lnk - c:\program files\winkey\WinKey.exe
IE: &Add animation to IncrediMail Style Box - c:\progra~1\incred~1\bin\resources\WebMenuImg.htm
IE: &Viewpoint Search - c:\program files\viewpoint\viewpoint toolbar\ViewBar.dll/CXTSEARCH.HTML
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: Download using Download &Express - file://c:\windows\system32\metaproducts\Add_Url.htm
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\system32\msjava.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} - hxxp://office.microsoft.com/productupdates/content/opuc.cab
DPF: {6F750202-1362-4815-A476-88533DE61D0C} - hxxp://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_2-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
TCP: Interfaces\{3FE8BD33-6964-40A9-AD2C-97B3A6D16929} : DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\windows\system32\metaproducts\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\windows\system32\metaproducts\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\windows\system32\metaproducts\mdpph.dll
Notify: itlnfw32 - itlnfw32.dll
Notify: itlntfy - itlnfw32.dll
AppInit_DLLs: c:\windows\system32\nihedufo.dll sivamube.dll c:\windows\system32\mutipuyu.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: joguvebez - {f8cbc64e-9611-47e1-a07b-375d763aac0a} - No File
SSODL: kavejovir - {752584fa-e18b-4a69-b452-0c1efc86d167} - No File
STS: {f8cbc64e-9611-47e1-a07b-375d763aac0a} - No File
STS: {752584fa-e18b-4a69-b452-0c1efc86d167} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
LSA: Notification Packages = scecli yagepodo.dll
.
============= SERVICES / DRIVERS ===============
.
R2 itlperf;Intel CPU;c:\windows\system32\svchost.exe -k itlsvc [2002-9-3 12800]
R2 NTI BackupNowEZSvr;NTI BackupNowEZSvr;c:\program files\newtech infosystems\backup now ez\BackupNowEZSvr.exe [2009-9-19 45312]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-4-23 1251720]
S1 iiqmmsvh;iiqmmsvh;\??\c:\windows\system32\drivers\iiqmmsvh.sys --> c:\windows\system32\drivers\iiqmmsvh.sys [?]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 165264]
S1 MpKsl15bad665;MpKsl15bad665;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\mpksl15bad665.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\MpKsl15bad665.sys [?]
S1 MpKsl40f73b73;MpKsl40f73b73;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\mpksl40f73b73.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\MpKsl40f73b73.sys [?]
S1 MpKsl4d44bc6b;MpKsl4d44bc6b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{22d8dfd2-293f-46f4-b0b4-80fc0ab43736}\mpksl4d44bc6b.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{22d8dfd2-293f-46f4-b0b4-80fc0ab43736}\MpKsl4d44bc6b.sys [?]
S1 MpKsla353c698;MpKsla353c698;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{88995069-b1e3-4094-b3b6-c3f6aa376a75}\mpksla353c698.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{88995069-b1e3-4094-b3b6-c3f6aa376a75}\MpKsla353c698.sys [?]
S1 MpKslb78e1369;MpKslb78e1369;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\mpkslb78e1369.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\MpKslb78e1369.sys [?]
S2 GoogleUpdateBeta;Google Update Service;c:\documents and settings\localservice\local settings\application data\google\update\googleupdatebeta.exe /svc --> c:\documents and settings\localservice\local settings\application data\google\update\GoogleUpdateBeta.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-27 136176]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-6-27 136176]
.
=============== Created Last 30 ================
.
2011-06-23 08:10:49 -------- d-----w- C:\8deaa65787caeaf7444d50834175
2011-06-23 08:10:46 20480 ----a-w- c:\windows\system32\drivers\hidserv.dll
2011-06-23 08:05:59 57856 -c--a-w- c:\windows\system32\dllcache\EXCH_scripto.dll
2011-06-23 08:04:58 10129408 -c--a-w- c:\windows\system32\dllcache\hwxkor.dll
2011-06-23 08:03:57 598071 -c--a-w- c:\windows\system32\dllcache\fpmmc.dll
2011-06-23 08:00:33 73728 -c--a-w- c:\windows\system32\dllcache\icwtutor.exe
2011-06-23 07:58:19 189440 -c--a-w- c:\windows\system32\dllcache\wuaueng.dll
2011-06-23 07:58:19 139776 -c--a-w- c:\windows\system32\dllcache\wuauclt.exe
2011-06-23 07:48:04 7046 ----a-r- c:\windows\SET9A.tmp
2011-06-23 07:48:02 13608 ----a-r- c:\windows\SET7C.tmp
2011-06-23 07:47:58 1086182 ----a-r- c:\windows\SET65.tmp
2011-06-23 07:37:10 -------- d-----w- C:\Recovery
2011-05-25 00:02:29 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-05-25 00:02:29 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-05-25 00:02:29 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-05-25 00:02:29 13312 ----a-w- c:\windows\system32\irclass.dll
2011-05-25 00:02:01 7046 ----a-r- c:\windows\SETA4.tmp
2011-05-25 00:02:00 13608 ----a-r- c:\windows\SET86.tmp
2011-05-25 00:01:56 1086182 ----a-r- c:\windows\SET71.tmp
2011-05-24 22:30:59 49152 -c--a-w- c:\windows\system32\dllcache\msador15.dll
2011-05-24 22:28:47 272896 -c--a-w- c:\windows\system32\dllcache\pinball.exe
2011-05-24 22:25:56 5888 ----a-w- c:\windows\system32\drivers\splitter.sys
2011-05-24 22:25:51 50048 ----a-w- c:\windows\system32\drivers\DMusic.sys
2011-05-24 22:19:11 7046 ----a-r- c:\windows\SET93.tmp
2011-05-24 22:19:09 13608 ----a-r- c:\windows\SET75.tmp
2011-05-24 22:19:05 1086182 ----a-r- c:\windows\SET60.tmp
2011-05-24 21:43:14 56576 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-05-24 21:13:01 38024 ----a-w- c:\windows\system32\drivers\termdd.sys
2011-05-24 21:10:16 696320 -c--a-w- c:\windows\system32\dllcache\sapi.dll
2011-05-24 21:10:16 696320 ----a-w- c:\program files\common files\microsoft shared\speech\sapi.dll
2011-05-24 21:10:14 22016 -c--a-w- c:\windows\system32\dllcache\agt0408.dll
2011-05-24 21:10:14 19968 -c--a-w- c:\windows\system32\dllcache\agt040e.dll
2011-05-24 21:10:14 19456 -c--a-w- c:\windows\system32\dllcache\agt041f.dll
2011-05-24 21:10:14 19456 -c--a-w- c:\windows\system32\dllcache\agt0419.dll
2011-05-24 21:10:14 19456 -c--a-w- c:\windows\system32\dllcache\agt0415.dll
2011-05-24 21:10:14 19456 -c--a-w- c:\windows\system32\dllcache\agt0405.dll
2011-05-24 21:10:08 132096 ----a-w- c:\windows\system\WINSPOOL.DRV
2011-05-24 21:10:08 10496 -c--a-w- c:\windows\system32\dllcache\irenum.sys
2011-05-24 21:10:08 10496 ----a-w- c:\windows\system32\drivers\irenum.sys
2011-05-24 21:10:07 71168 ----a-w- c:\windows\system32\storprop.dll
2011-05-24 21:09:38 7046 ----a-r- c:\windows\SET174.tmp
2011-05-24 21:09:36 13608 ----a-r- c:\windows\SET156.tmp
2011-05-24 21:09:32 1086182 ----a-r- c:\windows\SET141.tmp
.
==================== Find3M ====================
.
2011-05-07 14:48:17 215552 ------w- c:\windows\system32\itlpfw32.dll
.
============= FINISH: 2:12:01.10 ===============
Edit: http://forums.spybot.info/showthread.php?p=404974#post404974
1. Removed the hard drive and installed in another computer.
2. Utilized Spybot and Malwarebytes anti malware programs to clean the disk from the other computer.
3. Reinstalled the disk into the Dell and system would not boot.
4. Utilized the XP Recovery console to restore the master boot record.
5. Now the computer can boot, but many errors and can not run most programs.
6. Used the XP installation disk to do a system restore/repair.
7. System still has significant issues; but am now able to run the pre post procedures.
8. backed up the Registry with ERUNT
9. Ran DDS see below and attached
10. Spybot is still detecting errors as follows:
Virtumonde.prx
Fraud.DesktopSecurity2010
Fraud.HDDDefragmenter
FraudInternetSecurity2011
MicrosoftWindows.AppFirewallBypass
MircosoftWindowsSecurityCenter.FirewallBypass
Win32.FraudLoader.edt
Thanks so much!!!
Roger
---------------------- DDS Log -------------------------------------------
DDS (Ver_2011-06-12.02) - NTFSx86
Internet Explorer: 6.0.2800.1106
Run by Christara at 2:11:03 on 2011-06-23
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.511.227 [GMT -7:00]
.
AV: Microsoft Security Essentials *Disabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe -k itlsvc
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\NewTech Infosystems\Backup Now EZ\BackupNowEZSvr.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\rundll32.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: {868cdff6-81ae-451f-a89e-7ae501bbfab9} - c:\windows\system32\dpnhupn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: ShopAtHomeIEHelper Class: {e8daaa30-6caa-4b58-9603-8e54238219e2} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: ShopAtHome.com Toolbar: {98279c38-de4b-4bcf-93c9-8ec26069d6f4} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [ToolBoxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum







mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1
mRun: [ladarujaz] Rundll32.exe "c:\windows\system32\mutipuyu.dll",a
mRun: [BackupNowEZtray] "c:\program files\newtech infosystems\backup now ez\BackupNowEZtray.exe" -k
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SelectRebates] c:\program files\selectrebates\SelectRebates.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [SRFirstRun] rundll32 srclient.dll,CreateFirstRunRp
mRun: [DXDllRegExe] c:\windows\registeredpackages\{44bba855-cc51-11cf-aafa-00aa00b6015c}\dxdllreg.exe
mRun: [SchedulingAgent] mstinit.exe /firstlogon
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [R8388QA8U8] c:\windows\temp\Sth.exe
dRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
dRun: [5GUTNY6MFK] c:\windows\temp\Stg.exe
dRunOnce: [RunNarrator] Narrator.exe
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\paypal~1.lnk - c:\program files\paypal\payment wizard\outlook express\OEHook.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snsicon.lnk - c:\program files\second nature\Snsicon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winkey.lnk - c:\program files\winkey\WinKey.exe
IE: &Add animation to IncrediMail Style Box - c:\progra~1\incred~1\bin\resources\WebMenuImg.htm
IE: &Viewpoint Search - c:\program files\viewpoint\viewpoint toolbar\ViewBar.dll/CXTSEARCH.HTML
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: Download using Download &Express - file://c:\windows\system32\metaproducts\Add_Url.htm
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\system32\msjava.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} - hxxp://office.microsoft.com/productupdates/content/opuc.cab
DPF: {6F750202-1362-4815-A476-88533DE61D0C} - hxxp://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_2-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
TCP: Interfaces\{3FE8BD33-6964-40A9-AD2C-97B3A6D16929} : DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\windows\system32\metaproducts\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\windows\system32\metaproducts\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\windows\system32\metaproducts\mdpph.dll
Notify: itlnfw32 - itlnfw32.dll
Notify: itlntfy - itlnfw32.dll
AppInit_DLLs: c:\windows\system32\nihedufo.dll sivamube.dll c:\windows\system32\mutipuyu.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: joguvebez - {f8cbc64e-9611-47e1-a07b-375d763aac0a} - No File
SSODL: kavejovir - {752584fa-e18b-4a69-b452-0c1efc86d167} - No File
STS: {f8cbc64e-9611-47e1-a07b-375d763aac0a} - No File
STS: {752584fa-e18b-4a69-b452-0c1efc86d167} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
LSA: Notification Packages = scecli yagepodo.dll
.
============= SERVICES / DRIVERS ===============
.
R2 itlperf;Intel CPU;c:\windows\system32\svchost.exe -k itlsvc [2002-9-3 12800]
R2 NTI BackupNowEZSvr;NTI BackupNowEZSvr;c:\program files\newtech infosystems\backup now ez\BackupNowEZSvr.exe [2009-9-19 45312]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-4-23 1251720]
S1 iiqmmsvh;iiqmmsvh;\??\c:\windows\system32\drivers\iiqmmsvh.sys --> c:\windows\system32\drivers\iiqmmsvh.sys [?]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 165264]
S1 MpKsl15bad665;MpKsl15bad665;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\mpksl15bad665.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\MpKsl15bad665.sys [?]
S1 MpKsl40f73b73;MpKsl40f73b73;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\mpksl40f73b73.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\MpKsl40f73b73.sys [?]
S1 MpKsl4d44bc6b;MpKsl4d44bc6b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{22d8dfd2-293f-46f4-b0b4-80fc0ab43736}\mpksl4d44bc6b.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{22d8dfd2-293f-46f4-b0b4-80fc0ab43736}\MpKsl4d44bc6b.sys [?]
S1 MpKsla353c698;MpKsla353c698;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{88995069-b1e3-4094-b3b6-c3f6aa376a75}\mpksla353c698.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{88995069-b1e3-4094-b3b6-c3f6aa376a75}\MpKsla353c698.sys [?]
S1 MpKslb78e1369;MpKslb78e1369;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\mpkslb78e1369.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{33d6fea7-330f-4e8c-8b0b-0020bb97a40c}\MpKslb78e1369.sys [?]
S2 GoogleUpdateBeta;Google Update Service;c:\documents and settings\localservice\local settings\application data\google\update\googleupdatebeta.exe /svc --> c:\documents and settings\localservice\local settings\application data\google\update\GoogleUpdateBeta.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-27 136176]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-6-27 136176]
.
=============== Created Last 30 ================
.
2011-06-23 08:10:49 -------- d-----w- C:\8deaa65787caeaf7444d50834175
2011-06-23 08:10:46 20480 ----a-w- c:\windows\system32\drivers\hidserv.dll
2011-06-23 08:05:59 57856 -c--a-w- c:\windows\system32\dllcache\EXCH_scripto.dll
2011-06-23 08:04:58 10129408 -c--a-w- c:\windows\system32\dllcache\hwxkor.dll
2011-06-23 08:03:57 598071 -c--a-w- c:\windows\system32\dllcache\fpmmc.dll
2011-06-23 08:00:33 73728 -c--a-w- c:\windows\system32\dllcache\icwtutor.exe
2011-06-23 07:58:19 189440 -c--a-w- c:\windows\system32\dllcache\wuaueng.dll
2011-06-23 07:58:19 139776 -c--a-w- c:\windows\system32\dllcache\wuauclt.exe
2011-06-23 07:48:04 7046 ----a-r- c:\windows\SET9A.tmp
2011-06-23 07:48:02 13608 ----a-r- c:\windows\SET7C.tmp
2011-06-23 07:47:58 1086182 ----a-r- c:\windows\SET65.tmp
2011-06-23 07:37:10 -------- d-----w- C:\Recovery
2011-05-25 00:02:29 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-05-25 00:02:29 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-05-25 00:02:29 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-05-25 00:02:29 13312 ----a-w- c:\windows\system32\irclass.dll
2011-05-25 00:02:01 7046 ----a-r- c:\windows\SETA4.tmp
2011-05-25 00:02:00 13608 ----a-r- c:\windows\SET86.tmp
2011-05-25 00:01:56 1086182 ----a-r- c:\windows\SET71.tmp
2011-05-24 22:30:59 49152 -c--a-w- c:\windows\system32\dllcache\msador15.dll
2011-05-24 22:28:47 272896 -c--a-w- c:\windows\system32\dllcache\pinball.exe
2011-05-24 22:25:56 5888 ----a-w- c:\windows\system32\drivers\splitter.sys
2011-05-24 22:25:51 50048 ----a-w- c:\windows\system32\drivers\DMusic.sys
2011-05-24 22:19:11 7046 ----a-r- c:\windows\SET93.tmp
2011-05-24 22:19:09 13608 ----a-r- c:\windows\SET75.tmp
2011-05-24 22:19:05 1086182 ----a-r- c:\windows\SET60.tmp
2011-05-24 21:43:14 56576 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-05-24 21:13:01 38024 ----a-w- c:\windows\system32\drivers\termdd.sys
2011-05-24 21:10:16 696320 -c--a-w- c:\windows\system32\dllcache\sapi.dll
2011-05-24 21:10:16 696320 ----a-w- c:\program files\common files\microsoft shared\speech\sapi.dll
2011-05-24 21:10:14 22016 -c--a-w- c:\windows\system32\dllcache\agt0408.dll
2011-05-24 21:10:14 19968 -c--a-w- c:\windows\system32\dllcache\agt040e.dll
2011-05-24 21:10:14 19456 -c--a-w- c:\windows\system32\dllcache\agt041f.dll
2011-05-24 21:10:14 19456 -c--a-w- c:\windows\system32\dllcache\agt0419.dll
2011-05-24 21:10:14 19456 -c--a-w- c:\windows\system32\dllcache\agt0415.dll
2011-05-24 21:10:14 19456 -c--a-w- c:\windows\system32\dllcache\agt0405.dll
2011-05-24 21:10:08 132096 ----a-w- c:\windows\system\WINSPOOL.DRV
2011-05-24 21:10:08 10496 -c--a-w- c:\windows\system32\dllcache\irenum.sys
2011-05-24 21:10:08 10496 ----a-w- c:\windows\system32\drivers\irenum.sys
2011-05-24 21:10:07 71168 ----a-w- c:\windows\system32\storprop.dll
2011-05-24 21:09:38 7046 ----a-r- c:\windows\SET174.tmp
2011-05-24 21:09:36 13608 ----a-r- c:\windows\SET156.tmp
2011-05-24 21:09:32 1086182 ----a-r- c:\windows\SET141.tmp
.
==================== Find3M ====================
.
2011-05-07 14:48:17 215552 ------w- c:\windows\system32\itlpfw32.dll
.
============= FINISH: 2:12:01.10 ===============
Last edited by a moderator: