Please help me get rid of "System Security", a rogue spyware program. I will not bother to describe this malware because there is already a detailed description posted to the Malware spyware removal guide forum (see http://www.bleepingcomputer.com/malware-re...ystem-security).
I have read the post about getting rid of this, and I've downloaded Malwarebytes' Anti-Malware (MBAM) software and run it twice and it does not get rid of it. Each time I run MBAM, it identifies the rogue software, but even when I try to remove it, it's still there! I have also run Avast! and Troja Remover--nothing works! Here is my DDS log (I'm attaching the "attach" file unzipped because it's so small):
DDS (Version 1.1.0) - NTFSx86
Run by Harry at 12:15:22.94 on Wed 12/31/2008
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.190.35 [GMT -5:00]
AV: avast! antivirus 4.8.1296 [VPS 081231-0] *On-access scanning enabled* (Updated)
FW: Sunbelt Kerio Personal Firewall *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdcserv.exe
C:\WINDOWS\System32\lxdccoms.exe
C:\PROGRA~1\Ontrack\SYSTEM~1\MXTask.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Documents and Settings\All Users\Application Data\103866954\230053460.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Harry\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uWindow Title = Microsoft Internet Explorer provided by Compaq
uSearch Bar = hxxp://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=searchfavweb&c=1c02&lc=0409
uInternet Connection Wizard,ShellNext = hxxp://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
mSearchAssistant = hxxp://my.netzero.net/s/search?r=minisearch
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll
BHO: X1IEHook Class: {52706ef7-d7a2-49ad-a615-e903858cf284} - c:\program files\netzero\qsacc\X1IEBHO.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: ZeroBar: {f0f8ecbe-d460-4b34-b007-56a92e8f84a7} - c:\program files\netzero\Toolbar.dll
TB: {C17590D2-ECB4-4B15-8820-F58798DCC118} - No File
TB: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No File
TB: {5A074B29-F830-49DE-A31B-5BB9D7F6B407} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AtiPTA] atiptaxx.exe
mRun: [CARPService] carpserv.exe
mRun: [TkBellExe] c:\program files\common files\real\update_ob\realsched.exe -osboot
mRun: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
mRun: [srmclean] c:\cpqs\scom\srmclean.exe
mRun: [Display Settings] c:\program files\hpq\notebook utilities\hptasks.exe /s
mRun: [QT4HPOT] c:\progra~1\hpq\one-to~1\OneTouch.EXE
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [lxdcmon.exe] "c:\program files\lexmark 1300 series\lxdcmon.exe"
mRun: [lxdcamon] "c:\program files\lexmark 1300 series\lxdcamon.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [230053460] "c:\documents and settings\all users\application data\103866954\230053460.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2008-12-30 14:45 54,156 a---h--- c:\windows\QTFont.qfn
2008-12-30 14:45 1,409 a------- c:\windows\QTFont.for
2008-12-29 17:16 <DIR> --d----- c:\docume~1\harry\applic~1\Malwarebytes
2008-12-29 17:16 15,504 a------- c:\windows\system32\drivers\mbam.sys
2008-12-29 17:16 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 17:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2008-12-29 17:15 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2008-12-29 14:36 <DIR> --d----- c:\docume~1\alluse~1\applic~1\103866954
==================== Find3M ====================
2008-12-13 01:40 3,593,216 -------- c:\windows\system32\dllcache\mshtml.dll
2008-11-07 16:45 2,174,976 -------- c:\windows\system32\dllcache\WMVCore.dll
2008-10-24 06:21 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 07:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-23 07:36 286,720 -------- c:\windows\system32\dllcache\gdi32.dll
2008-10-16 14:13 1,809,944 a------- c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 14:13 202,776 a------- c:\windows\system32\dllcache\wuweb.dll
2008-10-16 14:12 323,608 a------- c:\windows\system32\dllcache\wucltui.dll
2008-10-16 14:12 561,688 a------- c:\windows\system32\dllcache\wuapi.dll
2008-10-16 14:09 92,696 a------- c:\windows\system32\dllcache\cdm.dll
2008-10-16 14:09 51,224 a------- c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 14:08 34,328 a------- c:\windows\system32\dllcache\wups.dll
2008-10-16 14:06 268,648 a------- c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 a------- c:\windows\system32\muweb.dll
2008-10-16 08:11 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 08:11 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 11:34 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2008-10-15 02:06 633,632 -------- c:\windows\system32\dllcache\iexplore.exe
2008-10-15 02:04 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2008-10-03 05:02 247,326 a------- c:\windows\system32\strmdll.dll
2008-10-03 05:02 247,326 -------- c:\windows\system32\dllcache\strmdll.dll
1998-12-08 21:53 186,368 a------- c:\program files\common files\IRAREG.DLL
1998-12-08 21:53 99,840 a------- c:\program files\common files\IRAABOUT.DLL
1998-12-08 21:53 70,144 a------- c:\program files\common files\IRAMDMTR.DLL
1998-12-08 21:53 48,640 a------- c:\program files\common files\IRALPTTR.DLL
1998-12-08 21:53 31,744 a------- c:\program files\common files\IRAWEBTR.DLL
1998-12-08 21:53 17,920 a------- c:\program files\common files\IRASRIAL.DLL
2008-09-29 16:22 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092920080930\index.dat
============= FINISH: 12:17:28.58 ===============