I recently (about four days ago) go infected by a series of Trojans that I have been battling for the past several days. Initially, I could not update my Norton antivirus program (whenever I tried, it said all of the files were up to date, but the definition file was dated December 14), after reinstalling Norton I could update it, but it would say "scan complete" after scanning only 877 files. When attempting to run McAfee antivirus, half way through my computer would give me a Win32 error, and force a restart of windows. Whenever spybot would run it would find re-occurring instances of Virtumonde and Vundo Trojans, which it would successfully clean, only to find them again after restarting my computer. I ran several online virus scans, one of which gave me a prunnet.exe infection, and the symantec online virus scan pointed out two .dll files as viruses that were created at the time I initially noticed the infection. After manually deleting the two .dll infections and cleanly reinstalling all Norton End-Protection, I was able to update and run all of the programs. Norton caught over 14 trojans and deleted them. My system appeared to have been cleaned and ran well, however, I lost control over the Terminal Services and Remote Procedure Protocol Services (as in the option for startup type as well as start, stop, pause, and resume buttons were greyed out). I was able to regain control over terminal services by forcing a disable in safe mode. However, RPC options are still all greyed out. I also periodically hear my computer make a noise as if an error window pops open, though no window appears, and I noticed the noise corresponds to a second rundll32.exe process starting on my computer (which I then end). My computer is also making a lot of noise as if it is working something, even when I am only using firefox or microsoft word. I'm worried that my computer is still infected with something, and that in time it will just download more viruses and I will have to spend days getting rid of them all over again. Please help!!
Thanks!
DDS (Ver_09-01-07.01) - NTFSx86
Run by Owner at 18:29:47.62 on Sat 01/10/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1441 [GMT -5:00]
AV: Symantec Endpoint Protection *On-access scanning enabled* (Updated)
FW: Symantec Endpoint Protection *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {584983AA-F7C8-4DE7-8F32-CA89DCF40E6F} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: {d0637c55-da0b-46e9-b6ea-d5ef0da3ff82} - c:\windows\system32\khfEtRJC.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ATI Launchpad]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [<NO NAME>]
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [IntelAudioStudio] "c:\program files\intel audio studio\IntelAudioStudio.exe" TRAY
mRun: [NeroCheck] c:\windows\system32\\NeroCheck.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [<NO NAME>]
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{24c67b54-0718-445e-b663-3138d9246bd1}\Icon3E5562ED7.ico
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {44226DFF-747E-4edc-B30C-78752E50CD0C} - {44226DFF-747E-4edc-B30C-78752E50CD0C} - c:\program files\ati multimedia\tv\EXPLBAR.DLL
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: KATRACK.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\dr8dydl6.default\
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: XUL Cache: {F6CADF43-80E8-403D-91C4-A8393C60F2BF} - c:\windows\system32\config\systemprofile\local settings\application data\{f6cadf43-80e8-403d-91c4-a8393c60f2bf}\
============= SERVICES / DRIVERS ===============
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-1-8 99376]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090110.003\NAVENG.SYS [2009-1-10 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090110.003\NAVEX15.SYS [2009-1-10 876112]
R4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R4 ACEDRV09;ACEDRV09;c:\windows\system32\drivers\ACEDRV09.sys [2007-9-15 110304]
R4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-8-14 108392]
R4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-8-14 108392]
R4 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\autodesk\3ds max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [2008-3-9 65536]
R4 SlingAgentService;SlingAgentService;c:\program files\sling media\slingagent\SlingAgentService.exe [2008-12-10 88576]
R4 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2008-12-8 2440120]
S1 mferkdk;VSCore mferkdk;\??\c:\program files\mcafee\virusscan enterprise\mferkdk.sys --> c:\program files\mcafee\virusscan enterprise\mferkdk.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-11-18 23888]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
=============== Created Last 30 ================
2009-01-08 23:56 <DIR> --d----- C:\VundoFix Backups
2009-01-08 16:25 120 a--sh--- c:\windows\system32\xrsydkwf.ini
2009-01-08 13:52 92,488 a------- c:\windows\system32\drivers\SysPlant.sys
2009-01-08 13:51 123,952 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-08 13:51 60,800 a------- c:\windows\system32\S32EVNT1.DLL
2009-01-08 13:51 10,563 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-08 13:51 805 a------- c:\windows\system32\drivers\SYMEVENT.INF
2009-01-08 04:12 143 a------- c:\windows\system32\mcrh.tmp
2009-01-07 23:43 <DIR> --d----- C:\QUARANTINE
2009-01-07 21:31 1,495,552 a------- c:\windows\system32\epoPGPsdk.dll
2009-01-07 21:31 <DIR> --d----- c:\program files\common files\Cisco Systems
2009-01-07 16:23 120 a--sh--- c:\windows\system32\rsqmdasb.ini
2009-01-07 16:22 73,216 a------- c:\windows\system32\ffkuz.dll
2009-01-07 16:06 <DIR> --d----- c:\windows\Internet Logs
2009-01-07 16:04 110,080 a------- c:\windows\system32\drivers\dne2000.sys
2009-01-07 16:04 94,720 a------- c:\windows\system32\dneinobj.dll
2009-01-07 16:04 <DIR> --d----- c:\program files\common files\Deterministic Networks
2009-01-07 16:04 <DIR> --d----- c:\program files\Cisco Systems
2009-01-07 16:04 1,592 a------- c:\windows\VPNInstall.MIF
2009-01-07 16:03 <DIR> --d----- c:\temp\MU_Secure_Download
2009-01-06 22:03 2,206 a------- c:\windows\system32\tmp.reg
2009-01-06 20:10 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-01-06 20:09 <DIR> --d----- c:\documents and settings\owner\.housecall6.6
2009-01-06 17:22 93 a------- c:\windows\wininit.ini
2009-01-06 14:22 0 a------- c:\windows\system32\drivers\seneka.sys
2009-01-06 14:04 59 a------- c:\windows\system32\seneka.dat
2009-01-06 14:04 3 a------- c:\windows\system32\senekadf.dat
2009-01-06 13:59 123,852 a------- c:\windows\system32\senekalog.dat
2009-01-05 19:55 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Sling Media
2009-01-05 19:54 <DIR> --d----- c:\program files\Sling Media
==================== Find3M ====================
2008-12-16 14:34 55,024 a------- c:\windows\War3Unin.dat
2008-12-16 14:32 2,829 a------- c:\windows\War3Unin.pif
2008-12-16 14:32 139,264 a------- c:\windows\War3Unin.exe
2008-12-08 21:43 42,312 a------- c:\windows\system32\drivers\WPSDRVnt.sys
2008-12-08 21:43 357,704 a------- c:\windows\system32\sysfer.dll
2008-12-08 21:43 107,848 a------- c:\windows\system32\SymVPN.dll
2008-12-08 21:42 49,480 a------- c:\windows\system32\FwsVpn.dll
2008-11-21 16:47 524,288 a------- c:\windows\system32\DivXsm.exe
2008-11-21 16:47 3,596,288 a------- c:\windows\system32\qt-dx331.dll
2008-11-21 16:46 1,044,480 a------- c:\windows\system32\libdivx.dll
2008-11-21 16:46 200,704 a------- c:\windows\system32\ssldivx.dll
2008-11-21 16:44 161,096 a------- c:\windows\system32\DivXCodecVersionChecker.exe
2008-11-21 16:44 12,288 a------- c:\windows\system32\DivXWMPExtType.dll
2008-11-18 18:17 23,888 a------- c:\windows\system32\drivers\COH_Mon.sys
2008-11-18 18:01 10,537 a------- c:\windows\system32\drivers\coh_mon.cat
2008-11-18 18:01 706 a------- c:\windows\system32\drivers\COH_Mon.inf
2008-10-23 07:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-15 20:00 666,112 a------- c:\windows\system32\wininet.dll
============= FINISH: 18:30:59.14 ===============


