I recently got infected with win32:falder[trj]. Every few minutes my anti virus software (Avast) detects it but I can't remove it. I select DELETE but it keeps coming back. Also, my internet is opening pages from weird sites. And, Script Blocker pops up every time I open a web page.
My computer is running much slower now and for some reason, it has disabled "Windows Automatic Updates" and it won't allow me to enable it. When I go to windows security center and click on "Turn on automatic updates", nothing happens.
If you can help me with this problem, I would really appreciate it.
Here are the reports from DDS:
DDS (Ver_09-03-16.01) - NTFSx86
Run by Carol & Robert at 16:52:56.68 on Mon 04/06/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_12
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.512.158 [GMT -4:00]
AV: avast! antivirus 4.8.1335 [VPS 090406-0] *On-access scanning disabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\CAROL&~1\LOCALS~1\Temp\t87i6fn7.exe
C:\DOCUME~1\CAROL&~1\LOCALS~1\Temp\t87i6fn7.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\DOCUME~1\CAROL&~1\LOCALS~1\Temp\t87i6fn7.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Carol & Robert\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: {392ea4bb-b224-4474-8e1b-633d65b84b1d} - c:\windows\system32\opnmMeFx.dll
BHO: {885502ce-3c63-56da-e6f4-bc99f3905d94}: {49d5093f-99cb-4f6e-ad65-36c3ec205588} - c:\windows\system32\lmrfsh.dll
BHO: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\jkkKbXom.dll
BHO: c:\windows\system32\hsf73ikmdf3f.dll: {b2ba40a2-74f3-42bd-f434-2604812c8954} - c:\windows\system32\hsf73ikmdf3f.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [<NO NAME>] c:\docume~1\carol&~1\locals~1\temp\t87i6fn7.exe
uRun: [Windows Resurections] c:\docume~1\carol&~1\locals~1\temp\t87i6fn7.exe
mRun: [USRpdA] c:\windows\system32\usrmlnka.exe runservices \device\3cpipe-USRpdA
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [<NO NAME>]
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [88226d7a] rundll32.exe "c:\windows\system32\swfgrljy.dll",b
StartupFolder: c:\docume~1\carol&~1\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1231185238339
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231186212163
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab56649.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} - hxxp://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab
Notify: Antiwpa - antiwpa.dll
Notify: jkkKbXom - jkkKbXom.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: c:\windows\system32\hsf73ikmdf3f.dll: {b2ba40a2-74f3-42bd-f434-2604812c8954} - c:\windows\system32\hsf73ikmdf3f.dll
SEH: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\jkkKbXom.dll
SEH: {2f252b77-d86c-5f38-34e4-9d18ca76090f}: {f09067ac-81d9-4e43-83f5-c68d77b252f2} - c:\windows\system32\lmrfsh.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\opnmMeFx
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\carol&~1\applic~1\mozilla\firefox\profiles\gjvrsdkx.default\
FF - prefs.js: browser.startup.homepage - www.msn.com
FF - plugin: c:\documents and settings\carol & robert\application data\mozilla\plugins\npPxPlay.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-5 114768]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};c:\program files\cyberlink\powerdvd\000.fcl [2008-1-30 41456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-13 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-1-5 138680]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-1-5 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-1-5 352920]
=============== Created Last 30 ================
2009-04-06 16:41 <DIR> --d----- c:\program files\Trend Micro
2009-04-06 08:57 99,328 a------- c:\windows\system32\pareigmm.dll
2009-04-06 08:57 99,328 a------- c:\windows\system32\lmrfsh.dll
2009-04-06 08:56 1,389,977 ---sh--- c:\windows\system32\yjlrgfws.ini
2009-04-06 08:56 75,264 a------- c:\windows\system32\swfgrljy.dll
2009-04-06 08:54 7,603 a--sh--- c:\windows\system32\xFeMmnpo.ini2
2009-04-06 08:54 7,603 a--sh--- c:\windows\system32\xFeMmnpo.ini
2009-04-06 08:54 237,056 a------- c:\windows\system32\opnmMeFx.dll
2009-04-06 08:45 15,000 a------- c:\windows\system32\hsf73ikmdf3f.dll
2009-04-06 08:39 <DIR> --d----- c:\program files\Lavasoft
2009-04-06 08:39 35,840 a------- c:\windows\system32\jkkKbXom.dll
2009-04-05 13:44 <DIR> --d----- c:\docume~1\carol&~1\applic~1\PC-FAX TX
2009-03-31 09:02 <DIR> --d----- c:\program files\MSXML 4.0
2009-03-30 17:55 <DIR> --d--r-- c:\docume~1\carol&~1\applic~1\Brother
2009-03-30 17:47 818 a------- c:\windows\Brpfx04a.ini
2009-03-30 17:47 153 a------- c:\windows\brpcfx.ini
2009-03-30 17:47 419 a------- c:\windows\BRWMARK.INI
2009-03-30 17:47 27 a------- c:\windows\BRPP2KA.INI
2009-03-30 17:46 25,856 ac------ c:\windows\system32\dllcache\usbprint.sys
2009-03-30 17:46 25,856 a------- c:\windows\system32\drivers\usbprint.sys
2009-03-30 17:46 32,128 ac------ c:\windows\system32\dllcache\usbccgp.sys
2009-03-30 17:46 32,128 a------- c:\windows\system32\drivers\usbccgp.sys
2009-03-30 17:40 176,128 -------- c:\windows\system32\BroSNMP.dll
2009-03-30 17:40 73,728 -------- c:\windows\system32\BrDctF2.dll
2009-03-30 17:40 5,120 -------- c:\windows\system32\BrDctF2L.dll
2009-03-30 17:40 3,072 -------- c:\windows\system32\BrDctF2S.dll
2009-03-30 17:40 167,936 -------- c:\windows\system32\NSSearch.dll
2009-03-30 17:40 <DIR> --d----- c:\program files\Brother
2009-03-30 17:38 <DIR> --d----- c:\program files\Nuance
2009-03-30 17:37 31,567 a------- c:\windows\maxlink.ini
2009-03-30 17:36 <DIR> --d----- c:\program files\common files\ScanSoft Shared
2009-03-30 17:36 <DIR> --d----- c:\program files\ScanSoft
2009-03-30 17:35 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Brother
2009-03-29 16:06 <DIR> --d----- c:\docume~1\alluse~1\applic~1\vsosdk
2009-03-29 10:04 87,608 a------- c:\docume~1\carol&~1\applic~1\inst.exe
2009-03-29 10:04 47,360 a------- c:\windows\system32\drivers\pcouffin.sys
2009-03-29 10:04 47,360 a------- c:\docume~1\carol&~1\applic~1\pcouffin.sys
2009-03-29 10:04 217,127 a------- c:\windows\system32\drv43260.dll
2009-03-29 10:04 208,935 a------- c:\windows\system32\drv33260.dll
2009-03-29 10:04 176,165 a------- c:\windows\system32\drv23260.dll
2009-03-29 10:04 102,439 a------- c:\windows\system32\sipr3260.dll
2009-03-29 10:04 65,602 a------- c:\windows\system32\cook3260.dll
2009-03-29 10:04 626,688 a------- c:\windows\system32\vp7vfw.dll
2009-03-29 10:04 1,184,984 a------- c:\windows\system32\wvc1dmod.dll
2009-03-29 10:04 <DIR> --d----- c:\program files\VSO
2009-03-14 17:12 <DIR> --d----- c:\windows\Dream Day Wedding - Married in Manhattan
2009-03-14 17:12 <DIR> --d----- c:\program files\Dream Day Wedding - Married in Manhattan
2009-03-13 06:24 73,728 a------- c:\windows\system32\javacpl.cpl
2009-03-12 11:04 354 a------- c:\windows\system32\hpguapi.ini
2009-03-11 19:51 221,184 a------- c:\windows\system32\wmpns.dll
==================== Find3M ====================
2009-03-13 06:24 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-09 07:13 1,846,784 a------- c:\windows\system32\win32k.sys
2001-08-23 08:00 94,784 ---sh--- c:\windows\twain.dll
2008-04-13 20:12 50,688 ---sh--- c:\windows\twain_32.dll
2008-04-13 20:11 1,028,096 ---sh--- c:\windows\system32\mfc42.dll
2008-04-13 20:12 57,344 ---sh--- c:\windows\system32\msvcirt.dll
2008-04-13 20:12 413,696 ---sh--- c:\windows\system32\msvcp60.dll
2008-04-13 20:12 343,040 ---sh--- c:\windows\system32\msvcrt.dll
2008-04-13 20:12 551,936 ---sh--- c:\windows\system32\oleaut32.dll
2008-04-13 20:12 84,992 ---sh--- c:\windows\system32\olepro32.dll
2008-04-13 20:12 11,776 ---sh--- c:\windows\system32\regsvr32.exe
============= FINISH: 16:54:07.58 ===============
Attached File(s)
-
Attach.txt (9.67K)
Number of downloads: 5

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top
button at the top bar of this topic and Track this Topic. The topics you are tracking can be found
button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.









