Hello,
I contract virtumonde on my laptop and have run several programs including spybot, adaware, AVG, SD fix, dr web and had a friend look at the computer. I think he did the most damage. He stopped some services related the the virus file and deleted some of the registry keys whcih appeared to only have the virus. However, since he did that my network devices are not found, my start toolbar is missing and many of my sutomatic service are not running. Even if I try to srtat them I just get an error 1068.. I also can't drag and drop any files or copy and paste any files. they highlight but don;t drag and will not paste... I ran a DDS log the notes are below.
DDS (Ver_09-01-07.01) - NTFSx86
Run by WPotts at 18:57:15.75 on Thu 01/08/2009
Internet Explorer: 7.0.5730.13
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: {023B4938-0FE0-45EB-AD51-04ACE04525EF} - No File
BHO: {117F00FD-30D8-4683-880F-F372BA0E9128} - No File
BHO: {27550895-833c-41cc-8c78-5fb1600333ae} - No File
BHO: {482C069E-77C0-4C22-A732-7ED1FEE7743B} - No File
BHO: {8B507386-313D-4B78-8A7F-27E07339491E} - No File
BHO: {A8686CEF-A520-4791-BFFF-08521904877F} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [CARPService] carpserv.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [ShStatEXE] "c:\program files\network associates\virusscan\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\network associates\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [eCopy Scan Inbox Monitor] "c:\program files\ecopy\desktop 9.2\bin\InboxMonitor.exe" -run
mRun: [eDP2eD] "c:\program files\ecopy\desktop 9.2\bin\eDP2eD.exe"
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\system32\msjava.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: imagistics.com\oraproduction
Trusted Zone: oce.com\self-service
Trusted Zone: oce.com\www.itservicecenter
Trusted Zone: self-service
Trusted Zone: sprintpcs.com\manage
Notify: AtiExtEvent - Ati2evxx.dll
Notify: cbXPiGyV - cbXPiGyV.dll
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\wpotts\applic~1\mozilla\firefox\profiles\gslzswl9.default\
FF - prefs.js: browser.startup.homepage - hxxp://macomb.angellearning.com/frames.aspx|http://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbarff\components\vmAVGConnector.dll
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-01-08 16:59 <DIR> --d----- c:\windows\ERUNT
2009-01-08 16:49 <DIR> --d----- C:\SDFix
2009-01-08 16:06 <DIR> --d----- C:\test
2009-01-07 20:47 <DIR> --d----- c:\documents and settings\wpotts\DoctorWeb
2009-01-07 18:39 708,164 a--sh--- c:\windows\system32\tCMUFfhk.ini2
2009-01-07 18:39 708,164 a--sh--- c:\windows\system32\tCMUFfhk.ini
2009-01-06 14:18 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-01-06 14:18 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-01-04 21:55 <DIR> --d----- c:\program files\Lavasoft
2009-01-04 21:54 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-01-04 20:22 129,024 a------- c:\windows\system32\goyjhs.dll
2009-01-04 20:22 129,024 a------- c:\windows\system32\xduwofsj.dll
2009-01-03 14:58 <DIR> --d----- c:\program files\AVG
2009-01-03 14:56 143 a------- c:\windows\system32\mcrh.tmp
2009-01-03 11:15 22,016 a------- c:\windows\system32\digeste.dll
2008-12-19 09:08 107,368 a------- c:\windows\system32\GEARAspi.dll
2008-12-19 09:08 15,464 a------- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-12-19 09:08 <DIR> --d----- c:\program files\iPod
2008-12-19 09:08 <DIR> --d----- c:\program files\iTunes
2008-12-19 09:08 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-19 09:08 <DIR> --d----- c:\program files\Bonjour
2008-12-13 21:48 3,632,384 a------- c:\windows\system32\drivers\NETw5x32.sys
2008-12-13 21:48 2,756,608 a------- c:\windows\system32\NETw5r32.dll
2008-12-13 21:48 663,552 a------- c:\windows\system32\NETw5c32.dll
2008-12-13 21:48 <DIR> --d----- c:\program files\common files\Intel
2008-12-13 21:31 23,576 a------- c:\windows\system32\wuapi.dll.mui
==================== Find3M ====================
2008-12-04 20:18 104,417 a------- c:\windows\system32\nvModes.dat
2008-10-23 08:01 283,648 a------- c:\windows\system32\gdi32.dll
2008-10-16 15:38 826,368 a------- c:\windows\system32\wininet.dll
2008-10-16 14:07 208,744 a------- c:\windows\system32\muweb.dll
2007-08-13 09:56 56,912 a------- c:\documents and settings\wpotts\g2mdlhlpx.exe
============= FINISH: 18:58:06.41 ===============