I am posting because I have offered to clean up a computer for a coworker, and want to make sure I do a thorough job. So far, I have seen indications of at least 4 separate malware programs. The first was Antivirus 360, which I believe I deleted for the most part via manually removing the files and registry values. I have also seen VirusProtect 3.8 and 3.9, though I had no luck locating the files I was told to delete...so I am not sure if the infection is there or not. His computer already has "Verizon Internet Security" installed, and I used that for an initial scan to see what it found. I deleted what it found, though that was done in safe mode, before I deleted all the files manually for AV360. When I enable Verizon Internet Security, it pops up two warnings, which mention a file by the name of Trojan.Win32.Monderb.xgy, in the C:\WINDOWS\system32\ljJCvSiI.dll. I looked up that file, and saw it was connected with the "Vundo" virus...or something along those lines. His computer is not connected to the internet at the moment. I am using my laptop to access the net, and transferring files via a flash drive to his computer. I have scanned with DDS, and will provide the log. I also have HJT ready to run on his desktop, as well as ComboFix. Here is the DDS log:
DDS (Ver_09-01-19.01) - NTFSx86
Run by HP_Administrator at 16:34:39.23 on Mon 01/26/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1982.1442 [GMT -5:00]
AV: Authentium Antivirus *On-access scanning enabled* (Outdated)
AV: Verizon Internet Security Suite Anti-Virus *On-access scanning disabled* (Outdated)
FW: Verizon Internet Security Suite Firewall *disabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\DISC\DiscGui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
c:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Documents and Settings\HP_Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJ&fl=0&ptb=k14J7Z1D6WZSkMag3_DO5w&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: {ba8c85c0-3123-84cb-b1a4-921f52cc9f67}: {76f9cc25-f129-4a1b-bc48-32130c58c8ab} - c:\windows\system32\kitdje.dll
BHO: {7cab59b4-55a3-4737-9fd5-b93c6430bf78} - c:\windows\system32\huacpeqy.dll
BHO: {a63e645f-13bd-45ed-b15f-6e8c1bd57279} - c:\windows\system32\ljJCvSiI.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: {8118}: {c6922a9b-aa89-497c-9827-3101bdc17937} - c:\windows\system32\jvtkew.dll
BHO: {daf17490-d212-4f8c-9a4a-40f85ccaf603} - c:\windows\system32\yayaApnM.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {A8FB8EB3-183B-4598-924D-86F0E5E37085} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe
mRun: [DISCover] c:\program files\disc\DISCover.exe
mRun: [DiscUpdateManager] c:\program files\disc\DiscUpdateMgr.exe
mRun: [DMAScheduler] c:\program files\sonic\digitalmedia plus\digitalmedia archive\DMAScheduler.exe
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [<NO NAME>]
mRun: [PCDrProfiler]
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SeekmoOE] c:\program files\seekmo\bin\10.0.341.0\OEAddOn.exe
mRun: [SeekmoSA] "c:\program files\seekmo\bin\10.0.341.0\SeekmoSA.exe"
mRun: [Verizon_McciTrayApp] c:\program files\verizon\McciTrayApp.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\progra~1\common~1\instal~1\update~1\issch.exe" -start
mRun: [VerizonServicepoint.exe] "c:\program files\verizon\vsp\VerizonServicepoint.exe" /AUTORUN
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe
IE: &Search - http://edits.mywebsearch.com/toolbaredits/...arch.jhtml?p=ZJ
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_05\bin\npjpi150_05.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
Trusted Zone: trymedia.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
Notify: ljJCvSiI - ljJCvSiI.dll
AppInit_DLLs: kitdje.dll
SEH: {a63e645f-13bd-45ed-b15f-6e8c1bd57279} - c:\windows\system32\ljJCvSiI.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll, digeste.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\yayaApnM
============= SERVICES / DRIVERS ===============
R0 KL1;KL1;c:\windows\system32\drivers\kl1.sys [2008-12-28 112144]
R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2008-12-28 196368]
R4 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 ADSFilter;ADSFilter - (Aluria Filter Driver);c:\windows\system32\drivers\adsfilter.sys --> c:\windows\system32\drivers\ADSFilter.sys [?]
S3 Radialpoint Security Services;Verizon Internet Security Suite;c:\program files\verizon\verizon internet security suite\RpsSecurityAwareR.exe [2008-10-24 96496]
=============== Created Last 30 ================
2009-01-23 10:41 12,160 a------- c:\windows\system32\drivers\mouhid.sys
2009-01-23 10:41 14,848 a------- c:\windows\system32\drivers\kbdhid.sys
2009-01-23 10:40 9,600 a------- c:\windows\system32\drivers\hidusb.sys
2009-01-14 12:00 129,024 a------- c:\windows\system32\kitdje.dll
2009-01-14 12:00 129,024 a------- c:\windows\system32\esqkopdy.dll
2009-01-12 22:59 129,024 a------- c:\windows\system32\lqhcih.dll
2009-01-12 22:59 129,024 a------- c:\windows\system32\fdperivv.dll
2009-01-12 22:54 1,266,872 ---sh--- c:\windows\system32\wjhhqrcq.ini
2009-01-12 22:54 72,704 a------- c:\windows\system32\qcrqhhjw.dll
2009-01-11 22:53 1,342,086 ---sh--- c:\windows\system32\qdqhtoic.ini
2009-01-11 22:53 72,704 a------- c:\windows\system32\ciothqdq.dll
2009-01-11 22:52 129,024 a------- c:\windows\system32\twahvj.dll
2009-01-11 22:52 129,024 a------- c:\windows\system32\rfmqigjc.dll
2009-01-10 00:41 129,024 a------- c:\windows\system32\vuwlnr.dll
2009-01-10 00:41 129,024 a------- c:\windows\system32\luixdhyu.dll
2009-01-08 00:02 129,024 a------- c:\windows\system32\ynaepz.dll
2009-01-08 00:02 129,024 a------- c:\windows\system32\oihaijvp.dll
2009-01-07 23:43 1,342,086 ---sh--- c:\windows\system32\mrhwyylg.ini
2009-01-04 00:12 1,307,356 ---sh--- c:\windows\system32\krcitjkk.ini
2009-01-01 23:44 1,307,356 ---sh--- c:\windows\system32\xqlrwxgt.ini
2009-01-01 23:44 72,704 a------- c:\windows\system32\tgxwrlqx.dll
2009-01-01 23:43 129,024 a------- c:\windows\system32\hvpedr.dll
2009-01-01 23:43 129,024 a------- c:\windows\system32\jdddawdf.dll
2009-01-01 00:32 0 a------- c:\windows\system32\mcrh.tmp
2008-12-31 10:28 1,307,356 ---sh--- c:\windows\system32\uhadesiw.ini
2008-12-31 10:28 72,704 a------- c:\windows\system32\wisedahu.dll
2008-12-31 10:26 129,024 a------- c:\windows\system32\lriekq.dll
2008-12-31 10:26 129,024 a------- c:\windows\system32\xcalqtyc.dll
2008-12-29 21:29 129,024 a------- c:\windows\system32\gxpuwa.dll
2008-12-29 21:29 129,024 a------- c:\windows\system32\huxcvnrm.dll
2008-12-28 15:35 1,811,744 a--sh--- c:\windows\system32\drivers\fidbox.dat
2008-12-28 15:35 5,408 a--sh--- c:\windows\system32\drivers\fidbox2.dat
2008-12-28 15:35 2,252 a--sh--- c:\windows\system32\drivers\fidbox.idx
2008-12-28 15:35 1,508 a--sh--- c:\windows\system32\drivers\fidbox2.idx
2008-12-28 15:19 112,144 a------- c:\windows\system32\drivers\kl1.sys
2008-12-28 15:18 <DIR> --d----- c:\program files\Raxco
2008-12-27 23:11 72,704 a------- c:\windows\system32\atitapcw.dll
2008-12-27 23:11 1,755,117 ---sh--- c:\windows\system32\wcpatita.ini
2008-12-27 23:11 129,024 a------- c:\windows\system32\umkosk.dll
2008-12-27 23:11 129,024 a------- c:\windows\system32\cjmtwkrh.dll
==================== Find3M ====================
2009-01-26 16:32 1,647,668 a--sh--- c:\windows\system32\MnpAayay.ini2
2008-12-25 23:39 129,024 a------- c:\windows\system32\yxweegbo.dll
2008-12-25 23:39 129,024 a------- c:\windows\system32\afdvrq.dll
2008-12-24 00:45 129,024 a------- c:\windows\system32\rgatkubp.dll
2008-12-24 00:45 129,024 a------- c:\windows\system32\guocdb.dll
2008-12-22 10:20 72,704 a------- c:\windows\system32\kiqgsfiw.dll
2008-12-22 10:16 129,024 a------- c:\windows\system32\wmvkcu.dll
2008-12-22 10:16 129,024 a------- c:\windows\system32\gnjvorrs.dll
2008-12-22 01:49 129,024 a------- c:\windows\system32\rdkhnjjh.dll
2008-12-22 01:49 129,024 a------- c:\windows\system32\haaeom.dll
2008-12-15 10:45 129,024 a------- c:\windows\system32\gegptmux.dll
2008-12-15 10:45 129,024 a------- c:\windows\system32\cjswfp.dll
2008-12-14 00:30 129,024 a------- c:\windows\system32\tikiitkc.dll
2008-12-14 00:30 129,024 a------- c:\windows\system32\kbgssw.dll
2008-12-12 00:32 129,024 a------- c:\windows\system32\fkvlii.dll
2008-12-12 00:32 129,024 a------- c:\windows\system32\ehdgqkkj.dll
2008-12-05 01:40 114,688 a------- c:\windows\system32\rlwwviqp.dll
2008-12-05 01:40 114,688 a------- c:\windows\system32\jvtkew.dll
2008-11-27 03:00 72,704 a------- c:\windows\system32\ujqcfoyh.dll
2008-11-27 02:38 129,024 a------- c:\windows\system32\ohfgla.dll
2008-11-27 02:38 129,024 a------- c:\windows\system32\fpayhrqw.dll
2008-11-27 02:36 318,464 a------- c:\windows\system32\yayaApnM.dll
2008-11-27 02:31 25,600 a------- c:\windows\system32\ljJCvSiI.dll
2007-11-05 21:00 0 a------- c:\docume~1\hp_adm~1\applic~1\wklnhst.dat
============= FINISH: 16:35:55.98 ===============