I recently got infected with win32:falder[trj]. Every few minutes my anti virus software (Avast) detects it but I can't remove it. I select DELETE but it keeps coming back. Also, my internet is opening pages from weird sites. And, Script Blocker pops up every time I open a web page.
My computer is running much slower now and for some reason, it has disabled "Windows Automatic Updates" and it won't allow me to enable it. When I go to windows security center and click on "Turn on automatic updates", nothing happens.
If you can help me with this problem, I would really appreciate it.
Here are the reports from DDS:
DDS (Ver_09-03-16.01) - NTFSx86
Run by Carol & Robert at 16:52:56.68 on Mon 04/06/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_12
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.512.158 [GMT -4:00]
AV: avast! antivirus 4.8.1335 [VPS 090406-0] *On-access scanning disabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\CAROL&~1\LOCALS~1\Temp\t87i6fn7.exe
C:\DOCUME~1\CAROL&~1\LOCALS~1\Temp\t87i6fn7.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\DOCUME~1\CAROL&~1\LOCALS~1\Temp\t87i6fn7.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Carol & Robert\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: {392ea4bb-b224-4474-8e1b-633d65b84b1d} - c:\windows\system32\opnmMeFx.dll
BHO: {885502ce-3c63-56da-e6f4-bc99f3905d94}: {49d5093f-99cb-4f6e-ad65-36c3ec205588} - c:\windows\system32\lmrfsh.dll
BHO: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\jkkKbXom.dll
BHO: c:\windows\system32\hsf73ikmdf3f.dll: {b2ba40a2-74f3-42bd-f434-2604812c8954} - c:\windows\system32\hsf73ikmdf3f.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [<NO NAME>] c:\docume~1\carol&~1\locals~1\temp\t87i6fn7.exe
uRun: [Windows Resurections] c:\docume~1\carol&~1\locals~1\temp\t87i6fn7.exe
mRun: [USRpdA] c:\windows\system32\usrmlnka.exe runservices \device\3cpipe-USRpdA
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [<NO NAME>]
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [88226d7a] rundll32.exe "c:\windows\system32\swfgrljy.dll",b
StartupFolder: c:\docume~1\carol&~1\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1231185238339
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231186212163
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab56649.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} - hxxp://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab
Notify: Antiwpa - antiwpa.dll
Notify: jkkKbXom - jkkKbXom.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: c:\windows\system32\hsf73ikmdf3f.dll: {b2ba40a2-74f3-42bd-f434-2604812c8954} - c:\windows\system32\hsf73ikmdf3f.dll
SEH: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\jkkKbXom.dll
SEH: {2f252b77-d86c-5f38-34e4-9d18ca76090f}: {f09067ac-81d9-4e43-83f5-c68d77b252f2} - c:\windows\system32\lmrfsh.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\opnmMeFx
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\carol&~1\applic~1\mozilla\firefox\profiles\gjvrsdkx.default\
FF - prefs.js: browser.startup.homepage - www.msn.com
FF - plugin: c:\documents and settings\carol & robert\application data\mozilla\plugins\npPxPlay.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-5 114768]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};c:\program files\cyberlink\powerdvd\000.fcl [2008-1-30 41456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-13 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-1-5 138680]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-1-5 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-1-5 352920]
=============== Created Last 30 ================
2009-04-06 16:41 <DIR> --d----- c:\program files\Trend Micro
2009-04-06 08:57 99,328 a------- c:\windows\system32\pareigmm.dll
2009-04-06 08:57 99,328 a------- c:\windows\system32\lmrfsh.dll
2009-04-06 08:56 1,389,977 ---sh--- c:\windows\system32\yjlrgfws.ini
2009-04-06 08:56 75,264 a------- c:\windows\system32\swfgrljy.dll
2009-04-06 08:54 7,603 a--sh--- c:\windows\system32\xFeMmnpo.ini2
2009-04-06 08:54 7,603 a--sh--- c:\windows\system32\xFeMmnpo.ini
2009-04-06 08:54 237,056 a------- c:\windows\system32\opnmMeFx.dll
2009-04-06 08:45 15,000 a------- c:\windows\system32\hsf73ikmdf3f.dll
2009-04-06 08:39 <DIR> --d----- c:\program files\Lavasoft
2009-04-06 08:39 35,840 a------- c:\windows\system32\jkkKbXom.dll
2009-04-05 13:44 <DIR> --d----- c:\docume~1\carol&~1\applic~1\PC-FAX TX
2009-03-31 09:02 <DIR> --d----- c:\program files\MSXML 4.0
2009-03-30 17:55 <DIR> --d--r-- c:\docume~1\carol&~1\applic~1\Brother
2009-03-30 17:47 818 a------- c:\windows\Brpfx04a.ini
2009-03-30 17:47 153 a------- c:\windows\brpcfx.ini
2009-03-30 17:47 419 a------- c:\windows\BRWMARK.INI
2009-03-30 17:47 27 a------- c:\windows\BRPP2KA.INI
2009-03-30 17:46 25,856 ac------ c:\windows\system32\dllcache\usbprint.sys
2009-03-30 17:46 25,856 a------- c:\windows\system32\drivers\usbprint.sys
2009-03-30 17:46 32,128 ac------ c:\windows\system32\dllcache\usbccgp.sys
2009-03-30 17:46 32,128 a------- c:\windows\system32\drivers\usbccgp.sys
2009-03-30 17:40 176,128 -------- c:\windows\system32\BroSNMP.dll
2009-03-30 17:40 73,728 -------- c:\windows\system32\BrDctF2.dll
2009-03-30 17:40 5,120 -------- c:\windows\system32\BrDctF2L.dll
2009-03-30 17:40 3,072 -------- c:\windows\system32\BrDctF2S.dll
2009-03-30 17:40 167,936 -------- c:\windows\system32\NSSearch.dll
2009-03-30 17:40 <DIR> --d----- c:\program files\Brother
2009-03-30 17:38 <DIR> --d----- c:\program files\Nuance
2009-03-30 17:37 31,567 a------- c:\windows\maxlink.ini
2009-03-30 17:36 <DIR> --d----- c:\program files\common files\ScanSoft Shared
2009-03-30 17:36 <DIR> --d----- c:\program files\ScanSoft
2009-03-30 17:35 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Brother
2009-03-29 16:06 <DIR> --d----- c:\docume~1\alluse~1\applic~1\vsosdk
2009-03-29 10:04 87,608 a------- c:\docume~1\carol&~1\applic~1\inst.exe
2009-03-29 10:04 47,360 a------- c:\windows\system32\drivers\pcouffin.sys
2009-03-29 10:04 47,360 a------- c:\docume~1\carol&~1\applic~1\pcouffin.sys
2009-03-29 10:04 217,127 a------- c:\windows\system32\drv43260.dll
2009-03-29 10:04 208,935 a------- c:\windows\system32\drv33260.dll
2009-03-29 10:04 176,165 a------- c:\windows\system32\drv23260.dll
2009-03-29 10:04 102,439 a------- c:\windows\system32\sipr3260.dll
2009-03-29 10:04 65,602 a------- c:\windows\system32\cook3260.dll
2009-03-29 10:04 626,688 a------- c:\windows\system32\vp7vfw.dll
2009-03-29 10:04 1,184,984 a------- c:\windows\system32\wvc1dmod.dll
2009-03-29 10:04 <DIR> --d----- c:\program files\VSO
2009-03-14 17:12 <DIR> --d----- c:\windows\Dream Day Wedding - Married in Manhattan
2009-03-14 17:12 <DIR> --d----- c:\program files\Dream Day Wedding - Married in Manhattan
2009-03-13 06:24 73,728 a------- c:\windows\system32\javacpl.cpl
2009-03-12 11:04 354 a------- c:\windows\system32\hpguapi.ini
2009-03-11 19:51 221,184 a------- c:\windows\system32\wmpns.dll
==================== Find3M ====================
2009-03-13 06:24 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-09 07:13 1,846,784 a------- c:\windows\system32\win32k.sys
2001-08-23 08:00 94,784 ---sh--- c:\windows\twain.dll
2008-04-13 20:12 50,688 ---sh--- c:\windows\twain_32.dll
2008-04-13 20:11 1,028,096 ---sh--- c:\windows\system32\mfc42.dll
2008-04-13 20:12 57,344 ---sh--- c:\windows\system32\msvcirt.dll
2008-04-13 20:12 413,696 ---sh--- c:\windows\system32\msvcp60.dll
2008-04-13 20:12 343,040 ---sh--- c:\windows\system32\msvcrt.dll
2008-04-13 20:12 551,936 ---sh--- c:\windows\system32\oleaut32.dll
2008-04-13 20:12 84,992 ---sh--- c:\windows\system32\olepro32.dll
2008-04-13 20:12 11,776 ---sh--- c:\windows\system32\regsvr32.exe
============= FINISH: 16:54:07.58 ===============