I hope this note finds you and yours well.
Issues-- my AVG picked up 66 instances of Win32/Cryptor which were unable to be healed and removed. My system doesn't seem to be running slowly or anything but obviously I have a problem that needs to be removed. I haven't changed any of my passwords yet.
As instructed in the tutorial, I am pasting the DDS results below as well as attaching them.
Thanks in advance for any help!
With best regards,
Jim
DDS (Ver_09-06-26.01) - FAT32x86
Run by Jack at 10:11:41.35 on Mon 07/27/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.254.62 [GMT -7:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
SVCHOST.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
SVCHOST.EXE
SVCHOST.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Jack\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\eFax Messenger 4.3\J2GTray.exe
SVCHOST.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Subliminal Blaster 2.0\subliminalblaster.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\Documents and Settings\Jack\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Google Update] "c:\documents and settings\jack\local settings\application data\google\update\GoogleUpdate.exe" /c
uRunOnce: [SpybotDeletingB5748] command /c del "c:\windows\system32\drivers\hjgruintqxqupu.sys"
uRunOnce: [SpybotDeletingD3277] cmd /c del "c:\windows\system32\drivers\hjgruintqxqupu.sys"
uRunOnce: [SpybotDeletingB9855] command /c del "c:\windows\system32\hjgruidnksbrwl.dll"
uRunOnce: [SpybotDeletingD2970] cmd /c del "c:\windows\system32\hjgruidnksbrwl.dll"
uRunOnce: [SpybotDeletingB8649] command /c del "c:\windows\system32\hjgruinkfxwvkl.dll"
uRunOnce: [SpybotDeletingD8627] cmd /c del "c:\windows\system32\hjgruinkfxwvkl.dll"
uRunOnce: [SpybotDeletingB5373] command /c del "c:\windows\temp\hjgruioqoiiwtqxt.tmp"
uRunOnce: [SpybotDeletingD5729] cmd /c del "c:\windows\temp\hjgruioqoiiwtqxt.tmp"
uRunOnce: [SpybotDeletingB2699] command /c del "c:\windows\temp\hjgruicshfnxmbjf.tmp"
uRunOnce: [SpybotDeletingD1932] cmd /c del "c:\windows\temp\hjgruicshfnxmbjf.tmp"
uRunOnce: [SpybotDeletingB622] command /c del "c:\windows\system32\hjgruioabshgqn.dat"
uRunOnce: [SpybotDeletingD340] cmd /c del "c:\windows\system32\hjgruioabshgqn.dat"
uRunOnce: [SpybotDeletingB886] command /c del "c:\windows\system32\hjgruiuounpmow.dat"
uRunOnce: [SpybotDeletingD594] cmd /c del "c:\windows\system32\hjgruiuounpmow.dat"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRunOnce: [SpybotDeletingA5222] command /c del "c:\windows\system32\drivers\hjgruintqxqupu.sys"
mRunOnce: [SpybotDeletingC7843] cmd /c del "c:\windows\system32\drivers\hjgruintqxqupu.sys"
mRunOnce: [SpybotDeletingA8450] command /c del "c:\windows\system32\hjgruidnksbrwl.dll"
mRunOnce: [SpybotDeletingC8125] cmd /c del "c:\windows\system32\hjgruidnksbrwl.dll"
mRunOnce: [SpybotDeletingA6751] command /c del "c:\windows\system32\hjgruinkfxwvkl.dll"
mRunOnce: [SpybotDeletingC2965] cmd /c del "c:\windows\system32\hjgruinkfxwvkl.dll"
mRunOnce: [SpybotDeletingA2395] command /c del "c:\windows\temp\hjgruioqoiiwtqxt.tmp"
mRunOnce: [SpybotDeletingC1362] cmd /c del "c:\windows\temp\hjgruioqoiiwtqxt.tmp"
mRunOnce: [SpybotDeletingA9485] command /c del "c:\windows\temp\hjgruicshfnxmbjf.tmp"
mRunOnce: [SpybotDeletingC2483] cmd /c del "c:\windows\temp\hjgruicshfnxmbjf.tmp"
mRunOnce: [SpybotDeletingA8559] command /c del "c:\windows\system32\hjgruioabshgqn.dat"
mRunOnce: [SpybotDeletingC6712] cmd /c del "c:\windows\system32\hjgruioabshgqn.dat"
mRunOnce: [SpybotDeletingA3943] command /c del "c:\windows\system32\hjgruiuounpmow.dat"
mRunOnce: [SpybotDeletingC9679] cmd /c del "c:\windows\system32\hjgruiuounpmow.dat"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\efax43~1.lnk - c:\program files\efax messenger 4.3\J2GTray.exe
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {00000075-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxacm.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171324097977
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://sdlc-esd.sun.com/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?AuthParam=1212358168_c672e00787d51d51d4a28abbfbc4bb21&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab&File=jinstall-6u6-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jack\applic~1\mozilla\firefox\profiles\jjhpnzok.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
============= SERVICES / DRIVERS ===============
R0 lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-10 64160]
R1 avgldx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-7-9 335752]
R1 avgmfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-7-9 27784]
R1 avgtdix;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-7-9 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-9 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-9 298776]
R2 lavasoft ad-aware service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
S1 9fdfaef;9fdfaef;c:\windows\system32\drivers\9fdfaef.sys [2009-7-8 65536]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-1-27 33752]
S3 nv3;nv3;c:\windows\system32\drivers\nv3.sys [2007-1-10 198144]
=============== Created Last 30 ================
2009-07-18 14:18 90,112 a------- c:\windows\DUMP6b07.tmp
2009-07-18 14:18 90,112 a------- c:\windows\DUMP6655.tmp
2009-07-18 14:18 90,112 a------- c:\windows\DUMP62b2.tmp
2009-07-18 14:17 <DIR> --dsh--- C:\FOUND.085
2009-07-16 19:43 686 a------- c:\windows\wininit.ini
2009-07-15 11:40 <DIR> --d----- c:\windows\system32\lowsec
2009-07-13 17:59 54,156 a---h--- c:\windows\QTFont.qfn
2009-07-13 17:59 1,409 a------- c:\windows\QTFont.for
2009-07-10 10:27 15,688 a------- c:\windows\system32\lsdelete.exe
2009-07-10 10:12 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-07-10 10:10 <DIR> --d-h--- c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-09 17:43 <DIR> --d-h--- C:\$AVG8.VAULT$
2009-07-09 16:05 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-07-09 16:05 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-07-09 16:05 335,752 a------- c:\windows\system32\drivers\avgldx86.sys
2009-07-09 16:05 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-07-08 21:32 65,536 a------- c:\windows\system32\drivers\9fdfaef.sys
2009-07-08 21:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\93816276
2009-07-08 21:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\13806284
2009-07-08 21:31 2 a------- C:\943724550
==================== Find3M ====================
2009-07-17 23:21 251,658,240 a------- c:\windows\DUMP704f.tmp
2009-07-16 10:28 90,112 a------- c:\windows\DUMP8dce.tmp
2009-07-15 12:34 90,112 a------- c:\windows\DUMP6687.tmp
2009-07-13 15:34 90,112 a------- c:\windows\DUMP66f5.tmp
2009-07-10 10:14 90,112 a------- c:\windows\DUMP6077.tmp
2009-07-09 09:26 90,112 a------- c:\windows\DUMP41e0.tmp
2009-07-08 21:40 90,112 a------- c:\windows\DUMP3c7a.tmp
2009-06-24 16:53 48,640 a------- C:\dse.exe
2009-05-07 08:32 345,600 a------- c:\windows\system32\localspl.dll
2009-05-07 08:32 345,600 -------- c:\windows\system32\dllcache\localspl.dll
2009-04-28 21:56 827,392 a------- c:\windows\system32\wininet.dll
2009-04-28 21:56 44,544 a------- c:\windows\system32\dllcache\pngfilt.dll
2009-04-28 21:56 1,159,680 -------- c:\windows\system32\dllcache\urlmon.dll
2009-04-28 21:56 827,392 -------- c:\windows\system32\dllcache\wininet.dll
2009-04-28 21:56 671,232 -------- c:\windows\system32\dllcache\mstime.dll
2009-04-28 21:56 233,472 -------- c:\windows\system32\dllcache\webcheck.dll
2009-04-28 21:56 105,984 -------- c:\windows\system32\dllcache\url.dll
2009-04-28 21:56 102,912 -------- c:\windows\system32\dllcache\occache.dll
2009-04-28 21:56 3,596,288 -------- c:\windows\system32\dllcache\mshtml.dll
2009-04-28 21:56 477,696 -------- c:\windows\system32\dllcache\mshtmled.dll
2009-04-28 21:56 193,024 -------- c:\windows\system32\dllcache\msrating.dll
2007-01-10 17:11 266 ---sh--- c:\program files\desktop.ini
2007-01-10 17:11 11,079 ----h--- c:\program files\folder.htt
2008-12-17 17:29 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008121720081218\index.dat
============= FINISH: 10:14:51.64 ===============