I had a pretty standard malware attack. Desktop background changed to image saying I was infected (attached). Some processes were set to run on startup, and a system tray icon of a red circle with a white "X" in it showed up. On startup, the malware would start and run a "system scan" looking for infections. Typically I would rightclick on the APP in the windows toolbar and close the application before it could scan too much. This would still leave the icon in the system tray, which would have a pop-up every few seconds telling me I was infected.
The malware disabled the taskmanager, which is extra annoying. I installed HJT and spybot search-and-destroy. I couldn't see anything obvious in the HJT scan, but the Spybot search took care of the problem.
Apparently, the malware (or possibly another user on this computer, but I doubt it) disabled the firewall, and the the malware was back in similar fashion. The Spybot search this time took care of the system tray icon and the application from running on startup, but the background is still locked so I would like to get rid of the rest of this problem.
Any information on this would be helpful. From what I can see, the C:\WINDOWS\system32\sdra64.exe file looks particularly suspicious, and I would normally start with getting rid of this, but if I can do it all in one clean with some help I would prefer this.
Thanks in advance!
joe
DDS (Ver_09-07-30.01) - NTFSx86
Run by Joe Jalbert at 19:25:17.40 on Mon 09/07/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_05
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.210 [GMT -4:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\CloneCD\CloneCDTray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\myView Media Manager\winserver\myViewMediaManager.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\Program Files\myView Media Manager\winserver\myViewMMUPnPrespd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\myView Media Manager\winserver\myViewMMApache.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\myView Media Manager\winserver\myViewMMApache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Downloads\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Shell=Explorer.exe logon.exe
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"
mRun: [CloneCDElbyCDFL] "c:\program files\clonecd\ElbyCheck.exe" /L ElbyCDFL
mRun: [CloneCDTray] "c:\program files\clonecd\CloneCDTray.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [winupdate.exe] c:\windows\system32\winupdate.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\myview~1.lnk - c:\program files\myview media manager\winserver\p.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172752942789
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\joejal~1\applic~1\mozilla\firefox\profiles\472pax13.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 ElbyVCD;ElbyVCD;c:\windows\system32\drivers\ElbyVCD.sys [2002-11-28 22016]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-23 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-3-11 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-23 108552]
R1 CBUL32;Measurement Computing DataAcq;c:\windows\system32\drivers\CBUL32.sys [2006-12-1 53920]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-8-22 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-4 297752]
R3 crtaud;Conexant Riptide WDM Audio Driver;c:\windows\system32\drivers\crtaud.sys [2007-10-9 42112]
R3 rpfun;Conexant Riptide Dummy Driver;c:\windows\system32\drivers\rpfun.sys [2007-10-9 3840]
R3 rthwcls;Conexant Riptide Bus / Firmware Downloader;c:\windows\system32\drivers\rthwcls.sys [2007-10-9 30720]
S0 rmof13d;rmof13d;\SystemRoot\\SystemRoot\System32\drivers\rmof13d.sys --> \SystemRoot\\SystemRoot\System32\drivers\rmof13d.sys [?]
S1 3cea1bb8.sys;3cea1bb8.sys;\??\c:\windows\system32\drivers\3cea1bb8.sys --> c:\windows\system32\drivers\3cea1bb8.sys [?]
S1 665ee5d5.sys;665ee5d5.sys;\??\c:\windows\system32\drivers\665ee5d5.sys --> c:\windows\system32\drivers\665ee5d5.sys [?]
S1 lnp8787;lnp8787;c:\windows\system32\drivers\lnp8787.sys [2009-8-31 45344]
S3 nk_bus;Nokia USB Bus Service;c:\windows\system32\drivers\nk_bus.sys [2007-8-10 22144]
=============== Created Last 30 ================
2009-09-07 01:37 45,344 a------- c:\windows\system32\drivers\tibc90c.sys
2009-09-07 01:37 25,088 a------- c:\windows\system32\tapi.nfo
2009-09-05 10:40 0 a------- c:\windows\system32\18467.exe
2009-09-05 09:40 0 a------- c:\windows\system32\41.exe
2009-09-05 09:39 20,992 a------- c:\windows\system32\winhelper.dll
2009-08-31 21:28 45,344 a------- c:\windows\system32\drivers\lnp8787.sys
2009-08-26 21:34 45,344 a------- c:\windows\system32\drivers\rmof13d.sys
2009-08-25 00:06 <DIR> --d----- c:\docume~1\alluse~1\applic~1\10876154
2009-08-23 21:48 230 a------- c:\windows\wininit.ini
2009-08-23 21:13 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-08-23 21:13 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-08-23 20:42 831 a------- c:\windows\system32\critical_warning.html
2009-08-23 20:41 28,164 a------- c:\windows\system32\logon.exe
2009-08-16 03:30 1,089,593 -c------ c:\windows\system32\dllcache\ntprint.cat
2009-08-15 18:48 <DIR> --d----- c:\windows\system32\XPSViewer
2009-08-15 18:47 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 18:47 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 18:47 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 18:47 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-08-15 18:47 117,760 -------- c:\windows\system32\prntvpt.dll
2009-08-15 18:47 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 18:47 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-08-12 23:51 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2009-08-12 23:51 1,315,328 -c------ c:\windows\system32\dllcache\msoe.dll
==================== Find3M ====================
2009-08-22 13:59 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-08-22 13:57 335,240 a------- c:\windows\system32\drivers\avgldx86.sys
2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a------- c:\windows\system32\wmpdxm.dll
2009-06-29 12:12 827,392 a------- c:\windows\system32\wininet.dll
2009-06-29 12:12 78,336 a------- c:\windows\system32\ieencode.dll
2009-06-29 12:12 17,408 -------- c:\windows\system32\corpol.dll
2009-06-16 10:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-12 08:31 80,896 a------- c:\windows\system32\tlntsess.exe
2009-06-12 08:31 76,288 a------- c:\windows\system32\telnet.exe
2009-06-10 10:13 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 09:19 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 02:14 132,096 a------- c:\windows\system32\wkssvc.dll
2009-03-02 04:07 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009030220090303\index.dat
============= FINISH: 19:28:09.53 ===============