So, here's a description of some of the symptoms of my infected computer. Personal Guard 2009 was mysteriously installed on my computer without my knowledge and it is impossible to remove it with traditional software removing techniques, such as the Add/Remove Programs feature. When I browse the internet with Firefox, Internet Explorer windows pop up but they don't show a web page. They are just blank. Of course, the traditional pop up windows that appear in Firefox come standard with all viruses. I have downloaded Malwarebytes and it is blocking it from running. There is a trick that I know by renaming the program to windows trusted name that will trick the virus into letting the renamed program run. That didn't work because even though I am a computer administrator, a message appeared stating that I do not have sufficient user privileges to run "winlogon" (which is what I renamed the program Malwarebytes to). Also, I am unable to start in Safe Mode and I am unable to run msconfig.
Attached is a Word document containing a list of viruses the CA Antivirus has detected and a HiJackThis Log too.
------------------------------------------------------------------------------------------------------------------------------------------
DDS (Ver_09-10-26.01) - NTFSx86
Run by ANTONIO at 21:21:20.14 on Sat 11/07/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.447.206 [GMT -5:00]
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\ANTONIO\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ANTONIO\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = cdn;*.local
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SansaDispatch] c:\documents and settings\antonio\application data\sandisk\sansa updater\SansaDispatch.exe
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [ddoctorv2] "c:\program files\comcast\desktop doctor\bin\sprtcmd.exe" /P ddoctorv2
mRun: [<NO NAME>]
mRun: [AlcxMonitor] ALCXMNTR.EXE
mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe"
mRun: [rukokuzek] Rundll32.exe "c:\windows\system32\buyenayo.dll",a
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\windows\system32\VetRedir.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
AppInit_DLLs: c:\windows\system32\divosewo.dll c:\windows\system32\tevupiru.dll jusiwona.dll c:\windows\system32\yoletepu.dll c:\windows\system32\rijavuza.dll c:\windows\system32\buyenayo.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: SysNet - {6915A590-F99F-42B3-820A-0C054A98B566} - c:\documents and settings\all users\microsoft adata\sysnet.dll
SSODL: surajukay - {46c31e69-ff17-48f9-85cd-042c1212c043} - c:\windows\system32\zulagovi.dll
SSODL: wipewopug - {530b2027-ffe4-4f00-ab25-f6dd0a827043} - c:\windows\system32\zulagovi.dll
SSODL: pewometog - {9b53e818-a438-4710-8e7c-139f6f174f4c} - c:\windows\system32\rijavuza.dll
SSODL: jalahomar - {4a05dd98-cbef-4353-84fc-450ba6f00546} - c:\windows\system32\zulagovi.dll
SSODL: juduvoraw - {f21b4160-1609-4ab9-bd42-f8c057563a1d} - c:\windows\system32\rijavuza.dll
SSODL: yububupom - {af23bfd0-2778-474b-8316-871e7b3124eb} - c:\windows\system32\rijavuza.dll
SSODL: wayisokad - {186e5ae6-6ea8-4b65-959b-8db534d06e55} - c:\windows\system32\rijavuza.dll
SSODL: vesujusoj - {ce06e379-a4e1-4112-984f-83b079033e5a} - c:\windows\system32\yemavema.dll
SSODL: jedehobor - {33cd6972-ffb4-4833-aa34-2bdf5645e414} - c:\windows\system32\zifubogu.dll
SSODL: pafafipaw - {be7c03cc-208e-4e68-994c-4fd6cb9997ab} - c:\windows\system32\buyenayo.dll
STS: kupuhivus: {46c31e69-ff17-48f9-85cd-042c1212c043} - c:\windows\system32\zulagovi.dll
STS: gahurihor: {530b2027-ffe4-4f00-ab25-f6dd0a827043} - c:\windows\system32\zulagovi.dll
STS: mujuzedij: {9b53e818-a438-4710-8e7c-139f6f174f4c} - c:\windows\system32\rijavuza.dll
STS: tokatiluy: {4a05dd98-cbef-4353-84fc-450ba6f00546} - c:\windows\system32\zulagovi.dll
STS: kupuhivus: {f21b4160-1609-4ab9-bd42-f8c057563a1d} - c:\windows\system32\rijavuza.dll
STS: kupuhivus: {af23bfd0-2778-474b-8316-871e7b3124eb} - c:\windows\system32\rijavuza.dll
STS: tokatiluy: {186e5ae6-6ea8-4b65-959b-8db534d06e55} - c:\windows\system32\rijavuza.dll
STS: mujuzedij: {ce06e379-a4e1-4112-984f-83b079033e5a} - c:\windows\system32\yemavema.dll
STS: mujuzedij: {33cd6972-ffb4-4833-aa34-2bdf5645e414} - c:\windows\system32\zifubogu.dll
STS: tokatiluy: {be7c03cc-208e-4e68-994c-4fd6cb9997ab} - c:\windows\system32\buyenayo.dll
LSA: Authentication Packages = msv1_0 nwprovau
LSA: Notification Packages = scecli zebekeli.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\antonio\applic~1\mozilla\firefox\profiles\y8ttptvj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-11-07 23:33:27 0 d-----w- c:\docume~1\antonio\applic~1\SanDisk
2009-11-07 23:10:40 0 d-----w- c:\documents and settings\antonio\Tracing
2009-11-07 22:49:26 0 d-----w- c:\program files\Microsoft
2009-11-07 22:47:10 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-07 22:36:49 0 d-----w- c:\program files\common files\Windows Live
2009-11-05 01:56:28 0 d-----w- c:\program files\Trend Micro
2009-10-31 04:44:50 51197 ----a-w- c:\windows\spoov.exe
2009-10-31 04:44:50 47872 ----a-w- c:\windows\certsystem.exe
2009-10-31 04:44:50 38352 ----a-w- c:\windows\regred.exe
2009-10-31 04:44:50 33149 ----a-w- c:\windows\usexplorer.exe
2009-10-31 04:44:50 28320 ----a-w- c:\windows\securits.com
2009-10-31 04:44:50 18941 ----a-w- c:\windows\microsoftdef.dll
2009-10-31 04:44:49 0 d-----w- c:\program files\Personal Guard 2009
2009-10-31 04:44:42 0 d-----w- c:\documents and settings\all users\Microsoft AData
==================== Find3M ====================
2009-11-01 14:44:52 739696 ----a-w- c:\windows\system32\drivers\vetefile.sys
2009-11-01 14:44:52 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-11-01 14:44:52 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2009-11-01 14:44:52 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2009-11-01 14:44:52 161008 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2009-11-01 14:44:52 133520 ----a-w- c:\windows\system32\drivers\veteboot.sys
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-05 00:48:27 37 ----a-w- c:\documents and settings\antonio\jagex_runescape_preferences.dat
2009-09-05 00:47:26 45 ----a-w- c:\documents and settings\antonio\jagex_runescape_preferences2.dat
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-07 15:53:12 90112 --sha-w- c:\windows\system32\buyenayo.dll
2009-08-01 14:38:35 38400 --sha-w- c:\windows\system32\gafilumu.dll
2009-08-03 13:20:13 38912 --sha-w- c:\windows\system32\hupabubi.dll
2009-08-05 13:30:08 38912 --sha-w- c:\windows\system32\jepafuzi.dll
2009-08-07 01:30:31 37888 --sha-w- c:\windows\system32\jepewosi.dll
2009-07-31 16:50:19 52224 --sha-w- c:\windows\system32\jusiwona.dll
2009-07-31 16:50:19 52224 --sha-w- c:\windows\system32\kohigewi.dll
2009-08-06 01:29:59 37888 --sha-w- c:\windows\system32\lobebafu.dll
2009-08-02 02:37:25 60928 --sha-w- c:\windows\system32\mabarili.dll
2009-08-04 20:22:43 38400 --sha-w- c:\windows\system32\muguvora.dll
2009-07-31 16:49:35 90624 --sha-w- c:\windows\system32\mulanaha.dll
2009-08-06 13:30:42 37888 --sha-w- c:\windows\system32\nasijuye.dll
2009-07-31 04:49:22 178688 --sha-w- c:\windows\system32\noyahopi.dll
2009-08-02 20:27:51 37888 --sha-w- c:\windows\system32\pafiloha.dll
2009-08-07 15:53:13 37888 --sha-w- c:\windows\system32\pasagami.dll
2009-07-31 16:49:35 52224 --sha-w- c:\windows\system32\raramuge.dll
2009-08-02 02:37:25 37888 --sha-w- c:\windows\system32\tobuhifo.dll
2009-07-31 04:49:22 96768 --sha-w- c:\windows\system32\vuzejofu.dll
2009-08-04 02:07:07 37888 --sha-w- c:\windows\system32\yosimanu.dll
2009-07-31 16:50:19 52224 --sha-w- c:\windows\system32\zebekeli.dll
2009-08-07 01:30:31 89600 --sha-w- c:\windows\system32\zifubogu.dll
2009-08-04 02:07:07 89600 --sha-w- c:\windows\system32\zulagovi.dll
2009-06-18 21:14:28 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009061820090619\index.dat
============= FINISH: 21:26:11.95 ===============