Worm:Win32/Vundo.B
Trojan:Java/Selace.A
Trojan:Win32/Malagent
Exploit:Java/CVE-2008-5353.B
Trojan:Java/Selace.B
Trojan:Win32/Vundo.gen!G
Trojan:Win32/FakeSpyguard
Trojan:Win32/Vundo.MD
I'm assuming a virus is regenerating itself on start-up. I'm hoping you can help me bring this machine back to full health and then outline the steps to keep it safe & secure in the future.
Another issue I should mention. I planned on using some of the anti-malware software in Safe mode. Seemed like the thing to do when consulting other advice on dealing with infections. When booting up, I get to the screen where I select Safe Mode but when I hit enter it reboots the system again. Bottomline is that I can't get it into Safe mode. I can only get the computer to come up when starting Windows normally. Another symptom of my computer's ills?
DDS (Ver_09-12-01.01) - NTFSx86
Run by Administrator at 15:41:23.12 on Sun 12/13/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.112 [GMT -5:00]
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.rr.com/
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
Trusted Zone: excite.com\www
Trusted Zone: rr.com\activation
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://activation.rr.com/install/download/tgctlcm.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {64D01C7F-810D-446E-A07E-365764235644} - hxxp://kraisoft.com/files/realone/atomaders.cab
DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} - hxxp://www.christianrock2.net/amp3dj.cab
DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - hxxp://mediaplayer.walmart.com/installer/install.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} - hxxp://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_02-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: ackpbsc - c:\windows\system32\ackpbsc.dll
Notify: acunlock - c:\program files\actividentity\activclient\acunlock.dll
AppInit_DLLs: c:\windows\system32\sumonibe.dll c:\windows\system32\wezewugi.dll c:\windows\system32\jokilake.dll c:\windows\system32\fokivilo.dll c:\windows\system32\buhedina.dll c:\windows\system32\bupudofa.dll c:\windows\system32\kemuboti.dll c:\windows\system32\fekabota.dll c:\windows\system32\lolanayo.dll c:\windows\system32\gitadumi.dll c:\windows\system32\kilatape.dll,luruwono.dll
SSODL: wunusabew - {0a219e12-5f0e-4bae-8d94-9e096a5f1ceb} - No File
SSODL: nideloyop - {fb1bd32b-5782-4d31-81c9-a3f8b0abdeb1} - No File
SSODL: rufudasaf - {0364757b-39f0-4562-ba1a-49cf60b9e5c7} - No File
STS: {0a219e12-5f0e-4bae-8d94-9e096a5f1ceb} - No File
STS: {fb1bd32b-5782-4d31-81c9-a3f8b0abdeb1} - No File
STS: {0364757b-39f0-4562-ba1a-49cf60b9e5c7} - No File
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli zotemiso.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\pjr79dpq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.rr.com/flash/index.cfm
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.zencast -
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-11-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-11-23 74480]
R3 atifglrx;atifglrx;c:\windows\system32\drivers\fglrxm.sys [2002-11-11 417029]
S1 mnbseyzl;mnbseyzl;\??\c:\windows\system32\drivers\mnbseyzl.sys --> c:\windows\system32\drivers\mnbseyzl.sys [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-11-23 7408]
S3 SCR131C;SCRx31 Serial Smart Card Reader;c:\windows\system32\drivers\SCR131C.sys [2002-11-7 181875]
S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader;c:\windows\system32\drivers\SCR33X2K.sys [2004-4-6 64088]
S4 accoca;ActivClient Middleware Service;c:\program files\actividentity\activclient\accoca.exe [2007-5-3 182576]
S4 FGLRXUtil;FGLRXUTIL;c:\windows\system32\frxhser.exe [2002-11-11 53248]
S4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-1-23 92296]
=============== Created Last 30 ================
2009-12-02 05:47:27 0 d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-12-01 19:02:13 8192 --sha-w- c:\windows\Thumbs.db
2009-12-01 19:01:52 5632 --sha-w- c:\documents and settings\administrator\Thumbs.db
2009-11-30 20:38:39 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-11-30 20:38:39 215920 ----a-w- c:\windows\system32\muweb.dll
2009-11-30 20:38:39 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2009-11-29 01:01:44 0 d-----w- c:\program files\Defraggler
2009-11-29 00:47:04 0 d-----w- c:\program files\Foxit Software
2009-11-29 00:47:04 0 d-----w- c:\docume~1\admini~1\applic~1\Foxit
2009-11-29 00:45:09 0 d-----w- c:\program files\VS Revo Group
2009-11-28 23:36:02 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-28 23:33:41 0 d-----w- c:\program files\Microsoft Security Essentials
2009-11-28 23:28:07 0 d-----w- c:\program files\CCleaner
2009-11-28 20:59:06 0 d-----w- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-11-28 20:58:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-28 20:58:58 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-28 20:58:58 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-11-28 20:58:57 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-28 20:12:38 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-11-28 20:12:21 0 d-----w- c:\program files\SUPERAntiSpyware
2009-11-28 20:12:21 0 d-----w- c:\docume~1\admini~1\applic~1\SUPERAntiSpyware.com
2009-11-28 20:11:32 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-11-28 18:41:27 266360 ----a-w- c:\windows\system32\TweakUI.exe
2009-11-28 18:41:27 160217 ----a-w- c:\windows\system32\PowerToysLicense.rtf
==================== Find3M ====================
2009-12-13 20:28:03 5632 -csha-w- c:\program files\Thumbs.db
2009-10-29 07:45:38 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20:16 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30:16 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-09-29 18:07:01 34224 ---ha-w- c:\windows\system32\mlfcache.dat
2008-09-14 15:59:25 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091420080915\index.dat
============= FINISH: 15:42:35.23 ===============