Hi,
It appears that one of our home computers has been infected with troj_agent.inc, based on both the anti-virus software messages and some anecdotal evidence (unwanted processes running that match virus descriptions, viral entries in the registry that immediately reappear even after manual removing with regedit, etc.).
The PC is running Windows XP, SP2. When my kids called to report the problem, I immediately had them disconnect from the internet, and it has not been reconnected since.
Below is the DDS log, and the zipped attach.txt file is attached.
Any help or suggestions you can offer would be greatly appreciated.
Thanks,
DDS (Ver_09-03-16.01) - NTFSx86
Run by at 9:23:03.17 on Fri 05/01/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.151 [GMT -5:00]
AV: Trend Micro PC-cillin Internet Security *On-access scanning enabled* (Outdated)
FW: Trend Micro PC-cillin Internet Security (Firewall) *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Michael\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
uDefault_Page_URL = hxxp://www.dell4me.com/myway
mDefault_Page_URL = hxxp://www.dell4me.com/myway
mStart Page = hxxp://www.dell4me.com/myway
uURLSearchHooks: N/A: {4d25f926-b9fe-4682-bf72-8ab8210d6d75} - c:\program files\mywaysa\srchasde\deSrcAs.dll
uURLSearchHooks: N/A: {00a6faf6-072e-44cf-8957-5838f569a31d} - c:\program files\mywebsearch\bar\2.bin\MWSSRCAS.DLL
BHO: {a0ba6929-aea3-4656-af01-65bdeaebee59} - c:\windows\system32\wegaloru.dll
BHO: c:\windows\system32\sjg9s8guigjs.dll: {b2ba40a2-74f0-42bd-f434-12345a2c8953} - c:\windows\system32\sjg9s8guigjs.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [OE_OEM] "c:\program files\trend micro\internet security 12\tmas_oe\TMAS_OEMon.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [DellTransferAgent] "c:\documents and settings\all users\application data\dell\transferagent\TransferAgent.exe"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [MimBoot] c:\progra~1\musicm~1\musicm~3\mimboot.exe
mRun: [MMTray] "c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe"
mRun: [pccguide.exe] "c:\program files\trend micro\internet security 12\pccguide.exe"
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [sysldtray] c:\windows\ld08.exe
mRun: [Ywujuy] rundll32.exe "c:\windows\Hmiqasaxoga.dll",e
mRun: [niralekozi] Rundll32.exe "c:\windows\system32\lopibeki.dll",s
mRun: [CPM33b1c5d6] Rundll32.exe "c:\windows\system32\delutaha.dll",a
mRun: [3082f64a] rundll32.exe "c:\windows\system32\veyetidi.dll",b
mRun: [Nxecoludosayerox] rundll32.exe "c:\windows\aqipuveb.dll",e
StartupFolder: c:\docume~1\michael\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.0\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\dell wireless\PRISMCFG.exe
IE: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_Print.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: turbotax.com
Trusted Zone: musicmatch.com\online
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\suhaleti.dll c:\windows\system32\yanadeya.dll c:\windows\system32\delutaha.dll
SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\delutaha.dll
STS: c:\windows\system32\sjg9s8guigjs.dll: {b2ba40a2-74f0-42bd-f434-12345a2c8953} - c:\windows\system32\sjg9s8guigjs.dll
STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\delutaha.dll
LSA: Notification Packages = scecli c:\windows\system32\yanadeya.dll
================= FIREFOX ===================
FF - ProfilePath -
FF - HiddenExtension: XUL Cache: {68A63756-BEDA-4B8F-AC7F-6854F52A55EC} - c:\documents and settings\nicole\local settings\application data\{68A63756-BEDA-4B8F-AC7F-6854F52A55EC}
FF - HiddenExtension: XUL Cache: {32D5DCC0-A54B-4E73-8EAB-9BBF0B158C16} - c:\documents and settings\michael\local settings\application data\{32D5DCC0-A54B-4E73-8EAB-9BBF0B158C16}
FF - HiddenExtension: XUL Cache: {BC077293-0BC0-45CA-8591-EB4729FD131E} - c:\documents and settings\holly\local settings\application data\{BC077293-0BC0-45CA-8591-EB4729FD131E}
FF - HiddenExtension: XUL Cache: {06B21EA1-8F31-4C05-BC25-FCD24A946ECC} - c:\documents and settings\larissa\local settings\application data\{06b21ea1-8f31-4c05-bc25-fcd24a946ecc}\
============= SERVICES / DRIVERS ===============
R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Tmfilter;Tmfilter;c:\windows\system32\drivers\tmxpflt.sys [2005-8-30 205328]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\trendm~1\intern~1\Tmntsrv.exe [2005-8-30 290889]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2005-8-30 585792]
R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2005-8-30 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\trendm~1\intern~1\tmproxy.exe [2005-8-30 262215]
S2 FCI;FCI;c:\windows\system32\svchost.exe:ext.exe --> c:\windows\system32\svchost.exe:ext.exe [?]
S2 MyWebSearchService;My Web Search Service;c:\progra~1\mywebs~1\bar\2.bin\mwssvc.exe [2009-4-29 28762]
S4 PRISMSVC;PRISMSVC;c:\windows\system32\PRISMSVC.exe [2006-5-7 57344]
=============== Created Last 30 ================
2009-05-01 07:03 <DIR> --d----- c:\windows\SxsCaPendDel
2009-05-01 06:59 <DIR> --d----- c:\windows\system32\appmgmt
2009-04-30 18:41 1 ----h--- c:\windows\f23567.dat
2009-04-30 18:41 34,304 ----h--- c:\windows\freddy41.exe
2009-04-30 18:41 2 ----h--- c:\windows\t55ft2667f44.dat
2009-04-30 16:41 1 a------- c:\windows\9g2234wesdf3dfgjf23
2009-04-30 16:41 10,752 ----h--- c:\windows\pp06.exe
2009-04-30 16:41 2 ----h--- c:\windows\t55ft2692f44.dat
2009-04-30 16:40 14,848 a------- c:\windows\system32\DL32.exe
2009-04-30 16:40 <DIR> --d----- c:\windows\system32\796525
2009-04-30 16:40 0 a------- c:\windows\mqcd.dbt
2009-04-30 16:40 16,384 ----h--- c:\windows\ld08.exe
2009-04-30 04:39 1,407,011 ---sh--- c:\windows\system32\iditeyev.ini
2009-04-27 04:16 1,407,011 ---sh--- c:\windows\system32\isehohel.ini
2009-04-26 16:15 9,216 a------- c:\windows\instsp2.exe
2009-04-20 14:06 146,944 a------- c:\windows\ejibaqey.dll
2009-04-16 21:26 399,360 -------- c:\windows\system32\dllcache\rpcss.dll
2009-04-16 21:26 283,648 -------- c:\windows\system32\dllcache\pdh.dll
2009-04-16 21:26 110,592 -------- c:\windows\system32\dllcache\services.exe
2009-04-16 21:26 60,416 -------- c:\windows\system32\dllcache\colbact.dll
2009-04-16 21:26 35,328 -------- c:\windows\system32\dllcache\sc.exe
2009-04-16 21:26 473,088 -------- c:\windows\system32\dllcache\fastprox.dll
2009-04-16 21:26 453,120 -------- c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 21:26 227,840 -------- c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 21:26 616,960 -------- c:\windows\system32\dllcache\advapi32.dll
2009-04-16 21:26 714,752 -------- c:\windows\system32\dllcache\ntdll.dll
2009-04-16 21:24 1,193,414 -------- c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 21:24 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
2009-04-13 11:06 <DIR> --d----- c:\program files\common files\AnswerWorks 5.0
==================== Find3M ====================
2009-05-01 09:23 94,204 a------- c:\windows\system32\drivers\18ee5625.sys
2009-04-30 16:40 101,888 a------- C:\wwmeoblk.exe
2009-04-30 16:39 7,680 a------- C:\celkadaa.exe
2009-04-30 16:39 577,536 a------- c:\windows\system32\user32.DLL
2009-04-30 16:39 577,536 a------- c:\windows\system32\dllcache\user32.dll
2009-04-30 16:39 262,144 a------- c:\windows\system32\nvrsk.dll
2009-04-30 16:39 14,336 a------- c:\windows\system32\OLD50.tmp
2009-04-30 16:39 113,664 a------- C:\kggi.exe
2009-04-30 16:39 15,000 a------- c:\windows\system32\sjg9s8guigjs.dll
2009-04-30 16:39 62,464 a--sh--- c:\windows\system32\pebudure.exe
2009-04-30 16:39 105,472 a--sh--- c:\windows\system32\delutaha.dll
2009-04-30 16:39 102,400 a--sh--- c:\windows\system32\zajosola.dll
2009-04-30 04:40 69,120 a--sh--- c:\windows\system32\bufezika.dll
2009-04-30 04:39 105,472 a--sh--- c:\windows\system32\hoguforu.dll
2009-04-30 04:39 60,416 a--sh--- c:\windows\system32\miwajiho.exe
2009-04-30 04:39 97,792 -------- c:\windows\system32\veyetidi.dll
2009-04-29 16:42 28,672 a------- c:\windows\system32\f3PSSavr.scr
2009-04-29 16:39 105,984 a--sh--- c:\windows\system32\yisawaje.dll
2009-04-29 16:39 98,304 a--sh--- c:\windows\system32\hizitapi.dll
2009-04-29 16:39 60,416 a--sh--- c:\windows\system32\wofurave.exe
2009-04-27 16:16 98,304 a--sh--- c:\windows\system32\sulowogu.dll
2009-04-27 16:16 105,984 a--sh--- c:\windows\system32\suhaleti.dll.vir
2009-04-27 16:16 58,368 a--sh--- c:\windows\system32\wepafehi.exe
2009-04-27 04:16 105,472 a--sh--- c:\windows\system32\fumomeme.dll.vir
2009-04-27 04:15 60,928 a--sh--- c:\windows\system32\kevejupu.exe
2009-04-26 16:15 97,280 a--sh--- c:\windows\system32\nomojumi.dll
2009-04-26 16:15 105,984 a--sh--- c:\windows\system32\barakihu.dll
2009-04-26 16:15 59,904 a--sh--- c:\windows\system32\lewenemu.exe
2009-03-21 09:18 986,112 -------- c:\windows\system32\dllcache\kernel32.dll
2009-03-07 10:44 4,184 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-03-06 09:44 283,648 a------- c:\windows\system32\pdh.dll
2009-03-02 18:27 1,499,136 -------- c:\windows\system32\dllcache\shdocvw.dll
2009-02-20 16:44 3,067,904 -------- c:\windows\system32\dllcache\mshtml.dll
2009-02-19 04:50 18,432 -------- c:\windows\system32\dllcache\iedw.exe
2009-02-09 05:20 723,456 a------- c:\windows\system32\lsasrv.dll
2009-02-09 05:20 399,360 a------- c:\windows\system32\rpcss.dll
2009-02-09 05:20 723,456 -------- c:\windows\system32\dllcache\lsasrv.dll
2009-02-09 05:20 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 05:20 616,960 a------- c:\windows\system32\advapi32.dll
2009-02-09 05:19 1,846,272 a------- c:\windows\system32\win32k.sys
2009-02-09 05:19 1,846,272 -------- c:\windows\system32\dllcache\win32k.sys
2009-02-06 12:24 2,180,480 -------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 12:22 2,136,064 a------- c:\windows\system32\ntoskrnl.exe
2009-02-06 12:22 2,136,064 -------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 12:14 110,592 a------- c:\windows\system32\services.exe
2009-02-06 11:54 35,328 a------- c:\windows\system32\sc.exe
2009-02-06 11:49 2,015,744 a------- c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:49 2,057,728 -------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 11:49 2,015,744 -------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-03 15:08 55,808 a------- c:\windows\system32\secur32.dll
2009-02-03 15:08 55,808 -------- c:\windows\system32\dllcache\secur32.dll
2009-01-30 04:40 69,120 a--sh--- c:\windows\system32\lopibeki.dll
2009-01-26 16:09 67,072 a--sh--- c:\windows\system32\mezakuga.dll.vir
2009-01-29 16:39 68,608 a--sh--- c:\windows\system32\sofajesa.dll
2009-01-30 04:40 69,120 a--sh--- c:\windows\system32\wegaloru.dll
2009-01-30 04:40 69,120 a--sh--- c:\windows\system32\yanadeya.dll.vir
============= FINISH: 9:24:12.45 ===============