StickyƒING£RS
Topic Starter
I am running windows xp after boot up the following show up in order:
-ec2: iTunesHelper.exe - Bad Image "The application or DLL C:\WINDOWS|system32\winhelper86.dll is not a valid WIndows image. Please check this against your installation diskette."
-AOLDial.exe - Bad Image "The application or DLL C:\WINDOWS|system32\winhelper86.dll is not a valid WIndows image. Please check this against your installation diskette."
-sprtcmd.exe - Bad Image "The application or DLL C:\WINDOWS|system32\winhelper86.dll is not a valid WIndows image. Please check this against your installation diskette."
-HelperMsgListenerWnd: iTunesHelper.exe - Bad Image "The application or DLL C:\WINDOWS|system32\winhelper86.dll is not a valid WIndows image. Please check this against your installation diskette."
* . WARNING; Application cannot be executed. The file is infected
* . wallpaper has changed to " your system is infected"… screen and it will not allow me to change in the settings
* . bottom right corner has a red circle with white x
* . warning sign that says "Attention! Sysem detected a potential hazard (TrojanSPM/LX) on you computer…
The computer has both Spybot and Malwarebytes' Anti-Malware running when this infection occurred both have been used to scan the computer and appeared to have the issue quarantined or removed but the infection is still there.
Thanks and Regards
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/12/15 21:32
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAFC2C000 Size: 49152 File Visible: No Signed: -
Status: -
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:25:00.70 on Tue 12/15/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.363 [GMT -6:00]
AV: AntiMalware *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\CenturyTel\Home Network Manager\AffinegyService.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\WinPcap\rpcapd.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\rundll32.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\AOL\1167193101\ee\AOLSoftware.exe
C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CenturyTel\Home Network Manager\HomeNetworkManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\CenturyTel\Home Network Manager\ndis_events.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Documents and Settings\Dawn Galvin\Desktop\dds(2).scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.aol.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
uWindow Title = Microsoft Internet Explorer provided by CenturyTel
mWindow Title = Microsoft Internet Explorer provided by CenturyTel
mSearch Bar = about:blank
uInternet Connection Wizard,ShellNext = hxxp://us.mcafee.com/apps/vso/en-us/vso10/setexp.asp?systempopup=true&affid=105-72&dtag=hgvclb1&langid=1
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {8CAA65F8-E703-4CF0-93D4-EDCF8D8ABC5B} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [Aim6]
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: []
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [DLCFCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCFtime.dll,_RunDLLEntry@16
mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
mRun: [HostManager] c:\program files\common files\aol\1167193101\ee\AOLSoftware.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [InstaLAN] "c:\program files\centurytel\home network manager\HomeNetworkManager.exe" startup
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imaget~1.lnk - c:\program files\sony corporation\image transfer\SonyTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\winhelper86.dll
Trusted Zone: musicmatch.com\online
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://usbii.webex.com/client/T26L10NSP49EP30/training/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: text/html - {a42a5361-a0c6-4b1d-88a1-2ce3996d15e1} -
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-10-21 214664]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-8-2 32512]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-11-20 19160]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-10-21 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-10-21 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-10-21 40552]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2006-8-7 30192]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-10-21 34248]
=============== Created Last 30 ================
2009-12-15 20:26 0 a——- c:\windows\system32\24464.exe
2009-12-15 20:21 4,508 a——- c:\windows\system32\tmp.reg
2009-12-15 20:06 0 a——- c:\windows\system32\26962.exe
2009-12-15 19:46 0 a——- c:\windows\system32\29358.exe
2009-12-15 19:26 0 a——- c:\windows\system32\11478.exe
2009-12-14 19:05 0 a——- c:\windows\system32\15724.exe
2009-12-14 18:45 0 a——- c:\windows\system32\19169.exe
2009-12-14 18:25 0 a——- c:\windows\system32\26500.exe
2009-12-14 15:38 –d—– c:\program files\Trend Micro
2009-12-13 18:34 0 a——- c:\windows\system32\AVR10.exe
2009-12-13 18:34 0 a——- c:\windows\system32\winhelper86.dll
2009-12-11 15:38 0 a——- c:\windows\system32\6334.exe
2009-12-11 15:18 0 a——- c:\windows\system32\18467.exe
2009-12-11 14:57 35,328 a——- c:\windows\system32\winlogon86.exe
2009-11-20 21:22 –d—– c:\program files\Spybot - Search & Destroy
2009-11-20 21:22 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-11-20 21:15 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-20 21:15 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-11-20 21:15 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-11-20 17:13 –dsh— c:\documents and settings\dawn galvin\IECompatCache
2009-11-19 12:18 –dsh— c:\documents and settings\dawn galvin\PrivacIE
2009-11-19 12:14 –dsh— c:\documents and settings\dawn galvin\IETldCache
2009-11-18 18:19 5,632 a——- c:\windows\system32\ptpusb.dll
2009-11-18 18:19 15,104 a——- c:\windows\system32\drivers\usbscan.sys
2009-11-18 18:19 15,104 a——- c:\windows\system32\dllcache\usbscan.sys
2009-11-18 18:19 159,232 a——- c:\windows\system32\ptpusd.dll
2009-11-17 17:11 92,160 ——– c:\windows\system32\dllcache\iecompat.dll
2009-11-17 17:10 –d—– c:\windows\ie8updates
2009-11-17 17:10 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2009-11-17 17:10 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2009-11-17 17:07 -cd-h— c:\windows\ie8
2009-11-17 17:06 –d—– c:\windows\system32\MpEngineStore
==================== Find3M ====================
2009-12-14 19:35 3,350 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-12-13 14:01 96,512 a——- c:\windows\system32\drivers\atapi.sys
2009-12-13 14:01 96,512 a——- c:\windows\system32\dllcache\atapi.sys
2009-10-29 01:45 916,480 a——- c:\windows\system32\wininet.dll
2009-10-29 01:45 916,480 ——– c:\windows\system32\dllcache\wininet.dll
2009-10-29 01:45 5,940,736 ——– c:\windows\system32\dllcache\mshtml.dll
2009-10-29 01:45 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll
2009-10-29 01:45 206,848 ——– c:\windows\system32\dllcache\occache.dll
2009-10-29 01:45 594,432 ——– c:\windows\system32\dllcache\msfeeds.dll
2009-10-29 01:45 55,296 ——– c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-29 01:45 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll
2009-10-29 01:45 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll
2009-10-29 01:45 184,320 ——– c:\windows\system32\dllcache\iepeers.dll
2009-10-29 01:45 11,069,952 ——– c:\windows\system32\dllcache\ieframe.dll
2009-10-29 01:45 387,584 ——– c:\windows\system32\dllcache\iedkcs32.dll
2009-10-28 08:40 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-10-20 23:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 23:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-20 23:38 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll
2009-10-20 23:38 25,088 ——– c:\windows\system32\dllcache\httpapi.dll
2009-10-20 10:20 265,728 a——- c:\windows\system32\drivers\http.sys
2009-10-20 10:20 265,728 ——– c:\windows\system32\dllcache\http.sys
2009-10-13 04:30 270,336 a——- c:\windows\system32\oakley.dll
2009-10-13 04:30 270,336 ——– c:\windows\system32\dllcache\oakley.dll
2009-10-12 07:38 149,504 a——- c:\windows\system32\rastls.dll
2009-10-12 07:38 149,504 ——– c:\windows\system32\dllcache\rastls.dll
2009-10-12 07:38 79,872 a——- c:\windows\system32\raschap.dll
2009-10-12 07:38 79,872 ——– c:\windows\system32\dllcache\raschap.dll
2009-09-26 10:44 13,008 a——- c:\docume~1\dawnga~1\applic~1\wklnhst.dat
2009-01-23 21:46 63,624 a——- c:\docume~1\dawnga~1\applic~1\GDIPFONTCACHEV1.DAT
2009-09-02 17:30 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009090220090903\index.dat
============= FINISH: 21:28:39.90 ===============