BnTheMan
Topic Starter
The office I work at has 3 computers, in which he allows his disabled clients to use for pleasure. I had warned him that the computers are not protected running off one network security monitoring company. Each computer must have their own AV install ed but he will not listen, and now I know for sure that one is infected, and the other 2 are possibably infected as well.
I cannot explain everything that cause this, but for what I have seen, several tool bar helpers have been installed, and some sort of what looks like a russian firewall application, which at first used to say all my applications where infected. Once I seen, that, I ran MBAM, which reported 49 trojans where removed. I then did an online Scan, using Panda Active Scan, and that reported some more trojans. I could not have the AV scanner remove them because, the program wanted to me to purchase a full license. So I tried deleting them manually, but a few of them continue to reinstall itself. As your site ask's, here is my DDS.txt log
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 4:19:03 on 2012-12-18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.130 [GMT -5:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\user\Local Settings\Application Data\Yandex\Updater\praetorian.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uURLSearchHooks: {b4efb02b-cd4a-44b9-b5d9-aa486cdffab6} -
uURLSearchHooks: {472734EA-242A-422b-ADF8-83D1E48CC825} -
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Praetorian] c:\documents and settings\user\local settings\application data\yandex\updater\praetorian.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
TCP: NameServer = 64.115.0.9 64.115.0.10
TCP: Interfaces\{07A278B3-9029-4675-BE09-61B75E3F6497} : DHCPNameServer = [removed] [removed]
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2012-12-13 28552]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-10-16 399432]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-8-29 676936]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-8-29 22856]
S0 cerc6;cerc6; [x]
.
=============== Created Last 30 ================
.
2012-12-13 09:34:34 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys
2012-12-13 09:34:18 ——– d—–w- c:\program files\Panda Security
2012-12-12 08:59:52 ——– d—–w- c:\windows\system32\appmgmt
.
==================== Find3M ====================
.
2012-12-12 11:40:12 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-12 11:40:12 697272 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-29 23:54:26 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 4:19:42,17 ===============