This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unable to instal any antivirus software on Windows XP

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am unable to install anti virus software on windows XP below is my log file: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:09:31 AM, on 3/3/2009 Platform: Windows XP SP2, v.2082 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2082) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winfkqlgx.exe C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winmwpdp.exe C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe C:\WINDOWS\system32\dwwin.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT" O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user') O4 - Global Startup: IDW Logging Tool.lnk = C:\WINDOWS\system32\idwlog.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{A28B95B7-652B-45A6-A035-385407A64407}: NameServer = 218.248.255.195 218.248.240.174 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – End of file - 4369 bytes
Hi sahil, welcome to the forum.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
I will post back soon with additional instructions.


Thanks
Hi sahil,

Did you uninstall Norton (Symantec)?

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.


Next It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]



Please post back with
  • Rooter log
  • combofixlog

Please let us know how your computer is now.

Thanks
Hi sahil,


Please repost the combofix log and the Rooter log. Do Not attach logs unless asked to do so.

Open the logs in notepad.
  • at the top of notepad, click Format
  • Make sure word wrap is not checked
  • Right click the text and select Select All
  • Right click the highlighted text and select Copy
  • Right click in the reply box and select Paste
The combofix log can be found at C:\Combofix.txt

Please post a new Hijackthis log also.

Thanks
this is new hijack log :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:15:50 AM, on 3/4/2009
Platform: Windows XP SP2, v.2082 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2082)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: IDW Logging Tool.lnk = C:\WINDOWS\system32\idwlog.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related; Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{A28B95B7-652B-45A6-A035-385407A64407}: NameServer = 218.248.255.195 218.248.240.174
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

–
End of file - 4390 bytes

——————————————————————————————————–
This is combo-fix log file:

ComboFix 09-03-03.01 - Administrator 2009-03-04 0:19:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.190.35 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
FW: Norton Internet Security *enabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\8.bat
C:\autorun.inf
c:\documents and settings\Administrator\Application Data\sysrc32.exe
c:\documents and settings\Administrator\Desktop\XP Police Antivirus.LNK
c:\documents and settings\Administrator\Start Menu\XP Police Antivirus.LNK
c:\program files\XPPoliceAntivirus
c:\program files\XPPoliceAntivirus\AVCoreFn.dll
c:\program files\XPPoliceAntivirus\bdconf.cfg
c:\program files\XPPoliceAntivirus\Core.dll
c:\program files\XPPoliceAntivirus\plugins\vb0.dat
c:\program files\XPPoliceAntivirus\plugins\vb1.dat
c:\program files\XPPoliceAntivirus\plugins\vb2.dat
c:\program files\XPPoliceAntivirus\setup.dat
c:\program files\XPPoliceAntivirus\sounds\alert.wav
c:\program files\XPPoliceAntivirus\sounds\click.wav
c:\program files\XPPoliceAntivirus\sounds\fire.wav
c:\program files\XPPoliceAntivirus\xppolice.exe
c:\windows\system32\28463
c:\windows\system32\nmdfgds0.dll
D:\8.bat
D:\Autorun.inf
E:\8.bat
E:\Autorun.inf
F:\8.bat
F:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-02-04 to 2009-03-04 )))))))))))))))))))))))))))))))
.

2009-03-03 23:55 . 2009-03-04 00:14 d——– C:\Rooter$
2009-03-03 11:23 . 2009-03-03 11:23 71,168 –a—— c:\documents and settings\Administrator\Application Data\syssl.exe
2009-03-03 11:22 . 2009-03-03 11:22 71,168 –a—— c:\documents and settings\Administrator\Application Data\nSvcAppFlt.exe
2009-03-03 11:22 . 2009-03-03 11:24 14,336 –a—— c:\windows\iehost32.dll
2009-03-03 11:22 . 2009-03-03 11:24 9,728 –a—— c:\windows\regsv32.exe
2009-03-03 10:38 . 2009-03-03 10:38 d——– c:\program files\Trend Micro
2009-03-03 07:25 . 2009-03-03 11:59 869 –a—— C:\ABC1.class
2009-03-03 07:15 . 2009-03-03 12:26 1,273 –a—— C:\ABC1.java
2009-03-03 06:48 . 2009-03-03 07:24 676 –a—— C:\ABC.class
2009-03-03 06:35 . 2009-03-03 07:14 825 –a—— C:\ABC.java
2009-03-03 06:09 . 2009-03-03 06:15 439 –a—— C:\array1.class
2009-03-03 06:09 . 2009-03-03 06:15 225 –a—— C:\array1.java
2009-03-03 06:03 . 2009-03-03 06:03 d——– C:\Java
2009-03-03 06:01 . 2005-11-10 13:03 49,265 –a—— c:\windows\system32\jpicpl32.cpl
2009-03-03 04:52 . 2009-03-03 04:54 d——– c:\program files\Norton Internet Security
2009-03-03 04:51 . 2004-08-26 14:03 104,144 –a—— c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-03 04:51 . 2004-08-26 14:03 83,168 –a—— c:\windows\system32\S32EVNT1.DLL
2009-03-03 04:23 . 2009-03-03 11:49 d——– c:\program files\Symantec
2009-03-02 11:52 . 2009-03-02 11:52 d——– c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-03-02 11:52 . 2009-03-02 11:52 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-27 10:24 . 2009-02-27 10:25 d——– C:\TCC
2009-02-24 07:04 . 2009-02-24 07:04 d——– c:\documents and settings\Administrator\Application Data\GRETECH
2009-02-23 21:14 . 2004-02-16 19:55 26,496 –a–c— c:\windows\system32\dllcache\usbstor.sys
2009-02-23 12:58 . 2009-02-23 12:58 d——– c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2009-02-23 12:58 . 2009-03-03 11:49 d——– c:\documents and settings\All Users.WINDOWS\Application Data\Symantec
2009-02-23 12:11 . 2009-02-23 12:11 d——– c:\program files\Windows Sidebar
2009-02-23 12:11 . 2009-02-23 12:11 d——– c:\program files\Norton AntiVirus
2009-02-23 12:10 . 2009-02-23 12:10 10,652 –a—— c:\windows\system32\drivers\SYMEVENT.CAT
2009-02-23 12:10 . 2009-02-23 12:10 806 –a—— c:\windows\system32\drivers\SYMEVENT.INF
2009-02-23 11:53 . 2009-02-23 11:53 d——– c:\documents and settings\Administrator\Application Data\vlc
2009-02-23 11:18 . 2009-02-23 11:18 0 –a—— c:\windows\nsreg.dat
2009-02-23 11:15 . 2009-02-23 11:15 0 –a—— C:\86a4
2009-02-23 07:12 . 2009-02-23 11:36 d——– c:\documents and settings\Administrator\Application Data\Symantec
2009-02-23 07:08 . 2009-02-23 07:08 940,794 –a—— c:\windows\system32\LoopyMusic.wav
2009-02-23 07:08 . 2009-02-23 07:08 146,650 –a—— c:\windows\system32\BuzzingBee.wav
2009-02-23 07:08 . 2005-08-24 12:56 74,752 –a—— c:\windows\system32\drivers\Rtnicxp.sys
2009-02-23 07:04 . 2005-04-16 22:20 487,424 -r——- c:\windows\RtlExUpd.dll
2009-02-23 07:04 . 2004-11-18 10:42 22,752 –a—— c:\windows\system32\spupdsvc.exe
2009-02-23 07:02 . 2005-08-30 09:12 524,850 -ra—— c:\windows\system32\drivers\ativcaxx.cpa
2009-02-23 07:02 . 2005-08-30 21:05 516,096 ——— c:\windows\system32\ati2sgag.exe
2009-02-23 07:02 . 2005-08-31 00:08 307,200 -ra—— c:\windows\system32\atiiiexx.dll
2009-02-23 07:02 . 2005-08-26 09:54 104,373 -ra—— c:\windows\system32\atiicdxx.dat
2009-02-23 07:02 . 2005-06-08 14:45 58,560 -ra—— c:\windows\system32\drivers\ativckxx.vp
2009-02-23 07:02 . 2005-08-31 01:01 23,936 -ra—— c:\windows\system32\drivers\ativvpxx.vp
2009-02-23 07:02 . 2005-07-01 20:54 5,496 -ra—— c:\windows\system32\atifglpf.xml
2009-02-23 07:02 . 2005-08-30 09:12 929 -ra—— c:\windows\system32\drivers\ativcaxx.vp
2009-02-23 06:56 . 2004-02-16 19:47 95,488 –a—— c:\windows\system32\drivers\atapi.sys
2009-02-23 06:56 . 2004-02-16 19:47 95,488 –a–c— c:\windows\system32\dllcache\atapi.sys
2009-02-23 06:56 . 2004-02-16 19:47 24,960 –a—— c:\windows\system32\drivers\pciidex.sys
2009-02-23 06:56 . 2004-02-16 19:47 24,960 –a–c— c:\windows\system32\dllcache\pciidex.sys
2009-02-23 06:56 . 2001-08-17 13:51 3,328 –a—— c:\windows\system32\drivers\pciide.sys
2009-02-23 06:56 . 2001-08-17 13:51 3,328 –a–c— c:\windows\system32\dllcache\pciide.sys
2009-02-23 06:44 . 2009-03-04 00:22 d——– c:\documents and settings\Administrator
2009-02-23 06:41 . 2009-02-23 06:41 d–hs—- c:\documents and settings\NetworkService.NT AUTHORITY
2009-02-23 06:41 . 2009-02-23 06:41 d–hs—- c:\documents and settings\LocalService.NT AUTHORITY
2009-02-23 06:41 . 2009-02-23 06:41 8,192 –a—— c:\windows\REGLOCS.OLD
2009-02-23 06:38 . 2002-09-03 14:33 10,129,408 –a–c— c:\windows\system32\dllcache\hwxkor.dll
2009-02-23 06:37 . 2002-09-03 14:33 13,463,552 –a–c— c:\windows\system32\dllcache\hwxjpn.dll
2009-02-23 06:36 . 2003-06-02 23:41 876,653 –a–c— c:\windows\system32\dllcache\fp4awel.dll
2009-02-23 06:35 . 2009-02-23 11:23 d–hs—- c:\documents and settings\All Users.WINDOWS\DRM
2009-02-23 06:34 . 2002-09-03 14:34 4,399,505 –a–c— c:\windows\system32\dllcache\nls302en.lex
2009-02-23 06:33 . 2004-02-18 04:02 4,256,768 –a–c— c:\windows\system32\dllcache\wmm2res.dll
2009-02-23 06:32 . 2002-09-03 14:33 227,840 –a–c— c:\windows\system32\dllcache\avtapi.dll
2009-02-23 06:31 . 2004-02-18 04:02 1,654,272 –a–c— c:\windows\system32\dllcache\comsvcs.dll
2009-02-23 04:37 . 2009-02-23 04:37 423 –ah—– C:\idwlog.cookie
2009-02-23 04:32 . 2009-02-23 06:41 d——– C:\idwlog
2009-02-22 20:54 . 2004-02-16 11:47 57,344 –a—— c:\windows\system32\drivers\redbook.sys
2009-02-22 20:54 . 2001-08-17 05:59 3,072 –a—— c:\windows\system32\drivers\audstub.sys
2009-02-22 20:53 . 2001-08-17 14:36 67,072 –a—— c:\windows\system32\usbui.dll

———————————————————————————————–
this is rooter log file:

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2, v.2082
X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 2.80GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Administrator ( Administrator )
BOOT : Normal boot


Firewall : Norton Internet Security 2005 (Activated)

A:\ (USB)
C:\ (Local Disk) - NTFS - Total:19 Go (Free:10 Go)
D:\ (Local Disk) - FAT32 - Total:18 Go (Free:0 Go)
E:\ (Local Disk) - FAT32 - Total:18 Go (Free:0 Go)
F:\ (Local Disk) - FAT32 - Total:19 Go (Free:1 Go)
G:\ (CD or DVD)

2009-03-04| 0:14

———————-\\ Search..

———————-\\ Rogues..

C:\DOCUME~1\ADMINI~1\STARTM~1\XP Police Antivirus.LNK
C:\PROGRA~1\XPPoliceAntivirus


1 - "C:\Rooter$\Rooter_1.txt" - Tue 03/03/2009|23:55
2 - "C:\Rooter$\Rooter_2.txt" - 2009-03-04| 0:14
Hi sahil,

You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.


Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Desktop is a good place.
  • Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply along with a new HijackThis log.
Please post back with the Kaspersky scan log and a new HJT log

Thanks
Hi sahil,

Let's see if this will tell us anything.

Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file paths, one at a time into the "Suspicious files to scan" box on the top of the page:
  • Wait until the results are complete and you have saved them before submitting the next one.
  • Please make sure each sample is identified

    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI