Angrypoonani
Topic Starter
So I got the/an XP Internet Security Virus which I removed with a combination of several MalewareBytes' Anti-Malware and Symantec AntiVirus Scans over many restarts and logons to the two different OS's on my system, one infected one not. The aftermath of the removal has left all of my browsers hijacked to some degree and now a few of my system processes randomly hog all of the CPU and several new processes that I am not familiar with have appeared:
- I'll randomly get rerouted to other webpages and I can not look up many anti-virus help websites. This happens on Safari(4.0.4 - 531.21.10), Firefox(3.6.3), IE(?), and on Chrome(4.1.249.1045) I cannot even get to the net
- Ill get random CPU hogs, Sometimes it's been explorer.exe (50-80%), wuauclt.exe(60-70%), lsass.exe((50-65%) for no reason as in the system has just started up. And once one of the SYS svchost.exe was taking all the CPU but I think that was because XP updates were being downloaded…. Not sure what was up with that
- Several processes that I've never seen before have been appearing: msiexec.exe and a few others that I can't remember but are not running now.
- In fact, my computer won't even let me post on this forum!!! It throws out connection errors… Luckily I have another computer and am posting this from it
Please help! any help is appreciated!
I read through the instruction post and here are those logs:
DDS.txt: ( I replaced all instances of the user name with "user""
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:51:29.92 on Wed 04/14/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1356 [GMT -5:00]
AV: Digital Protection *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Safari\Safari.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wscntfy.exe
K:\”user”\Documents\Downloads\Programs\Antivirus\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=c:\windows\system32\Userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [Google Update] "c:\documents and settings\”user”\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (rootkit-scan)] "c:\program files\mab\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\”user”\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198424729015
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198486014593
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {0B32A2C0-6477-490C-8493-123B39C1B224} = 208.67.222.222,208.67.220.220
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\”user”\applic~1\mozilla\firefox\profiles\xojix7eh.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fnsr%3D1%26ui%3Dhtml%26zy%3Dl FF - plugin: c:\documents and settings\”user”\local settings\application data\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npnul32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.closed", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.document", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.frames", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.history", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.length", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.opener", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.parent", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.self", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.top", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.window", "allAccess");
c:\program files\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
============= SERVICES / DRIVERS ===============
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-11-21 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-11-21 169576]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2009-9-22 12672]
R2 CX88XBAR;AVerMedia AVerTV MPEG Crossbar (Dual-Input);c:\windows\system32\drivers\A88BarBB.sys [2007-12-22 10112]
R2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\rosettastoneltdservices\RosettaStoneDaemon.exe [2009-4-25 443712]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-3-14 1816768]
R3 CXAVSAUD;AVerMedia AVerTV AvStream Audio Capture;c:\windows\system32\drivers\A88AudBB.sys [2007-12-22 9216]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-4-12 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100413.005\naveng.sys [2010-4-13 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100413.005\navex15.sys [2010-4-13 1324720]
S2 Ias;Windows Protected Manager;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S3 diskchk;diskchk;\??\c:\windows\system32\diskchk.sys –> c:\windows\system32\diskchk.sys [?]
S3 rt2870;Belkin 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys –> c:\windows\system32\drivers\rt2870.sys [?]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-3-14 116416]
=============== Created Last 30 ================
2010-04-14 20:48 411,368 a——- c:\windows\system32\deployJava1.dll
2010-04-13 23:39 –d—– c:\program files\Trend Micro
2010-04-13 19:30 –d—– c:\program files\TC Electronic
2010-04-13 19:30 –d—– c:\docume~1\alluse~1\applic~1\Psicraft
2010-04-13 00:43 54,016 a——- c:\windows\system32\drivers\txmqfd.sys
2010-04-12 23:18 –d—– c:\docume~1\”user”\applic~1\Malwarebytes
2010-04-12 23:18 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-12 23:18 20,824 a——- c:\windows\system32\drivers\mbam.sys
2010-04-12 23:18 –d—– c:\program files\MAB
2010-04-12 23:18 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-04-12 20:53 552 a——- c:\windows\system32\d3d8caps.dat
2010-04-12 20:48 1,181 a——- c:\docume~1\alluse~1\applic~1\pragmamfeklnmal.dll
2010-04-12 20:48 34,688 ac—— c:\windows\system32\dllcache\lbrtfdc.sys
2010-04-12 20:48 34,688 a——- c:\windows\system32\drivers\lbrtfdc.sys
2010-04-12 20:48 8,576 ac—— c:\windows\system32\dllcache\i2omgmt.sys
2010-04-12 20:48 8,576 a——- c:\windows\system32\drivers\i2omgmt.sys
2010-04-12 20:48 8,192 ac—— c:\windows\system32\dllcache\changer.sys
2010-04-12 20:48 8,192 a——- c:\windows\system32\drivers\changer.sys
2010-04-12 20:48 –d—– C:\spoolerlogs
2010-04-12 20:47 –d—– c:\docume~1\”user”\applic~1\A5F591985610789523F2F2EBA4F20A38
2010-04-10 19:49 –d—– c:\program files\iPod
2010-04-10 19:49 –d—– c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-10 19:42 –d—– c:\program files\Bonjour
2010-03-31 23:16 –d—– c:\program files\NCH Software
2010-03-31 23:09 –d—– c:\docume~1\”user”\applic~1\BonkEnc
2010-03-26 17:25 –d—– c:\program files\WinSCP
2010-03-17 21:53 94,208 a——- c:\windows\system32\QuickTimeVR.qtx
2010-03-17 21:53 69,632 a——- c:\windows\system32\QuickTime.qts
==================== Find3M ====================
2010-04-13 22:54 96,512 a——- c:\windows\system32\drivers\atapi.sys
2010-04-13 19:58 61,696 a——- c:\windows\system32\drivers\ohci1394.sys
2010-04-08 11:41 1,536 a——- c:\docume~1\”user”\applic~1\Sketchpad 5 Preferences.dat
2010-03-11 07:38 832,512 a——- c:\windows\system32\wininet.dll
2010-03-11 07:38 78,336 a——- c:\windows\system32\ieencode.dll
2010-03-11 07:38 17,408 ——– c:\windows\system32\corpol.dll
2010-02-12 11:46 107,808 a——- c:\windows\system32\dns-sd.exe
2010-02-12 11:46 91,424 a——- c:\windows\system32\dnssd.dll
2010-02-10 13:33 53,296 ac–h— c:\windows\system32\mlfcache.dat
2009-04-29 14:42 1,009 ac—— c:\program files\updates.xml
2009-04-29 14:42 57 a——- c:\program files\active-update.xml
2008-09-06 18:57 16,384 ac-sh— c:\windows\system32\config\systemprofile\cookies\index.dat
2008-09-06 18:57 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
2008-09-06 18:57 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090620080907\index.dat
2008-09-06 18:57 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat
============= FINISH: 20:52:42.76 ===============
GMER.txt ( I have replaced all instances of the user name with "user")
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-15 08:18:49
Windows 5.1.2600 Service Pack 3
Running: 72or0ezd.exe; Driver: C:\DOCUME~1\”user”\LOCALS~1\Temp\kxtdqpoc.sys
—- System - GMER 1.0.15 —-
SSDT 8A6C0E68 ZwAlertResumeThread
SSDT 8A657E78 ZwAlertThread
SSDT 8A5C1230 ZwAllocateVirtualMemory
SSDT 8A4FF908 ZwConnectPort
SSDT 8A7C5B40 ZwCreateMutant
SSDT 8A4FB580 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA461C350]
SSDT 8A55FF08 ZwFreeVirtualMemory
SSDT 8A5E72F0 ZwImpersonateAnonymousToken
SSDT 8A62BCD0 ZwImpersonateThread
SSDT 8A6ECAA8 ZwMapViewOfSection
SSDT 8A6FDE50 ZwOpenEvent
SSDT 8A55FF40 ZwOpenProcessToken
SSDT 8A704BB0 ZwOpenThreadToken
SSDT 8A6D0A30 ZwQueryValueKey
SSDT 8A5AC258 ZwResumeThread
SSDT 8A704B78 ZwSetContextThread
SSDT 8A6F9CC0 ZwSetInformationProcess
SSDT 8A663BE8 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA461C580]
SSDT 8A6FD660 ZwSuspendProcess
SSDT 8A66FE78 ZwSuspendThread
SSDT 8A6E2D50 ZwTerminateProcess
SSDT 8A651E78 ZwTerminateThread
SSDT 8A6F9CF8 ZwUnmapViewOfSection
SSDT 8A6C0F80 ZwWriteVirtualMemory
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!ZwYieldExecution + 407 804E4C61 7 Bytes [9C, 6F, 8A, E8, 3B, 66, 8A] {PUSHF ; OUTSD ; MOV CH, AL; CMP ESP, [ESI-0x76]}
.rsrc C:\WINDOWS\system32\drivers\ohci1394.sys entry point in ".rsrc" section [0xF7613114]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB88E1360, 0x307F47, 0xE8000020]
init C:\WINDOWS\System32\Drivers\sunkfilt.sys entry point in "init" section [0xB371D300]
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\Explorer.EXE[280] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\WINDOWS\Explorer.EXE[280] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C4000A
.text C:\WINDOWS\Explorer.EXE[280] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0098000A
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0097000C
.text C:\WINDOWS\System32\svchost.exe[1140] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 026B000A
.text C:\WINDOWS\System32\svchost.exe[1140] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 026A000A
.text C:\Program Files\Safari\Safari.exe[2168] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 003F000A
.text C:\Program Files\Safari\Safari.exe[2168] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00E6000A
.text C:\Program Files\Safari\Safari.exe[2168] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 003D000C
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device -> \Driver\atapi \Device\Harddisk0\DR0 8A7EAAC8
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys@imagepath \systemroot\system32\drivers\PRAGMApddjfoetkr.sys
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@PRAGMAc \\?\globalroot\systemroot\system32\PRAGMAjgefygunhx.dll
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@PRAGMAd \\?\globalroot\systemroot\system32\drivers\PRAGMApddjfoetkr.sys
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@PRAGMAsrcr \\?\globalroot\systemroot\system32\PRAGMApxvndlhrjk.dat
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@pragmaserf \\?\globalroot\systemroot\system32\PRAGMAxjunaobdlx.dll
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@pragmabbr \\?\globalroot\systemroot\system32\PRAGMAwaojgutfks.dll
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\drivers\ohci1394.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-
Hijackthis.txt ( I have replaced all instances of my user name with "user")
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:13 PM, on 4/14/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Safari\Safari.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] "C:\Program Files\MAB\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\”user”\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1198424729015
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1198486014593
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B32A2C0-6477-490C-8493-123B39C1B224}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B32A2C0-6477-490C-8493-123B39C1B224}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{0B32A2C0-6477-490C-8493-123B39C1B224}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS3\Services\Tcpip\..\{0B32A2C0-6477-490C-8493-123B39C1B224}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RosettaStoneDaemon - Rosetta Stone Ltd. - C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
–
End of file - 8403 bytes
I think I have MalwareBytes' Scan logs and Symantec AntiVirus scan logs somewhere if you want these.
My Computer just updated from microsoft, however, I am experiencing the same problems… Do I need to run the scans again???
- I'll randomly get rerouted to other webpages and I can not look up many anti-virus help websites. This happens on Safari(4.0.4 - 531.21.10), Firefox(3.6.3), IE(?), and on Chrome(4.1.249.1045) I cannot even get to the net
- Ill get random CPU hogs, Sometimes it's been explorer.exe (50-80%), wuauclt.exe(60-70%), lsass.exe((50-65%) for no reason as in the system has just started up. And once one of the SYS svchost.exe was taking all the CPU but I think that was because XP updates were being downloaded…. Not sure what was up with that
- Several processes that I've never seen before have been appearing: msiexec.exe and a few others that I can't remember but are not running now.
- In fact, my computer won't even let me post on this forum!!! It throws out connection errors… Luckily I have another computer and am posting this from it
Please help! any help is appreciated!
I read through the instruction post and here are those logs:
DDS.txt: ( I replaced all instances of the user name with "user""
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:51:29.92 on Wed 04/14/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1356 [GMT -5:00]
AV: Digital Protection *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Safari\Safari.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wscntfy.exe
K:\”user”\Documents\Downloads\Programs\Antivirus\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=c:\windows\system32\Userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [Google Update] "c:\documents and settings\”user”\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (rootkit-scan)] "c:\program files\mab\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\”user”\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198424729015
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198486014593
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {0B32A2C0-6477-490C-8493-123B39C1B224} = 208.67.222.222,208.67.220.220
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\”user”\applic~1\mozilla\firefox\profiles\xojix7eh.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fnsr%3D1%26ui%3Dhtml%26zy%3Dl FF - plugin: c:\documents and settings\”user”\local settings\application data\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npnul32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.closed", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.document", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.frames", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.history", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.length", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.opener", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.parent", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.self", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.top", "allAccess");
c:\program files\greprefs\all.js - pref("capability.policy.default.Window.window", "allAccess");
c:\program files\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
============= SERVICES / DRIVERS ===============
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-11-21 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-11-21 169576]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2009-9-22 12672]
R2 CX88XBAR;AVerMedia AVerTV MPEG Crossbar (Dual-Input);c:\windows\system32\drivers\A88BarBB.sys [2007-12-22 10112]
R2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\rosettastoneltdservices\RosettaStoneDaemon.exe [2009-4-25 443712]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-3-14 1816768]
R3 CXAVSAUD;AVerMedia AVerTV AvStream Audio Capture;c:\windows\system32\drivers\A88AudBB.sys [2007-12-22 9216]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-4-12 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100413.005\naveng.sys [2010-4-13 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100413.005\navex15.sys [2010-4-13 1324720]
S2 Ias;Windows Protected Manager;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S3 diskchk;diskchk;\??\c:\windows\system32\diskchk.sys –> c:\windows\system32\diskchk.sys [?]
S3 rt2870;Belkin 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys –> c:\windows\system32\drivers\rt2870.sys [?]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-3-14 116416]
=============== Created Last 30 ================
2010-04-14 20:48 411,368 a——- c:\windows\system32\deployJava1.dll
2010-04-13 23:39 –d—– c:\program files\Trend Micro
2010-04-13 19:30 –d—– c:\program files\TC Electronic
2010-04-13 19:30 –d—– c:\docume~1\alluse~1\applic~1\Psicraft
2010-04-13 00:43 54,016 a——- c:\windows\system32\drivers\txmqfd.sys
2010-04-12 23:18 –d—– c:\docume~1\”user”\applic~1\Malwarebytes
2010-04-12 23:18 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-12 23:18 20,824 a——- c:\windows\system32\drivers\mbam.sys
2010-04-12 23:18 –d—– c:\program files\MAB
2010-04-12 23:18 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-04-12 20:53 552 a——- c:\windows\system32\d3d8caps.dat
2010-04-12 20:48 1,181 a——- c:\docume~1\alluse~1\applic~1\pragmamfeklnmal.dll
2010-04-12 20:48 34,688 ac—— c:\windows\system32\dllcache\lbrtfdc.sys
2010-04-12 20:48 34,688 a——- c:\windows\system32\drivers\lbrtfdc.sys
2010-04-12 20:48 8,576 ac—— c:\windows\system32\dllcache\i2omgmt.sys
2010-04-12 20:48 8,576 a——- c:\windows\system32\drivers\i2omgmt.sys
2010-04-12 20:48 8,192 ac—— c:\windows\system32\dllcache\changer.sys
2010-04-12 20:48 8,192 a——- c:\windows\system32\drivers\changer.sys
2010-04-12 20:48 –d—– C:\spoolerlogs
2010-04-12 20:47 –d—– c:\docume~1\”user”\applic~1\A5F591985610789523F2F2EBA4F20A38
2010-04-10 19:49 –d—– c:\program files\iPod
2010-04-10 19:49 –d—– c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-10 19:42 –d—– c:\program files\Bonjour
2010-03-31 23:16 –d—– c:\program files\NCH Software
2010-03-31 23:09 –d—– c:\docume~1\”user”\applic~1\BonkEnc
2010-03-26 17:25 –d—– c:\program files\WinSCP
2010-03-17 21:53 94,208 a——- c:\windows\system32\QuickTimeVR.qtx
2010-03-17 21:53 69,632 a——- c:\windows\system32\QuickTime.qts
==================== Find3M ====================
2010-04-13 22:54 96,512 a——- c:\windows\system32\drivers\atapi.sys
2010-04-13 19:58 61,696 a——- c:\windows\system32\drivers\ohci1394.sys
2010-04-08 11:41 1,536 a——- c:\docume~1\”user”\applic~1\Sketchpad 5 Preferences.dat
2010-03-11 07:38 832,512 a——- c:\windows\system32\wininet.dll
2010-03-11 07:38 78,336 a——- c:\windows\system32\ieencode.dll
2010-03-11 07:38 17,408 ——– c:\windows\system32\corpol.dll
2010-02-12 11:46 107,808 a——- c:\windows\system32\dns-sd.exe
2010-02-12 11:46 91,424 a——- c:\windows\system32\dnssd.dll
2010-02-10 13:33 53,296 ac–h— c:\windows\system32\mlfcache.dat
2009-04-29 14:42 1,009 ac—— c:\program files\updates.xml
2009-04-29 14:42 57 a——- c:\program files\active-update.xml
2008-09-06 18:57 16,384 ac-sh— c:\windows\system32\config\systemprofile\cookies\index.dat
2008-09-06 18:57 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
2008-09-06 18:57 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090620080907\index.dat
2008-09-06 18:57 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat
============= FINISH: 20:52:42.76 ===============
GMER.txt ( I have replaced all instances of the user name with "user")
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-15 08:18:49
Windows 5.1.2600 Service Pack 3
Running: 72or0ezd.exe; Driver: C:\DOCUME~1\”user”\LOCALS~1\Temp\kxtdqpoc.sys
—- System - GMER 1.0.15 —-
SSDT 8A6C0E68 ZwAlertResumeThread
SSDT 8A657E78 ZwAlertThread
SSDT 8A5C1230 ZwAllocateVirtualMemory
SSDT 8A4FF908 ZwConnectPort
SSDT 8A7C5B40 ZwCreateMutant
SSDT 8A4FB580 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA461C350]
SSDT 8A55FF08 ZwFreeVirtualMemory
SSDT 8A5E72F0 ZwImpersonateAnonymousToken
SSDT 8A62BCD0 ZwImpersonateThread
SSDT 8A6ECAA8 ZwMapViewOfSection
SSDT 8A6FDE50 ZwOpenEvent
SSDT 8A55FF40 ZwOpenProcessToken
SSDT 8A704BB0 ZwOpenThreadToken
SSDT 8A6D0A30 ZwQueryValueKey
SSDT 8A5AC258 ZwResumeThread
SSDT 8A704B78 ZwSetContextThread
SSDT 8A6F9CC0 ZwSetInformationProcess
SSDT 8A663BE8 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA461C580]
SSDT 8A6FD660 ZwSuspendProcess
SSDT 8A66FE78 ZwSuspendThread
SSDT 8A6E2D50 ZwTerminateProcess
SSDT 8A651E78 ZwTerminateThread
SSDT 8A6F9CF8 ZwUnmapViewOfSection
SSDT 8A6C0F80 ZwWriteVirtualMemory
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!ZwYieldExecution + 407 804E4C61 7 Bytes [9C, 6F, 8A, E8, 3B, 66, 8A] {PUSHF ; OUTSD ; MOV CH, AL; CMP ESP, [ESI-0x76]}
.rsrc C:\WINDOWS\system32\drivers\ohci1394.sys entry point in ".rsrc" section [0xF7613114]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB88E1360, 0x307F47, 0xE8000020]
init C:\WINDOWS\System32\Drivers\sunkfilt.sys entry point in "init" section [0xB371D300]
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\Explorer.EXE[280] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\WINDOWS\Explorer.EXE[280] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C4000A
.text C:\WINDOWS\Explorer.EXE[280] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0098000A
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0097000C
.text C:\WINDOWS\System32\svchost.exe[1140] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 026B000A
.text C:\WINDOWS\System32\svchost.exe[1140] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 026A000A
.text C:\Program Files\Safari\Safari.exe[2168] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 003F000A
.text C:\Program Files\Safari\Safari.exe[2168] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00E6000A
.text C:\Program Files\Safari\Safari.exe[2168] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 003D000C
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device -> \Driver\atapi \Device\Harddisk0\DR0 8A7EAAC8
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys@imagepath \systemroot\system32\drivers\PRAGMApddjfoetkr.sys
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@PRAGMAc \\?\globalroot\systemroot\system32\PRAGMAjgefygunhx.dll
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@PRAGMAd \\?\globalroot\systemroot\system32\drivers\PRAGMApddjfoetkr.sys
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@PRAGMAsrcr \\?\globalroot\systemroot\system32\PRAGMApxvndlhrjk.dat
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@pragmaserf \\?\globalroot\systemroot\system32\PRAGMAxjunaobdlx.dll
Reg HKLM\SYSTEM\ControlSet001\Services\PRAGMAd.sys\modules@pragmabbr \\?\globalroot\systemroot\system32\PRAGMAwaojgutfks.dll
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\drivers\ohci1394.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-
Hijackthis.txt ( I have replaced all instances of my user name with "user")
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:13 PM, on 4/14/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Safari\Safari.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] "C:\Program Files\MAB\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\”user”\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1198424729015
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1198486014593
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B32A2C0-6477-490C-8493-123B39C1B224}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B32A2C0-6477-490C-8493-123B39C1B224}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{0B32A2C0-6477-490C-8493-123B39C1B224}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS3\Services\Tcpip\..\{0B32A2C0-6477-490C-8493-123B39C1B224}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RosettaStoneDaemon - Rosetta Stone Ltd. - C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
–
End of file - 8403 bytes
I think I have MalwareBytes' Scan logs and Symantec AntiVirus scan logs somewhere if you want these.
My Computer just updated from microsoft, however, I am experiencing the same problems… Do I need to run the scans again???