This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Keylogger Suspicion

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I believe that my computer activity is being monitored and would appreciate any help in identifying any programs that might be installed on my computer without my knowledge. It is my home personal computer and my privacy is being invaded. I would appreciate any help as this is very frustrating. Here is the Hijackthis log. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 2:09:31 PM, on 6/29/2012 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\M-AudioTaskBarIcon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe C:\Program Files\DataGuard\Dataguard.exe C:\Program Files\BitTorrent\BitTorrent.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\WinZip\WZQKPICK32.EXE C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Common Files\Java\Java Update\jucheck.exe C:\Documents and Settings\Joe\My Documents\Downloads\HiJackThis.exe O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.7.1.5\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.7.1.5\IPS\IPSBHO.DLL O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.7.1.5\coIEPlg.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\system32\M-AudioTaskBarIcon.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Lexmark X84-X85 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe O4 - HKLM\..\Run: [Lexmark X84-X85 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe O4 - HKLM\..\Run: [DataGuard] C:\Program Files\DataGuard\Dataguard.exe r O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" /MINIMIZED O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK32.EXE O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe – End of file - 6641 bytes
Hello kadn55f and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

my privacy is being invaded

What exactly is happening? Please let me know.

HJT is rather outdated. Lets take a closer look at your machine with the following scans:

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


Please post the DDS logs and the GMER log in your next reply. If you encounter any problems with the scans come back and let me know.
Hey there, thanks for the reply. I really appreciate your help. I just want to make sure that my personal information isn't compromised.

Here is the gmer.

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-06-29 18:34:03
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST380012A rev.4.06
Running: gmer.exe; Driver: C:\DOCUME~1\Joe\LOCALS~1\Temp\afxcrpoc.sys


—- System - GMER 1.0.15 —-

SSDT 89130D88 ZwAlertResumeThread
SSDT 8910D728 ZwAlertThread
SSDT 8A139E58 ZwAllocateVirtualMemory
SSDT 8914F748 ZwAssignProcessToJobObject
SSDT 8A1A0270 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xACB86D40]
SSDT 8912B760 ZwCreateMutant
SSDT 890E7188 ZwCreateSymbolicLinkObject
SSDT 8A110528 ZwCreateThread
SSDT 8914F7E8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xACB86FC0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xACB87680]
SSDT 890E56E0 ZwDuplicateObject
SSDT 89120758 ZwFreeVirtualMemory
SSDT 8912B850 ZwImpersonateAnonymousToken
SSDT 89130CA8 ZwImpersonateThread
SSDT 891C9A88 ZwLoadDriver
SSDT 89120658 ZwMapViewOfSection
SSDT 89127F70 ZwOpenEvent
SSDT \??\C:\WINDOWS\system32\drivers\dataguard.sys ZwOpenProcess [0xAC97CB00]
SSDT 890052B8 ZwOpenProcessToken
SSDT 8910C808 ZwOpenSection
SSDT 890E5770 ZwOpenThread
SSDT 891080E0 ZwProtectVirtualMemory
SSDT 891092C0 ZwResumeThread
SSDT 8913C378 ZwSetContextThread
SSDT 8914ED10 ZwSetInformationProcess
SSDT 8914F8C8 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xACB87910]
SSDT 89127E90 ZwSuspendProcess
SSDT 891093A0 ZwSuspendThread
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xACAAE640]
SSDT 8913C2B8 ZwTerminateThread
SSDT 890E8CB8 ZwUnmapViewOfSection
SSDT 89128780 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2CC0 80504578 4 Bytes CALL ECD95A74
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB964C000, 0x1C8292, 0xE8000020]
? C:\DOCUME~1\Joe\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1240] USER32.dll!SetWindowLongA 7E42C29D 5 Bytes JMP 1066003B C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1240] USER32.dll!SetWindowLongW 7E42C2BB 5 Bytes JMP 1065FFCA C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1240] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 1043AEF3 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1240] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 1043B50D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3068] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 0115FA35 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3068] kernel32.dll!VirtualAlloc 7C809AF1 5 Bytes JMP 014007C5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3068] kernel32.dll!MapViewOfFile 7C80B9A5 5 Bytes JMP 0140079E C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3068] GDI32.dll!CreateDIBSection 77F19E19 5 Bytes JMP 01400728 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- EOF - GMER 1.0.15 —-

And the dds

.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_22
Run by [removed] at 18:50:22 on 2012-06-29
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3326.2375 [GMT -4:00]
.
AV: Norton Internet Security *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\M-AudioTaskBarIcon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\DataGuard\Dataguard.exe
C:\Program Files\BitTorrent\BitTorrent.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\WinZip\WZQKPICK32.EXE
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\19.7.1.5\coIEPlg.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\19.7.1.5\ips\IPSBHO.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\19.7.1.5\coIEPlg.dll
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [SetDefaultMIDI] MIDIDef.exe
uRun: [BitTorrent] "c:\program files\bittorrent\BitTorrent.exe" /MINIMIZED
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [M-Audio Taskbar Icon] c:\windows\system32\M-AudioTaskBarIcon.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [CTSysVol] c:\program files\rocketfish\rf5.1\surround mixer\CTSysVol.exe /r
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Lexmark X84-X85 Button Monitor] c:\progra~1\lexmar~1\ACMonitor_X84-X85.exe
mRun: [Lexmark X84-X85 Button Manager] c:\progra~1\lexmar~1\AcBtnMgr_X84-X85.exe
mRun: [PrinTray] c:\windows\system32\spool\drivers\w32x86\3\printray.exe
mRun: [DataGuard] c:\program files\dataguard\Dataguard.exe r
StartupFolder: c:\docume~1\joe\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK32.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{5A2196B7-76D8-4C70-AFBA-65C4ECE450A8} : DhcpNameServer = 192.168.1.1
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\joe\application data\mozilla\firefox\profiles\c1heeupx.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1307010.005\symds.sys [2012-6-27 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1307010.005\symefa.sys [2012-6-27 905336]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_19.1.0.28\definitions\bashdefs\20120619.001\BHDrvx86.sys [2012-6-19 821920]
R1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\nis\1307010.005\ccsetx86.sys [2012-6-27 132744]
R1 DataGuard AntiKeylogger Kernel Service;DataGuard AntiKeylogger Kernel Service;c:\windows\system32\drivers\dataguard.sys [2012-6-29 50176]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1307010.005\ironx86.sys [2012-6-27 149624]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
R2 GEST Service;GEST Service for program management.;c:\program files\gigabyte\energysaver\GSvr.exe [2011-11-19 68136]
R2 NIS;Norton Internet Security;c:\program files\norton internet security\engine\19.7.1.5\ccsvchst.exe [2012-6-27 138232]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-6-27 106656]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_19.1.0.28\definitions\ipsdefs\20120628.001\IDSXpx86.sys [2012-6-28 369632]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_19.1.0.28\definitions\virusdefs\20120628.024\NAVENG.SYS [2012-6-29 87928]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_19.1.0.28\definitions\virusdefs\20120628.024\NAVEX15.SYS [2012-6-29 1589752]
R3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [2011-11-19 627072]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-11-19 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-11-19 136176]
S3 MAUSBFASTTRACK;Service for M-Audio FastTrack;c:\windows\system32\drivers\MAudioFastTrack.sys [2011-11-28 158344]
S3 MAUSBFT;Service for M-Audio Fast Track;c:\windows\system32\drivers\mausbft.sys –> c:\windows\system32\drivers\mausbft.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-6-29 113120]
.
=============== Created Last 30 ================
.
2012-06-29 16:08:10 50176 —-a-w- c:\windows\system32\drivers\dataguard.sys
2012-06-29 16:08:09 ——– d—–w- c:\program files\DataGuard
2012-06-29 15:51:21 ——– d—–w- c:\program files\Mozilla Maintenance Service
2012-06-29 15:51:00 157608 —-a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2012-06-29 15:51:00 113120 —-a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2012-06-29 15:50:59 770384 —-a-w- c:\program files\mozilla firefox\msvcr100.dll
2012-06-29 15:50:59 421200 —-a-w- c:\program files\mozilla firefox\msvcp100.dll
2012-06-28 15:42:31 299520 —-a-w- c:\windows\uninst.exe
2012-06-28 15:41:54 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2012-06-28 15:41:54 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2012-06-28 15:41:45 4672 —-a-w- c:\windows\system32\LXBOUSCI.DLL
2012-06-28 15:41:45 33792 —-a-w- c:\windows\system32\LXBOUSCI.EXE
2012-06-28 15:41:30 ——– d—–w- c:\program files\LexmarkX84-X85
2012-06-28 15:41:13 ——– d—–w- C:\Lxkx85
2012-06-27 21:07:17 ——– d—–w- c:\documents and settings\joe\application data\SUPERAntiSpyware.com
2012-06-27 21:07:01 ——– d—–w- c:\program files\SUPERAntiSpyware
2012-06-27 21:07:01 ——– d—–w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2012-06-27 19:55:57 ——– d—–w- c:\program files\common files\ODBC
2012-06-27 19:53:01 ——– d—–w- c:\windows\system32\NtmsData
2012-06-27 18:12:06 388216 —-a-w- c:\windows\system32\drivers\nis\1307010.005\symtdi.sys
2012-06-27 18:12:06 345208 —-a-w- c:\windows\system32\drivers\nis\1307010.005\symtdiv.sys
2012-06-27 18:12:06 318584 —-a-w- c:\windows\system32\drivers\nis\1307010.005\symnets.sys
2012-06-27 18:12:05 905336 —-a-w- c:\windows\system32\drivers\nis\1307010.005\symefa.sys
2012-06-27 18:12:05 574072 —-a-w- c:\windows\system32\drivers\nis\1307010.005\srtsp.sys
2012-06-27 18:12:05 340088 —-a-r- c:\windows\system32\drivers\nis\1307010.005\symds.sys
2012-06-27 18:12:05 32888 —-a-w- c:\windows\system32\drivers\nis\1307010.005\srtspx.sys
2012-06-27 18:12:05 149624 —-a-w- c:\windows\system32\drivers\nis\1307010.005\ironx86.sys
2012-06-27 18:12:05 132744 —-a-w- c:\windows\system32\drivers\nis\1307010.005\ccsetx86.sys
2012-06-27 18:11:38 ——– d—–w- c:\windows\system32\drivers\nis\1307010.005
2012-06-27 15:18:15 ——– d—–w- c:\windows\system32\LogFiles
2012-06-27 15:18:00 44024 —-a-r- c:\windows\system32\drivers\SymIM.sys
2012-06-27 14:38:40 60872 —-a-w- c:\windows\system32\S32EVNT1.DLL
2012-06-27 14:38:39 141944 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-06-27 14:38:39 ——– d—–w- c:\program files\Symantec
2012-06-27 14:38:39 ——– d—–w- c:\program files\common files\Symantec Shared
2012-06-27 14:37:01 ——– d—–w- c:\windows\system32\drivers\NIS
2012-06-27 14:36:58 ——– d—–w- c:\program files\Norton Internet Security
2012-06-27 14:12:09 ——– d—–w- c:\documents and settings\all users\application data\Norton
2012-06-27 14:08:35 ——– d—–w- c:\program files\NortonInstaller
2012-06-27 14:08:35 ——– d—–w- c:\documents and settings\all users\application data\NortonInstaller
2012-06-24 13:48:48 ——– d—–w- c:\documents and settings\joe\local settings\application data\CRE
2012-06-24 11:00:59 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-24 11:00:59 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-24 11:00:59 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-06-24 01:59:41 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-06-24 01:45:58 ——– d—–w- c:\windows\pss
2012-06-23 23:29:07 ——– d—–w- c:\documents and settings\joe\local settings\application data\WMTools Downloaded Files
2012-06-23 16:07:55 ——– d—–w- c:\windows\system32\wbem\repository\FS
2012-06-23 16:07:54 ——– d—–w- c:\windows\system32\wbem\Repository
2012-06-23 15:36:25 ——– d—–w- c:\program files\BitTorrent
2012-06-23 15:36:25 ——– d—–w- c:\documents and settings\joe\application data\BitTorrent
2012-06-22 11:32:03 ——– d—–w- c:\documents and settings\joe\application data\BitTorrent(3)
2012-06-16 13:37:21 ——– d—–w- c:\documents and settings\joe\application data\BitTorrent(2)
.
==================== Find3M ====================
.
2012-06-29 17:48:26 17488 —-a-w- c:\windows\gdrv.sys
2012-06-02 19:19:44 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19:38 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19:38 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32(3)(3).dll
2012-05-16 07:58:35 667136 —-a-w- c:\windows\system32\wininet.dll
2012-05-16 07:58:35 667136 —-a-w- c:\windows\system32\wininet(2)(2).dll
2012-05-15 13:20:33 1863168 —-a-w- c:\windows\system32\win32k.sys
2012-05-15 13:20:33 1863168 —-a-w- c:\windows\system32\win32k(2)(2).sys
2012-05-04 13:16:13 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32:19 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-27 02:00:59 73728 —-a-w- c:\windows\system32\javacpl.cpl
2012-04-27 02:00:58 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-04-20 19:29:52 81920 —-a-w- c:\windows\system32\ieencode.dll
2012-04-20 19:29:52 633344 —-a-w- c:\windows\system32\urlmon(2)(2).dll
2012-04-20 19:29:52 61952 —-a-w- c:\windows\system32\tdc.ocx
2012-04-20 19:29:52 37888 —-a-w- c:\windows\system32\url(2)(2).dll
2012-04-20 19:29:52 1510400 —-a-w- c:\windows\system32\shdocvw(2)(2).dll
2012-04-19 12:44:57 369664 —-a-w- c:\windows\system32\html.iec
2012-04-04 19:56:40 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 18:50:33.68 ===============







and the attach

Attachments:

Hello kadn55f

Thank you for the logs.


  • P2P Programs:


  • P2P programs are a major source of Malware infections.
  • From your log I see you have BitTorrent. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
  • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
  • If you wish to keep the program(s), please do not use them until your computer is cleaned.
  • Information regarding the risk of using these programs can be found from here and here.
  • It is strongly recommend that you uninstall any P2P programs you have on your system.
  • To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
  • A list of currently installed programs will be displayed.
  • Find the "BitTorrent" program, click on it once and then click on the "Remove" button.
  • If you are prompted to re-boot your computer to complete the uninstall please do so.


    PLEASE NOTE:
  • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.


You mentioned in your first post that you thought that your computer privacy was being invaded. What makes you think that this is the case?

Is the machine behaving strangely in any way? Once we have this information we'll continue :)
Due to lack of response, this topic is now closed. If you are the topic starter and need this topic reopened, please PM a staff member (include the address of this thread in your request). Everyone else please start a new topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI