This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Strange things happening [Closed] [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Guys, Using an old Windows XP machine that my wife uses for the Internet. Complained because a Java app wouldn't work in a Girl Guiding site. Also complains because it's slow, also had to do 2 goes at doing the recent Windows Update. Tried to update Java but kep failing. Uninstalled and installed again but Java verifcation fails.. Tried running the OTL tool but it was corrupt. Ran DDS, and this is the output… . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 16:04:48.50 on 11/07/2013 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.25.2 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.356 [GMT 1:00] . AV: Norton 360 *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton 360 *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe C:\Program Files\Pure Networks\Network Magic\nmapp.exe C:\Program Files\Virgin Media\Digital Home Support\DHSClient.exe C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE C:\Program Files\Virgin Media\Digital Home Support\HsdService.exe C:\Program Files\Norton Management\Engine\3.2.0.19\ccSvcHst.exe C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\Program Files\Virgin Media\Service Manager\ServicepointService.exe C:\WINDOWS\System32\tcpsvcs.exe C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe C:\Program Files\Norton Management\Engine\3.2.0.19\ccSvcHst.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Webroot\Washer\WasherSvc.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe C:\Program Files\Java\jre7\bin\jqs.exe C:\Documents and Settings\Home\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZU&fl=0&ptb=5gwcvK9KE3eV3suLgnoEUg&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms} uSearch Bar = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR uStart Page = hxxp://uk.yahoo.com/ uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyServer = 192.168.1.1:80 uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\20.4.0.40\coIEPlg.dll BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\20.4.0.40\ips\IPSBHO.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\20.4.0.40\coIEPlg.dll uRun: [Window Washer] "c:\program files\webroot\washer\wwDisp.exe" uRun: [\\New_Home\EPSON Stylus SX200 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiefe.exe /fu "c:\windows\temp\E_S2FC.tmp" /EF "HKCU" uRun: [Auto EPSON Stylus SX200 Series on New_Home] c:\windows\system32\spool\drivers\w32x86\3\e_fatiefe.exe /fu "c:\windows\temp\E_S39.tmp" /EF "HKCU" uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe" -s uRunOnce: [Index Washer] c:\program files\webroot\washer\WashIdx.exe "Home" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe" mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash mRun: [DHSClient.exe] "c:\program files\virgin media\digital home support\DHSClient.exe" /AUTORUN mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE uPolicies-explorer: NoActiveDesktop = 01000000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.euro.dell.com/systemprofiler/SysPro.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} - hxxp://www.pcpitstop.com/internet/pcpConnCheck.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} - hxxp://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://spaces.msn.com//PhotoUpload/MsnPUpld.cab DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.geni.com/ImageUploader5.cab DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342016991031 DPF: {6F0892F7-0D44-41C3-BF07-7599873FAA04} - hxxps://go.girlguiding.org.uk/crystalreportviewers115/ActiveXControls/ActiveXViewer.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - hxxps://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} - hxxp://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://webcam.fba.org.uk/activex/AMC.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab DPF: {F09BFD07-20B5-46D8-A6D5-BE4EF22F1F4D} DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxsrvc.dll Notify: WRNotifier - WRLogonNTF.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll, . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\home\applic~1\mozilla\firefox\profiles\phayyqil.default\ FF - prefs.js: browser.startup.homepage - hxxp://uk.yahoo.com/ FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll FF - plugin: c:\program files\virgin media\service manager\nprpspa.dll FF - plugin: c:\windows\system32\adobe\director\np32dsw_1166636.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_202.dll . ============= SERVICES / DRIVERS =============== . R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2007-5-30 38448] R0 OEMBase;SONY USB CAMERA Base Driver;c:\windows\system32\drivers\u1pvcbs.sys [2005-3-5 8593] R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\1404000.028\symds.sys [2013-6-17 367704] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\1404000.028\symefa.sys [2013-6-17 934488] R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.1.2\definitions\bashdefs\20130702.001\BHDrvx86.sys [2013-7-3 1002072] R1 ccSet_MCLIENT;Norton Management Settings Manager;c:\windows\system32\drivers\mclient\0302000.013\ccsetx86.sys [2012-10-23 134304] R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\1404000.028\ccsetx86.sys [2013-6-17 134744] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\1404000.028\ironx86.sys [2013-6-17 175264] R2 HsdService;HsdService;c:\program files\virgin media\digital home support\HsdService.exe [2011-5-4 1406264] R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2002-8-29 14336] R2 MCLIENT;Norton Management;c:\program files\norton management\engine\3.2.0.19\ccsvchst.exe [2012-10-23 143928] R2 N360;Norton 360;c:\program files\norton 360\engine\20.4.0.40\ccsvchst.exe [2013-6-17 144368] R2 PDFSfilter;PDFsFilter;c:\windows\system32\drivers\PDFsFilter.sys [2012-8-23 69016] R2 ServicepointService;ServicepointService;c:\program files\virgin media\service manager\ServicepointService.exe [2011-5-4 689464] R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2005-11-16 2368] R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2013-3-22 93072] R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2009-5-23 598856] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2013-1-15 106656] R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.1.2\definitions\ipsdefs\20130710.001\IDSXpx86.sys [2013-7-10 373728] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.1.2\definitions\virusdefs\20130711.001\NAVENG.SYS [2013-7-11 93272] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.1.2\definitions\virusdefs\20130711.001\NAVEX15.SYS [2013-7-11 1611992] S2 Ca533av;Trust 730S LCD PowerC@M ZOOM, WDM Video Capture;c:\windows\system32\drivers\ca533av.sys –> c:\windows\system32\drivers\Ca533av.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate1c986149c43f6dc;Google Update Service (gupdate1c986149c43f6dc);c:\program files\google\update\GoogleUpdate.exe [2009-2-3 133104] S2 ioloFileInfoList;iolo FileInfoList Service; [x] S2 ioloSystemService;iolo System Service; [x] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944] S3 AWHelpServer;Alias Wavefront Help Server; [x] S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2012-9-18 23456] S3 FASTNIC;Sitecom PCI Fast 10/100 Ethernet Adapter LN-020;c:\windows\system32\drivers\FASTNIC.sys [2004-7-11 38528] S3 GemCCID;GemCCID;c:\windows\system32\drivers\gemccid.sys –> c:\windows\system32\drivers\GemCCID.sys [?] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-2-3 133104] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-10 117144] S3 NokiaSuite3;NokiaSuite3;c:\windows\system32\drivers\NokiaSuite3.sys [2005-3-24 837696] S3 OEMStream;SONY USB CAMERA Video Capture Device;c:\windows\system32\drivers\u1pvcsm.sys [2005-3-5 251539] S3 PCDSRVC{E9D79540-57D5953E-06020200}_0;PCDSRVC{E9D79540-57D5953E-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2012-11-26 22640] S3 pgusbwdm;usb-audio.de driver (commercial V2.6.1);c:\windows\system32\drivers\pgusbwdm.sys [2007-6-3 99200] S3 ptiusbf;PTI USB Filter;c:\windows\system32\drivers\ptiusbf.sys –> c:\windows\system32\drivers\PTIUSBF.SYS [?] S3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [2006-7-4 11520] S3 USBAV191;Instant VideoXpress;c:\windows\system32\drivers\USBAV191.SYS [2005-12-27 120128] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2002-8-29 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-4-18 754856] . =============== File Associations =============== . JSEFile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 . =============== Created Last 30 ================ . 2013-07-11 10:40:26 ——– d—–w- c:\windows\system32\MRT 2013-07-11 10:32:24 144896 —-a-w- c:\windows\system32\javacpl.cpl 2013-07-11 10:32:16 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-06-24 15:07:17 44064 —-a-r- c:\windows\system32\drivers\SymIM.sys 2013-06-17 14:06:09 396760 —-a-w- c:\windows\system32\drivers\n360\1404000.028\symtdi.sys 2013-06-17 14:06:09 352344 —-a-w- c:\windows\system32\drivers\n360\1404000.028\symtdiv.sys 2013-06-17 14:06:09 339544 —-a-w- c:\windows\system32\drivers\n360\1404000.028\symnets.sys 2013-06-17 14:06:09 21400 —-a-r- c:\windows\system32\drivers\n360\1404000.028\symelam.sys 2013-06-17 14:06:08 934488 —-a-w- c:\windows\system32\drivers\n360\1404000.028\symefa.sys 2013-06-17 14:06:08 603224 —-a-w- c:\windows\system32\drivers\n360\1404000.028\srtsp.sys 2013-06-17 14:06:08 367704 —-a-w- c:\windows\system32\drivers\n360\1404000.028\symds.sys 2013-06-17 14:06:08 32344 —-a-w- c:\windows\system32\drivers\n360\1404000.028\srtspx.sys 2013-06-17 14:06:08 175264 —-a-w- c:\windows\system32\drivers\n360\1404000.028\ironx86.sys 2013-06-17 14:06:08 134744 —-a-w- c:\windows\system32\drivers\n360\1404000.028\ccsetx86.sys 2013-06-17 14:05:19 14818 —-a-w- c:\windows\system32\drivers\n360\1404000.028\symvtcer.dat 2013-06-17 14:05:18 ——– d—–w- c:\windows\system32\drivers\n360\1404000.028 . ==================== Find3M ==================== . 2013-07-11 10:31:30 867240 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-07-11 10:31:30 789416 —-a-w- c:\windows\system32\deployJava1.dll 2013-07-11 10:09:12 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-07-11 10:09:12 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-06-07 22:55:44 385024 —-a-w- c:\windows\system32\html.iec 2013-06-07 21:56:06 920064 —-a-w- c:\windows\system32\wininet.dll 2013-06-07 21:56:06 43520 —-a-w- c:\windows\system32\licmgr10.dll 2013-06-07 21:56:05 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2013-06-04 07:23:02 562688 —-a-w- c:\windows\system32\qedit.dll 2013-06-04 01:40:45 1876736 —-a-w- c:\windows\system32\win32k.sys 2013-05-10 11:43:16 1696256 —-a-w- c:\windows\system32\wmv9vcm.dll 2013-05-08 23:28:02 1543680 —-a-w- c:\windows\system32\wmvdecod.dll 2013-05-03 01:30:20 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-05-03 00:38:17 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe 2005-12-21 15:19:04 774144 —-a-w- c:\program files\RngInterstitial.dll . ============= FINISH: 16:05:46.51 ===============
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi Marius,

Many thanks for your help.

Here is the contents of ark.txt


————————————————

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-13 14:34:24
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0 WDC_WD12 rev.15.0 111.76GB
Running: 90n1vwym.exe; Driver: C:\DOCUME~1\Home\LOCALS~1\Temp\fxtdypob.sys


—- System - GMER 2.1 —-

SSDT 85EA8FD0 ZwAlertResumeThread
SSDT 85EC0A18 ZwAlertThread
SSDT 8627C398 ZwAllocateVirtualMemory
SSDT 85D99808 ZwAssignProcessToJobObject
SSDT 85C50A58 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwCreateKey [0xB411AED0]
SSDT 85D91008 ZwCreateMutant
SSDT 85CE7650 ZwCreateSymbolicLinkObject
SSDT 85D91278 ZwCreateThread
SSDT 862299B8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteKey [0xB411B150]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteValueKey [0xB411B810]
SSDT 85C474E0 ZwDuplicateObject
SSDT 862B9F40 ZwFreeVirtualMemory
SSDT 85EA8B50 ZwImpersonateAnonymousToken
SSDT 85EA8CD8 ZwImpersonateThread
SSDT 85E98E90 ZwLoadDriver
SSDT 85FBCB38 ZwMapViewOfSection
SSDT 85EA65C8 ZwOpenEvent
SSDT 8627B6B0 ZwOpenProcess
SSDT 85EC58D0 ZwOpenProcessToken
SSDT 85E09060 ZwOpenSection
SSDT 861EE7F8 ZwOpenThread
SSDT 861F2678 ZwProtectVirtualMemory
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwRenameKey [0xB411BD70]
SSDT 85EC40C0 ZwResumeThread
SSDT 85EC4B90 ZwSetContextThread
SSDT 862BF580 ZwSetInformationProcess
SSDT 8624EE18 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwSetValueKey [0xB411BA90]
SSDT 85D91060 ZwSuspendProcess
SSDT 85EC4450 ZwSuspendThread
SSDT 85EC69C8 ZwTerminateProcess
SSDT 85EC4950 ZwTerminateThread
SSDT 85EC5190 ZwUnmapViewOfSection
SSDT 86203DC0 ZwWriteVirtualMemory

—- Devices - GMER 2.1 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS

Device \Driver\prodrv06 \Device\ProDrv06 E274C798

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 hotcore3.sys
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 hotcore3.sys

Device \Driver\IdeChnDr \Device\Ide\IdeDeviceP1T0L0 prosync1.sys
Device \Driver\IdeChnDr \Device\Ide\IdeDeviceP1T1L0 prosync1.sys
Device \Driver\IdeChnDr \Device\Ide\IdeDeviceP0T0L0 prosync1.sys
Device \Driver\IdeChnDr \Device\Ide\IdeChnDr0 prosync1.sys
Device \Driver\IdeChnDr \Device\Ide\IdeChnDr1 prosync1.sys
Device \Driver\IdeChnDr \Device\Ide\IdeDeviceP0T1L0 prosync1.sys

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 hotcore3.sys

Device \Driver\prohlp02 \Device\ProHlp02 E1B74E08

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS

Device mrxsmb.sys
Device \Driver\aic78xx \Device\Scsi\aic78xx1 prosync1.sys
Device Fastfat.SYS

AttachedDevice fltmgr.sys

—- Registry - GMER 2.1 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\PDFSfilter\Parameters\{7d3c4abe-adb5-11d8-99e1-806d6172696f}@NumExtendFileExtentsSaved 467064
Reg HKLM\SYSTEM\RAdmin\v2.0
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\tÀ 0x1C 0xA1 0xB0 0xC5 …
Reg HKLM\SYSTEM\RAdmin\v2.0\
Reg HKLM\SYSTEM\RAdmin\v2.0\@þÿ\0\0ÿÿ\20À 0xA4 0x23 0x23 0x4F …
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\temp\aulauncher.exe 1

—- EOF - GMER 2.1 —-
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications


====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Hi Marius,

I ran Combofix and include the log file below.

One thing that surprised me was that it deleted files.

————————————————–

ComboFix 13-07-14.01 - Home 14/07/2013 16:59:19.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.349 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Home\WINDOWS
c:\program files\Luxor 2
c:\program files\Luxor 2\3rdparty.gvf
c:\program files\Luxor 2\assets\splashscreen.jpg
c:\program files\Luxor 2\assets\Thumbs.db
c:\program files\Luxor 2\data.mjz
c:\program files\Luxor 2\DSETUP.dll
c:\program files\Luxor 2\engine.dll
c:\program files\Luxor 2\file.dll
c:\program files\Luxor 2\fmodex.dll
c:\program files\Luxor 2\gfx.dll
c:\program files\Luxor 2\gfx_dd7.dll
c:\program files\Luxor 2\gfx_dx8.dll
c:\program files\Luxor 2\img_jpg.dll
c:\program files\Luxor 2\img_png.dll
c:\program files\Luxor 2\img_tga.dll
c:\program files\Luxor 2\locale\english.mjz
c:\program files\Luxor 2\logger.dll
c:\program files\Luxor 2\luxor2.exe
c:\program files\Luxor 2\luxor2.html
c:\program files\Luxor 2\platform.dll
c:\program files\Luxor 2\Read_Me.html
c:\program files\Luxor 2\snd3d.dll
c:\program files\Luxor 2\snd3d_fmod.dll
c:\program files\Luxor 2\thread.dll
c:\program files\Luxor 2\Uninstall.exe
c:\windows\system\DPLAY.DLL
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_FAD
.
.
((((((((((((((((((((((((( Files Created from 2013-06-14 to 2013-07-14 )))))))))))))))))))))))))))))))
.
.
2013-07-11 10:40 . 2013-07-11 10:46 ——– d—–w- c:\windows\system32\MRT
2013-07-11 10:32 . 2013-07-11 10:31 144896 —-a-w- c:\windows\system32\javacpl.cpl
2013-07-11 10:32 . 2013-07-11 10:31 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-06-24 15:07 . 2013-03-05 02:14 44064 —-a-r- c:\windows\system32\drivers\SymIM.sys
2013-06-17 14:05 . 2013-06-24 15:05 ——– d—–w- c:\windows\system32\drivers\N360\1404000.028
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-11 10:31 . 2012-08-01 13:58 867240 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-07-11 10:31 . 2010-05-05 10:59 789416 —-a-w- c:\windows\system32\deployJava1.dll
2013-07-11 10:09 . 2013-03-02 19:24 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-11 10:09 . 2013-03-02 19:24 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-17 22:38 . 2010-09-03 15:47 142496 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2013-06-07 22:55 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2013-06-07 21:56 . 2004-02-06 17:05 920064 —-a-w- c:\windows\system32\wininet.dll
2013-06-07 21:56 . 2002-08-29 04:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-06-07 21:56 . 2002-08-29 04:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2013-06-04 07:23 . 2002-12-11 23:14 562688 —-a-w- c:\windows\system32\qedit.dll
2013-06-04 01:40 . 2002-08-29 04:00 1876736 —-a-w- c:\windows\system32\win32k.sys
2013-05-10 11:43 . 2003-06-23 01:44 1696256 —-a-w- c:\windows\system32\wmv9vcm.dll
2013-05-08 23:28 . 2006-10-18 21:47 1543680 —-a-w- c:\windows\system32\wmvdecod.dll
2013-05-03 01:30 . 1979-12-31 23:00 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-05-03 00:38 . 1979-12-31 23:00 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe
2005-12-21 15:19 . 2005-12-21 15:19 774144 —-a-w- c:\program files\RngInterstitial.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2007-11-26 1206600]
"\\New_Home\EPSON Stylus SX200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIEFE.EXE" [2007-12-13 188928]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2013-03-22 248208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2009-07-08 472112]
"DHSClient.exe"="c:\program files\Virgin Media\Digital Home Support\DHSClient.exe" [2011-03-23 2032952]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2012-04-18 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE -b -l [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HsdService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\rtcshare.exe"=
"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=
"c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"c:\\Program Files\\messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Virgin Media\\Service Manager\\ServicepointService.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe"= c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet,0.0.0.0/255.255.255.255:Enabled:Pure Networks Platform Service
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 hotcore3;hotcore3;c:\windows\SYSTEM32\DRIVERS\hotcore3.sys [30/05/2007 14:47 38448]
R0 OEMBase;SONY USB CAMERA Base Driver;c:\windows\SYSTEM32\DRIVERS\u1pvcbs.sys [05/03/2005 21:37 8593]
R0 SymDS;Symantec Data Store;c:\windows\SYSTEM32\DRIVERS\N360\1404000.028\symds.sys [17/06/2013 15:06 367704]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\N360\1404000.028\symefa.sys [17/06/2013 15:06 934488]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\BASHDefs\20130702.001\BHDrvx86.sys [03/07/2013 14:52 1002072]
R1 ccSet_MCLIENT;Norton Management Settings Manager;c:\windows\SYSTEM32\DRIVERS\MCLIENT\0302000.013\ccsetx86.sys [23/10/2012 11:56 134304]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\SYSTEM32\DRIVERS\N360\1404000.028\ccsetx86.sys [17/06/2013 15:06 134744]
R1 SymIRON;Symantec Iron Driver;c:\windows\SYSTEM32\DRIVERS\N360\1404000.028\ironx86.sys [17/06/2013 15:06 175264]
R2 HsdService;HsdService;c:\program files\Virgin Media\Digital Home Support\HsdService.exe [04/05/2011 16:01 1406264]
R2 Iprip;RIP Listener;c:\windows\System32\svchost.exe -k netsvcs [29/08/2002 05:00 14336]
R2 MCLIENT;Norton Management;c:\program files\Norton Management\Engine\3.2.0.19\ccsvchst.exe [23/10/2012 11:56 143928]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\20.4.0.40\ccsvchst.exe [17/06/2013 15:05 144368]
R2 PDFSfilter;PDFsFilter;c:\windows\SYSTEM32\DRIVERS\PDFsFilter.sys [23/08/2012 17:56 69016]
R2 ServicepointService;ServicepointService;c:\program files\Virgin Media\Service Manager\ServicepointService.exe [04/05/2011 16:00 689464]
R2 SVKP;SVKP;c:\windows\SYSTEM32\SVKP.sys [16/11/2005 10:40 2368]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [22/03/2013 06:07 93072]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [23/05/2009 00:04 598856]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [15/01/2013 14:17 106656]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\IPSDefs\20130712.001\IDSXpx86.sys [13/07/2013 12:45 373728]
S2 Ca533av;Trust 730S LCD PowerC@M ZOOM, WDM Video Capture;c:\windows\system32\Drivers\Ca533av.sys –> c:\windows\system32\Drivers\Ca533av.sys [?]
S2 gupdate1c986149c43f6dc;Google Update Service (gupdate1c986149c43f6dc);c:\program files\Google\Update\GoogleUpdate.exe [03/02/2009 16:31 133104]
S2 ioloFileInfoList;iolo FileInfoList Service; [x]
S2 ioloSystemService;iolo System Service; [x]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13/07/2012 13:28 160944]
S3 AWHelpServer;Alias Wavefront Help Server; [x]
S3 DrvAgent32;DrvAgent32;c:\windows\SYSTEM32\DRIVERS\DrvAgent32.sys [18/09/2012 15:15 23456]
S3 FASTNIC;Sitecom PCI Fast 10/100 Ethernet Adapter LN-020;c:\windows\SYSTEM32\DRIVERS\FASTNIC.sys [11/07/2004 16:03 38528]
S3 GemCCID;GemCCID;c:\windows\system32\Drivers\GemCCID.sys –> c:\windows\system32\Drivers\GemCCID.sys [?]
S3 NokiaSuite3;NokiaSuite3;c:\windows\SYSTEM32\DRIVERS\NokiaSuite3.sys [24/03/2005 22:12 837696]
S3 OEMStream;SONY USB CAMERA Video Capture Device;c:\windows\SYSTEM32\DRIVERS\u1pvcsm.sys [05/03/2005 21:37 251539]
S3 PCDSRVC{E9D79540-57D5953E-06020200}_0;PCDSRVC{E9D79540-57D5953E-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\Dell Support Center\pcdsrvc.pkms [26/11/2012 20:50 22640]
S3 pgusbwdm;usb-audio.de driver (commercial V2.6.1);c:\windows\SYSTEM32\DRIVERS\pgusbwdm.sys [03/06/2007 12:33 99200]
S3 ptiusbf;PTI USB Filter;c:\windows\system32\DRIVERS\PTIUSBF.SYS –> c:\windows\system32\DRIVERS\PTIUSBF.SYS [?]
S3 scsiscan;SCSI Scanner Driver;c:\windows\SYSTEM32\DRIVERS\scsiscan.sys [04/07/2006 10:10 11520]
S3 USBAV191;Instant VideoXpress;c:\windows\SYSTEM32\DRIVERS\USBAV191.SYS [27/12/2005 01:44 120128]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2013-07-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-01 16:09]
.
2013-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 15:30]
.
2013-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 15:30]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZU&fl;=0&ptb;=5gwcvK9KE3eV3suLgnoEUg&url;=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st;=sb&searchfor;={searchTerms}
uStart Page = hxxp://uk.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 192.168.1.1:80
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
TCP: DhcpNameServer = 192.168.0.1
DPF: {6F0892F7-0D44-41C3-BF07-7599873FAA04} - hxxps://go.girlguiding.org.uk/crystalreportviewers115/ActiveXControls/ActiveXViewer.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://webcam.fba.org.uk/activex/AMC.cab
DPF: {F09BFD07-20B5-46D8-A6D5-BE4EF22F1F4D}
FF - ProfilePath - c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\phayyqil.default\
FF - prefs.js: browser.startup.homepage - hxxp://uk.yahoo.com/
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-svcWRSSSDK
AddRemove-Luxor 2 - c:\program files\Luxor 2\Uninstall.exe
AddRemove-SnapTrack - c:\program files\SnapTrack\Uninst.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-07-14 17:15
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files:
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MCLIENT]
"ImagePath"="\"c:\program files\Norton Management\Engine\3.2.0.19\ccSvcHst.exe\" /s \"MCLIENT\" /m \"c:\program files\Norton Management\Engine\3.2.0.19\diMaster.dll\" /prefetch:1"
–
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\20.4.0.40\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PCDSRVC{E9D79540-57D5953E-06020200}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1752798392-3228812582-103374333-1006\RemoteAccess\Profile\xÞt`Þt*]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
.
[HKEY_USERS\S-1-5-21-1752798392-3228812582-103374333-1006\RemoteAccess\Profile\x *]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2608)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Bonjour\mDNSResponder.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\windows\System32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\Common Files\Raxco\Shared\PDEngine.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2013-07-14 17:19:42 - machine was rebooted
ComboFix-quarantined-files.txt 2013-07-14 16:19
.
Pre-Run: 81,728,299,008 bytes free
Post-Run: 81,947,009,024 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 39131DDA44929671A1C275BB1E9A033C
8F558EB6672622401DA993E1E865C861
Hi Marius, Tried to upload the Zip file and received this message… Malware Submission There was an error uploading your file. Your file is either 0 bytes or has exceeded the maximum file size of 5MB that we allow to be uploaded. Checked the file size and it's 19,393kb.
OK, then check the zip via VirusTotal and post the log:


Please check the file in the code box via Virustotal
  • Click browse
  • copy the following into the search box
  • and click open.
  • click Send File.
please be patinet until the file is uploade completely. If you get the message

File already submitted: The file sent has already been analysed by VirusTotal in the past. This is same basic info regarding the sample itself and its last analysis:

click on Reanalyse. Wait until Current status: Finished appears. Now, copy the link from within your browser´s adress bar and poste it here.
Full System Scan with Malwarebytes Antimalware

  • If not existing, please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If the program is already installed:
  • Run Malwarebytes Antimalware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform fullscan, place a checkmark on all hard drives, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.
Hi Marius, Here is the log file from Malwarebytes. ——————————————————– Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.07.15.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Home :: STUDY [administrator] 15/07/2013 09:25:53 MBAM-log-2013-07-15 (12-09-51).txt Scan type: Full scan (C:\|F:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 353584 Time elapsed: 1 hour(s), 35 minute(s), 37 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKLM\SYSTEM\CurrentControlSet\Services\SVKP (Trojan.Agent) -> No action taken. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 5 C:\Documents and Settings\Home\My Documents\Laptop_Documents\MyDocuments\Downloads\repairsetup.exe (Rogue.ErrorRepairProfessional) -> No action taken. C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\PopUninstall.exe (Trojan.FakeAlert.RRE) -> No action taken. F:\My_Documents_4\Documents\ZIP Files\Torrent_stuff\Downloads\hard.disk.tools.[All]\Acronis Disk Director Suite v10.0.2117\Keygen.exe (RiskWare.Tool.HCK) -> No action taken. F:\My_Documents_4\Documents\Laptop_Documents\MyDocuments\Downloads\repairsetup.exe (Rogue.ErrorRepairProfessional) -> No action taken. C:\WINDOWS\SYSTEM32\SVKP.sys (Trojan.Agent) -> No action taken. (end)
We don´t support any illegal operations. Please remove any and all cracked/illegal software from your computer before we continue. If we run into evidence of such files again, your topic will be closed. Report when you´re done.
Hi Marius, I only used Torrent for a short time many years ago and didn't like it. This was removed way back, as I said this is an old XP PC most software has been removed from here. Malwarebytes wouldn't let me continue without choosing to delete these files, so all 5 of these have now been removed.
Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Hi Marius, Scan complete. Text File created, contents below… ————————————————————————— C:\Documents and Settings\Home\My Documents\Laptop_Documents\MyDocuments\Downloads\fo-www6.exe probably a variant of Win32/Spy.VB.BOOHXUL trojan C:\Documents and Settings\Home\My Documents\Laptop_Documents\MyDocuments\Downloads\Window_Washer_6.0_2005\fo-www6.exe probably a variant of Win32/Spy.VB.BOOHXUL trojan F:\My_Documents_4\Downloads\YTDSetup.exe a variant of Win32/Bundled.Toolbar.Ask.D application

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI