I posted in the "Am I Infected?" forum where I was advised to post some log results and finally directed to this forum. I followed the steps for posting here, and I should note that the first time I tried to create the gmer log my computer froze (white screen with bluish diagonal lines) for a minute or so, then rebooted. Luckily it was at the beginning of the scan, because I ran it again and it took several hours to complete. All other logs were created without incident.
Thank you for all the help.
DDS log:.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by HP_Administrator at 13:43:44 on 2012-05-05
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.964 [GMT -4:00]
.
AV: Norton AntiVirus *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\Engine\19.7.0.9\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Norton AntiVirus\Engine\19.7.0.9\ccSvcHst.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\19.7.0.9\ips\IPSBHO.DLL
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe
mRun: [PCDrProfiler]
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Cmaudio8788] RunDll32 cmicnfgp.cpl,CMICtrlWnd
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [<NO NAME>]
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1 71.243.0.12
TCP: Interfaces\{513E3D03-091D-485D-BF24-104A4C4A914C} : DhcpNameServer = 192.168.1.1 71.243.0.12
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nav\1307000.009\symds.sys [2012-5-3 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1307000.009\symefa.sys [2012-5-3 905336]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_19.1.0.28\definitions\bashdefs\20120413.001\BHDrvx86.sys [2012-4-13 821880]
R1 ccSet_NAV;Norton AntiVirus Settings Manager;c:\windows\system32\drivers\nav\1307000.009\ccsetx86.sys [2012-5-3 132744]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nav\1307000.009\ironx86.sys [2012-5-3 149624]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-6 99328]
R2 NAV;Norton AntiVirus;c:\program files\norton antivirus\engine\19.7.0.9\ccsvchst.exe [2012-5-3 138232]
R3 cmudaxp;C-Media Oxygen HD Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [2012-5-2 1428544]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-5-3 106104]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_19.1.0.28\definitions\ipsdefs\20120505.001\IDSXpx86.sys [2012-5-4 356792]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_19.1.0.28\definitions\virusdefs\20120504.033\NAVENG.SYS [2012-5-5 86136]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_19.1.0.28\definitions\virusdefs\20120504.033\NAVEX15.SYS [2012-5-5 1576312]
.
=============== Created Last 30 ================
.
2012-05-05 14:32:56 -------- d-----w- c:\documents and settings\hp_administrator.desktop\application data\Malwarebytes
2012-05-05 14:32:47 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-05 14:32:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-05-05 14:32:47 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-05-04 22:28:42 -------- d-----w- c:\documents and settings\hp_administrator.desktop\local settings\application data\NPE
2012-05-04 22:03:03 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2012-05-04 22:02:54 229888 ------w- c:\windows\system32\dllcache\fxscover.exe
2012-05-04 22:02:26 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2012-05-04 22:01:06 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2012-05-04 21:58:19 105472 ------w- c:\windows\system32\dllcache\mup.sys
2012-05-04 21:55:15 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys
2012-05-04 21:55:08 3072 ------w- c:\windows\system32\iacenc.dll
2012-05-04 21:55:08 3072 ------w- c:\windows\system32\dllcache\iacenc.dll
2012-05-04 21:54:43 45568 ------w- c:\windows\system32\dllcache\wab.exe
2012-05-04 21:54:43 -------- d-----w- c:\documents and settings\hp_administrator.desktop\application data\HpUpdate
2012-05-04 21:53:57 139784 ------w- c:\windows\system32\dllcache\rdpwd.sys
2012-05-04 00:16:24 48128 ------w- c:\windows\system32\dllcache\iyuv_32.dll
2012-05-04 00:16:01 6144 ------w- c:\windows\system32\dllcache\iecompat.dll
2012-05-03 23:58:46 -------- d-----w- c:\windows\system32\scripting
2012-05-03 23:58:46 -------- d-----w- c:\windows\system32\en
2012-05-03 23:58:46 -------- d-----w- c:\windows\system32\bits
2012-05-03 23:26:51 20992 ------w- c:\windows\system32\spupdwxp.exe
2012-05-03 23:25:59 13776 ------w- c:\windows\system32\drivers\recagent.sys
2012-05-03 23:24:45 33792 ------w- c:\windows\system32\mmcperf.exe
2012-05-03 23:21:44 388216 ----a-w- c:\windows\system32\drivers\nav\1307000.009\symtdi.sys
2012-05-03 23:21:44 345208 ----a-w- c:\windows\system32\drivers\nav\1307000.009\symtdiv.sys
2012-05-03 23:21:43 905336 ----a-w- c:\windows\system32\drivers\nav\1307000.009\symefa.sys
2012-05-03 23:21:43 318584 ----a-w- c:\windows\system32\drivers\nav\1307000.009\symnets.sys
2012-05-03 23:21:42 340088 ----a-r- c:\windows\system32\drivers\nav\1307000.009\symds.sys
2012-05-03 23:21:42 32888 ----a-w- c:\windows\system32\drivers\nav\1307000.009\srtspx.sys
2012-05-03 23:21:41 574072 ----a-w- c:\windows\system32\drivers\nav\1307000.009\srtsp.sys
2012-05-03 23:21:41 149624 ----a-w- c:\windows\system32\drivers\nav\1307000.009\ironx86.sys
2012-05-03 23:21:40 132744 ----a-w- c:\windows\system32\drivers\nav\1307000.009\ccsetx86.sys
2012-05-03 23:20:46 -------- d-----w- c:\windows\system32\drivers\nav\1307000.009
2012-05-03 23:08:01 -------- d-s---w- c:\documents and settings\hp_administrator.desktop\UserData
2012-05-03 23:07:54 456320 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2012-05-03 23:07:46 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2012-05-03 23:05:55 730112 ------w- c:\windows\system32\dllcache\lsasrv.dll
2012-05-03 23:05:55 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2012-05-03 23:05:55 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2012-05-03 23:05:55 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2012-05-03 23:05:55 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2012-05-03 23:05:55 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2012-05-03 23:05:55 110592 ------w- c:\windows\system32\dllcache\services.exe
2012-05-03 23:05:54 718336 ------w- c:\windows\system32\dllcache\ntdll.dll
2012-05-03 23:05:54 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2012-05-03 23:05:54 2192768 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2012-05-03 23:05:54 2148864 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2012-05-03 23:05:53 2027008 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2012-05-03 23:03:10 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2012-05-03 23:02:14 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2012-05-03 23:01:01 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2012-05-03 23:01:01 218112 ------w- c:\windows\system32\dllcache\wordpad.exe
2012-05-03 23:00:49 272128 ------w- c:\windows\system32\drivers\bthport.sys
2012-05-03 23:00:49 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2012-05-03 23:00:37 357888 ------w- c:\windows\system32\dllcache\srv.sys
2012-05-03 23:00:11 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2012-05-03 22:59:57 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2012-05-03 22:59:57 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2012-05-03 22:59:26 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-05-03 22:59:26 476960 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-05-03 22:59:26 472864 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-03 22:51:45 -------- d-----w- c:\windows\system32\PreInstall
2012-05-03 06:46:50 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-05-03 06:46:47 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2012-05-03 06:46:44 6144 ----a-w- c:\windows\system32\kbd106.dll
2012-05-03 06:46:43 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2012-05-03 06:46:42 21504 ----a-w- c:\windows\system32\hidserv.dll
2012-05-03 06:46:39 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-05-03 05:23:26 -------- d-sh--r- c:\windows\system32\dllcache
2012-05-03 04:14:51 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2012-05-03 04:14:50 602112 ------w- c:\windows\system32\dllcache\msfeeds.dll
2012-05-03 04:14:50 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-05-03 04:14:50 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2012-05-03 04:14:50 2000384 ------w- c:\windows\system32\dllcache\iertutil.dll
2012-05-03 04:14:49 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2012-05-03 04:14:49 11082752 ------w- c:\windows\system32\dllcache\ieframe.dll
2012-05-03 04:04:14 60872 ----a-w- c:\windows\system32\S32EVNT1.DLL
2012-05-03 04:04:14 141944 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-05-03 04:03:20 -------- d-----w- c:\windows\system32\drivers\NAV
2012-05-03 04:03:17 -------- d-----w- c:\program files\Norton AntiVirus
2012-05-03 03:22:02 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2012-05-03 03:21:53 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2012-05-03 03:21:48 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-05-03 03:08:02 -------- d-----w- c:\windows\system32\appmgmt
2012-05-03 02:59:50 712704 ----a-r- c:\windows\system32\Audio3Dp.dll
2012-05-03 02:59:50 151623 ----a-r- c:\windows\system32\cmasiop.dll
2012-05-03 02:59:49 712704 ----a-w- c:\windows\system32\dllcache\a3d.dll
2012-05-03 02:59:49 712704 ----a-r- c:\windows\system32\a3d.dll
2012-05-03 02:59:49 32768 ----a-r- c:\windows\system32\cmudaxp.dll
2012-05-03 02:59:49 32768 ----a-r- c:\windows\system32\CmPropP.dll
2012-05-03 02:59:49 28672 ----a-r- c:\windows\system32\cmrmdrvp.dll
2012-05-03 02:59:49 253952 ----a-r- c:\windows\system32\cmrmdrvp.exe
2012-05-03 02:59:49 1428544 ----a-r- c:\windows\system32\drivers\cmudaxp.sys
2012-05-03 02:58:25 -------- d-sh--w- C:\cmdcons
2012-05-03 02:51:40 -------- d-----w- c:\windows\system32\SoftwareDistribution
2012-05-02 22:25:13 -------- d-----w- c:\documents and settings\all users\application data\PCSettings
2012-04-27 03:34:05 88064 ----a-w- c:\documents and settings\all users\application data\388cLdcK.exe
.
==================== Find3M ====================
.
2012-05-04 00:02:21 45056 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\uninstallui\eHelpSetup.exe
2012-05-04 00:02:20 61440 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemutil.dll
2012-05-04 00:02:20 44032 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\scripts\devcon.exe
2012-05-04 00:02:20 40960 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\ScDmi.dll
2012-05-04 00:02:20 341048 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\HPBasicDetection3.dll
2012-05-04 00:02:20 32768 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\uploadHSC.dll
2012-05-04 00:02:20 32768 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\Scom.dll
2012-05-04 00:02:20 163840 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemcheck.dll
2012-03-01 11:01:32 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01:32 43520 ------w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01:32 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10:16 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10:16 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17:40 385024 ------w- c:\windows\system32\html.iec
.
============= FINISH: 13:47:03.84 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top











