Previous to Norton they had AVG installed. I doubt they would have had any firewall software apart from windows own.
Basically whilst they had AVG on they picked up a Security Tool virus that kept doing a fake file scan everytime windows booted up, they managed to get rid of that and removed AVG then I installed Norton once Norton completed it did a reboot and when XP booted up again Explorer was gone and Norton flashed up warning saying it had found Suspicious.Mystic.
I'm limited in knowing what is on the computer because all I have is the desktop Background and the cursor I have been able to access and browse files through Task Manager but not much else.
From browsing on the internet I have looked through processes and the Registry and there doesn't to be any Suspicious.Mystic files, but I'm sure they are there.
Any help getting rid of this would be greatly appreciated.
DDS (Ver_10-11-10.01) - NTFSx86
Run by Maureen at 19:21:13.84 on 17/11/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1271.837 [GMT 0:00]
AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\regedit.exe
E:\Mark\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://aol.co.uk/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.1.0.32\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.1.0.32\IPSBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\4.1.0.32\coIEPlg.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [ActivFilter] c:\program files\activ software\activdriver\ActivFilter.exe
mRun: [ActivControl] c:\program files\activ software\activdriver\ActivControl2.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRun: [sniffer] c:\windows\temp\_ex-08.exe
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYATgBKADMAMgAtAEcAMwBMAEEAQQ"&"inst=NwA3AC0ANAA1ADkANAAzADkAOQA4ADUALQBUAEI"&"prod=90"&"ver=9.0.864
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\maureen\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0401000.020\SymDS.sys [2010-11-15 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0401000.020\SymEFA.sys [2010-11-15 172592]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20100211.001\BHDrvx86.sys [2010-11-15 536112]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0401000.020\cchpx86.sys [2010-11-15 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0401000.020\Ironx86.sys [2010-11-15 116784]
R2 N360;Norton 360;c:\program files\norton 360\engine\4.1.0.32\ccSvcHst.exe [2010-11-15 126392]
R3 ActivHIDSerMini;Promethean Serial Board Driver;c:\windows\system32\drivers\activhidsermini.sys [2006-10-4 40064]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-11-15 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20091105.001\IDSxpx86.sys [2010-11-15 329592]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101115.002\naveng.sys [2010-11-15 86064]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101115.002\navex15.sys [2010-11-15 1371184]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\drivers\activmouse.sys [2006-10-4 5632]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-3 136176]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2010-11-9 50704]
S4 iteraid;iteraid; [x]
S4 Si3112r;Si3112r; [x]
S4 viasraid;viasraid; [x]
=============== Created Last 30 ================
2010-11-15 21:15:48 488383 -c--a-w- c:\windows\system32\dllcache\hsf_v124.sys
2010-11-15 21:14:58 126976 -c--a-w- c:\windows\system32\dllcache\hpgt34tk.dll
2010-11-15 21:13:52 92160 -c--a-w- c:\windows\system32\dllcache\fuusd.dll
2010-11-15 21:12:53 45568 -c--a-w- c:\windows\system32\dllcache\esunib.dll
2010-11-15 21:11:59 69194 -c--a-w- c:\windows\system32\dllcache\el656cd5.sys
2010-11-15 21:10:59 103044 -c--a-w- c:\windows\system32\dllcache\digidxb.sys
2010-11-15 21:09:59 10240 -c--a-w- c:\windows\system32\dllcache\compbatt.sys
2010-11-15 21:05:59 13824 -c--a-w- c:\windows\system32\dllcache\bulltlp3.sys
2010-11-15 21:04:50 6272 -c--a-w- c:\windows\system32\dllcache\apmbatt.sys
2010-11-15 21:04:49 36224 -c--a-w- c:\windows\system32\dllcache\an983.sys
2010-11-15 21:04:49 12032 -c--a-w- c:\windows\system32\dllcache\amsint.sys
2010-11-15 21:04:48 16969 -c--a-w- c:\windows\system32\dllcache\amb8002.sys
2010-11-15 21:04:47 5248 -c--a-w- c:\windows\system32\dllcache\aliide.sys
2010-11-15 21:04:47 27678 -c--a-w- c:\windows\system32\dllcache\ali5261.sys
2010-11-15 21:04:47 26624 -c--a-w- c:\windows\system32\dllcache\alifir.sys
2010-11-15 21:04:46 56960 -c--a-w- c:\windows\system32\dllcache\aic78xx.sys
2010-11-15 21:04:45 55168 -c--a-w- c:\windows\system32\dllcache\aic78u2.sys
2010-11-15 21:04:45 12800 -c--a-w- c:\windows\system32\dllcache\aha154x.sys
2010-11-15 21:01:04 46112 -c--a-w- c:\windows\system32\dllcache\adptsf50.sys
2010-11-15 21:01:04 101888 -c--a-w- c:\windows\system32\dllcache\adpu160m.sys
2010-11-15 21:01:03 747392 -c--a-w- c:\windows\system32\dllcache\adm8830.sys
2010-11-15 21:01:03 10880 -c--a-w- c:\windows\system32\dllcache\admjoy.sys
2010-11-15 21:01:02 584448 -c--a-w- c:\windows\system32\dllcache\adm8810.sys
2010-11-15 21:01:02 553984 -c--a-w- c:\windows\system32\dllcache\adm8820.sys
2010-11-15 21:01:01 7424 -c--a-w- c:\windows\system32\dllcache\adicvls.sys
2010-11-15 21:01:01 20160 -c--a-w- c:\windows\system32\dllcache\adm8511.sys
2010-11-15 19:59:53 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-11-12 13:33:18 -------- d-----w- c:\docume~1\alluse~1\applic~1\Norton
2010-11-09 21:12:26 -------- d-----w- c:\docume~1\alluse~1\applic~1\MFAData
2010-11-09 20:49:19 50704 ----a-w- c:\windows\system32\drivers\npf.sys
2010-11-09 20:49:19 281104 ----a-w- c:\windows\system32\wpcap.dll
2010-11-09 20:49:19 100880 ----a-w- c:\windows\system32\Packet.dll
2010-11-07 20:29:52 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-11-07 20:29:52 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-11-07 20:29:05 -------- d-----w- c:\program files\iPod
2010-11-07 20:29:02 -------- d-----w- c:\program files\iTunes
2010-11-07 20:29:02 -------- d-----w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-11-07 20:28:05 -------- d-----w- c:\docume~1\maureen\locals~1\applic~1\Apple
2010-11-07 20:27:26 -------- d-----w- c:\program files\Bonjour
2010-11-07 20:26:48 -------- d-----w- c:\docume~1\maureen\locals~1\applic~1\Apple Computer
2010-11-03 17:00:00 -------- d-----w- c:\docume~1\maureen\locals~1\applic~1\Google
2010-10-29 19:10:03 -------- d-----w- c:\program files\common files\Activ Software
2010-10-29 19:10:00 -------- d-----w- c:\program files\Activ Software
2010-10-29 19:10:00 -------- d-----w- c:\docume~1\alluse~1\applic~1\Activ Software
==================== Find3M ====================
2010-09-18 11:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-08 11:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 11:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
============= FINISH: 19:22:16.76 ===============