Thank you for the information and logs.
Tha Java problem seems to be related to a file called
jvm.dll - a check in your GSI parser says it may belong to Oracle - F:\oracle\ora92\jdk\jre\bin\hotspot\jvm.dll
I dont know if the file is also active in any other location on your computer or not, but its worth a go contacting Oracle Support or checking in other forums about this problem.
I am presuming your H drive is for USB (removable pen-drives). They are highly infected, and its likley other systems its been used on are infected aswell - unless autoruns has been disabled.
First of all, disable Autoruns on your computer if its enabled... In Kaspersky, click SystemSecurity - SecurityAnalyzer... follow the prompts. If there are any tick-boxes in the list which say "autoruns for USBs", "autoruns for removable storage" or something along those lines, tick it and click Next and follow the prompts.
Execute the following script in AVZ. Instructions shown
here.
*Note: Your PC will automatically restart without prompt after running the script, so save and exit all non-essential applications before running.
CODE
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('C:\WINDOWS\system32\ltdrunsrv.dll','');
QuarantineFile('C:\WINDOWS\system32\ltdlogsrv.dll','');
QuarantineFile('C:\WINDOWS\system32\drivers\tcpz-x86d.sys','');
QuarantineFile('C:\WINDOWS\System32\*.scr','');
QuarantineFile('C:\WINDOWS\System32\2FL49QC8KM\*.*','');
QuarantineFile('C:\WINDOWS\System32\AW16ADMLP2\*.*','');
QuarantineFile('C:\WINDOWS\System32\ZYRBY36XN6\*.*','');
QuarantineFile('c:\windows\system32\advancelink\*.*','');
QuarantineFile('C:\WINDOWS\System32\i\*.*','');
QuarantineFile('C:\WINDOWS\System32\J4UOG4K8OX\*.*','');
QuarantineFile('C:\WINDOWS\System32\RFKISAI20C\*.*','');
QuarantineFile('C:\WINDOWS\System32\VARNT8B4LG\*.*','');
QuarantineFile('C:\DOCUMENTS AND SETTINGS\LocalService\Local Settings\Temporary Internet Files\Content.IE5\VEF45CJ8\*.*','');
QuarantineFile('C:\DOCUMENTS AND SETTINGS\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IVTIMB01\*.*','');
QuarantineFile('C:\DOCUMENTS AND SETTINGS\LocalService\Local Settings\Temporary Internet Files\Content.IE5\ER15OPW9\*.*','');
QuarantineFile('C:\DOCUMENTS AND SETTINGS\LocalService\Local Settings\Temporary Internet Files\Content.IE5\3M8O7T64\*.*','');
DeleteFile('C:\WINDOWS\system32\ltdrunsrv.dll');
DeleteFile('C:\WINDOWS\system32\ltdlogsrv.dll');
DeleteFile('C:\WINDOWS\system32\drivers\tcpz-x86d.sys');
DeleteFileMask('C:\WINDOWS\System32\2FL49QC8KM\','*.*',true);
DeleteFileMask('C:\WINDOWS\System32\AW16ADMLP2\','*.*',true);
DeleteFileMask('C:\WINDOWS\System32\ZYRBY36XN6\','*.*',true);
DeleteFileMask('c:\windows\system32\advancelink\','*.*',true);
DeleteFileMask('C:\WINDOWS\System32\i\','*.*',true);
DeleteFileMask('C:\WINDOWS\System32\J4UOG4K8OX\','*.*',true);
DeleteFileMask('C:\WINDOWS\System32\RFKISAI20C\','*.*',true);
DeleteFileMask('C:\WINDOWS\System32\VARNT8B4LG\','*.*',true);
DeleteFileMask('C:\DOCUMENTS AND SETTINGS\LocalService\Local Settings\Temporary Internet Files\Content.IE5\VEF45CJ8\','*.*',true);
DeleteFileMask('C:\DOCUMENTS AND SETTINGS\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IVTIMB01\','*.*',true);
DeleteFileMask('C:\DOCUMENTS AND SETTINGS\LocalService\Local Settings\Temporary Internet Files\Content.IE5\ER15OPW9\','*.*',true);
DeleteFileMask('C:\DOCUMENTS AND SETTINGS\LocalService\Local Settings\Temporary Internet Files\Content.IE5\3M8O7T64\','*.*',true);
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Download and run
ATFCleaner.
Tick all the rows which say "Temp" or "Temporary Intenet Files" eg, Windows Temp.
Then click EmptySelected - OK - Exit
After run script, attach a Combofix log, please review and follow these instructions carefully.
Before Saving combofix to Desktop, please rename combofix to something like 123.exe to stop malware from disabling it.
Now, please make sure no other programs are running, close all other windows and pause Kaspersky (right click the K icon and click pause protection > Choose the
option "resume manually" if still active) until after the scanning and removal process has taken place.
Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.
Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall.
It may take a while to complete scanning and this is normal.
You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after
scanning has completed.
Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post. Also, please don't
forget to resume the Kaspersky that you paused.
Download Combofix from here ->
http://download.bleepingcomputer.com/sUBs/ComboFix.exe