TechSpot

Included logs for you analysis

Inactive
By flydonna
Jul 13, 2010
  1. I followed your steps for Virus/Malware removal. I am including the logs produced. I would also like to add that MalwareBytes did find 10 entries yesterday and supposedly deleted them when I did a Full Scan - but I'm still getting MarketScore Spyware popping up everty time I boot up my computer.

    Mbam Log
    04:56:22 Donnas MESSAGE Protection started successfully
    04:56:26 Donnas MESSAGE IP Protection started successfully
    05:01:03 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\MSVCR71.DLL Spyware.MarketScore QUARANTINE
    05:01:04 Donnas ERROR Quarantine failed: UtilityReadFile failed with error code 3
    05:01:23 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\MSVCR71.DLL Spyware.MarketScore DENY
    05:02:00 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\RLSERVICE.EXE Spyware.MarketScore QUARANTINE
    05:02:01 Donnas ERROR Quarantine failed: UtilityReadFile failed with error code 3
    05:02:14 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\MSVCR71.DLL Spyware.MarketScore DENY
    05:02:16 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\RLSERVICE.EXE Spyware.MarketScore DENY
    05:02:32 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\MSVCR71.DLL Spyware.MarketScore DENY
    05:02:34 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\RLSERVICE.EXE Spyware.MarketScore DENY
    05:42:28 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\MSVCR71.DLL Spyware.MarketScore DENY
    05:42:30 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\RLSERVICE.EXE Spyware.MarketScore DENY
    06:22:59 Donnas MESSAGE IP Protection stopped
    06:23:01 Donnas MESSAGE Database updated successfully
    06:23:01 Donnas MESSAGE IP Protection started successfully
    06:47:58 Donnas MESSAGE Protection started successfully
    06:48:01 Donnas MESSAGE IP Protection started successfully
    06:52:00 Donnas MESSAGE Protection started successfully
    06:52:04 Donnas MESSAGE IP Protection started successfully
    06:55:26 Donnas MESSAGE IP Protection stopped
    06:55:26 Donnas MESSAGE IP Protection started successfully
    06:59:16 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\MSVCR71.DLL Spyware.MarketScore QUARANTINE
    06:59:17 Donnas ERROR Quarantine failed: UtilityReadFile failed with error code 3
    06:59:18 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\RLSERVICE.EXE Spyware.MarketScore QUARANTINE
    06:59:19 Donnas ERROR Quarantine failed: UtilityReadFile failed with error code 3
    06:59:29 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\MSVCR71.DLL Spyware.MarketScore DENY
    06:59:29 Donnas DETECTION C:\PROGRAM FILES (X86)\RELEVANTKNOWLEDGE\RLSERVICE.EXE Spyware.MarketScore DENY

    I had trouble zipping the DDS text file so I have included it as part of this post also.


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-03-17.01)

    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 6/20/2010 8:33:55 AM
    System Uptime: 7/13/2010 6:49:36 AM (1 hours ago)

    Motherboard: Dell Inc. | | 0KVMW2
    Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz | U2E1 | 2267/1333mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 451 GiB total, 411.296 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP15: 6/20/2010 1:14:57 PM - Windows Backup
    RP16: 6/20/2010 7:00:06 PM - Windows Backup
    RP17: 6/25/2010 10:04:04 PM - Windows Update
    RP18: 6/27/2010 1:12:10 PM - Windows Update
    RP19: 6/27/2010 1:16:11 PM - Installed Works Suite OS Pack
    RP20: 6/27/2010 1:29:00 PM - Installed Microsoft Word 2002
    RP21: 6/27/2010 8:59:14 PM - Windows Backup
    RP22: 6/28/2010 2:14:57 PM - Windows Backup
    RP23: 6/28/2010 2:17:09 PM - Windows Backup
    RP24: 6/28/2010 2:18:05 PM - Windows Backup
    RP25: 7/5/2010 8:42:42 PM - Installed iTunes
    RP26: 7/5/2010 9:20:35 PM - Removed Dell DataSafe Online.
    RP27: 7/5/2010 9:33:57 PM - Windows Backup
    RP28: 7/11/2010 7:28:32 AM - Windows Update
    RP29: 7/11/2010 7:29:38 AM - Windows Update
    RP30: 7/12/2010 4:59:19 AM - Windows Backup
    RP31: 7/12/2010 7:10:14 AM - Windows Backup
    RP32: 7/12/2010 7:40:52 PM - Removed Adobe Reader 9.1.2.
    RP33: 7/12/2010 7:47:58 PM - Auslogics Regisry Defrag - before defragmentation

    ==== Installed Programs ======================

    ABBYY FineReader 6.0 Sprint
    Advanced Audio FX Engine
    Apple Application Support
    Apple Software Update
    ATI Catalyst Control Center
    Auslogics Registry Cleaner
    Auslogics Registry Defrag
    Banctec Service Agreement
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    ccc-core-static
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCleaner
    Cisco EAP-FAST Module
    Cisco LEAP Module
    Cisco PEAP Module
    Dell DataSafe Local Backup
    Dell DataSafe Local Backup - Support Software
    Dell Dock
    Dell Getting Started Guide
    Dell Support Center (Support Software)
    Dell Toolbar
    Dell Webcam Central
    erLT
    GoToAssist 8.0.0.514
    Java Auto Updater
    Java(TM) 6 Update 20
    Junk Mail filter update
    Live! Cam Avatar Creator
    Logitech SetPoint
    Malwarebytes' Anti-Malware
    McAfee Security Center
    Microsoft Choice Guard
    Microsoft Office 2010
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Word 2002
    MSVCRT
    PowerDVD DX
    QuickTime
    Roxio Burn
    Security Update for CAPICOM (KB931906)
    Skins
    Skype Toolbars
    Skype™ 4.2
    WildTangent Games
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Mail
    Windows Live Messenger
    Windows Live Movie Maker
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Live Writer
    Works Suite OS Pack

    ==== Event Viewer Messages From Past Week ========

    7/13/2010 6:48:15 AM, Error: Service Control Manager [7034] - The Dock Login Service service terminated unexpectedly. It has done this 1 time(s).
    7/13/2010 6:44:26 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the McShield service.
    7/13/2010 6:36:04 AM, Error: Service Control Manager [7034] - The McAfee Scanner service terminated unexpectedly. It has done this 1 time(s).
    7/13/2010 6:36:03 AM, Error: Service Control Manager [7031] - The McShield service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
    7/12/2010 9:35:59 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}
    7/12/2010 9:32:17 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:32:16 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    7/12/2010 9:32:16 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    7/12/2010 9:32:16 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
    7/12/2010 9:32:16 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    7/12/2010 9:32:15 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    7/12/2010 9:32:09 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC discache mfehidk mfenlfk NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vwififlt Wanarpv6 WfpLwf
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The McShield service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The McAfee Validation Trust Protection Service service depends on the McAfee Inc. mfehidk service which failed to start because of the following error: A device attached to the system is not functioning.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The McAfee Proxy Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The McAfee Personal Firewall service depends on the Windows Firewall service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The McAfee Firewall Core Service service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The McAfee Anti-Spam Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    7/12/2010 9:31:58 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    7/12/2010 7:52:04 PM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
    7/12/2010 1:36:54 PM, Error: Service Control Manager [7034] - The RelevantKnowledge service terminated unexpectedly. It has done this 1 time(s).
    7/11/2010 9:00:18 AM, Error: bowser [8003] - The master browser has received a server announcement from the computer DEVIN_ADMINI-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{EE9383A4-96A7-42F7-AC6F-13BFF4810D79}. The master browser is stopping or an election is being forced.

    ==== End Of File ===========================
     

    Attached Files:

  2. Broni

    Broni Malware Annihilator Posts: 47,048   +256

Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.