TechSpot

Malwarebytes has successfully blocked access to site

By gdalton
May 20, 2013
  1. Hello, a user of mine keeps getting this message. I've run malwarebytes, AVG, and a couple of other scanners and they all come back clean. I've attached the log file from the dds scan as suggested. Any help would be appreciated.
     

    Attached Files:

  2. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    Welcome aboard [​IMG]

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
     
  3. gdalton

    gdalton TS Rookie Topic Starter

    Please see log file of attach below....


    • .
      UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
      IF REQUESTED, ZIP IT UP & ATTACH IT
      .
      DDS (Ver_2012-11-20.01)
      .
      Microsoft Windows 7 Professional
      Boot Device: \Device\HarddiskVolume1
      Install Date: 7/25/2011 2:42:40 PM
      System Uptime: 5/20/2013 11:57:52 AM (1 hours ago)
      .
      Motherboard: LENOVO | | 2516DCU
      Processor: Intel(R) Core(TM) i5 CPU M 560 @ 2.67GHz | None | 2667/133mhz
      .
      ==== Disk Partitions =========================
      .
      C: is FIXED (NTFS) - 287 GiB total, 132.638 GiB free.
      D: is CDROM ()
      F: is NetworkDisk (NTFS) - 200 GiB total, 55.722 GiB free.
      Q: is FIXED (NTFS) - 10 GiB total, 2.328 GiB free.
      .
      ==== Disabled Device Manager Items =============
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0012
      Manufacturer: Hewlett-Packard
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0012
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: hp LaserJet 2430
      Device ID: ROOT\MULTIFUNCTION\0013
      Manufacturer: Hewlett-Packard
      Name: hp LaserJet 2430
      PNP Device ID: ROOT\MULTIFUNCTION\0013
      Service:
      .
      Class GUID:
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0014
      Manufacturer:
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0014
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: Officejet 6000 E609a
      Device ID: ROOT\MULTIFUNCTION\0015
      Manufacturer: HP
      Name: Officejet 6000 E609a
      PNP Device ID: ROOT\MULTIFUNCTION\0015
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0016
      Manufacturer: Hewlett-Packard
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0016
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: hp LaserJet 2430
      Device ID: ROOT\MULTIFUNCTION\0017
      Manufacturer: Hewlett-Packard
      Name: hp LaserJet 2430
      PNP Device ID: ROOT\MULTIFUNCTION\0017
      Service:
      .
      Class GUID:
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0018
      Manufacturer:
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0018
      Service:
      .
      Class GUID:
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0019
      Manufacturer:
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0019
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: Officejet 6000 E609a
      Device ID: ROOT\MULTIFUNCTION\0000
      Manufacturer: HP
      Name: Officejet 6000 E609a
      PNP Device ID: ROOT\MULTIFUNCTION\0000
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0020
      Manufacturer: Hewlett-Packard
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0020
      Service:
      .
      Class GUID:
      Description: hp LaserJet 2430
      Device ID: ROOT\MULTIFUNCTION\0001
      Manufacturer:
      Name: hp LaserJet 2430
      PNP Device ID: ROOT\MULTIFUNCTION\0001
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0021
      Manufacturer: Hewlett-Packard
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0021
      Service:
      .
      Class GUID:
      Description: hp LaserJet 2430
      Device ID: ROOT\MULTIFUNCTION\0002
      Manufacturer:
      Name: hp LaserJet 2430
      PNP Device ID: ROOT\MULTIFUNCTION\0002
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0022
      Manufacturer: Hewlett-Packard
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0022
      Service:
      .
      Class GUID:
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0003
      Manufacturer:
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0003
      Service:
      .
      Class GUID:
      Description: HP LaserJet 600 M603
      Device ID: ROOT\MULTIFUNCTION\0023
      Manufacturer:
      Name: HP LaserJet 600 M603
      PNP Device ID: ROOT\MULTIFUNCTION\0023
      Service:
      .
      Class GUID:
      Description: hp LaserJet 2430
      Device ID: ROOT\MULTIFUNCTION\0004
      Manufacturer:
      Name: hp LaserJet 2430
      PNP Device ID: ROOT\MULTIFUNCTION\0004
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: Officejet 6600
      Device ID: ROOT\MULTIFUNCTION\0024
      Manufacturer: HP
      Name: Officejet 6600
      PNP Device ID: ROOT\MULTIFUNCTION\0024
      Service:
      .
      Class GUID:
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0005
      Manufacturer:
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0005
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: Officejet 6100
      Device ID: ROOT\MULTIFUNCTION\0025
      Manufacturer: HP
      Name: Officejet 6100
      PNP Device ID: ROOT\MULTIFUNCTION\0025
      Service:
      .
      Class GUID:
      Description: Officejet 6000 E609n
      Device ID: ROOT\MULTIFUNCTION\0006
      Manufacturer:
      Name: Officejet 6000 E609n
      PNP Device ID: ROOT\MULTIFUNCTION\0006
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: HP LaserJet 4 Plus
      Device ID: ROOT\MULTIFUNCTION\0026
      Manufacturer: Hewlett-Packard
      Name: HP LaserJet 4 Plus
      PNP Device ID: ROOT\MULTIFUNCTION\0026
      Service:
      .
      Class GUID:
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0007
      Manufacturer:
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0007
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: HP LaserJet 600 M603
      Device ID: ROOT\MULTIFUNCTION\0008
      Manufacturer: Hewlett-Packard
      Name: HP LaserJet 600 M603
      PNP Device ID: ROOT\MULTIFUNCTION\0008
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: HP LaserJet P3010 Series
      Device ID: ROOT\MULTIFUNCTION\0009
      Manufacturer: Hewlett-Packard
      Name: HP LaserJet P3010 Series
      PNP Device ID: ROOT\MULTIFUNCTION\0009
      Service:
      .
      Class GUID:
      Description: Officejet 6000 E609a
      Device ID: ROOT\MULTIFUNCTION\0010
      Manufacturer:
      Name: Officejet 6000 E609a
      PNP Device ID: ROOT\MULTIFUNCTION\0010
      Service:
      .
      Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
      Description: hp color LaserJet 4650
      Device ID: ROOT\MULTIFUNCTION\0011
      Manufacturer: Hewlett-Packard
      Name: hp color LaserJet 4650
      PNP Device ID: ROOT\MULTIFUNCTION\0011
      Service:
      .
      ==== System Restore Points ===================
      .
      RP439: 5/10/2013 12:19:37 PM - Removed McAfee Agent.
      RP440: 5/10/2013 12:20:47 PM - Removed McAfee Agent.
      RP441: 5/10/2013 12:27:51 PM - Removed McAfee Agent.
      RP442: 5/10/2013 12:30:15 PM - Installed AVG 2013
      RP443: 5/10/2013 12:30:41 PM - Installed AVG 2013
      RP444: 5/15/2013 8:08:43 AM - Windows Update
      RP445: 5/20/2013 10:39:14 AM - Installed Sophos Virus Removal Tool.
      RP446: 5/20/2013 11:16:13 AM - Removed Mobile Broadband
      RP447: 5/20/2013 11:17:41 AM - Removed Sophos Virus Removal Tool.
      RP448: 5/20/2013 11:19:12 AM - Removed ThinkVantage Access Connections.
      RP449: 5/20/2013 11:34:34 AM - Removed Lenovo Warranty Information.
      RP450: 5/20/2013 11:35:06 AM - Removed Message Center Plus.
      RP451: 5/20/2013 11:55:42 AM - Removed AHLP
      .
      ==== Installed Programs ======================
      .
      4500_G510nz_Help
      4500G510nz
      4500G510nz_Software_Min
      64 Bit HP CIO Components Installer
      Adobe Acrobat X Standard
      Adobe AIR
      Adobe Flash Player 10 Plugin
      Adobe Flash Player 11 ActiveX
      Adobe Reader XI (11.0.03)
      Apple Application Support
      Apple Mobile Device Support
      Apple Software Update
      AVG 2013
      Bonjour
      BufferChm
      Burn.Now 4.5
      Cisco EAP-FAST Module
      Cisco LEAP Module
      Cisco PEAP Module
      Conexant 20585 SmartAudio HD
      Corel Burn.Now Lenovo Edition
      Corel DVD MovieFactory 7
      Corel DVD MovieFactory Lenovo Edition
      Create Recovery Media
      Destinations
      DeviceDiscovery
      Direct DiscRecorder
      Dmailer_Backup_Manager.exe
      DocMgr
      DocProc
      Dropbox
      FastFax
      FastFax Client
      Fax
      Google Chrome
      Google Earth
      Google Talk (remove only)
      Google Update Helper
      GoToMeeting 5.4.0.1083
      GPBaseService2
      Hewlett-Packard ACLM.NET v1.1.0.0
      HP Customer Participation Program 13.0
      HP Document Manager 2.0
      HP Imaging Device Functions 13.0
      HP LaserJet M1522 MFP Series 6.0
      HP Officejet 4500 G510n-z
      HP Product Detection
      HP Smart Web Printing 4.5
      HP Solution Center 13.0
      HP Update
      HPDiagnosticAlert
      hppLaserJetService
      HPProductAssistant
      HPSSupply
      IBM Lotus Sametime Connect 7.5.1
      IBM System I Access for Windows V6R1M0
      iCloud
      Integrated Camera Driver Installer Package Ver.1.1.0.19
      Intel(R) Control Center
      Intel(R) Graphics Media Accelerator Driver
      Intel(R) Management Engine Components
      Intel(R) Turbo Boost Technology Monitor
      InterVideo WinDVD 8
      iTunes
      Java 7 Update 21
      Java Auto Updater
      Java(TM) 6 Update 29 (64-bit)
      Lenovo Auto Scroll Utility
      Lenovo System Interface Driver
      Lenovo ThinkVantage Toolbox
      Live Support Chat for Web Site 5.4.4
      Lotus Notes 8.5.3
      Malwarebytes Anti-Malware version 1.75.0.1300
      MarketResearch
      Microsoft .NET Framework 4 Client Profile
      Microsoft .NET Framework 4 Extended
      Microsoft MapPoint North America 2004
      Microsoft Office 2007 Service Pack 3 (SP3)
      Microsoft Office Excel MUI (English) 2007
      Microsoft Office Office 64-bit Components 2007
      Microsoft Office Outlook MUI (English) 2007
      Microsoft Office PowerPoint MUI (English) 2007
      Microsoft Office Proof (English) 2007
      Microsoft Office Proof (French) 2007
      Microsoft Office Proof (Spanish) 2007
      Microsoft Office Proofing (English) 2007
      Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
      Microsoft Office Publisher MUI (English) 2007
      Microsoft Office Shared 64-bit MUI (English) 2007
      Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
      Microsoft Office Shared MUI (English) 2007
      Microsoft Office Shared Setup Metadata MUI (English) 2007
      Microsoft Office Small Business 2007
      Microsoft Office Word MUI (English) 2007
      Microsoft Silverlight
      Microsoft Visual C++ 2005 Redistributable
      Microsoft Visual C++ 2005 Redistributable (x64)
      Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
      MiraSlope
      MozyPro
      MSXML 4.0 SP2 (KB954430)
      MSXML 4.0 SP2 (KB973688)
      Network64
      OCR Software by I.R.I.S. 13.0
      On Screen Display
      QuickTime
      Radialpoint Servicepoint Dashboard Extensions version 13.4.2.29577
      Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7
      Rescue and Recovery
      RICOH R5U230 Media Driver ver.2.06.02.02
      Safari
      Scan
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
      Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
      Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
      Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
      Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
      Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
      Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
      Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
      Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
      Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
      Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
      Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition
      Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
      Shop for HP Supplies
      SmartWebPrinting
      Snapshot Viewer
      SolutionCenter
      Status
      Synaptics Pointing Device Driver
      System Update
      Territory Mapper US V3.0
      ThinkPad FullScreen Magnifier
      ThinkPad Modem Adapter
      ThinkPad Power Management Driver
      ThinkPad Power Manager
      ThinkPad UltraNav Utility
      ThinkPad Wireless LAN Adapter Software
      ThinkVantage Active Protection System
      Toolbox
      TrayApp
      UltraVnc
      Update for 2007 Microsoft Office System (KB967642)
      Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
      Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
      Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
      Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
      Update for Microsoft .NET Framework 4 Extended (KB2468871)
      Update for Microsoft .NET Framework 4 Extended (KB2533523)
      Update for Microsoft .NET Framework 4 Extended (KB2600217)
      Update for Microsoft Office 2007 Help for Common Features (KB963673)
      Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
      Update for Microsoft Office Excel 2007 Help (KB963678)
      Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
      Update for Microsoft Office Outlook 2007 Help (KB963677)
      Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817359) 32-Bit Edition
      Update for Microsoft Office Powerpoint 2007 Help (KB963669)
      Update for Microsoft Office Publisher 2007 Help (KB963667)
      Update for Microsoft Office Script Editor Help (KB963671)
      Update for Microsoft Office Word 2007 Help (KB963665)
      Visual Studio 2010 x64 Redistributables
      WebReg
      Windows Driver Package - Intel (e1kexpress) Net (06/22/2010 11.5.10.1012)
      Windows Driver Package - Intel (HECIx64) System (09/17/2009 6.0.0.1179)
      Windows Driver Package - Intel System (06/04/2009 1.0.0.0002)
      Windows Driver Package - Intel System (10/28/2009 9.1.1.1022)
      Windows Driver Package - Intel USB (08/20/2009 9.1.1.1020)
      Windows Driver Package - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4)
      Windows Driver Package - Ricoh Company MS Host Controller (10/26/2009 6.10.02.07)
      Windows Driver Package - Synaptics (SynTP) Mouse (04/22/2010 15.0.18.0)
      Windows Live Mesh ActiveX Control for Remote Connections
      .
      ==== Event Viewer Messages From Past Week ========
      .
      5/20/2013 9:56:24 AM, Error: Service Control Manager [7034] - The ThinkVantage Registry Monitor Service service terminated unexpectedly. It has done this 1 time(s).
      5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The On Screen Display service terminated unexpectedly. It has done this 1 time(s).
      5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The Lenovo Keyboard Noise Reduction service terminated unexpectedly. It has done this 1 time(s).
      5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).
      5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The AcSvc service terminated unexpectedly. It has done this 1 time(s).
      5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The AcPrfMgrSvc service terminated unexpectedly. It has done this 1 time(s).
      5/20/2013 9:17:17 AM, Error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the computer that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state.
      5/20/2013 12:00:47 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver ZDesigner QL 420/QL 420 Plus required for printer ZDesigner QL 420/QL 420 Plus is unknown. Contact the administrator to install the driver before you log in again.
      5/20/2013 12:00:46 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver SAVIN C4040 PCL 6 required for printer SAVIN C4040 is unknown. Contact the administrator to install the driver before you log in again.
      5/20/2013 12:00:44 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver ZDesigner S4M-203dpi ZPL required for printer ZDesigner S4M-203dpi ZPL is unknown. Contact the administrator to install the driver before you log in again.
      5/20/2013 12:00:43 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver SAVIN C4040 PCL 6 required for printer !!usjefdc1!SAVIN C4040 is unknown. Contact the administrator to install the driver before you log in again.
      5/20/2013 12:00:43 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.
      5/20/2013 12:00:41 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver HP Universal Printing PCL 5 required for printer !!usjefdc1!HP P3015 in Jefferson Credit is unknown. Contact the administrator to install the driver before you log in again.
      5/20/2013 11:57:26 AM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
      5/20/2013 11:37:50 AM, Error: NETLOGON [5719] - This computer was not able to set up a secure session with a domain controller in domain TENCATE due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.
      5/20/2013 11:24:42 AM, Error: Microsoft-Windows-GroupPolicy [1055] - The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: a) Name Resolution failure on the current domain controller. b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).
      5/16/2013 8:09:51 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the MBAMScheduler service to connect.
      5/16/2013 8:09:51 AM, Error: Service Control Manager [7000] - The MBAMScheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
      5/15/2013 10:46:09 AM, Error: NetBT [4321] - The name "TENCATE :1d" could not be registered on the interface with IP address 10.15.16.137. The computer with the IP address 10.15.17.2 did not allow the name to be claimed by this computer.
      .
      ==== End Of File ===========================
     
  4. gdalton

    gdalton TS Rookie Topic Starter

    Please see log file of DDS below....


    DDS (Ver_2012-11-20.01) - NTFS_AMD64
    Internet Explorer: 9.0.8112.16483 BrowserJavaVersion: 10.21.2
    Run by k.little at 12:02:02 on 2013-05-20
    Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3892.2167 [GMT -4:00]
    .
    AV: AVG AntiVirus Business Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: AVG AntiVirus Business Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
    C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\ibmpmsvc.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\LogonUI.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    c:\centenn.ial\audit\CAgent32.exe
    c:\centenn.ial\audit\xferwan.exe
    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
    C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
    C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
    C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
    C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
    C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe
    C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
    C:\Program Files\Common Files\Motive\McciCMService.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\Windows\system32\svchost.exe -k HPService
    C:\Windows\system32\UI0Detect.exe
    C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
    C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\rdpclip.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\TpShocks.exe
    C:\Users\k.little\AppData\Roaming\Dmailer\Dmailer_Backup_Manager.exe
    C:\Program Files (x86)\Digital Line Detect\DLG.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\MozyPro\mozyprostat.exe
    C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Users\k.little\AppData\Roaming\Dropbox\bin\Dropbox.exe
    C:\Windows\system32\taskeng.exe
    C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
    C:\Windows\system32\rundll32.exe
    C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\AVG\AVG2013\avgui.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\igfxext.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Windows\system32\svchost.exe -k HsfXAudioService
    C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\MozyPro\mozyprobackup.exe
    C:\Windows\system32\sppsvc.exe
    c:\Program Files (x86)\Lenovo\System Update\SUService.exe
    C:\Program Files\MozyPro\mozyprobackup.exe
    C:\Program Files\MozyPro\mozyprobackup.exe
    C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    c:\centenn.ial\audit\lpamd64.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.mirafi.com/
    uWindow Title = Windows Internet Explorer provided by TenCate America SSC
    uURLSearchHooks: {ef468e5b-5b30-4136-a833-7f2e3a31afdf} - <orphaned>
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
    BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    EB: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - <orphaned>
    EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
    EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
    uRun: [Sametime Connect 7.5] "C:\Program Files (x86)\IBM\Sametime Connect\sametime.exe" -noSplash
    uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    uRun: [googletalk] C:\Users\k.little\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
    uRun: [Dmailer_Backup_Manager.exe] C:\Users\k.little\AppData\Roaming\Dmailer\Dmailer_Backup_Manager.exe
    uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
    uRun: [ProvideSupportOperatorConsole] C:\PROGRA~2\PROVID~1\LIVESU~1\PROVID~1.EXE
    mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
    mRun: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
    mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
    mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
    mRun: [Discovery User Input] c:\Discovery\User Input\userin32.exe
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    StartupFolder: C:\Users\K785E~1.LIT\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\k.little\AppData\Roaming\Dropbox\bin\Dropbox.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DIGITA~1.LNK - C:\Program Files (x86)\Digital Line Detect\DLG.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MOZYPR~1.LNK - C:\Program Files\MozyPro\mozyprostat.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\UPDATE~1.LNK - C:\Program Files (x86)\Quadrant Software\FastFax\autoupl.exe
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    uPolicies-Explorer: NoDrives = dword:0
    uPolicies-Explorer: ForceRunOnStartMenu = dword:1
    mPolicies-Explorer: NoDrives = dword:0
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    mPolicies-System: legalnoticecaption = TenCate Security Policy Notification
    mPolicies-System: legalnoticetext = Welcome to the Global TenCate Network. As an employee or agent of TenCate, or related entities, your use of any technology resources or access to information is subject to the Royal TenCate Informaton Security Policy. That policy can be found on the TenCate iNetwork Portal at (http://portal.tencate.com/md/isamer/DocumentsC:\Windows\fonts20All%20Users/Policies/IT_Security_Policy_v0_13.pdf)
    mPolicies-System: disablecad = dword:1
    mPolicies-System: SoftwareSASGeneration = dword:1
    IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
    IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    TCP: NameServer = 10.15.17.8 10.15.33.8
    TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74} : DHCPNameServer = 10.15.17.8 10.15.33.8
    TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\2556E61696373716E63656F57455543545 : DHCPNameServer = 12.158.249.5
    TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\34143524F40234F6E666562756E63656 : DHCPNameServer = 66.78.202.254 66.78.210.254
    TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\642756560294E6475627E65647 : DHCPNameServer = 66.78.202.254 66.78.210.254
    TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\94E6374716E6470294E6475627E65647 : DHCPNameServer = 66.78.202.254 66.78.210.254
    TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\C4567616369702C4F6467656 : DHCPNameServer = 12.127.17.72 12.127.16.68
    TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\C6964747C65686F6573756 : DHCPNameServer = 192.168.254.254
    TCP: Interfaces\{DCD40EB3-694A-4ACA-B0FE-57EDE43D7590} : DHCPNameServer = 10.15.17.8 10.15.33.8
    SSODL: WebCheck - <orphaned>
    mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
    x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    x64-Run: [SynTPEnh] H.EXE
    x64-Run: [TPHOTKEY] OVO\HOTKEY\TPOSDSVC.EXE
    x64-Run: [TpShocks] TpShocks.exe
    x64-Run: [SmartAudio] T\SAII\SAIICPL.EXE /T
    x64-Run: [HotKeysCmds] DOWS\SYSTEM32\HKCMD.EXE
    x64-Run: [Persistence] DOWS\SYSTEM32\IGFXPERS.EXE
    x64-Run: [AcWin7Hlpr] ABLER.EXE
    x64-DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    x64-SSODL: WebCheck - <orphaned>
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2013-2-8 71480]
    R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2013-2-8 311096]
    R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2013-2-8 116536]
    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2013-2-8 45880]
    R0 DzHDD64;DzHDD64;C:\Windows\System32\drivers\DZHDD64.SYS [2011-1-13 30320]
    R0 TPDIGIMN;TPDIGIMN;C:\Windows\System32\drivers\ApsHM64.sys [2010-6-16 23664]
    R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2013-3-29 246072]
    R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2013-2-8 206136]
    R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-3-21 240952]
    R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\System32\drivers\smiifx64.sys [2010-7-30 15400]
    R1 mozyproFilter;mozyproFilter;C:\Windows\System32\drivers\mozypro.sys [2012-3-30 67328]
    R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2013-4-25 4936752]
    R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-4-18 283136]
    R2 HsfXAudioService;HsfXAudioService;C:\Windows\System32\svchost.exe -k HsfXAudioService [2009-7-13 27136]
    R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2010-7-30 45496]
    R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe [2010-7-30 93032]
    R2 LNSUSvc;Lotus Notes Smart Upgrade Service;C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe [2011-9-16 189832]
    R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe [2011-9-16 4455560]
    R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-5-9 418376]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-5-9 701512]
    R2 McciCMService64;McciCMService64;C:\Program Files\Common Files\Motive\McciCMService.exe [2012-12-31 517632]
    R2 mozyprobackup;MozyPro Backup Service;C:\Program Files\MozyPro\mozyprobackup.exe [2012-3-19 54632]
    R2 rimspci;rimspci;C:\Windows\System32\drivers\rimspe64.sys [2011-1-13 61952]
    R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2010-7-30 63928]
    R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2009-9-29 12728]
    R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-1-13 2533400]
    R3 5U877;USB Video Device;C:\Windows\System32\drivers\5U877.sys [2011-1-13 163072]
    R3 CAXHWAZL;CAXHWAZL;C:\Windows\System32\drivers\CAXHWAZL.sys [2011-1-13 292864]
    R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2011-1-13 295088]
    R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2011-1-13 56344]
    R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-1-13 158976]
    R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-1-13 271872]
    R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-5-9 25928]
    R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\Windows\System32\drivers\rtl8192se.sys [2011-1-13 1111144]
    R3 TVTI2C;Lenovo SM bus driver;C:\Windows\System32\drivers\tvti2c.sys [2009-10-8 41536]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 HP LaserJet Service;HP LaserJet Service;C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2010-3-3 136192]
    S3 cdprku;cdprku;C:\Windows\System32\drivers\cdprku.sys [2011-9-14 27176]
    S3 DozeSvc;Lenovo Doze Mode Service;C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [2011-1-13 164200]
    S3 HPFXFAX;HPFXFAX;C:\Windows\System32\drivers\hpfx64fax.sys [2007-7-16 23064]
    S3 LanProbe;LanProbe;C:\CENTENN.IAL\AUDIT\lpamd64.exe [2011-9-14 269824]
    S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
    S3 pmxdrv;pmxdrv;C:\Windows\System32\drivers\pmxdrv.sys [2011-1-13 31152]
    S3 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2011-1-13 75112]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-10-24 19456]
    S3 rixdpcie;rixdpcie;C:\Windows\System32\drivers\rixdpe64.sys [2011-1-13 55808]
    S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
    S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
    S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
    S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-10-24 57856]
    S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-9-29 126392]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-7-29 1255736]
    .
    =============== Created Last 30 ================
    .
    2013-05-20 14:40:46 -------- d-----w- C:\ProgramData\Sophos
    2013-05-20 13:56:23 -------- d-----w- C:\Stinger_Quarantine
    2013-05-20 13:56:17 -------- d-----w- C:\Program Files (x86)\stinger
    2013-05-20 12:47:16 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    2013-05-20 12:47:16 -------- d-----w- C:\Program Files\iTunes
    2013-05-20 12:47:16 -------- d-----w- C:\Program Files\iPod
    2013-05-20 12:47:16 -------- d-----w- C:\Program Files (x86)\iTunes
    2013-05-15 12:22:53 983400 ------w- C:\Windows\System32\drivers\dxgkrnl.sys
    2013-05-15 12:22:53 265064 ------w- C:\Windows\System32\drivers\dxgmms1.sys
    2013-05-15 12:22:53 144384 ------w- C:\Windows\System32\cdd.dll
    2013-05-15 12:20:54 111448 ------w- C:\Windows\System32\consent.exe
    2013-05-15 12:20:49 70144 ------w- C:\Windows\System32\appinfo.dll
    2013-05-15 12:20:46 1930752 ------w- C:\Windows\System32\authui.dll
    2013-05-15 12:20:46 1796096 ------w- C:\Windows\SysWow64\authui.dll
    2013-05-15 12:20:31 48640 ------w- C:\Windows\System32\wwanprotdim.dll
    2013-05-15 12:20:31 230400 ------w- C:\Windows\System32\wwansvc.dll
    2013-05-15 12:20:11 3153920 ------w- C:\Windows\System32\win32k.sys
    2013-05-15 12:11:39 2382848 ------w- C:\Windows\SysWow64\mshtml.tlb
    2013-05-15 12:11:39 2382848 ------w- C:\Windows\System32\mshtml.tlb
    2013-05-15 12:09:59 887808 ------w- C:\Program Files\Internet Explorer\iedvtool.dll
    2013-05-15 12:09:59 678912 ------w- C:\Program Files (x86)\Internet Explorer\iedvtool.dll
    2013-05-15 12:09:59 499200 ------w- C:\Program Files\Internet Explorer\jsdbgui.dll
    2013-05-15 12:09:59 387584 ------w- C:\Program Files (x86)\Internet Explorer\jsdbgui.dll
    2013-05-11 10:37:28 209472 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
    2013-05-10 16:33:01 -------- d-----w- C:\Users\k.little\AppData\Roaming\AVG2013
    2013-05-10 16:31:19 -------- d--h--w- C:\$AVG
    2013-05-10 16:31:19 -------- d-----w- C:\ProgramData\AVG2013
    2013-05-10 16:30:29 -------- d-----w- C:\Program Files (x86)\AVG
    2013-05-10 16:29:41 -------- d--h--w- C:\ProgramData\Common Files
    2013-05-10 16:29:41 -------- d-----w- C:\Users\k.little\AppData\Local\MFAData
    2013-05-10 16:29:41 -------- d-----w- C:\Users\k.little\AppData\Local\Avg2013
    2013-05-10 16:29:41 -------- d-----w- C:\ProgramData\MFAData
    2013-05-10 07:57:38 27208 ----a-w- C:\Windows\System32\AdobePDFUI.dll
    2013-05-10 07:57:34 55872 ----a-w- C:\Windows\System32\AdobePDF.dll
    2013-05-09 19:23:29 -------- d-sh--w- C:\$RECYCLE.BIN
    2013-05-09 17:57:59 98816 ------w- C:\Windows\sed.exe
    2013-05-09 17:57:59 256000 ------w- C:\Windows\PEV.exe
    2013-05-09 17:57:59 208896 ------w- C:\Windows\MBR.exe
    2013-05-09 12:25:13 -------- d-----w- C:\Users\k.little\AppData\Roaming\Malwarebytes
    2013-05-09 12:23:46 -------- d-----w- C:\ProgramData\Malwarebytes
    2013-05-09 12:23:43 25928 ------w- C:\Windows\System32\drivers\mbam.sys
    2013-05-09 12:23:43 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2013-05-09 12:23:08 95648 ------w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
    2013-04-25 21:05:10 1656680 ------w- C:\Windows\System32\drivers\ntfs.sys
    .
    ==================== Find3M ====================
    .
    2013-05-15 13:57:21 71048 ------w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-05-15 13:57:21 692104 ------w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2013-05-09 12:22:56 866720 ------w- C:\Windows\SysWow64\npdeployJava1.dll
    2013-05-09 12:22:56 788896 ------w- C:\Windows\SysWow64\deployJava1.dll
    2013-04-13 05:49:23 135168 ------w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
    2013-04-13 05:49:19 350208 ------w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
    2013-04-13 05:49:19 308736 ------w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
    2013-04-13 05:49:19 111104 ------w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
    2013-04-13 04:45:16 474624 ------w- C:\Windows\apppatch\AcSpecfc.dll
    2013-04-13 04:45:15 2176512 ------w- C:\Windows\apppatch\AcGenral.dll
    2013-04-05 01:08:44 2312704 ------w- C:\Windows\System32\jscript9.dll
    2013-04-05 01:00:30 1392128 ------w- C:\Windows\System32\wininet.dll
    2013-04-05 00:59:24 1494528 ------w- C:\Windows\System32\inetcpl.cpl
    2013-04-05 00:56:16 173056 ------w- C:\Windows\System32\ieUnatt.exe
    2013-04-05 00:55:47 599040 ------w- C:\Windows\System32\vbscript.dll
    2013-04-04 22:11:34 1800704 ------w- C:\Windows\SysWow64\jscript9.dll
    2013-04-04 22:02:59 1427968 ------w- C:\Windows\SysWow64\inetcpl.cpl
    2013-04-04 22:02:17 1129472 ------w- C:\Windows\SysWow64\wininet.dll
    2013-04-04 21:58:51 142848 ------w- C:\Windows\SysWow64\ieUnatt.exe
    2013-04-04 21:57:45 420864 ------w- C:\Windows\SysWow64\vbscript.dll
    2013-03-29 06:53:48 246072 ------w- C:\Windows\System32\drivers\avgidsdrivera.sys
    2013-03-21 07:08:24 240952 ------w- C:\Windows\System32\drivers\avgtdia.sys
    2013-03-19 06:04:06 5550424 ------w- C:\Windows\System32\ntoskrnl.exe
    2013-03-19 05:46:56 43520 ------w- C:\Windows\System32\csrsrv.dll
    2013-03-19 05:04:13 3968856 ------w- C:\Windows\SysWow64\ntkrnlpa.exe
    2013-03-19 05:04:10 3913560 ------w- C:\Windows\SysWow64\ntoskrnl.exe
    2013-03-19 04:47:50 6656 ------w- C:\Windows\SysWow64\apisetschema.dll
    2013-03-19 03:06:33 112640 ------w- C:\Windows\System32\smss.exe
    .
    ============= FINISH: 12:03:22.42 ===============
     
  5. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    [​IMG] Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop.
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    [​IMG] Download Malwarebytes Anti-Rootkit (MBAR) from HERE
    • Unzip downloaded file.
    • Open the folder where the contents were unzipped and run mbar.exe
    • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    • Wait while the system shuts down and the cleanup process is performed.
    • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...