Inactive Malwarebytes has successfully blocked access to site

Status
Not open for further replies.
Hello, a user of mine keeps getting this message. I've run malwarebytes, AVG, and a couple of other scanners and they all come back clean. I've attached the log file from the dds scan as suggested. Any help would be appreciated.
 

Attachments

  • attach.txt
    20.1 KB · Views: 1
  • dds.txt
    23.5 KB · Views: 1
Welcome aboard

Please, complete all steps listed here: https://www.techspot.com/community/...lware-removal-preliminary-instructions.58138/
Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
Attached logs won't be reviewed.

Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
 
Please see log file of attach below....


  • .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows 7 Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/25/2011 2:42:40 PM
    System Uptime: 5/20/2013 11:57:52 AM (1 hours ago)
    .
    Motherboard: LENOVO | | 2516DCU
    Processor: Intel(R) Core(TM) i5 CPU M 560 @ 2.67GHz | None | 2667/133mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 287 GiB total, 132.638 GiB free.
    D: is CDROM ()
    F: is NetworkDisk (NTFS) - 200 GiB total, 55.722 GiB free.
    Q: is FIXED (NTFS) - 10 GiB total, 2.328 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0012
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0012
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2430
    Device ID: ROOT\MULTIFUNCTION\0013
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2430
    PNP Device ID: ROOT\MULTIFUNCTION\0013
    Service:
    .
    Class GUID:
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0014
    Manufacturer:
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0014
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Officejet 6000 E609a
    Device ID: ROOT\MULTIFUNCTION\0015
    Manufacturer: HP
    Name: Officejet 6000 E609a
    PNP Device ID: ROOT\MULTIFUNCTION\0015
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0016
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0016
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2430
    Device ID: ROOT\MULTIFUNCTION\0017
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2430
    PNP Device ID: ROOT\MULTIFUNCTION\0017
    Service:
    .
    Class GUID:
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0018
    Manufacturer:
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0018
    Service:
    .
    Class GUID:
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0019
    Manufacturer:
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0019
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Officejet 6000 E609a
    Device ID: ROOT\MULTIFUNCTION\0000
    Manufacturer: HP
    Name: Officejet 6000 E609a
    PNP Device ID: ROOT\MULTIFUNCTION\0000
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0020
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0020
    Service:
    .
    Class GUID:
    Description: hp LaserJet 2430
    Device ID: ROOT\MULTIFUNCTION\0001
    Manufacturer:
    Name: hp LaserJet 2430
    PNP Device ID: ROOT\MULTIFUNCTION\0001
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0021
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0021
    Service:
    .
    Class GUID:
    Description: hp LaserJet 2430
    Device ID: ROOT\MULTIFUNCTION\0002
    Manufacturer:
    Name: hp LaserJet 2430
    PNP Device ID: ROOT\MULTIFUNCTION\0002
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0022
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0022
    Service:
    .
    Class GUID:
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0003
    Manufacturer:
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0003
    Service:
    .
    Class GUID:
    Description: HP LaserJet 600 M603
    Device ID: ROOT\MULTIFUNCTION\0023
    Manufacturer:
    Name: HP LaserJet 600 M603
    PNP Device ID: ROOT\MULTIFUNCTION\0023
    Service:
    .
    Class GUID:
    Description: hp LaserJet 2430
    Device ID: ROOT\MULTIFUNCTION\0004
    Manufacturer:
    Name: hp LaserJet 2430
    PNP Device ID: ROOT\MULTIFUNCTION\0004
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Officejet 6600
    Device ID: ROOT\MULTIFUNCTION\0024
    Manufacturer: HP
    Name: Officejet 6600
    PNP Device ID: ROOT\MULTIFUNCTION\0024
    Service:
    .
    Class GUID:
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0005
    Manufacturer:
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0005
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Officejet 6100
    Device ID: ROOT\MULTIFUNCTION\0025
    Manufacturer: HP
    Name: Officejet 6100
    PNP Device ID: ROOT\MULTIFUNCTION\0025
    Service:
    .
    Class GUID:
    Description: Officejet 6000 E609n
    Device ID: ROOT\MULTIFUNCTION\0006
    Manufacturer:
    Name: Officejet 6000 E609n
    PNP Device ID: ROOT\MULTIFUNCTION\0006
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4 Plus
    Device ID: ROOT\MULTIFUNCTION\0026
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4 Plus
    PNP Device ID: ROOT\MULTIFUNCTION\0026
    Service:
    .
    Class GUID:
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0007
    Manufacturer:
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0007
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 600 M603
    Device ID: ROOT\MULTIFUNCTION\0008
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 600 M603
    PNP Device ID: ROOT\MULTIFUNCTION\0008
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0009
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0009
    Service:
    .
    Class GUID:
    Description: Officejet 6000 E609a
    Device ID: ROOT\MULTIFUNCTION\0010
    Manufacturer:
    Name: Officejet 6000 E609a
    PNP Device ID: ROOT\MULTIFUNCTION\0010
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp color LaserJet 4650
    Device ID: ROOT\MULTIFUNCTION\0011
    Manufacturer: Hewlett-Packard
    Name: hp color LaserJet 4650
    PNP Device ID: ROOT\MULTIFUNCTION\0011
    Service:
    .
    ==== System Restore Points ===================
    .
    RP439: 5/10/2013 12:19:37 PM - Removed McAfee Agent.
    RP440: 5/10/2013 12:20:47 PM - Removed McAfee Agent.
    RP441: 5/10/2013 12:27:51 PM - Removed McAfee Agent.
    RP442: 5/10/2013 12:30:15 PM - Installed AVG 2013
    RP443: 5/10/2013 12:30:41 PM - Installed AVG 2013
    RP444: 5/15/2013 8:08:43 AM - Windows Update
    RP445: 5/20/2013 10:39:14 AM - Installed Sophos Virus Removal Tool.
    RP446: 5/20/2013 11:16:13 AM - Removed Mobile Broadband
    RP447: 5/20/2013 11:17:41 AM - Removed Sophos Virus Removal Tool.
    RP448: 5/20/2013 11:19:12 AM - Removed ThinkVantage Access Connections.
    RP449: 5/20/2013 11:34:34 AM - Removed Lenovo Warranty Information.
    RP450: 5/20/2013 11:35:06 AM - Removed Message Center Plus.
    RP451: 5/20/2013 11:55:42 AM - Removed AHLP
    .
    ==== Installed Programs ======================
    .
    4500_G510nz_Help
    4500G510nz
    4500G510nz_Software_Min
    64 Bit HP CIO Components Installer
    Adobe Acrobat X Standard
    Adobe AIR
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 11 ActiveX
    Adobe Reader XI (11.0.03)
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    AVG 2013
    Bonjour
    BufferChm
    Burn.Now 4.5
    Cisco EAP-FAST Module
    Cisco LEAP Module
    Cisco PEAP Module
    Conexant 20585 SmartAudio HD
    Corel Burn.Now Lenovo Edition
    Corel DVD MovieFactory 7
    Corel DVD MovieFactory Lenovo Edition
    Create Recovery Media
    Destinations
    DeviceDiscovery
    Direct DiscRecorder
    Dmailer_Backup_Manager.exe
    DocMgr
    DocProc
    Dropbox
    FastFax
    FastFax Client
    Fax
    Google Chrome
    Google Earth
    Google Talk (remove only)
    Google Update Helper
    GoToMeeting 5.4.0.1083
    GPBaseService2
    Hewlett-Packard ACLM.NET v1.1.0.0
    HP Customer Participation Program 13.0
    HP Document Manager 2.0
    HP Imaging Device Functions 13.0
    HP LaserJet M1522 MFP Series 6.0
    HP Officejet 4500 G510n-z
    HP Product Detection
    HP Smart Web Printing 4.5
    HP Solution Center 13.0
    HP Update
    HPDiagnosticAlert
    hppLaserJetService
    HPProductAssistant
    HPSSupply
    IBM Lotus Sametime Connect 7.5.1
    IBM System I Access for Windows V6R1M0
    iCloud
    Integrated Camera Driver Installer Package Ver.1.1.0.19
    Intel(R) Control Center
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) Management Engine Components
    Intel(R) Turbo Boost Technology Monitor
    InterVideo WinDVD 8
    iTunes
    Java 7 Update 21
    Java Auto Updater
    Java(TM) 6 Update 29 (64-bit)
    Lenovo Auto Scroll Utility
    Lenovo System Interface Driver
    Lenovo ThinkVantage Toolbox
    Live Support Chat for Web Site 5.4.4
    Lotus Notes 8.5.3
    Malwarebytes Anti-Malware version 1.75.0.1300
    MarketResearch
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Extended
    Microsoft MapPoint North America 2004
    Microsoft Office 2007 Service Pack 3 (SP3)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Office 64-bit Components 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared 64-bit MUI (English) 2007
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Small Business 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 Redistributable (x64)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    MiraSlope
    MozyPro
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Network64
    OCR Software by I.R.I.S. 13.0
    On Screen Display
    QuickTime
    Radialpoint Servicepoint Dashboard Extensions version 13.4.2.29577
    Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7
    Rescue and Recovery
    RICOH R5U230 Media Driver ver.2.06.02.02
    Safari
    Scan
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
    Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
    Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
    Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
    Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
    Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
    Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
    Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
    Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
    Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition
    Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
    Shop for HP Supplies
    SmartWebPrinting
    Snapshot Viewer
    SolutionCenter
    Status
    Synaptics Pointing Device Driver
    System Update
    Territory Mapper US V3.0
    ThinkPad FullScreen Magnifier
    ThinkPad Modem Adapter
    ThinkPad Power Management Driver
    ThinkPad Power Manager
    ThinkPad UltraNav Utility
    ThinkPad Wireless LAN Adapter Software
    ThinkVantage Active Protection System
    Toolbox
    TrayApp
    UltraVnc
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft .NET Framework 4 Extended (KB2468871)
    Update for Microsoft .NET Framework 4 Extended (KB2533523)
    Update for Microsoft .NET Framework 4 Extended (KB2600217)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817359) 32-Bit Edition
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Visual Studio 2010 x64 Redistributables
    WebReg
    Windows Driver Package - Intel (e1kexpress) Net (06/22/2010 11.5.10.1012)
    Windows Driver Package - Intel (HECIx64) System (09/17/2009 6.0.0.1179)
    Windows Driver Package - Intel System (06/04/2009 1.0.0.0002)
    Windows Driver Package - Intel System (10/28/2009 9.1.1.1022)
    Windows Driver Package - Intel USB (08/20/2009 9.1.1.1020)
    Windows Driver Package - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4)
    Windows Driver Package - Ricoh Company MS Host Controller (10/26/2009 6.10.02.07)
    Windows Driver Package - Synaptics (SynTP) Mouse (04/22/2010 15.0.18.0)
    Windows Live Mesh ActiveX Control for Remote Connections
    .
    ==== Event Viewer Messages From Past Week ========
    .
    5/20/2013 9:56:24 AM, Error: Service Control Manager [7034] - The ThinkVantage Registry Monitor Service service terminated unexpectedly. It has done this 1 time(s).
    5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The On Screen Display service terminated unexpectedly. It has done this 1 time(s).
    5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The Lenovo Keyboard Noise Reduction service terminated unexpectedly. It has done this 1 time(s).
    5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).
    5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The AcSvc service terminated unexpectedly. It has done this 1 time(s).
    5/20/2013 9:56:23 AM, Error: Service Control Manager [7034] - The AcPrfMgrSvc service terminated unexpectedly. It has done this 1 time(s).
    5/20/2013 9:17:17 AM, Error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the computer that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state.
    5/20/2013 12:00:47 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver ZDesigner QL 420/QL 420 Plus required for printer ZDesigner QL 420/QL 420 Plus is unknown. Contact the administrator to install the driver before you log in again.
    5/20/2013 12:00:46 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver SAVIN C4040 PCL 6 required for printer SAVIN C4040 is unknown. Contact the administrator to install the driver before you log in again.
    5/20/2013 12:00:44 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver ZDesigner S4M-203dpi ZPL required for printer ZDesigner S4M-203dpi ZPL is unknown. Contact the administrator to install the driver before you log in again.
    5/20/2013 12:00:43 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver SAVIN C4040 PCL 6 required for printer !!usjefdc1!SAVIN C4040 is unknown. Contact the administrator to install the driver before you log in again.
    5/20/2013 12:00:43 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.
    5/20/2013 12:00:41 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver HP Universal Printing PCL 5 required for printer !!usjefdc1!HP P3015 in Jefferson Credit is unknown. Contact the administrator to install the driver before you log in again.
    5/20/2013 11:57:26 AM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
    5/20/2013 11:37:50 AM, Error: NETLOGON [5719] - This computer was not able to set up a secure session with a domain controller in domain TENCATE due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.
    5/20/2013 11:24:42 AM, Error: Microsoft-Windows-GroupPolicy [1055] - The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: a) Name Resolution failure on the current domain controller. b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).
    5/16/2013 8:09:51 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the MBAMScheduler service to connect.
    5/16/2013 8:09:51 AM, Error: Service Control Manager [7000] - The MBAMScheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    5/15/2013 10:46:09 AM, Error: NetBT [4321] - The name "TENCATE :1d" could not be registered on the interface with IP address 10.15.16.137. The computer with the IP address 10.15.17.2 did not allow the name to be claimed by this computer.
    .
    ==== End Of File ===========================
 
Please see log file of DDS below....


DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16483 BrowserJavaVersion: 10.21.2
Run by k.little at 12:02:02 on 2013-05-20
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3892.2167 [GMT -4:00]
.
AV: AVG AntiVirus Business Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Business Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\LogonUI.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\centenn.ial\audit\CAgent32.exe
c:\centenn.ial\audit\xferwan.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe
C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\UI0Detect.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\rdpclip.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\TpShocks.exe
C:\Users\k.little\AppData\Roaming\Dmailer\Dmailer_Backup_Manager.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\MozyPro\mozyprostat.exe
C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\k.little\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Windows\system32\rundll32.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\System32\mobsync.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\MozyPro\mozyprobackup.exe
C:\Windows\system32\sppsvc.exe
c:\Program Files (x86)\Lenovo\System Update\SUService.exe
C:\Program Files\MozyPro\mozyprobackup.exe
C:\Program Files\MozyPro\mozyprobackup.exe
C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
c:\centenn.ial\audit\lpamd64.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.mirafi.com/
uWindow Title = Windows Internet Explorer provided by TenCate America SSC
uURLSearchHooks: {ef468e5b-5b30-4136-a833-7f2e3a31afdf} - <orphaned>
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
EB: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - <orphaned>
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [Sametime Connect 7.5] "C:\Program Files (x86)\IBM\Sametime Connect\sametime.exe" -noSplash
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [googletalk] C:\Users\k.little\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
uRun: [Dmailer_Backup_Manager.exe] C:\Users\k.little\AppData\Roaming\Dmailer\Dmailer_Backup_Manager.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
uRun: [ProvideSupportOperatorConsole] C:\PROGRA~2\PROVID~1\LIVESU~1\PROVID~1.EXE
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
mRun: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
mRun: [Discovery User Input] c:\Discovery\User Input\userin32.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\K785E~1.LIT\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\k.little\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DIGITA~1.LNK - C:\Program Files (x86)\Digital Line Detect\DLG.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MOZYPR~1.LNK - C:\Program Files\MozyPro\mozyprostat.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\UPDATE~1.LNK - C:\Program Files (x86)\Quadrant Software\FastFax\autoupl.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: ForceRunOnStartMenu = dword:1
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: legalnoticecaption = TenCate Security Policy Notification
mPolicies-System: legalnoticetext = Welcome to the Global TenCate Network. As an employee or agent of TenCate, or related entities, your use of any technology resources or access to information is subject to the Royal TenCate Informaton Security Policy. That policy can be found on the TenCate iNetwork Portal at (http://portal.tencate.com/md/isamer/DocumentsC:\Windows\fonts20All%20Users/Policies/IT_Security_Policy_v0_13.pdf)
mPolicies-System: disablecad = dword:1
mPolicies-System: SoftwareSASGeneration = dword:1
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TCP: NameServer = 10.15.17.8 10.15.33.8
TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74} : DHCPNameServer = 10.15.17.8 10.15.33.8
TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\2556E61696373716E63656F57455543545 : DHCPNameServer = 12.158.249.5
TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\34143524F40234F6E666562756E63656 : DHCPNameServer = 66.78.202.254 66.78.210.254
TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\642756560294E6475627E65647 : DHCPNameServer = 66.78.202.254 66.78.210.254
TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\94E6374716E6470294E6475627E65647 : DHCPNameServer = 66.78.202.254 66.78.210.254
TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\C4567616369702C4F6467656 : DHCPNameServer = 12.127.17.72 12.127.16.68
TCP: Interfaces\{72C4D48A-F085-41D3-ACC5-C38E1FC90B74}\C6964747C65686F6573756 : DHCPNameServer = 192.168.254.254
TCP: Interfaces\{DCD40EB3-694A-4ACA-B0FE-57EDE43D7590} : DHCPNameServer = 10.15.17.8 10.15.33.8
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [SynTPEnh] H.EXE
x64-Run: [TPHOTKEY] OVO\HOTKEY\TPOSDSVC.EXE
x64-Run: [TpShocks] TpShocks.exe
x64-Run: [SmartAudio] T\SAII\SAIICPL.EXE /T
x64-Run: [HotKeysCmds] DOWS\SYSTEM32\HKCMD.EXE
x64-Run: [Persistence] DOWS\SYSTEM32\IGFXPERS.EXE
x64-Run: [AcWin7Hlpr] ABLER.EXE
x64-DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2013-2-8 71480]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2013-2-8 311096]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2013-2-8 116536]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2013-2-8 45880]
R0 DzHDD64;DzHDD64;C:\Windows\System32\drivers\DZHDD64.SYS [2011-1-13 30320]
R0 TPDIGIMN;TPDIGIMN;C:\Windows\System32\drivers\ApsHM64.sys [2010-6-16 23664]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2013-3-29 246072]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2013-2-8 206136]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-3-21 240952]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\System32\drivers\smiifx64.sys [2010-7-30 15400]
R1 mozyproFilter;mozyproFilter;C:\Windows\System32\drivers\mozypro.sys [2012-3-30 67328]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2013-4-25 4936752]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-4-18 283136]
R2 HsfXAudioService;HsfXAudioService;C:\Windows\System32\svchost.exe -k HsfXAudioService [2009-7-13 27136]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2010-7-30 45496]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe [2010-7-30 93032]
R2 LNSUSvc;Lotus Notes Smart Upgrade Service;C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe [2011-9-16 189832]
R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe [2011-9-16 4455560]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-5-9 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-5-9 701512]
R2 McciCMService64;McciCMService64;C:\Program Files\Common Files\Motive\McciCMService.exe [2012-12-31 517632]
R2 mozyprobackup;MozyPro Backup Service;C:\Program Files\MozyPro\mozyprobackup.exe [2012-3-19 54632]
R2 rimspci;rimspci;C:\Windows\System32\drivers\rimspe64.sys [2011-1-13 61952]
R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2010-7-30 63928]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2009-9-29 12728]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-1-13 2533400]
R3 5U877;USB Video Device;C:\Windows\System32\drivers\5U877.sys [2011-1-13 163072]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\System32\drivers\CAXHWAZL.sys [2011-1-13 292864]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2011-1-13 295088]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2011-1-13 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-1-13 158976]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-1-13 271872]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-5-9 25928]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\Windows\System32\drivers\rtl8192se.sys [2011-1-13 1111144]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\System32\drivers\tvti2c.sys [2009-10-8 41536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 HP LaserJet Service;HP LaserJet Service;C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2010-3-3 136192]
S3 cdprku;cdprku;C:\Windows\System32\drivers\cdprku.sys [2011-9-14 27176]
S3 DozeSvc;Lenovo Doze Mode Service;C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [2011-1-13 164200]
S3 HPFXFAX;HPFXFAX;C:\Windows\System32\drivers\hpfx64fax.sys [2007-7-16 23064]
S3 LanProbe;LanProbe;C:\CENTENN.IAL\AUDIT\lpamd64.exe [2011-9-14 269824]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
S3 pmxdrv;pmxdrv;C:\Windows\System32\drivers\pmxdrv.sys [2011-1-13 31152]
S3 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2011-1-13 75112]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-10-24 19456]
S3 rixdpcie;rixdpcie;C:\Windows\System32\drivers\rixdpe64.sys [2011-1-13 55808]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-10-24 57856]
S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-9-29 126392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-7-29 1255736]
.
=============== Created Last 30 ================
.
2013-05-20 14:40:46 -------- d-----w- C:\ProgramData\Sophos
2013-05-20 13:56:23 -------- d-----w- C:\Stinger_Quarantine
2013-05-20 13:56:17 -------- d-----w- C:\Program Files (x86)\stinger
2013-05-20 12:47:16 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-05-20 12:47:16 -------- d-----w- C:\Program Files\iTunes
2013-05-20 12:47:16 -------- d-----w- C:\Program Files\iPod
2013-05-20 12:47:16 -------- d-----w- C:\Program Files (x86)\iTunes
2013-05-15 12:22:53 983400 ------w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-05-15 12:22:53 265064 ------w- C:\Windows\System32\drivers\dxgmms1.sys
2013-05-15 12:22:53 144384 ------w- C:\Windows\System32\cdd.dll
2013-05-15 12:20:54 111448 ------w- C:\Windows\System32\consent.exe
2013-05-15 12:20:49 70144 ------w- C:\Windows\System32\appinfo.dll
2013-05-15 12:20:46 1930752 ------w- C:\Windows\System32\authui.dll
2013-05-15 12:20:46 1796096 ------w- C:\Windows\SysWow64\authui.dll
2013-05-15 12:20:31 48640 ------w- C:\Windows\System32\wwanprotdim.dll
2013-05-15 12:20:31 230400 ------w- C:\Windows\System32\wwansvc.dll
2013-05-15 12:20:11 3153920 ------w- C:\Windows\System32\win32k.sys
2013-05-15 12:11:39 2382848 ------w- C:\Windows\SysWow64\mshtml.tlb
2013-05-15 12:11:39 2382848 ------w- C:\Windows\System32\mshtml.tlb
2013-05-15 12:09:59 887808 ------w- C:\Program Files\Internet Explorer\iedvtool.dll
2013-05-15 12:09:59 678912 ------w- C:\Program Files (x86)\Internet Explorer\iedvtool.dll
2013-05-15 12:09:59 499200 ------w- C:\Program Files\Internet Explorer\jsdbgui.dll
2013-05-15 12:09:59 387584 ------w- C:\Program Files (x86)\Internet Explorer\jsdbgui.dll
2013-05-11 10:37:28 209472 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2013-05-10 16:33:01 -------- d-----w- C:\Users\k.little\AppData\Roaming\AVG2013
2013-05-10 16:31:19 -------- d--h--w- C:\$AVG
2013-05-10 16:31:19 -------- d-----w- C:\ProgramData\AVG2013
2013-05-10 16:30:29 -------- d-----w- C:\Program Files (x86)\AVG
2013-05-10 16:29:41 -------- d--h--w- C:\ProgramData\Common Files
2013-05-10 16:29:41 -------- d-----w- C:\Users\k.little\AppData\Local\MFAData
2013-05-10 16:29:41 -------- d-----w- C:\Users\k.little\AppData\Local\Avg2013
2013-05-10 16:29:41 -------- d-----w- C:\ProgramData\MFAData
2013-05-10 07:57:38 27208 ----a-w- C:\Windows\System32\AdobePDFUI.dll
2013-05-10 07:57:34 55872 ----a-w- C:\Windows\System32\AdobePDF.dll
2013-05-09 19:23:29 -------- d-sh--w- C:\$RECYCLE.BIN
2013-05-09 17:57:59 98816 ------w- C:\Windows\sed.exe
2013-05-09 17:57:59 256000 ------w- C:\Windows\PEV.exe
2013-05-09 17:57:59 208896 ------w- C:\Windows\MBR.exe
2013-05-09 12:25:13 -------- d-----w- C:\Users\k.little\AppData\Roaming\Malwarebytes
2013-05-09 12:23:46 -------- d-----w- C:\ProgramData\Malwarebytes
2013-05-09 12:23:43 25928 ------w- C:\Windows\System32\drivers\mbam.sys
2013-05-09 12:23:43 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-05-09 12:23:08 95648 ------w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-04-25 21:05:10 1656680 ------w- C:\Windows\System32\drivers\ntfs.sys
.
==================== Find3M ====================
.
2013-05-15 13:57:21 71048 ------w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-15 13:57:21 692104 ------w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-09 12:22:56 866720 ------w- C:\Windows\SysWow64\npdeployJava1.dll
2013-05-09 12:22:56 788896 ------w- C:\Windows\SysWow64\deployJava1.dll
2013-04-13 05:49:23 135168 ------w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ------w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ------w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ------w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ------w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ------w- C:\Windows\apppatch\AcGenral.dll
2013-04-05 01:08:44 2312704 ------w- C:\Windows\System32\jscript9.dll
2013-04-05 01:00:30 1392128 ------w- C:\Windows\System32\wininet.dll
2013-04-05 00:59:24 1494528 ------w- C:\Windows\System32\inetcpl.cpl
2013-04-05 00:56:16 173056 ------w- C:\Windows\System32\ieUnatt.exe
2013-04-05 00:55:47 599040 ------w- C:\Windows\System32\vbscript.dll
2013-04-04 22:11:34 1800704 ------w- C:\Windows\SysWow64\jscript9.dll
2013-04-04 22:02:59 1427968 ------w- C:\Windows\SysWow64\inetcpl.cpl
2013-04-04 22:02:17 1129472 ------w- C:\Windows\SysWow64\wininet.dll
2013-04-04 21:58:51 142848 ------w- C:\Windows\SysWow64\ieUnatt.exe
2013-04-04 21:57:45 420864 ------w- C:\Windows\SysWow64\vbscript.dll
2013-03-29 06:53:48 246072 ------w- C:\Windows\System32\drivers\avgidsdrivera.sys
2013-03-21 07:08:24 240952 ------w- C:\Windows\System32\drivers\avgtdia.sys
2013-03-19 06:04:06 5550424 ------w- C:\Windows\System32\ntoskrnl.exe
2013-03-19 05:46:56 43520 ------w- C:\Windows\System32\csrsrv.dll
2013-03-19 05:04:13 3968856 ------w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04:10 3913560 ------w- C:\Windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47:50 6656 ------w- C:\Windows\SysWow64\apisetschema.dll
2013-03-19 03:06:33 112640 ------w- C:\Windows\System32\smss.exe
.
============= FINISH: 12:03:22.42 ===============
 
redtarget.gif
Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop.
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • Wait until the Status box shows Scan Finished
  • Click on Delete.
  • Wait until the Status box shows Deleting Finished.
  • Click on Report and copy/paste the content of the Notepad into your next reply.
  • RKreport.txt could also be found on your desktop.
  • If more than one log is produced post all logs.
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

redtarget.gif
Download Malwarebytes Anti-Rootkit (MBAR) from HERE
  • Unzip downloaded file.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt
 
Status
Not open for further replies.
Back