TechSpot

Xp anti spyware 2011 infection

Resolved
By Jskid
Nov 16, 2010
Topic Status:
Not open for further replies.
  1. Hello, I've never made a post like this before.

    A computer is severally infected with xp anti spyware 2011. I can connect to it using Remote Desktop. It's policy to use Spybot Search & Destroy but in the past I've found this to be insufficient. Given that the computer must remain connected to the internet (for Remote Desktop) what program should I run?

    EDIT: the company is very conservative about installing products we haven't tested, for example we don't use I.E. 8 as it may mess up online applications. Is there any risk of the spyware removal program messing up some settings?
     
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    I see you have 80 posts so you've been around for a while
    To begin with:
    If this is a company computer, please have the company IT person help you.

    I will not take responsibility for any conflict you might have with your company software when you are asked to run scans for the malware.
     
  3. Jskid

    Jskid TS Enthusiast Topic Starter Posts: 429

    Thanks for the help
    I would like to say that I do not have a conflict with my company because I don't like Spybot Search & Destroy.
     
  4. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Spybot Search and Destroy is not a program we run.
    If you would like us to check the system for malware, please follow the steps in the Preliminary Virus and Malware Removal thread HERE.

    When you have finished, leave the logs for review in your next reply .

    Important!
    Please do not use any other cleaning programs or scans while I'm helping you, unless I direct you to. Do not use a Registry cleaner or make any changes in the Registry.
     
  5. Jskid

    Jskid TS Enthusiast Topic Starter Posts: 429

    When following these steps should I log into a local account or a domain account?
     
  6. Jskid

    Jskid TS Enthusiast Topic Starter Posts: 429

    Step 3: Malwarebytes
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 5139

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 7.0.5730.13

    17/Nov/2010 11:58:14 AM
    mbam-log-2010-11-17 (11-58-14).txt

    Scan type: Quick scan
    Objects scanned: 214239
    Time elapsed: 8 minute(s), 37 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 3
    Folders Infected: 0
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Documents and Settings\navsaro\Local Settings\Application Data\pw.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Documents and Settings\navsaro\Local Settings\Application Data\opRSK (Malware.Trace) -> Quarantined and deleted successfully.

    Step 4: GMER
    GMER 1.0.15.15530 - http://www.gmer.net
    Rootkit quick scan 2010-11-17 12:14:58
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e ST340014AS rev.3.43
    Running: b00zye5n.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kwdyqpod.sys


    ---- Devices - GMER 1.0.15 ----

    Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

    AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
    AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
    AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
    AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

    ---- EOF - GMER 1.0.15 ----

    Step 5: DDS
    DDS.txt

    DDS (Ver_10-11-10.01) - NTFSx86
    Run by Administrator at 12:17:23.96 on 17/Nov/2010
    Internet Explorer: 7.0.5730.13
    Microsoft Windows XP Professional 5.1.2600.3.1252.2.1033.18.1015.497 [GMT -8:00]

    AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\EPSON\EPSON Advanced Printer Driver 4\EpsonPHLog.exe
    C:\Program Files\EPSON\EPSON Advanced Printer Driver 4\EpsonPH.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\Program Files\Symantec AntiVirus\SavRoam.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\rdpclip.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\Administrator\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    mDefault_Page_URL = hxxp://nsculive
    mSearchAssistant = hxxp://www.google.com/ie
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
    mRun: [<NO NAME>]
    mRun: [EpsonAPD4SV] c:\program files\epson\epson advanced printer driver 4\tools\eapsv\EAPSV.EXE
    mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
    mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [igfxtray] c:\windows\system32\igfxtray.exe
    mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
    mRun: [igfxpers] c:\windows\system32\igfxpers.exe
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    dRunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"
    dRunOnce: [TSClientAXDisabler] cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat"
    dRunOnce: [WUAppSetup] c:\program files\common files\logishrd\WUApp32.exe -v 0x046d -p 0x08b2 -f video -m logitech -d 10.5.1.2023
    StartupFolder: c:\documents and settings\all users\start menu\programs\startup\PivDel.bat
    uPolicies-explorer: NoInstrumentation = 1 (0x1)
    mPolicies-system: dontdisplaylockeduserid = 1 (0x1)
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    Trusted Zone: cutrainingonline.com
    Trusted Zone: hiredesk.net
    Trusted Zone: prolender.net\training
    Trusted Zone: prolender.net\www
    DPF: eFormsCab - hxxp://monaco:8080/Workplace/forms/misc/eFormsWeb.cab
    DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
    DPF: {100C659D-2B0B-4BEF-B79A-34E4659B9A9C} - hxxp://miami/ePower/cab/RDACLNT.CAB
    DPF: {154E3A83-BDE2-441E-A22C-EDAED67CF23A} - hxxp://miami/ePower/cab/RDARES.CAB
    DPF: {24F10A0C-7983-4934-849D-582F940A8AC3} - hxxp://miami/ePower/cab/RdaObjCreate.cab
    DPF: {286BCCBE-B061-4EF3-BAFA-C6D36F164DAB} - hxxp://seymour/ePower/cab/RDAPREFS.CAB
    DPF: {28E4BE08-1C25-4CE4-A9AA-3495A9D08C8E} - hxxp://miami/ePower/cab/RSHORTCUT.CAB
    DPF: {309F16B3-B30C-4114-BE89-E63C4F593B41} - hxxp://miami/ePower/cab/RDAPRTL.CAB
    DPF: {59A48F67-03E2-460F-9E0C-B3860634172A} - hxxp://miami/ePower/cab/RDARPRT.CAB
    DPF: {60927435-8441-4532-B2B7-45C9DE62945F} - hxxp://miami/ePower/cab/RdaUI.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1252539747343
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {8C42DAC2-0B6A-4F80-9794-3130E1C28345} - hxxp://miami/ePower/cab/RDAEMAIL.CAB
    DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} - hxxp://sydney/crystalreportviewers10/ActiveXControls/ActiveXViewer.cab
    DPF: {A4BD9732-328D-11D4-BB89-00A0C9843488} - hxxp://miami/ePower/cab/RN1SENDX.CAB
    DPF: {AE4F48D0-6A0A-11D3-9FB0-005004A79108} - hxxp://miami/ePower/cab/DFOUTILS.CAB
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {E774F171-CCB6-424B-877B-1D4F95DF60AD} - hxxp://seymour/ePower/cab/RDALETEX.CAB
    DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://meeting.temenos.com/dana-cached/sc/JuniperSetupClient.cab
    DPF: {F4901BF2-3FB9-4948-BB0E-5BD2AFF09085} - hxxp://miami/ePower/cab/RDASHARE.CAB
    Notify: igfxcui - igfxdev.dll
    Notify: NavLogon - c:\windows\system32\NavLogon.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ============= SERVICES / DRIVERS ===============

    R1 PlutoDrv;PlutoDrv;c:\windows\system32\drivers\PlutoDrv.sys [2005-5-13 48640]
    R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2008-5-28 337280]
    R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2008-5-28 54656]
    R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2008-6-24 191848]
    R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2008-6-24 169320]
    R2 EpsonPOSLog;Epson Point of Service Log Service;c:\program files\epson\epson advanced printer driver 4\EpsonPHLog.exe [2009-1-24 290816]
    R2 EpsonPOSPort;Epson Point of Service Port Handler;c:\program files\epson\epson advanced printer driver 4\EpsonPH.exe [2010-1-13 376832]
    R2 Esdpdx01;Esdpdx01;c:\windows\system32\drivers\ESDPDX01.SYS [2010-1-13 95495]
    R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2008-9-30 116664]
    R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2008-9-30 1956792]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-7-16 102448]
    R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20101116.004\naveng.sys [2010-11-17 86064]
    R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20101116.004\navex15.sys [2010-11-17 1371184]
    S1 FPUSB;SecuGen USB FRD Service;c:\windows\system32\drivers\VenusDrv.sys [2005-5-13 21400]

    =============== Created Last 30 ================

    2010-11-17 19:42:04 -------- d-----w- c:\docume~1\admini~1\applic~1\Malwarebytes
    2010-11-17 19:41:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-11-17 19:41:54 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-11-17 19:41:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-11-17 19:41:54 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2010-11-17 18:07:49 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2010-11-16 19:50:49 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
    2010-11-09 18:11:23 5632 ----a-w- c:\windows\system32\ptpusb.dll
    2010-11-09 18:11:22 159232 ----a-w- c:\windows\system32\ptpusd.dll
    2010-11-09 18:11:21 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
    2010-11-09 18:11:21 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys

    ==================== Find3M ====================

    2010-09-15 10:29:49 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2010-08-26 15:56:38 398744 ----a-r- c:\windows\cpnprt2.cid
    2010-08-26 15:56:37 398744 ------w- c:\windows\system32\cpnprt2.cid

    ============= FINISH: 12:18:11.41 ===============

    Attach.txt

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-11-10.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 30/Jun/2010 10:55:46 AM
    System Uptime: 17/Nov/2010 12:00:05 PM (0 hours ago)

    Motherboard: Hewlett-Packard | | 09E8h
    Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | XU1 PROCESSOR | 2793/800mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 37 GiB total, 24.187 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP35: 19/Aug/2010 1:28:15 PM - System Checkpoint
    RP36: 20/Aug/2010 1:40:01 PM - System Checkpoint
    RP37: 24/Aug/2010 9:46:44 AM - System Checkpoint
    RP38: 25/Aug/2010 9:58:34 AM - System Checkpoint
    RP39: 26/Aug/2010 2:04:48 PM - System Checkpoint
    RP40: 27/Aug/2010 2:43:56 PM - System Checkpoint
    RP41: 31/Aug/2010 9:06:39 AM - System Checkpoint
    RP42: 01/Sep/2010 9:09:03 AM - System Checkpoint
    RP43: 02/Sep/2010 10:01:26 AM - System Checkpoint
    RP44: 03/Sep/2010 12:22:01 PM - System Checkpoint
    RP45: 07/Sep/2010 10:11:15 AM - System Checkpoint
    RP46: 08/Sep/2010 10:56:43 AM - System Checkpoint
    RP47: 09/Sep/2010 11:39:18 AM - System Checkpoint
    RP48: 10/Sep/2010 12:54:06 PM - System Checkpoint
    RP49: 11/Sep/2010 1:19:20 PM - System Checkpoint
    RP50: 14/Sep/2010 11:56:32 AM - System Checkpoint
    RP51: 15/Sep/2010 12:49:11 PM - System Checkpoint
    RP52: 16/Sep/2010 1:49:10 PM - System Checkpoint
    RP53: 17/Sep/2010 4:28:04 PM - System Checkpoint
    RP54: 21/Sep/2010 10:43:59 AM - System Checkpoint
    RP55: 23/Sep/2010 9:11:50 AM - System Checkpoint
    RP56: 24/Sep/2010 10:30:24 AM - System Checkpoint
    RP57: 25/Sep/2010 12:44:42 PM - System Checkpoint
    RP58: 28/Sep/2010 10:42:04 AM - System Checkpoint
    RP59: 29/Sep/2010 12:29:34 PM - System Checkpoint
    RP60: 30/Sep/2010 12:43:05 PM - System Checkpoint
    RP61: 01/Oct/2010 1:18:13 PM - System Checkpoint
    RP62: 02/Oct/2010 3:17:27 PM - System Checkpoint
    RP63: 04/Oct/2010 2:31:22 PM - System Checkpoint
    RP64: 05/Oct/2010 3:41:54 PM - System Checkpoint
    RP65: 06/Oct/2010 8:45:06 AM - Removed Network Recording Player
    RP66: 07/Oct/2010 9:49:04 AM - Removed Network Recording Player
    RP67: 08/Oct/2010 11:42:59 AM - System Checkpoint
    RP68: 12/Oct/2010 12:21:41 PM - System Checkpoint
    RP69: 13/Oct/2010 12:40:37 PM - System Checkpoint
    RP70: 14/Oct/2010 1:38:15 PM - System Checkpoint
    RP71: 15/Oct/2010 1:39:32 PM - System Checkpoint
    RP72: 19/Oct/2010 9:34:35 AM - System Checkpoint
    RP73: 20/Oct/2010 9:39:01 AM - System Checkpoint
    RP74: 21/Oct/2010 12:37:55 PM - System Checkpoint
    RP75: 22/Oct/2010 12:40:09 PM - System Checkpoint
    RP76: 23/Oct/2010 1:36:54 PM - System Checkpoint
    RP77: 27/Oct/2010 12:25:43 PM - System Checkpoint
    RP78: 28/Oct/2010 12:26:53 PM - System Checkpoint
    RP79: 29/Oct/2010 12:30:42 PM - System Checkpoint
    RP80: 02/Nov/2010 9:05:05 AM - System Checkpoint
    RP81: 03/Nov/2010 10:07:11 AM - System Checkpoint
    RP82: 04/Nov/2010 10:40:01 AM - System Checkpoint
    RP83: 05/Nov/2010 11:39:59 AM - System Checkpoint
    RP84: 06/Nov/2010 11:58:12 AM - System Checkpoint
    RP85: 08/Nov/2010 3:57:12 PM - System Checkpoint
    RP86: 09/Nov/2010 4:17:41 PM - System Checkpoint
    RP87: 10/Nov/2010 5:22:20 PM - System Checkpoint
    RP88: 11/Nov/2010 5:57:26 PM - System Checkpoint
    RP89: 13/Nov/2010 9:13:54 AM - System Checkpoint
    RP90: 16/Nov/2010 3:32:36 PM - System Checkpoint
    RP91: 17/Nov/2010 10:07:06 AM - Installed Java(TM) 6 Update 22

    ==== Installed Programs ======================

    32 Bit HP BiDi Channel Components Installer
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Reader 9.1
    Attachmate KEA! 2000
    ChequeScribe I
    Compatibility Pack for the 2007 Office system
    Coupon Printer for Windows
    CutePDF Writer 2.7
    ePad Ink - 1.06
    EPSON Advanced Printer Driver 4
    EPSON APD4 Point and Print Support
    FoxPro Runtime v6 SP4
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB915800-v4)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB981793)
    IntegriSign Desktop 6.21
    Intel(R) Graphics Media Accelerator Driver
    Java 2 Runtime Environment, SE v1.4.2
    Java Auto Updater
    Java(TM) 6 Update 22
    LiveUpdate 3.2 (Symantec Corporation)
    Logitech Audio Echo Cancellation Component
    Logitech Video Enumerator
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Base Smart Card Cryptographic Service Provider Package
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Professional Edition 2003
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    MRM Photo Utility
    MSXML 4.0 SP2 (KB925672)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP2 Parser and SDK
    MVision
    Network Recording Player
    SecuGen EyeD Mouse Client
    Security Update for Windows Internet Explorer 7 (KB938127-v2)
    Security Update for Windows Internet Explorer 7 (KB972260)
    Security Update for Windows Internet Explorer 7 (KB976325)
    Security Update for Windows Internet Explorer 7 (KB982381)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB911565)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows Search 4 - KB963093
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371-v2)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972260)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB981349)
    Symantec AntiVirus
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows XP (KB943729)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows PowerShell(TM) 1.0
    Windows PowerShell(TM) 1.0 MUI pack
    Windows XP Service Pack 3
    WinZip

    ==== Event Viewer Messages From Past Week ========

    17/Nov/2010 12:02:25 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
    17/Nov/2010 12:01:08 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
    17/Nov/2010 11:24:04 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    17/Nov/2010 11:24:04 AM, error: Service Control Manager [7034] - The Epson Point of Service Port Handler service terminated unexpectedly. It has done this 1 time(s).
    17/Nov/2010 11:24:02 AM, error: Service Control Manager [7034] - The Epson Point of Service Log Service service terminated unexpectedly. It has done this 1 time(s).
    16/Nov/2010 11:28:17 AM, error: TermServDevices [1111] - Driver HP Color LaserJet CM4730 MFP PCL 5 required for printer !!sv001a!01_HR_HP4730 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:28:00 AM, error: TermServDevices [1111] - Driver HP Universal Printing PCL 6 required for printer !!sv005a!05_HP2025_Office11 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:28:00 AM, error: TermServDevices [1111] - Driver HP Universal Printing PCL 6 required for printer !!sv005a!05_HP2025_Office1 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:59 AM, error: TermServDevices [1111] - Driver HP Universal Printing PCL 6 required for printer !!sv005a!05_HP2025_Office3 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:59 AM, error: TermServDevices [1111] - Driver HP Universal Printing PCL 6 required for printer !!sv005a!05_HP2025_Office2 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:58 AM, error: TermServDevices [1111] - Driver HP Universal Printing PCL 6 required for printer !!sv005a!05_HP2025_Office6 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:58 AM, error: TermServDevices [1111] - Driver HP Universal Printing PCL 6 required for printer !!sv005a!05_HP2025_Office5 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:58 AM, error: TermServDevices [1111] - Driver HP Universal Printing PCL 6 required for printer !!sv005a!05_HP2025_Office4 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:57 AM, error: TermServDevices [1111] - Driver HP Universal Printing PCL 6 required for printer !!sv005a!05_HP2025_Office8 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:57 AM, error: TermServDevices [1111] - Driver HP Universal Printing PCL 6 required for printer !!sv005a!05_HP2025_Office7 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:56 AM, error: TermServDevices [1111] - Driver HP LaserJet 9050 mfp PCL 6 required for printer !!sv007a!07_Accounting_HP9050 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:56 AM, error: TermServDevices [1111] - Driver HP Color LaserJet 4700 PCL 5c required for printer !!sv007a!07_Marketing_HP4700Color is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:47 AM, error: TermServDevices [1111] - Driver Xerox WorkCentre 7655 rev2 PCL6 required for printer !!sv007a!07_Reception_Xerox7655 is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 11:27:40 AM, error: TermServDevices [1111] - Driver PDFill Writer required for printer PDFill PDF&Image Writer is unknown. Contact the administrator to install the driver before you log in again.
    16/Nov/2010 10:50:06 AM, error: TermServDevices [1112] - Failed to register for user printing preferences change notification. Open the Services snap-in and confirm that the Printer Spooler service is running
    10/Nov/2010 9:55:11 AM, error: Service Control Manager [7022] - The Windows Image Acquisition (WIA) service hung on starting.

    ==== End Of File ===========================
     
  7. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Does your homeage need .org? mDefault_Page_URL = hxxp://nsculive

    Looks pretty good so far. Please run the following:

    Run Eset NOD32 Online AntiVirus scan HERE
    1. Tick the box next to YES, I accept the Terms of Use.
    2. Click Start
    3. When asked, allow the Active X control to install
    4. Disable your current Antivirus software. You can usually do this with its Notification Tray icon near the clock.
    5. Click Start
    6. Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is checked
    7. Click Scan
    8. Wait for the scan to finish
    9. Re-enable your Antivirus software.
    10. A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.
    ====================================
    Download the HijackThis Installer and save to the desktop:
    1. Double-click on HJTInstall.exe to run the program.
    2. By default it will install to C:\Program Files\Trend Micro\HijackThis.
    3. Accept the license agreement by clicking the "I Accept" button.
    4. Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
    5. Click "Save log" to save the log file and then the log will open in notepad.
    6. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    7. Come back here to this thread and paste (Ctrl+V) the log in your next reply.

    NOTE: Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
     
  8. Jskid

    Jskid TS Enthusiast Topic Starter Posts: 429

    No that's right.

    Eset Online Scan log
    ESETSmartInstaller@High as CAB hook log:
    OnlineScanner.ocx - registred OK
    # version=7
    # iexplore.exe=7.00.6000.17055 (vista_gdr.100414-0533)
    # OnlineScanner.ocx=1.0.0.6211
    # api_version=3.0.2
    # EOSSerial=5a4eee32b39fec4aa833f6c24ce48782
    # end=finished
    # remove_checked=false
    # archives_checked=false
    # unwanted_checked=true
    # unsafe_checked=false
    # antistealth_checked=true
    # utc_time=2010-11-18 06:27:10
    # local_time=2010-11-18 10:27:10 (-0800, Pacific Standard Time)
    # country="Canada"
    # lang=9
    # osver=5.1.2600 NT Service Pack 3
    # compatibility_mode=8192 67108863 100 0 0 0 0 0
    # scanned=38257
    # found=0
    # cleaned=0
    # scan_time=1142

    HijackThis log
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 10:31:28 AM, on 18/Nov/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.17055)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\EPSON\EPSON Advanced Printer Driver 4\EpsonPHLog.exe
    C:\Program Files\EPSON\EPSON Advanced Printer Driver 4\EpsonPH.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Symantec AntiVirus\SavRoam.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\rdpclip.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\logon.scr
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\Trend Micro\HijackThis\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nsculive
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [EpsonAPD4SV] C:\Program Files\EPSON\EPSON Advanced Printer Driver 4\Tools\EAPSV\EAPSV.EXE
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
    O4 - S-1-5-18 Startup: Outlook.vbs (User 'SYSTEM')
    O4 - .DEFAULT Startup: Outlook.vbs (User 'Default user')
    O4 - Global Startup: PivDel.bat
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://nsculive
    O15 - Trusted Zone: *.cutrainingonline.com (HKLM)
    O15 - Trusted Zone: http://*.hiredesk.net (HKLM)
    O15 - Trusted Zone: http://training.prolender.net (HKLM)
    O15 - ESC Trusted Zone: http://runonce.msn.com (HKLM)
    O16 - DPF: eFormsCab - http://monaco:8080/Workplace/forms/misc/eFormsWeb.cab
    O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} (Device Detection) - http://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
    O16 - DPF: {100C659D-2B0B-4BEF-B79A-34E4659B9A9C} (Pivotal ePower Lifecycle Engine (Version 5.7) - Platform Access (rdaclnt.dll)) - http://miami/ePower/cab/RDACLNT.CAB
    O16 - DPF: {154E3A83-BDE2-441E-A22C-EDAED67CF23A} (Pivotal eRelationship Active Access (Version 5.7) - Resources (rdares.dll)) - http://miami/ePower/cab/RDARES.CAB
    O16 - DPF: {24F10A0C-7983-4934-849D-582F940A8AC3} (Pivotal ePower Lifecycle Engine (Version 5.7) - Instantiator (rdaobjcreate.dll)) - http://miami/ePower/cab/RdaObjCreate.cab
    O16 - DPF: {286BCCBE-B061-4EF3-BAFA-C6D36F164DAB} (Pivotal eRelationship Active Access (Version 5.7) - Portal Preferences Page (rprefs.dll)) - http://seymour/ePower/cab/RDAPREFS.CAB
    O16 - DPF: {28E4BE08-1C25-4CE4-A9AA-3495A9D08C8E} (Pivotal eRelationship Active Access (version 5.7) - Shortcut Handler (rshortcut.dll)) - http://miami/ePower/cab/RSHORTCUT.CAB
    O16 - DPF: {309F16B3-B30C-4114-BE89-E63C4F593B41} (Pivotal eRelationship Active Access (Version 5.7) - Smart Portal (rdaprtl.dll)) - http://miami/ePower/cab/RDAPRTL.CAB
    O16 - DPF: {59A48F67-03E2-460F-9E0C-B3860634172A} (Pivotal eRelationship Active Access (Version 5.7) - Stealth Report Interface (rdaRprt.dll)) - http://miami/ePower/cab/RDARPRT.CAB
    O16 - DPF: {60927435-8441-4532-B2B7-45C9DE62945F} (Pivotal eRelationship Active Access (Version 5.7) - Portal Control Proxy (rdaui.dll)) - http://miami/ePower/cab/RdaUI.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1252539747343
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {8C42DAC2-0B6A-4F80-9794-3130E1C28345} (Pivotal eRelationship Active Access (Version 5.7) - Email Connector (rdaemail.dll)) - http://miami/ePower/cab/RDAEMAIL.CAB
    O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://sydney/crystalreportviewers10/ActiveXControls/ActiveXViewer.cab
    O16 - DPF: {A4BD9732-328D-11D4-BB89-00A0C9843488} (Pivotal ePower Lifecycle Engine (Version 5.7) - EMail Class (rn1sendx.dll)) - http://miami/ePower/cab/RN1SENDX.CAB
    O16 - DPF: {AE4F48D0-6A0A-11D3-9FB0-005004A79108} (Pivotal eRelationship Active Access (Version 5.7) - Plug-in Result Return Collection (dfoutils.dll)) - http://miami/ePower/cab/DFOUTILS.CAB
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {E774F171-CCB6-424B-877B-1D4F95DF60AD} (Pivotal eRelationship Active Access (Version 5.7) - Letter Express (rdaletex.dll)) - http://seymour/ePower/cab/RDALETEX.CAB
    O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://meeting.temenos.com/dana-cached/sc/JuniperSetupClient.cab
    O16 - DPF: {F4901BF2-3FB9-4948-BB0E-5BD2AFF09085} (Pivotal eRelationship Active Access (Version 5.7) - Shared Object Library Interface (rdashare.dll)) - http://miami/ePower/cab/RDASHARE.CAB
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nscu.ca
    O17 - HKLM\Software\..\Telephony: DomainName = nscu.ca
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = nscu.ca
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: Epson Point of Service Log Service (EpsonPOSLog) - SEIKO EPSON CORPORATION - C:\Program Files\EPSON\EPSON Advanced Printer Driver 4\EpsonPHLog.exe
    O23 - Service: Epson Point of Service Port Handler (EpsonPOSPort) - SEIKO EPSON CORPORATION - C:\Program Files\EPSON\EPSON Advanced Printer Driver 4\EpsonPH.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    --
    End of file - 10434 bytes
     
  9. Jskid

    Jskid TS Enthusiast Topic Starter Posts: 429

    It appears the file association is messed up. When I try to run any office products (e.g. word.exe) it asks me what program I want to open it with.
    EDIT: but only on one persons account
     
  10. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    For the Office Open with problem:
    Logon under the account that has the problem:
    • Click on Start> Control Panel> Folder Options
    • Select the File Type tab> let it populate.
    • Scroll to and highlight the File Extension you want to change
    • Click on Change in the Details> Open With section
    • Choose the appropriate program
    • Click on OK> Apply> OK

    The most common Word file extension is .doc So you would choose .doc[/b to Open With> Microsoft Word If there are other File Extensions used in Word that won't 'open with' correctly, follow this same process for each file extension.
     
  11. Jskid

    Jskid TS Enthusiast Topic Starter Posts: 429

    Alright thanks, I think the problem is fixed.
     
     
  12. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    It appears that this is a work-related system- is that correct? We did refer to that earlier:
    Pivotal eRelationship Active Access
    Pivotal ePower Lifecycle Engine
    NSCU Domain
    O4 - Global Startup: PivDel.bat
    And the sites in the Trusted Zone.

    It also appears you have printer problems:
    Driver HP Universal Printing PCL 6 required for printer
    Driver HP LaserJet 9050 mfp PCL 6 required for printer
    Driver HP Color LaserJet 4700 PCL 5c required for printer
    Driver PDFill Writer required for printer
    Driver Xerox WorkCentre 7655 rev2 PCL6 required for printer

    I do not change, close or otherwise handle any work-related software, nor do I take responsibility for it's security.

    Malwarebytes removed some infections and the remaining logs look good. But since the Security Center was seen to be disabled, I need to make sure that has been handled and isn't still blocked:>

    Please download ComboFix from Here and save to your Desktop.

    • [1]. Do NOT rename Combofix unless instructed.
      [2].Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      [3].Close any open browsers.
      [4]. Double click combofix.exe & follow the prompts to run.
    • NOTE: Combofix will disconnect your machine from the Internet as soon as it starts. The connection is automatically restored before CF completes its run. If it does not, restart your computer to restore your connection.
      [5]. If Combofix asks you to install Recovery Console, please allow it.
      [6]. If Combofix asks you to update the program, always allow.
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      [7]. A report will be generated after the scan. Please paste the C:\ComboFix.txt in next reply.
    Note: Do not mouseclick combofix's window while it's running. That may cause it to stall.
    Note: Make sure you re-enable your security programs, when you're done with Combofix..

    This should be the last scan.
     
  13. Jskid

    Jskid TS Enthusiast Topic Starter Posts: 429

    It is. Is this an issue?
     
  14. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Yes, it is.
    First, you are connecting using Remote Desktop- I don't know why or if this is the only way you can connect..
    And you have set forth some company policies:
    "It's policy to use Spybot Search & Destroy "- you don't like this program and say there is no problem with the company if you don't use it.

    In Post #2 I said:
    But you said nothing about the IT for the company.
    You asked whether you should log in under the local account or the domain- those aren't choices I can make for you.

    You tell me:
    The answer is Yes. Malware cleaning on free online forums is always done at the risk of the user. While most of us do the best we can, there is always a chance of causing some conflict.

    I see multiple programs running in your logs that are for your work. I don't not open these, remove these or otherwise instruct you to do anything with these programs. Your work software is not my responsibility. I don't know where they came from, what they do, if they have spyware with them. Many employers use keyloggers to monitor the work of their employees. Because of that, I cannot tell you if the system us clean.

    Please removing all of the tools we used and the files and folders they created
    • Uninstall ComboFix and all Backups of the files it deleted (if you installed it)
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
      [​IMG]
    • Download OTCleanIt by OldTimer and save it to your Desktop.
    • Double click OTCleanIt.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.

    Usually the last part is removing the old restore points and setting a new clean one- if the cleaning has been completed. But I will skip that part since I don't know your company policy.

    Empty the Recycle Bin

    Please consult the IT for the company if you require further assistance
     
  15. Jskid

    Jskid TS Enthusiast Topic Starter Posts: 429

    Problem fixed. You can close this thread now.
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.