DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_32
Run by ttu1 at 20:43:52 on 2012-09-09
Microsoft Windows 7 Enterprise 6.1.7601.1.1252.1.1033.18.8149.5202 [GMT -4:00]
.
AV: McAfee VirusScan Enterprise *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee VirusScan Enterprise Antispyware Module *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
c:\Program Files (x86)\Novell\CASA\bin\micasad.exe
C:\Windows\system32\CmgShieldSvc.exe
C:\Windows\system32\EMSService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
c:\Novell\ZENworks\bin\ZenworksWindowsService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Lotus\Notes\nslsvice.exe
C:\Program Files\Novell\Client\XTier\Services\XTSvcMgr.exe
C:\Program Files (x86)\ABC\Licenser\LocalClient\i386\ClientNT.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Windows\SysWOW64\atashost.exe
C:\Program Files (x86)\Courion Corporation\Courion Client Manager\CourClientSvr.exe
C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
C:\Lotus\Notes\SUService.exe
C:\Lotus\Notes\nsd.exe
C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Windows\system32\mfevtps.exe
C:\Program Files (x86)\ABC\Licenser\LocalClient\i386\cpsyssrv.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe
C:\Windows\system32\conhost.exe
C:\Lotus\Notes\ntmulti.exe
c:\Novell\ZENworks\bin\nzrWinVNC.exe
C:\Windows\system32\DRIVERS\o2flash.exe
c:\Novell\ZENworks\bin\nzrWinVNCApp.exe
C:\Program Files (x86)\Wireless AutoSwitch\WrlsAutoSW.exs
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
c:\Novell\ZENworks\bin\ZenUserDaemon.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Google\Google Pinyin 2\GooglePinyinService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
C:\Program Files (x86)\McAfee\Common Framework\McTray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\System32\nwtray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\iprntctl.exe
C:\Windows\System32\iprntlgn.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\System32\CmgShieldUI.exe
C:\Windows\System32\EmsServiceHelper.exe
C:\Program Files\iFolder\iFolderApp.exe
C:\Novell\ZENworks\bin\ZenNotifyIcon.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\SSH Communications Security\SSH Tectia\SSH Tectia AUX\Support binaries\ssh-broker-gui.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\iFolder\lib\simias\web\bin\Simias.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\McAfee\Common Framework\McScript_InUse.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120210150231.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
EB: &IEWatch: {e69657ff-19ac-4849-bf35-91243eef1687} - C:\Program Files (x86)\IEWatch\IEWatch.dll
uRun: [<NO NAME>]
uRun: [iFolder] "C:\Program Files\iFolder\iFolderApp.exe" -checkautorun
mRun: [ZenNotifyIcon] c:\Novell\Zenworks\bin\ZenNotifyIcon.exe
mRun: [NalView] c:\Novell\ZENworks\bin\nalview.exe
mRun: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
mRun: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRunOnce: [Repair Adobe Reader Resources] "msiexec" /i {AC76BA86-7AD7-1033-7B44-A95000000001} /qn REINSTALL=Resources
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SSHTEC~1.LNK - C:\Program Files (x86)\SSH Communications Security\SSH Tectia\SSH Tectia AUX\Support binaries\ssh-broker-gui.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\VPNGUI~1.LNK - C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe
uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1)
uPolicies-explorer: NoWelcomeScreen = 1 (0x1)
uPolicies-explorer: DisallowRun = 1 (0x1)
uPolicies-disallowrun: 1 = ds-rwe.exe
uPolicies-disallowrun: 2 = jupdate.exe
uPolicies-disallowrun: 3 = jusched.exe
uPolicies-disallowrun: 4 = kazaa.exe
uPolicies-disallowrun: 5 = limewirewin.exe
uPolicies-disallowrun: 6 = ssl32dr.exe
uPolicies-disallowrun: 7 = windde32.exe
uPolicies-disallowrun: 8 = winlog.exe
uPolicies-disallowrun: 9 = freecell.exe
uPolicies-disallowrun: 10 = chess.exe
uPolicies-disallowrun: 11 = hearts.exe
uPolicies-disallowrun: 12 = mahjong.exe
uPolicies-disallowrun: 13 = minesweeper.exe
uPolicies-disallowrun: 14 = purpleplace.exe
uPolicies-disallowrun: 15 = solitaire.exe
uPolicies-disallowrun: 16 = spidersolitaire.exe
uPolicies-disallowrun: 17 = bckgzm.exe
uPolicies-disallowrun: 18 = chkrzm.exe
uPolicies-disallowrun: 19 = shvlzm.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 1 (0x1)
mPolicies-system: SynchronousMachineGroupPolicy = 1 (0x1)
mPolicies-system: SynchronousUserGroupPolicy = 1 (0x1)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBC} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
IE: {145581C9-1BCA-4ff2-8435-746011EC2180} - {01111111-D318-45F9-A54A-DAE0FB0D16B8} - C:\Windows\Downloaded Program Files\HemiIEButton.dll
IE: {78E5BB46-9A20-402F-BA66-B5634D177D77} - {E69657FF-19AC-4849-BF35-91243EEF1687} - C:\Program Files (x86)\IEWatch\IEWatch.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
Trusted Zone: filenet
Trusted Zone: harvardpilgrim.org
Trusted Zone: healthtrioconnect.com\www
Trusted Zone: hphc.org
Trusted Zone: hphc.org\filenet
Trusted Zone: hphc.org\webfocusmredev
Trusted Zone: hphc.org\webfocusmreprd
Trusted Zone: hphc.org\webfocusmreuat
Trusted Zone: uhc.com\myexternal
DPF: {01111111-D318-45F9-A54A-DAE0FB0D16B8} - hxxp://fmsprd1.hphc.org/OA_HTML/UPK/PlayerPackage/stdhemi/hemi/ietbutton/hemiiebutton.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {6C64B50D-0472-4CD6-9312-644BEF37D4E6} - hxxps://aim-uat.hphc.org/AIM/Courion/AccessOptions/HTML/PasswordCourierSS/CourLocal.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {A640B7AC-03CF-11D4-8F5F-0000E87715F0} - hxxps://support.cyber-ark.com/webclient/paweb/pasetup.cab
DPF: {AE3E8210-B33F-49C1-B4E2-860F5F4D732F} - hxxps://n2vapp072.hphc.org:444/dsview/applets/viewerLauncher.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} - vpnweb.cab
DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - hxxps://ntnotes004.hphc.org/dwa7W.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://akamaicdn.webex.com/client/WBXclient-T27L10NSP32EP1-13926/webex/ieatgpc1.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{97F43B78-DE9D-49A3-92F2-99C3D84A4B3B} : DhcpNameServer = 192.168.0.1
Notify: PCANotify - PCANotify.dll
LSA: Authentication Packages = msv1_0 ncv1_0 ZenV1_0
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120210150231.dll
BHO-X64: scriptproxy - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
EB-X64: {E69657FF-19AC-4849-BF35-91243EEF1687} - No File
mRun-x64: [ZenNotifyIcon] c:\Novell\Zenworks\bin\ZenNotifyIcon.exe
mRun-x64: [NalView] c:\Novell\ZENworks\bin\nalview.exe
mRun-x64: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
mRun-x64: [McAfeeUpdaterUI] "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
mRun-x64: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRunOnce-x64: [Repair Adobe Reader Resources] "msiexec" /i {AC76BA86-7AD7-1033-7B44-A95000000001} /qn REINSTALL=Resources
Hosts: 64.46.36.178 www.google-analytics.com.
Hosts: 64.46.36.178 ad-emea.doubleclick.net.
Hosts: 64.46.36.178 www.statcounter.com.
Hosts: 64.27.10.42 www.google-analytics.com.
Hosts: 64.27.10.42 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\TTu1\AppData\Roaming\Mozilla\Firefox\Profiles\TTu1\
FF - prefs.js: browser.startup.homepage - hxxp://online.hphc.org/
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Users\TTu1\AppData\Roaming\Mozilla\plugins\npnzrPlugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - plugin: C:\Windows\SysWOW64\npnipp.dll
FF - plugin: C:\Windows\SysWOW64\npnisp.dll
.
============= SERVICES / DRIVERS ===============
.
R0 CmgHiber;CmgHiber;C:\Windows\system32\DRIVERS\CmgHiber.sys --> C:\Windows\system32\DRIVERS\CmgHiber.sys [?]
R0 CmgShieldCEF;CmgShieldCEF;C:\Windows\system32\DRIVERS\CMGShCEF.sys --> C:\Windows\system32\DRIVERS\CMGShCEF.sys [?]
R0 CMGShieldReg;CMGShieldReg;C:\Windows\system32\DRIVERS\CmgShREG.sys --> C:\Windows\system32\DRIVERS\CmgShREG.sys [?]
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
R0 NCFilter;Novell UNC Filter - Filter;C:\Windows\system32\DRIVERS\NCFilter.sys --> C:\Windows\system32\DRIVERS\NCFilter.sys [?]
R0 NCRecognizer;Novell UNC Filter - Recognizer;C:\Windows\system32\DRIVERS\NCRecognizer.sys --> C:\Windows\system32\DRIVERS\NCRecognizer.sys [?]
R0 NCUncFilter;Novell UNC Filter - UNC Filter;C:\Windows\system32\DRIVERS\NCUncFilter.sys --> C:\Windows\system32\DRIVERS\NCUncFilter.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 ABC Client Monitor;ABC Client Monitor;C:\Program Files (x86)\ABC\Licenser\LocalClient\i386\ClientNT.exe [2011-4-14 389696]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-8-3 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 atashost;WebEx Service Host for Support Center;C:\Windows\SysWOW64\atashost.exe [2012-6-11 134456]
R2 CMGShield;CMGShield;C:\Windows\system32\CmgShieldSvc.exe --> C:\Windows\system32\CmgShieldSvc.exe [?]
R2 CourClientSvr;CourClientSvr;C:\Program Files (x86)\Courion Corporation\Courion Client Manager\CourClientSvr.exe [2012-3-21 225184]
R2 EMS;EMS;EMSService.exe --> EMSService.exe [?]
R2 LNSUSvc;Lotus Notes Smart Upgrade Service;C:\Lotus\Notes\SUService.exe [2011-9-16 189832]
R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;C:\Lotus\Notes\nsd.exe -svcinvoke -ini "C:\Lotus\Notes\notes.ini" --> C:\Lotus\Notes\nsd.exe -svcinvoke -ini C:\Lotus\Notes\notes.ini [?]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-9 655944]
R2 McAfeeFramework;McAfee Framework Service;C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe [2011-5-19 120128]
R2 McShield;McAfee McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2012-2-10 190256]
R2 McTaskManager;McAfee Task Manager;C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe [2011-1-12 209760]
R2 mfevtp;McAfee Validation Trust Protection Service;"C:\Windows\system32\mfevtps.exe" --> C:\Windows\system32\mfevtps.exe [?]
R2 Monitor System;Monitor System;C:\Program Files (x86)\ABC\Licenser\LocalClient\i386\cpsyssrv.exe [2011-4-14 303168]
R2 NCFSD;Novell Client File System Redirector;C:\Program Files\Novell\Client\XTier\Drivers\ncfsd.sys [2011-8-3 96792]
R2 NCIOCTL;Novell Xplat IoCtl Driver;C:\Program Files\Novell\Client\XTier\Drivers\ncioctl.sys [2011-8-3 83480]
R2 Novell Identity Store;Novell Identity Store;C:\Program Files (x86)\Novell\CASA\bin\micasad.exe [2011-5-26 253952]
R2 Novell ZENworks Agent Service;Novell ZENworks Agent Service;C:\Novell\ZENworks\bin\ZenworksWindowsService.exe [2011-11-5 28672]
R2 nzwinvnc;Novell ZENworks Remote Management powered by VNC;c:\Novell\ZENworks\bin\nzrWinVNC.exe -service --> c:\Novell\ZENworks\bin\nzrWinVNC.exe -service [?]
R2 vpnagent;Cisco AnyConnect Secure Mobility Agent;C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2012-1-13 476112]
R2 Wireless_AutoSwitch;Wireless AutoSwitch;C:\Program Files (x86)\Wireless AutoSwitch\WrlsAutoSW.exs [2011-5-25 146680]
R2 XTSvcMgr;Novell XTier Service Manager;C:\Program Files\Novell\Client\XTier\Services\xtsvcmgr.exe [2011-8-3 21016]
R3 acsock;acsock;C:\Windows\system32\DRIVERS\acsock64.sys --> C:\Windows\system32\DRIVERS\acsock64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 cvusbdrv;Dell ControlVault;C:\Windows\system32\Drivers\cvusbdrv.sys --> C:\Windows\system32\Drivers\cvusbdrv.sys [?]
R3 dfmirage;dfmirage;C:\Windows\system32\DRIVERS\dfmirage.sys --> C:\Windows\system32\DRIVERS\dfmirage.sys [?]
R3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;C:\Windows\system32\DRIVERS\e1c62x64.sys --> C:\Windows\system32\DRIVERS\e1c62x64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 O2MDRRDR;O2MDRRDR;C:\Windows\system32\DRIVERS\O2MDRvstx64.sys --> C:\Windows\system32\DRIVERS\O2MDRvstx64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Novell ZENworks Image-Safe Data Service;Novell ZENworks ISD Service;C:\Program Files (x86)\Novell\ZENworks\bin\preboot\novell-zisdservice.exe [2010-6-29 90112]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 GoToAssist Express Customer;GoToAssist Express Customer;C:\Program Files (x86)\Citrix\GoToAssist Express Customer\403\g2ax_service.exe [2012-7-12 609144]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;C:\Windows\system32\drivers\Synth3dVsc.sys --> C:\Windows\system32\drivers\Synth3dVsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;Remote Deskotop USB Hub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 ZENPreAgent;Novell ZENworks Pre Agent;C:\Windows\novell\zenworks\bin\ZENPreAgent.exe [2012-6-5 196608]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-8-14 250056]
.
=============== Created Last 30 ================
.
2012-09-09 18:00:56 711240 ----a-w- C:\Windows\isRS-000.tmp
2012-09-09 18:00:56 711240 ----a-w- C:\Windows\CEFC1da.isRS-000.tmp.TBD
2012-09-09 17:57:19 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-09-09 17:57:18 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-09-09 17:44:41 -------- d-----w- C:\Users\TTu1\AppData\Local\Macromedia
2012-09-09 03:14:54 -------- d-----w- C:\Users\TTu1\AppData\Roaming\Malwarebytes
2012-09-09 03:14:09 -------- d-----w- C:\ProgramData\Malwarebytes
2012-09-08 14:22:50 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-09-08 14:22:49 609792 ----a-w- C:\Windows\System32\vbscript.dll
2012-09-07 12:20:49 -------- d-----w- C:\Users\TTu1\AppData\Roaming\smkits
2012-09-01 14:53:26 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-09-01 14:50:27 59392 ----a-w- C:\Windows\System32\browcli.dll
2012-09-01 14:50:27 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2012-09-01 14:50:26 136704 ----a-w- C:\Windows\System32\browser.dll
2012-09-01 14:48:32 956416 ----a-w- C:\Windows\System32\localspl.dll
2012-08-14 13:43:56 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
.
==================== Find3M ====================
.
2012-08-24 22:10:29 59 ----a-w- C:\Windows\wpd99.drv
2012-08-15 16:55:33 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-17 14:02:13 476960 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-07-17 14:02:13 472864 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-07-12 13:45:12 110456 ----a-w- C:\Users\TTu1\g2ax_customer_downloadhelper_win32_x86.exe
2012-06-27 07:06:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
2012-06-27 05:53:07 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-27 04:53:10 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-27 04:10:55 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2009-10-14 22:37:42 114688 ----a-w- C:\Program Files (x86)\ad_ff.dll
.
============= FINISH: 20:44:27.87 ===============
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Enterprise
Boot Device: \Device\HarddiskVolume1
Install Date: 2/10/2012 2:28:59 PM
System Uptime: 9/9/2012 2:08:06 PM (6 hours ago)
.
Motherboard: Dell Inc. | | 08V9YG
Processor: Intel® Core i7-2820QM CPU @ 2.30GHz | CPU 1 | 2301/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 238 GiB total, 152.843 GiB free.
D: is CDROM ()
F: - No root directory. Drive type could not be determined.
H: is NetworkDisk (NcFsd) - 0 GiB total, 0 GiB free.
V: - No root directory. Drive type could not be determined.
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: PCI Serial Port
Device ID: PCI\VEN_8086&DEV_1C3D&SUBSYS_04A31028&REV_04\3&11583659&1&B3
Manufacturer:
Name: PCI Serial Port
PNP Device ID: PCI\VEN_8086&DEV_1C3D&SUBSYS_04A31028&REV_04\3&11583659&1&B3
Service:
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco Systems VPN Adapter for 64-bit Windows
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter for 64-bit Windows
PNP Device ID: ROOT\NET\0000
Service: CVirtA
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Device ID: ROOT\NET\0001
Manufacturer: Cisco Systems
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
PNP Device ID: ROOT\NET\0001
Service: vpnva
.
Class GUID:
Description:
Device ID: ACPI\SMO8800\1
Manufacturer:
Name:
PNP Device ID: ACPI\SMO8800\1
Service:
.
==== System Restore Points ===================
.
RP63: 7/11/2012 3:24:58 PM - Scheduled Checkpoint
RP64: 7/11/2012 3:47:44 PM - Windows Update
RP65: 7/12/2012 9:52:32 AM - Windows Update
RP66: 7/12/2012 10:00:24 AM - Removed Citrix Presentation Server Client
RP67: 7/12/2012 10:01:12 AM - Installed Citrix XenApp Plugin for Hosted Apps
RP68: 7/12/2012 10:18:54 AM - Installed Java 6 Update 23
RP69: 7/13/2012 9:14:33 AM - Windows Update
RP70: 7/20/2012 9:52:48 AM - Windows Update
RP71: 7/30/2012 5:25:43 PM - Scheduled Checkpoint
RP72: 8/7/2012 4:26:42 PM - Installed Softerra LDAP Browser 4.5 (64-bit)
RP73: 8/16/2012 1:14:16 AM - Scheduled Checkpoint
RP74: 9/1/2012 10:47:49 AM - Windows Update
RP75: 9/8/2012 10:22:05 AM - Windows Update
.
==== Hosts File Hijack ======================
.
Hosts: 64.46.36.178 www.google-analytics.com.
Hosts: 64.46.36.178 ad-emea.doubleclick.net.
Hosts: 64.46.36.178 www.statcounter.com.
Hosts: 64.27.10.42 www.google-analytics.com.
Hosts: 64.27.10.42 ad-emea.doubleclick.net.
Hosts: 64.27.10.42 www.statcounter.com.
.
==== Installed Programs ======================
.
.NET Data Provider for Teradata 13.01.00.02
2007 Microsoft Office Suite Service Pack 2 (SP2)
ABC LanLicenser Client
AccelerometerP11
Action Handler Resources
actions-langs
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.5.2
assetmanagementmodule-langs
auth-satellite-server-langs
BMC Remedy Action Request System 7.5.00 Install 1
bundle-langs
Catalyst Control Center InstallProxy
Cisco AnyConnect Secure Mobility Client
Cisco AnyConnect Secure Mobility Client
Cisco AnyConnect Start Before Login Module
Citrix XenApp Plugin for Hosted Apps
Classic Menu for Office 2007
ConsoleOne 1.3.5
content-distribution-point-langs
Courion Client Manager
Crystal11_Redistributables
FileNet IDM Viewer 4.0
GoToAssist Customer 1.6.0.403
IBM Lotus Sametime Connect 8.0.2
IEWatch Professional 5.1
inventory-langs
Java Auto Updater
Java 6 Update 32
Lotus Notes 8.5.3
Malwarebytes Anti-Malware version 1.62.0.1300
McAfee Agent
McAfee VirusScan Enterprise
Microsoft Office 2003 Web Components
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Visio Professional 2003
Microsoft Office Visio Viewer 2003 (English)
Microsoft Office Word MUI (English) 2007
Microsoft Redistributable Files (x86)
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Books Online (English)
Microsoft SQL Server 2005 Tools
Microsoft SQL Server Setup Support Files (English)
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual Studio 2005 Premier Partner Edition - ENU
Mozilla Firefox 5.0.1 (x86 en-US)
NICI (Shared) U.S./Worldwide (128 bit) (2.7.6-1)
novell-zenworks-patch-management-agent
Novell ZENworks
Novell ZENworks Adaptive Agent Help
Novell ZENworks Image-Safe Data Service
ODBC Driver for Teradata 13.10.0.2
OracleSmartHelp
patch-langs
Pdf995
policy-langs
Policy Action Handler Resources
Policy Handler Resources
primary-agent-langs
PrivateArk Client
remotemanagement-langs
Reporting Snapin
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft Office 2007 suites (KB2596666) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition
Shared ICU Libraries for Teradata 13.10.0.1
Softerra LDAP Administrator 2012.1
SSH Tectia Client
status-collection-point-langs
Symantec pcAnywhere
Teradata Administrator 13.10.0.2
Teradata BTEQ 13.10.0.1
Teradata CLIv2 13.10.0.1
Teradata Data Connector 13.10.0.2
Teradata GSS Client nt-i386
Teradata SQL Assistant 13.10.0.2
TextPad 5
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2007 System (KB2539530)
WebEx
windows-desktop-langs-x86_64
WinProxy-langs
WinZip 15.0
Wireless AutoSwitch XPV
zencore-agent-langs
zennotifyicon-langs
ZENworks Action Handlers
ZENworks Action Utilities
ZENworks Actions
ZENworks Agent Asset Management Module
ZENworks Agent Authentication Satellite Module
ZENworks Agent Bundle Management
ZENworks Agent Core Modules
ZENworks Agent Inventory Management
ZENworks Agent Patch Management
ZENworks Agent Policy Management
ZENworks Agent System Update Module
ZENworks Agent WinProxy Module
ZENworks Content Distribution Point
ZENworks Extensions Libraries
ZENworks Image-Safe Data Agent
ZENworks Image Management
ZENworks Imaging Server
ZENworks Information Icon
ZENworks Policy Handlers
ZENworks Policy Libraries
ZENworks Primary Agent
ZENworks Remote Management
ZENworks Remote Management Viewer
ZENworks Status Collection Point
ZENworks Uninstaller
ZENworks Version Information
ZENworks Windows UI
.
==== Event Viewer Messages From Past Week ========
.
9/9/2012 8:31:44 PM, Error: Schannel [36888] - The following fatal alert was generated: 40. The internal error state is 107.
9/9/2012 8:31:44 PM, Error: Schannel [36874] - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
9/9/2012 7:17:23 PM, Error: Microsoft-Windows-GroupPolicy [1129] - The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.
9/9/2012 7:11:05 PM, Error: NETLOGON [5719] - This computer was not able to set up a secure session with a domain controller in domain EHEALTH due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.
9/9/2012 2:08:19 PM, Error: CMGShieldReg [8217] - Failed to save settings.
9/9/2012 1:48:50 PM, Error: Microsoft-Windows-TerminalServices-RemoteConnectionManager [1067] - The terminal server cannot register 'TERMSRV' Service Principal Name to be used for server authentication. The following error occured: The specified domain either does not exist or could not be contacted. .
.
==== End Of File ===========================


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top










