Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Possible Virus Infection...


  • Please log in to reply
5 replies to this topic

#1 aznboi171

aznboi171

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:14 AM

Posted 13 August 2012 - 02:20 PM

Hi,

When browsing the Internet, I got a notification in my System Tray. I clicked on it and I saw an image of one of those fake virus scanning programs and I closed it only to see that I had installed a program called "Live Security Platinum". I was able to uninstall the program thanks to Google, but for some reason some of the links I clicked on led me to a site "seekportals.com". I'm not sure why that happened, but I found this website, saw this thread (Link), and followed the instructions posted here. I have posted my logs below.

Can anyone help me solve this problem? Any help is greatly appreciated.

---------------------------------------------------

LOGS:

Security Check Log:

Results of screen317's Security Check version 0.99.43
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
Norton Internet Security
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.62.0.1300
Java™ 6 Update 30
Java version out of Date!
Adobe Reader X (10.1.3)
Mozilla Firefox 12.0 Firefox out of Date!
Google Chrome 19.0.1084.56
Google Chrome 20.0.1132.47
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 11% Defragment your hard drive soon!
````````````````````End of Log``````````````````````

///////////////////////////////////////////////////////
Farbar Service Scanner Log:

Farbar Service Scanner Version: 06-08-2012
Ran by Albert Dieu (administrator) on 13-08-2012 at 12:59:55
Running from "C:\Users\Albert Dieu\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is set to Disabled. The default start type is Auto.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Disabled. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Disabled. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1

///////////////////////////////////////////////////////

MiniToolbox Log:

MiniToolBox by Farbar Version: 23-07-2012
Ran by Albert Dieu (administrator) on 13-08-2012 at 13:01:54
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

========================= FF Proxy Settings: ==============================

"network.proxy.no_proxies_on", "*.local"
"network.proxy.type", 0
========================= Hosts content: =================================

127.0.0.1 localhost

========================= IP Configuration: ================================

Intel® Centrino® Wireless-N 1030 = Wireless Network Connection (Connected)
Bluetooth Device (Personal Area Network) = Bluetooth Network Connection (Media disconnected)
Realtek PCIe GBE Family Controller = Local Area Connection (Media disconnected)
Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected)
Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 3 (Media disconnected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : DieuFamily-HP
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : gateway.2wire.net

Wireless LAN adapter Wireless Network Connection 3:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter #2
Physical Address. . . . . . . . . : AC-72-89-54-4D-F0
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wireless Network Connection 2:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter
Physical Address. . . . . . . . . : AC-72-89-54-4D-F0
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wireless Network Connection:

Connection-specific DNS Suffix . : gateway.2wire.net
Description . . . . . . . . . . . : Intel® Centrino® Wireless-N 1030
Physical Address. . . . . . . . . : AC-72-89-54-4D-EF
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::c6c:6244:f25c:fdec%15(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.2.11(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : August-13-12 9:28:08 AM
Lease Expires . . . . . . . . . . : August-16-12 12:21:56 PM
Default Gateway . . . . . . . . . : 192.168.2.1
DHCP Server . . . . . . . . . . . : 192.168.2.1
DHCPv6 IAID . . . . . . . . . . . : 380400265
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-59-0B-43-08-2E-5F-7D-79-F9
DNS Servers . . . . . . . . . . . : 192.168.2.1
NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
Physical Address. . . . . . . . . : 08-2E-5F-7D-79-F9
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Ethernet adapter Bluetooth Network Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network)
Physical Address. . . . . . . . . : AC-72-89-54-4D-F3
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 11:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:28fd:2444:b5f1:7329(Preferred)
Link-local IPv6 Address . . . . . : fe80::28fd:2444:b5f1:7329%20(Preferred)
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled

Tunnel adapter isatap.gateway.2wire.net:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : gateway.2wire.net
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 13:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft 6to4 Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Reusable ISATAP Interface {DE0955C5-B25C-4A81-9AD9-684487C50DBE}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{78EA8225-7F9D-41C4-8D41-BAEDCC3B18A7}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #4
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{F7D75FCD-37DE-4BD2-B1B7-659AFF7DEEE8}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #5
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{3AEFB00A-AC9E-46F9-A0A0-815CBCF12B54}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #6
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{DBD98453-252A-49C8-8CB0-4457A3DFB36B}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #7
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: mymodem
Address: 192.168.2.1

Name: google.com
Addresses: 2001:4860:4008:802::1004
74.125.226.71
74.125.226.68
74.125.226.70
74.125.226.66
74.125.226.78
74.125.226.67
74.125.226.64
74.125.226.69
74.125.226.72
74.125.226.73
74.125.226.65


Pinging google.com [74.125.226.71] with 32 bytes of data:
Reply from 74.125.226.71: bytes=32 time=23ms TTL=54
Reply from 74.125.226.71: bytes=32 time=13ms TTL=54

Ping statistics for 74.125.226.71:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 13ms, Maximum = 23ms, Average = 18ms
Server: mymodem
Address: 192.168.2.1

Name: yahoo.com
Addresses: 72.30.38.140
98.139.183.24
209.191.122.70


Pinging yahoo.com [72.30.38.140] with 32 bytes of data:
Reply from 72.30.38.140: bytes=32 time=136ms TTL=51
Reply from 72.30.38.140: bytes=32 time=90ms TTL=51

Ping statistics for 72.30.38.140:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 90ms, Maximum = 136ms, Average = 113ms
Server: mymodem
Address: 192.168.2.1

Name: bleepingcomputer.com
Address: 208.43.87.2


Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.

Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
17...ac 72 89 54 4d f0 ......Microsoft Virtual WiFi Miniport Adapter #2
16...ac 72 89 54 4d f0 ......Microsoft Virtual WiFi Miniport Adapter
15...ac 72 89 54 4d ef ......Intel® Centrino® Wireless-N 1030
13...08 2e 5f 7d 79 f9 ......Realtek PCIe GBE Family Controller
12...ac 72 89 54 4d f3 ......Bluetooth Device (Personal Area Network)
1...........................Software Loopback Interface 1
20...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
25...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
14...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
23...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
21...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #4
26...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #5
27...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #6
24...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #7
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.11 25
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.2.0 255.255.255.0 On-link 192.168.2.11 281
192.168.2.11 255.255.255.255 On-link 192.168.2.11 281
192.168.2.255 255.255.255.255 On-link 192.168.2.11 281
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.2.11 281
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.2.11 281
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
20 58 ::/0 On-link
1 306 ::1/128 On-link
20 58 2001::/32 On-link
20 306 2001:0:4137:9e76:28fd:2444:b5f1:7329/128
On-link
15 281 fe80::/64 On-link
20 306 fe80::/64 On-link
15 281 fe80::c6c:6244:f25c:fdec/128
On-link
20 306 fe80::28fd:2444:b5f1:7329/128
On-link
1 306 ff00::/8 On-link
20 306 ff00::/8 On-link
15 281 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 09 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation)
Catalog5 10 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 09 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation)
x64-Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (08/13/2012 09:28:14 AM) (Source: Application Error) (User: )
Description: Faulting application name: HPAuto.exe, version: 1.0.12935.3667, time stamp: 0x4d5cc461
Faulting module name: HPAuto.exe, version: 1.0.12935.3667, time stamp: 0x4d5cc461
Exception code: 0xc0000005
Fault offset: 0x0000000000007be2
Faulting process id: 0xaf4
Faulting application start time: 0xHPAuto.exe0
Faulting application path: HPAuto.exe1
Faulting module path: HPAuto.exe2
Report Id: HPAuto.exe3

Error: (08/13/2012 09:28:13 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/12/2012 10:28:35 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC

Error: (08/12/2012 10:28:35 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC

Error: (08/12/2012 10:28:35 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC

Error: (08/12/2012 09:29:44 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1139

Error: (08/12/2012 09:29:44 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1139

Error: (08/12/2012 09:29:44 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (08/12/2012 08:52:28 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 74335

Error: (08/12/2012 08:52:28 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 74335


System errors:
=============
Error: (08/13/2012 00:32:01 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.131.1594.0

Update Source: %NT AUTHORITY59

Update Stage: 4.0.1526.00

Source Path: 4.0.1526.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (08/13/2012 11:08:13 AM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.131.1594.0

Update Source: %NT AUTHORITY59

Update Stage: 4.0.1526.00

Source Path: 4.0.1526.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (08/13/2012 10:38:02 AM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.131.1594.0

Update Source: %NT AUTHORITY59

Update Stage: 4.0.1526.00

Source Path: 4.0.1526.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (08/13/2012 09:38:37 AM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.131.1594.0

Update Source: %NT AUTHORITY59

Update Stage: 4.0.1526.00

Source Path: 4.0.1526.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (08/13/2012 09:30:16 AM) (Source: Service Control Manager) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error:
%%1053

Error: (08/13/2012 09:30:16 AM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.

Error: (08/13/2012 09:28:14 AM) (Source: Service Control Manager) (User: )
Description: The HP Auto service terminated unexpectedly. It has done this 1 time(s).

Error: (08/12/2012 09:46:03 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.131.1594.0

Update Source: %NT AUTHORITY59

Update Stage: 4.0.1526.00

Source Path: 4.0.1526.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (08/12/2012 09:02:24 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.131.1594.0

Update Source: %NT AUTHORITY59

Update Stage: 4.0.1526.00

Source Path: 4.0.1526.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (08/12/2012 08:41:44 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.131.1594.0

Update Source: %NT AUTHORITY59

Update Stage: 4.0.1526.00

Source Path: 4.0.1526.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608


Microsoft Office Sessions:
=========================
Error: (06/06/2012 07:58:49 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 43 seconds with 0 seconds of active time. This session ended with a crash.

Error: (06/06/2012 07:54:27 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 45 seconds with 0 seconds of active time. This session ended with a crash.


=========================== Installed Programs ============================

Update for Microsoft Office 2007 (KB2508958)
ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212)
Adobe AIR (Version: 1.5.3.9130)
Adobe Community Help (Version: 3.2.1)
Adobe Community Help (Version: 3.2.1.650)
Adobe Flash Player 11 ActiveX (Version: 11.3.300.270)
Adobe Flash Player 11 Plugin (Version: 11.3.300.270)
Adobe Photoshop Elements 9 (Version: 9.0)
Adobe Premiere Elements 9 (Version: 9.0)
Adobe Reader X (10.1.3) MUI (Version: 10.1.3)
Adobe Shockwave Player 11.6 (Version: 11.6.5.635)
Agatha Christie - Peril at End House (Version: 2.2.0.95)
Apple Application Support (Version: 2.1.7)
Apple Mobile Device Support (Version: 5.1.1.4)
Apple Software Update (Version: 2.1.3.127)
ATI Catalyst Install Manager (Version: 3.0.816.0)
Bejeweled 2 Deluxe (Version: 2.2.0.95)
Bejeweled 3 (Version: 2.2.0.95)
Bing Bar (Version: 7.0.610.0)
Blackhawk Striker 2 (Version: 2.2.0.95)
Blasterball 3 (Version: 2.2.0.95)
Blio (Version: 2.2.7689)
Bonjour (Version: 3.0.0.10)
Bounce Symphony (Version: 2.2.0.95)
Build-a-lot 2 (Version: 2.2.0.95)
Cake Mania (Version: 2.2.0.95)
Canadian Rental Kit (Version: 07-1)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center (Version: 2011.0508.224.2391)
Catalyst Control Center Graphics Previews Common (Version: 2011.0508.224.2391)
Catalyst Control Center InstallProxy (Version: 2011.0508.224.2391)
Catalyst Control Center Localization All (Version: 2011.0508.224.2391)
Catalyst Control Center Profiles Mobile (Version: 2011.0508.224.2391)
ccc-utility64 (Version: 2011.0508.224.2391)
CCC Help Chinese Standard (Version: 2011.0508.0223.2391)
CCC Help Chinese Traditional (Version: 2011.0508.0223.2391)
CCC Help Czech (Version: 2011.0508.0223.2391)
CCC Help Danish (Version: 2011.0508.0223.2391)
CCC Help Dutch (Version: 2011.0508.0223.2391)
CCC Help English (Version: 2011.0508.0223.2391)
CCC Help Finnish (Version: 2011.0508.0223.2391)
CCC Help French (Version: 2011.0508.0223.2391)
CCC Help German (Version: 2011.0508.0223.2391)
CCC Help Greek (Version: 2011.0508.0223.2391)
CCC Help Hungarian (Version: 2011.0508.0223.2391)
CCC Help Italian (Version: 2011.0508.0223.2391)
CCC Help Japanese (Version: 2011.0508.0223.2391)
CCC Help Korean (Version: 2011.0508.0223.2391)
CCC Help Norwegian (Version: 2011.0508.0223.2391)
CCC Help Polish (Version: 2011.0508.0223.2391)
CCC Help Portuguese (Version: 2011.0508.0223.2391)
CCC Help Russian (Version: 2011.0508.0223.2391)
CCC Help Spanish (Version: 2011.0508.0223.2391)
CCC Help Swedish (Version: 2011.0508.0223.2391)
CCC Help Thai (Version: 2011.0508.0223.2391)
CCC Help Turkish (Version: 2011.0508.0223.2391)
Chuzzle Deluxe (Version: 2.2.0.95)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (Version: 15.4.5722.2)
CyberLink YouCam (Version: 3.5.1.3922)
D3DX10 (Version: 15.4.2368.0902)
Diner Dash 2 Restaurant Rescue (Version: 2.2.0.95)
Dora's World Adventure (Version: 2.2.0.95)
Elements 9 Organizer (Version: 9.0)
Elements STI Installer (Version: 1.0)
Energy Star Digital Logo (Version: 1.0.1)
Epson CreativeZone
Epson Easy Photo Print 2 (Version: 2.2.0.0)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (Version: 1.00.0000)
Epson Easy Photo Print Plug-in for Windows Live Photo Gallery
Epson Easy Photo Print Plug-in for Windows Live Photo Gallery Setup (Version: 1.00.0000)
Epson FAX Utility (Version: 1.10.00)
Epson PC-FAX Driver
EPSON Scan
EPSON WorkForce 320 Series Printer Uninstall
ESU for Microsoft Windows 7 (Version: 1.0.0)
Evernote v. 4.2.2 (Version: 4.2.2.3979)
Farm Frenzy (Version: 2.2.0.95)
FATE - The Traitor Soul (Version: 2.2.0.95)
FIFA 12 © EA version 1 (Version: 1)
Final Drive Nitro (Version: 2.2.0.95)
Galerie de photos Windows Live (Version: 15.4.3502.0922)
Google Chrome (Version: 21.0.1180.75)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.3.2710.138)
Google Update Helper (Version: 1.3.21.111)
Hewlett-Packard ACLM.NET v1.1.2.0 (Version: 1.00.0000)
HP 3D DriveGuard (Version: 4.1.16.1)
HP Auto (Version: 1.0.12935.3667)
HP Client Services (Version: 1.1.12938.3539)
HP Connection Manager (Version: 4.1.23.1)
HP Customer Experience Enhancements (Version: 6.0.1.7)
HP Documentation (Version: 1.1.0.0)
HP DVB-T TV Tuner 8.0.64.43 (Version: 8.0.64.43)
HP Games (Version: 1.0.2.4)
HP On Screen Display (Version: 1.1.2)
HP Power Manager (Version: 1.4.4)
HP Quick Launch (Version: 2.7.2)
HP Setup (Version: 8.6.4530.3651)
HP Setup Manager (Version: 1.1.13253.3682)
HP Software Framework (Version: 4.5.10.1)
HP Support Assistant (Version: 6.1.12.1)
iCloud (Version: 1.1.0.40)
IDT Audio (Version: 1.0.6345.0)
Intel PROSet Wireless
Intel® Control Center (Version: 1.2.1.1007)
Intel® Display Audio Driver (Version: 6.14.00.3074)
Intel® Identity Protection Technology 1.2.22.0 (Version: 1.2.22.0)
Intel® Management Engine Components (Version: 7.0.0.1144)
Intel® PROSet/Wireless for Bluetooth® + High Speed (Version: 15.0.0.0074)
Intel® PROSet/Wireless Software for Bluetooth® Technology (Version: 1.1.1.0581)
Intel® Rapid Storage Technology (Version: 10.6.0.1002)
Intel® WiDi (Version: 2.1.39.0)
Intel® Wireless Display
Intel® PROSet/Wireless WiFi Software (Version: 15.00.0000.0682)
iTunes (Version: 10.6.0.40)
Java Auto Updater (Version: 2.0.6.1)
Java™ 6 Update 24 (64-bit) (Version: 6.0.240)
Java™ 6 Update 30 (Version: 6.0.300)
Junk Mail filter update (Version: 15.4.3502.0922)
Magic Desktop (Version: 3.0)
Mah Jong Medley (Version: 2.2.0.95)
Malwarebytes Anti-Malware version 1.62.0.1300 (Version: 1.62.0.1300)
Mesh Runtime (Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft IntelliPoint 8.2 (Version: 8.20.468.0)
Microsoft Mathematics (64-bit) (Version: 4.0)
Microsoft Mathematics Add-in (32-bit) (Version: 2.0.040811.01)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2010 (Version: 14.0.4763.1000)
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Visio 2007 Service Pack 3 (SP3)
Microsoft Office Visio MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Visio Professional 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Security Client (Version: 4.0.1526.0)
Microsoft Security Essentials (Version: 4.0.1526.0)
Microsoft Silverlight (Version: 5.1.10411.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual Basic 6.0 Professional Edition
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Web Publishing Wizard 1.53
Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053)
Microsoft_VC90_CRT_x86 (Version: 1.00.0000)
Mozilla Firefox 12.0 (x86 en-US) (Version: 12.0)
Mozilla Maintenance Service (Version: 12.0)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
Mystery P.I. - Stolen in San Francisco (Version: 2.2.0.95)
Namco All-Stars PAC-MAN (Version: 2.2.0.95)
NBA 2K12 (Version: 1.0.0)
Norton Internet Security (Version: 18.7.2.3)
Opera 11.61 (Version: 11.61.1250)
Origin (Version: 8.6.0.357)
Paltalk Messenger (Version: 10.2)
Penguins! (Version: 2.2.0.95)
Plants vs. Zombies - Game of the Year (Version: 2.2.0.95)
PlayReady PC Runtime x86 (Version: 1.3.0)
plist Editor for Windows 1.0.2 (Version: 1.0.2)
Poker Superstars III (Version: 2.2.0.95)
Polar Bowler (Version: 2.2.0.95)
Polar Golfer (Version: 2.2.0.95)
PX Profile Update (Version: 1.00.1.)
Quake 3 Arena Demo
QuickTime (Version: 7.71.80.42)
Realtek Ethernet Controller Driver (Version: 7.41.216.2011)
Realtek PCIE Card Reader (Version: 6.1.7601.83)
Recovery Manager (Version: 2.0.0)
Safari (Version: 5.34.52.7)
Slingo Supreme (Version: 2.2.0.95)
SmartSound Quicktracks for Premiere Elements 9.0 (Version: 3.12.3090)
StreamTorrent 1.0
StudyWorks 2002
swMSM (Version: 12.0.0.1)
Synaptics TouchPad Driver (Version: 15.3.11.0)
System Requirements Lab CYRI (Version: 4.5.1.0)
The Weather Network
Tixati
Unity Web Player (Version: )
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Visio 2007 Help (KB963666)
Update for Microsoft Office Word 2007 Help (KB963665)
Update Installer for WildTangent Games App
Veetle TV (Version: 0.9.19)
VIP Access SDK (1.1.0.4) (Version: 1.1.0.4)
Virtual Villagers 4 - The Tree of Life (Version: 2.2.0.95)
VirtualCloneDrive
VLC media player 2.0.1 (Version: 2.0.1)
vShare.tv plugin 1.3 (Version: 1.3)
WildTangent Games App (HP Games) (Version: 4.0.5.36)
Windows Live (Version: 15.4.3502.0922)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3508.1109)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
WinPcap 4.1.2 (Version: 4.1.0.2001)
WinRAR 4.01 (64-bit) (Version: 4.01.0)
WinSCP 4.3.7 (Version: 4.3.7)
Zuma Deluxe (Version: 2.2.0.95)

========================= Devices: ================================

Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


========================= Memory info: ===================================

Percentage of memory in use: 59%
Total physical RAM: 4043.86 MB
Available physical RAM: 1648.05 MB
Total Pagefile: 8085.91 MB
Available Pagefile: 4961.22 MB
Total Virtual: 4095.88 MB
Available Virtual: 3959.5 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:674.35 GB) (Free:491.21 GB) NTFS
2 Drive d: (RECOVERY) (Fixed) (Total:23.99 GB) (Free:2.54 GB) NTFS

========================= Users: ========================================

User accounts for \\DIEUFAMILY-HP

Administrator Albert Dieu Guest


**** End of log ****
///////////////////////////////////////////////////////

MBAM Log:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.13.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Albert Dieu :: DIEUFAMILY-HP [administrator]

Protection: Enabled

13/08/2012 1:18:51 PM
mbam-log-2012-08-13 (13-18-51).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 281511
Time elapsed: 11 minute(s), 31 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
///////////////////////////////////////////////////////

aswMBR Log:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-13 13:32:42
-----------------------------
13:32:42.690 OS Version: Windows x64 6.1.7601 Service Pack 1
13:32:42.690 Number of processors: 4 586 0x2A07
13:32:42.690 ComputerName: DIEUFAMILY-HP UserName: Albert Dieu
13:32:45.770 Initialize success
13:34:24.534 AVAST engine defs: 12081300
13:35:35.453 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
13:35:35.453 Disk 0 Vendor: TOSHIBA_ GT00 Size: 715404MB BusType: 3
13:35:35.463 Disk 0 MBR read successfully
13:35:35.463 Disk 0 MBR scan
13:35:35.513 Disk 0 Windows 7 default MBR code
13:35:35.523 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
13:35:35.563 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 690537 MB offset 409600
13:35:35.623 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 24564 MB offset 1414629376
13:35:35.653 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1464936448
13:35:35.823 Disk 0 scanning C:\Windows\system32\drivers
13:35:50.340 Service scanning
13:36:41.250 Modules scanning
13:36:41.250 Disk 0 trace - called modules:
13:36:41.630 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
13:36:41.630 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005362790]
13:36:41.640 3 CLASSPNP.SYS[fffff88001c0143f] -> nt!IofCallDriver -> [0xfffffa8004e33890]
13:36:41.640 5 hpdskflt.sys[fffff88001fa1189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004cef050]
13:36:44.782 AVAST engine scan C:\Windows
13:36:49.392 AVAST engine scan C:\Windows\system32
13:41:38.009 AVAST engine scan C:\Windows\system32\drivers
13:41:53.981 AVAST engine scan C:\Users\Albert Dieu
13:44:58.402 Disk 0 MBR has been saved successfully to "C:\Users\Albert Dieu\Desktop\MBR.dat"
13:44:58.412 The log file has been saved successfully to "C:\Users\Albert Dieu\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-13 13:46:14
-----------------------------
13:46:14.674 OS Version: Windows x64 6.1.7601 Service Pack 1
13:46:14.674 Number of processors: 4 586 0x2A07
13:46:14.674 ComputerName: DIEUFAMILY-HP UserName: Albert Dieu
13:46:16.676 Initialize success
13:46:22.784 AVAST engine defs: 12081300
13:46:24.812 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
13:46:24.812 Disk 0 Vendor: TOSHIBA_ GT00 Size: 715404MB BusType: 3
13:46:24.844 Disk 0 MBR read successfully
13:46:24.844 Disk 0 MBR scan
13:46:24.859 Disk 0 Windows 7 default MBR code
13:46:24.859 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
13:46:24.875 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 690537 MB offset 409600
13:46:24.906 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 24564 MB offset 1414629376
13:46:24.922 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1464936448
13:46:25.015 Disk 0 scanning C:\Windows\system32\drivers
13:46:43.265 Service scanning
13:47:30.201 Modules scanning
13:47:30.201 Disk 0 trace - called modules:
13:47:30.716 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys
13:47:30.716 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005362790]
13:47:30.732 3 CLASSPNP.SYS[fffff88001c0143f] -> nt!IofCallDriver -> [0xfffffa8004e33890]
13:47:30.732 5 hpdskflt.sys[fffff88001fa1189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004cef050]
13:47:31.808 AVAST engine scan C:\Windows
13:47:42.291 AVAST engine scan C:\Windows\system32
13:51:28.309 AVAST engine scan C:\Windows\system32\drivers
13:51:59.285 AVAST engine scan C:\Users\Albert Dieu
14:12:48.905 AVAST engine scan C:\ProgramData
14:20:20.100 Scan finished successfully
14:20:44.442 Disk 0 MBR has been saved successfully to "C:\Users\Albert Dieu\Desktop\MBR.dat"
14:20:44.574 The log file has been saved successfully to "C:\Users\Albert Dieu\Desktop\aswMBR.txt"

****************************************************************************

End of Logs

BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:14 AM

Posted 13 August 2012 - 09:21 PM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results


Download

ESET online scanner

Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply


Download

adware cleaner

Launch it click on Delete

post the generated log

Which browser has redirects?

#3 aznboi171

aznboi171
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:14 AM

Posted 14 August 2012 - 05:02 PM

All browsers have the problem. Here are the logs:

TDSSkiller Log:

10:26:44.0011 5444 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
10:26:47.0521 5444 ============================================================
10:26:47.0521 5444 Current date / time: 2012/08/14 10:26:47.0521
10:26:47.0521 5444 SystemInfo:
10:26:47.0521 5444
10:26:47.0521 5444 OS Version: 6.1.7601 ServicePack: 1.0
10:26:47.0521 5444 Product type: Workstation
10:26:47.0521 5444 ComputerName: DIEUFAMILY-HP
10:26:47.0521 5444 UserName: Albert Dieu
10:26:47.0521 5444 Windows directory: C:\Windows
10:26:47.0521 5444 System windows directory: C:\Windows
10:26:47.0521 5444 Running under WOW64
10:26:47.0521 5444 Processor architecture: Intel x64
10:26:47.0521 5444 Number of processors: 4
10:26:47.0521 5444 Page size: 0x1000
10:26:47.0521 5444 Boot type: Normal boot
10:26:47.0521 5444 ============================================================
10:26:49.0798 5444 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:26:49.0814 5444 ============================================================
10:26:49.0814 5444 \Device\Harddisk0\DR0:
10:26:49.0814 5444 MBR partitions:
10:26:49.0814 5444 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800
10:26:49.0814 5444 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x544B4800
10:26:49.0814 5444 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x54518800, BlocksNum 0x2FFA000
10:26:49.0814 5444 \Device\Harddisk0\DR0\Partition3: MBR, Type 0xC, StartLBA 0x57512800, BlocksNum 0x336F0
10:26:49.0814 5444 ============================================================
10:26:49.0845 5444 C: <-> \Device\Harddisk0\DR0\Partition1
10:26:49.0892 5444 D: <-> \Device\Harddisk0\DR0\Partition2
10:26:49.0892 5444 ============================================================
10:26:49.0892 5444 Initialize success
10:26:49.0892 5444 ============================================================
10:27:13.0916 1648 ============================================================

/////////////////////////////////////////////////////////////////////////

esets Log:
(Copied to Clipboard because I couldn't export it)

C:\Documents and Settings\Albert Dieu\AppData\Local\Temp\ICReinstall\cnet2_fkeylogger_zip.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
C:\Documents and Settings\Albert Dieu\AppData\Local\Temp\is1598539481\BuzzdockSetup-Silent.exe probably a variant of Win32/Adware.ECOHET application cleaned by deleting - quarantined
C:\Documents and Settings\Albert Dieu\AppData\Local\Temp\is1598539481\MyBabylonTB.exe Win32/Toolbar.Babylon application cleaned by deleting - quarantined
Operating memory a variant of Win32/Packed.VMProtect.AAH trojan

/////////////////////////////////////////////////////////////////////////

adware cleaner Log:

# AdwCleaner v1.801 - Logfile created 08/14/2012 at 17:54:44
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Albert Dieu - DIEUFAMILY-HP
# Boot Mode : Normal
# Running from : C:\Users\Albert Dieu\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Program Files (x86)\vShare.tv plugin
File Deleted : C:\Users\Public\Desktop\eBay.lnk

***** [Registry] *****

Key Deleted : HKCU\Software\StartSearch

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-

B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-

B231E3B8F827}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-

9A57-88F4B05FD5DD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-

B330-F66DBB03C1B5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-

BCEE-B161AB4E4183}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-

BCEE-B161AB4E4183}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-

A13B-BE5456E7FC31}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-

BE5456E7FC31}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D782BB2-F2A5-11D3-BF4C-000000000000}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96

-B231E3B8F827}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v12.0 (en-US)

Profile name : default
File : C:\Users\Albert Dieu\AppData\Roaming\Mozilla\Firefox\Profiles\w9yskkaz.default\prefs.js

[OK] File is clean.

Profile name : default
File : C:\Users\Tiffany Dieu\AppData\Roaming\Mozilla\Firefox\Profiles\3jb9purg.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v21.0.1180.77

File : C:\Users\Albert Dieu\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted : "description": "The fastest way to search the web.",
Deleted : "description": "vshare.tv plugin",
Deleted : "name": "vshare plugin",
Deleted : "path": "chvsharetvplg.dll",
Deleted : "name": "vShare.tv plug-in",
Deleted : "path": "C:\\Users\\Albert Dieu\\AppData\\Local\\Google\\Chrome\\User Data\

\Default\\Extens[...]
Deleted : "name": "vShare.tv plug-in"
Deleted : "path": "C:\\Users\\Albert Dieu\\AppData\\LocalLow\\Unity\\WebPlayer\\loader\

\npUnity3D32.d[...]

File : C:\Users\Minh Dieu\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted : "description": "The fastest way to search the web.",
Deleted : "description": "vshare.tv plugin",
Deleted : "name": "vshare plugin",
Deleted : "path": "chvsharetvplg.dll",
Deleted : "name": "vShare.tv plug-in",
Deleted : "path": "C:\\Users\\Minh Dieu\\AppData\\Local\\Google\\Chrome\\User Data\

\Default\\Extensio[...]
Deleted : "name": "vShare.tv plug-in"

File : C:\Users\Tiffany Dieu\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted : "description": "The fastest way to search the web.",
Deleted : "description": "vshare.tv plugin",
Deleted : "name": "vshare plugin",
Deleted : "path": "chvsharetvplg.dll",
Deleted : "name": "vShare.tv plug-in",
Deleted : "path": "C:\\Users\\Tiffany Dieu\\AppData\\Local\\Google\\Chrome\\User Data\

\Default\\Exten[...]
Deleted : "name": "vShare.tv plug-in"

File : C:\Users\Huyen Nguyen\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted : "description": "The fastest way to search the web.",
Deleted : "description": "vshare.tv plugin",
Deleted : "name": "vshare plugin",
Deleted : "path": "chvsharetvplg.dll",
Deleted : "name": "vShare.tv plug-in",
Deleted : "path": "C:\\Users\\Huyen Nguyen\\AppData\\Local\\Google\\Chrome\\User Data\

\Default\\Exten[...]
Deleted : "name": "vShare.tv plug-in"

-\\ Opera v11.61.1250.0

File : C:\Users\Albert Dieu\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.

File : C:\Users\Tiffany Dieu\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [307 octets] - [13/08/2012 22:33:54]
AdwCleaner[S2].txt - [5151 octets] - [14/08/2012 17:54:44]

########## EOF - C:\AdwCleaner[S2].txt - [5279 octets] ##########

******END OF LOGS******

#4 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:14 AM

Posted 14 August 2012 - 05:39 PM

Any current issues>

#5 aznboi171

aznboi171
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:14 AM

Posted 15 August 2012 - 02:34 PM

So far, the problem has stopped, but I'll post if it happens again.

Thanks for the help.

#6 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:14 AM

Posted 15 August 2012 - 08:14 PM

Download

TFC

Launch it,it will close all running programs

click on START,it should ask for reboot.If TFC locks up the system,run it in safemode

Turn off your system restore,restart the PC,create a new restore point

http://windows.microsoft.com/en-US/windows7/Turn-System-Restore-on-or-off

Update your flash player

Update your JAVA from here

http://java.com/en/download/inc/windows_upgrade_xpi.jsp

Update your antivirus frequently,do not click on suspicious links

Safe surfing :)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users