Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Think I picked up a virus from either Citrix Receiver or a Word doc


  • This topic is locked This topic is locked
52 replies to this topic

#1 mdpeterson42

mdpeterson42

  • Members
  • 75 posts
  • OFFLINE
  •  
  • Local time:07:02 AM

Posted 21 September 2013 - 07:47 PM

My computer was running great until about a week ago.  That day I was using Citrix Receiver to do some work from home.  I also opened a Word doc and edited it even though I got a warning not to edit unless I trusted the source - since I was the source, I trusted it.  

 

Since then, the computer has been abysmally slow.  If I start in Normal mode, it will freeze after three minutes and become non-responsive.  If I boot in Safe Mode, it will freeze every few minutes, and then start working again, but it does everything very slowly.  I was trying to follow the Major Geeks malware removal guide (before I knew about this site) and it took 90 hours to do a HitmanPro scan and it was still going (but my computer died mid-scan).

 

Anyway, hoping I can get this fixed.  I managed to do a HijackThis scan - here are the results:

 

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 11:02:14 AM, on 9/21/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
 
 
Boot mode: Safe mode
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet.howrey.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidEM?clid=1033&p1=7&p2=tour
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SKDaemon.exe] C:\Program Files\Lenovo\Productivity Keyboard\SKDaemon.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [LENOVO.TPFNF6R] C:\Program Files\Lenovo\HOTKEY\TPFNF6R.exe
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\communicator.exe" /fromrunkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ScreenPrint32] C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe -startup
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CitrixReceiver] "c:\Documents and Settings\All Users\Start Menu\Programs\Citrix\Receiver Updater.lnk"
O4 - HKLM\..\Run: [ConnectionCenter] "c:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [Redirector] "c:\Program Files\Citrix\ICA Client\redirector.exe" /startup
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\VPN Client\vpngui.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - c:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - c:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - c:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - c:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DC.howrey.net
O17 - HKLM\Software\..\Telephony: DomainName = DC.howrey.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = DC.howrey.net
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\PROGRA~1\Citrix\ICACLI~1\RSHook.dll
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo  - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo  - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\VPN Client\cvpnd.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® Active Management Technology Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Power Manager DBC Service - Unknown owner - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
O23 - Service: SessionLauncher - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\DX9\SessionLauncher.exe (file missing)
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - c:\Program Files\Symantec AntiVirus\Smc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - c:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe
O23 - Service: Intel® Active Management Technology User Notification Service (UNS) - Intel Corporation - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
 
--
End of file - 17745 bytes

 



BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:02 AM

Posted 21 September 2013 - 11:15 PM



Hello mdpeterson42

I would like to welcome you to the Malware Removal section of the forum.

Around here they call me Gringo and I will be glad to help you with your malware problems.


Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the "Follow This Topic" Button, make sure that the "Receive notification" box is checked and that it is set to "Instantly" - This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.





I want you to reset the DMA you can do this by this script here - Reset DMA

If you have problems when you click on the link try to right click on the link and select "Save Target As" and then save to your desktop.
Once it is on your desktop right click on the file and select "Run"

If you still can't run it then you can go here "Reset DMA" to see what I want to do



Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 mdpeterson42

mdpeterson42
  • Topic Starter

  • Members
  • 75 posts
  • OFFLINE
  •  
  • Local time:07:02 AM

Posted 22 September 2013 - 02:37 AM

gringo,

thank you for your assistance.

I first ran the script in safe mode and rebooted when promoted. When it booted, I did not notice anything different. I decided to try the script in normal mode. I managed to run it, but the computer froze when I tried to reboot and I had to do a hard power off. When I turned it back on, it still had the same symptoms.

I almost forgot - when I ran it in normal mode, I got an error that the recovery location did not have enough free space.

Edited by mdpeterson42, 22 September 2013 - 02:41 AM.


#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:02 AM

Posted 22 September 2013 - 02:58 AM



I need to get some reports to get a base to start from so I need you to run these programs first.



-Download DDS-
  • Please download DDS from one of the links below and save it to your desktop:

    dds_scr.gif
    Download DDS and save it to your desktop

    Link1
    Link2
    Link3
    • Double-Click on dds.scr and a command window will appear. This is normal.
    • Shortly after two logs will appear:
      • DDS.txt
      • Attach.txt
    • A window will open instructing you save & post the logs
    • Save the logs to a convenient place such as your desktop
    • Copy the contents of both logs & post in your next reply
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 mdpeterson42

mdpeterson42
  • Topic Starter

  • Members
  • 75 posts
  • OFFLINE
  •  
  • Local time:07:02 AM

Posted 22 September 2013 - 03:06 AM

And running this in safe mode will get you the info you need?

#6 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:02 AM

Posted 22 September 2013 - 03:42 AM

Yes it will


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#7 mdpeterson42

mdpeterson42
  • Topic Starter

  • Members
  • 75 posts
  • OFFLINE
  •  
  • Local time:07:02 AM

Posted 22 September 2013 - 01:42 PM

I tried the scan twice and it froze up both times.

#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:02 AM

Posted 22 September 2013 - 03:47 PM


Hello mdpeterson42



Please download Farbar Recovery Scan Tool and save it to your desktop.


Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 mdpeterson42

mdpeterson42
  • Topic Starter

  • Members
  • 75 posts
  • OFFLINE
  •  
  • Local time:07:02 AM

Posted 23 September 2013 - 01:16 AM

Hey Gringo - FSRT is running (I expect it will take a while).

 

In the meantime, I had left the DDS window open and it actually completed the scan (only took three hours!).  Here is the log:

 

 

 

DDS (Ver_2012-11-20.01) - NTFS_x86 MINIMAL
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 10.21.2
Run by administrator at 11:36:18 on 2013-09-22
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3002.2625 [GMT -7:00]
.
AV: Symantec Endpoint Protection *Enabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Enabled* 
.
============== Running Processes ================
.
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
c:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://intranet.howrey.com/
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.8313.1002\swg.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [snp2uvc] c:\windows\vsnp2uvc.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SKDaemon.exe] c:\program files\lenovo\productivity keyboard\SKDaemon.exe
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [LENOVO.TPFNF6R] c:\program files\lenovo\hotkey\TPFNF6R.exe
mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [TpShocks] TpShocks.exe
mRun: [TPKBDLED] c:\windows\system32\TpScrLk.exe
mRun: [TPFNF7] c:\program files\lenovo\npdirect\TPFNF7SP.exe /r
mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper
mRun: [TVT Scheduler Proxy] c:\program files\common files\lenovo\scheduler\scheduler_proxy.exe
mRun: [LPManager] c:\progra~1\thinkv~1\prdctr\LPMGR.exe
mRun: [LPMailChecker] c:\progra~1\thinkv~1\prdctr\LPMLCHK.exe
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe
mRun: [Communicator] "c:\program files\microsoft office communicator\communicator.exe" /fromrunkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe"  -osboot
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [ScreenPrint32] c:\program files\screenprint32 v3\ScreenPrint32.exe -startup
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [CitrixReceiver] "c:\documents and settings\all users\start menu\programs\citrix\Receiver Updater.lnk"
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
mRun: [Redirector] "c:\program files\citrix\ica client\redirector.exe" /startup
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-f400-ba7e-000000000003}\_SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~2.lnk - c:\program files\adobe\acrobat 8.0\acrobat\AdobeCollabSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\thinkpad\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ciscos~1.lnk - c:\program files\vpn client\vpngui.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: ForceStartMenuLogoff = 1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Windows\System: UserPolicyMode = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\thinkpad\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{57C0B44B-F77B-49FC-B76D-C726B8F7E89A} : DHCPNameServer = 192.168.2.1
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: ACNotify - ACNotify.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: NavLogon - <no file>
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
AppInit_DLLs= c:\progra~1\citrix\icacli~1\RSHook.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
LSA: Notification Packages =  scecli ACGina
mASetup: >>Workshare Professional - c:\program files\workshare\modules\WmConfigAssistant.exe /userinit
mASetup: >>Workshare Protect Client - c:\program files\workshare\modules\Workshare.Protect.UserInit.exe
.
============= SERVICES / DRIVERS ===============
.
S3 60362804;60362804; [x]
.
=============== File Associations ===============
.
FileExt: .vbe: VBEFile=c:\windows\system32\CScript.exe "%1" %* [default=Open2]
FileExt: .vbs: VBSFile=c:\windows\system32\CScript.exe "%1" %* [default=Open2]
FileExt: .js: JSFile=c:\windows\system32\CScript.exe "%1" %* [default=Open2]
FileExt: .jse: JSEFile=c:\windows\system32\CScript.exe "%1" %* [default=Open2]
FileExt: .wsf: WSFFile=c:\windows\system32\CScript.exe "%1" %* [default=Open2]
ShellExec: SolidConverterSDKExe.exe: open="c:\program files\workshare\pdfconverter\scpdf\"
.
=============== Created Last 30 ================
.
2013-09-21 18:16:41 -------- d-----w- c:\program files\HitmanPro
2013-09-21 06:48:18 -------- d-----w- c:\windows\pss
2013-09-17 14:47:38 30976 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys
2013-09-17 14:46:46 -------- d-----w- c:\documents and settings\all users\application data\HitmanPro
2013-09-15 17:30:35 -------- d-----w- c:\documents and settings\administrator\application data\Malwarebytes
2013-09-15 17:24:01 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2013-09-15 17:20:53 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-15 17:20:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-09-13 05:51:15 1324 ----a-w- c:\windows\system32\d3d9caps.tmp
2013-09-13 04:19:35 -------- d-sh--w- c:\documents and settings\administrator\PrivacIE
2013-09-12 16:47:24 -------- d-----w- c:\documents and settings\administrator\application data\ICAClient
2013-09-12 16:46:55 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Adobe
2013-09-12 16:45:30 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Citrix
2013-09-12 16:43:35 -------- d-----w- c:\documents and settings\administrator\application data\Workshare
2013-09-12 16:43:13 -------- d-sh--w- c:\documents and settings\administrator\IETldCache
.
==================== Find3M  ====================
.
.
============= FINISH: 14:31:46.12 ===============


#10 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:02 AM

Posted 23 September 2013 - 03:24 AM

Hello


These scans do not take that long - have you considered that it could be the harddrive going bad?

to be safe back up anything you do not want to lose and let me have the Frst report when it is done


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#11 mdpeterson42

mdpeterson42
  • Topic Starter

  • Members
  • 75 posts
  • OFFLINE
  •  
  • Local time:07:02 AM

Posted 23 September 2013 - 11:11 AM

Gringo - 

 

I did think about that but the timing seem too coincidental.  One day it was fine and then I do two things that day that I had not previously done and then it starts acting poorly.  I dunno. 

 

Anyway, here are the FRST logs:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-09-2013
Ran by administrator (administrator) on LA-petersonm-L on 22-09-2013 23:48:38
Running from C:\Documents and Settings\Administrator\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Safe Mode (minimal)
 
==================== Processes (Whitelisted) ===================
 
(Symantec Corporation) c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Symantec Corporation) c:\Program Files\Symantec AntiVirus\Rtvscan.exe
(Microsoft Corporation) c:\windows\system32\ssmarque.scr
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [BluetoothAuthenticationAgent] - rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [snp2uvc] - C:\WINDOWS\vsnp2uvc.exe [569344 2006-12-28] (Sonix)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1323008 2008-10-06] (Synaptics, Inc.)
HKLM\...\Run: [SKDaemon.exe] - C:\Program Files\Lenovo\Productivity Keyboard\SKDaemon.exe [262144 2006-12-05] (LITE-ON TECHNOLOGY CORP.)
HKLM\...\Run: [TPHOTKEY] - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [68976 2009-03-13] (Lenovo Group Limited)
HKLM\...\Run: [LENOVO.TPFNF6R] - C:\Program Files\Lenovo\HOTKEY\TPFNF6R.exe [15136 2009-04-14] (Lenovo Group Limited)
HKLM\...\Run: [PWRMGRTR] - rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
HKLM\...\Run: [BLOG] - rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
HKLM\...\Run: [] - [x]
HKLM\...\Run: [TpShocks] - C:\WINDOWS\system32\TpShocks.exe [181536 2009-02-02] (Lenovo.)
HKLM\...\Run: [TPKBDLED] - C:\WINDOWS\system32\TpScrLk.exe [40960 2002-10-08] ()
HKLM\...\Run: [TPFNF7] - C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe [62240 2009-08-04] (Lenovo Group Limited)
HKLM\...\Run: [TPKMAPHELPER] - C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe [868352 2007-01-09] (Lenovo)
HKLM\...\Run: [TVT Scheduler Proxy] - C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [487424 2008-05-13] (Lenovo Group Limited)
HKLM\...\Run: [LPManager] - C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe [185688 2009-01-29] (Lenovo Group Limited)
HKLM\...\Run: [LPMailChecker] - C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe [124248 2009-01-29] (Lenovo Group Limited)
HKLM\...\Run: [EZEJMNAP] - C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [256576 2008-10-07] (Lenovo Group Ltd.)
HKLM\...\Run: [ACWLIcon] - C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe [172032 2009-04-17] (Lenovo )
HKLM\...\Run: [Communicator] - C:\Program Files\Microsoft Office Communicator\communicator.exe [5114208 2009-12-12] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Common Files\Real\Update_OB\realsched.exe [198160 2009-09-28] (RealNetworks, Inc.)
HKLM\...\Run: [ccApp] - c:\Program Files\Common Files\Symantec Shared\ccApp.exe [115560 2009-09-23] (Symantec Corporation)
HKLM\...\Run: [ScreenPrint32] - C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe [446464 2003-05-15] (Provtech Limited)
HKLM\...\Run: [Acrobat Assistant 8.0] - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [620152 2006-10-22] (Adobe Systems Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.)
HKLM\...\Run: [CitrixReceiver] - "c:\Documents and Settings\All Users\Start Menu\Programs\Citrix\Receiver Updater.lnk"
HKLM\...\Run: [ConnectionCenter] - c:\Program Files\Citrix\ICA Client\concentr.exe [383544 2012-12-14] (Citrix Systems, Inc.)
HKLM\...\Run: [Redirector] - c:\Program Files\Citrix\ICA Client\redirector.exe [129592 2012-12-14] (Citrix Systems, Inc.)
HKLM\...\Run: [ACTray] - C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe [425984 2009-04-17] (Lenovo )
HKLM Group Policy restriction on software: 2.exe <====== ATTENTION
HKLM Group Policy restriction on software: psexesvc.exe <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <====== ATTENTION
Winlogon\Notify\ACNotify: C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\tpfnf2: C:\Program Files\Lenovo\HOTKEY\notifyf2.dll ()
HKLM\...\Policies\Explorer: [ForceStartMenuLogoff] 1
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\Default User\...\RunOnce: [RealUpgradeHelper] - C:\Program Files\Common Files\Real\Update_OB\upgrdhlp.exe [ 2009-09-28] (RealNetworks, Inc.)
HKU\petersonm\...\Run: [Echo Cleanup] - c:\program files\Interwoven\WorkSite\portbl32.exe [ 2007-11-30] (Interwoven, Inc.)
HKU\petersonm\...\Run: [DW6] - "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
HKU\petersonm\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [ 2013-07-26] (Valve Corporation)
HKU\petersonm\...\Run: [Google Update] - C:\Documents and Settings\petersonm\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [ 2011-10-15] (Google Inc.)
HKU\petersonm\...\Run: [PCShowServer] - C:\Documents and Settings\petersonm\Local Settings\Application Data\DIRECTV Player\PCShowServerPMWrapper.exe [ 2012-10-15] (NDS Technologies)
Lsa: [Notification Packages] scecli ACGina
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
ShortcutTarget: Adobe Acrobat Speed Launcher.lnk -> C:\WINDOWS\Installer\{AC76BA86-1033-F400-BA7E-000000000003}\_SC_Acrobat.exe ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
ShortcutTarget: Adobe Acrobat Synchronizer.lnk -> C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk
ShortcutTarget: Cisco Systems VPN Client.lnk -> C:\Program Files\VPN Client\vpngui.exe (Cisco Systems, Inc.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
 
==================== Internet (Whitelisted) ====================
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet.howrey.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\saphtmlp.dll (SAP AG, Walldorf)
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\saphtmlp.dll (SAP AG, Walldorf)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
 
========================== Services (Whitelisted) =================
 
S2 acs; C:\WINDOWS\system32\acs.exe [467028 2008-03-27] (Atheros)
R2 ccEvtMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108392 2009-09-23] (Symantec Corporation)
S2 CcmExec; C:\WINDOWS\system32\CCM\CcmExec.exe [764768 2009-09-18] (Microsoft Corporation)
R2 ccSetMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108392 2009-09-23] (Symantec Corporation)
S2 CVPND; C:\Program Files\VPN Client\cvpnd.exe [1516584 2005-11-04] (Cisco Systems, Inc.)
S2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [45424 2009-05-21] (Lenovo Group Limited)
S3 LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [3093880 2009-07-13] (Symantec Corporation)
S2 Power Manager DBC Service; C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE [53248 2009-04-16] ()
S2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [909312 2009-02-27] (Intel® Corporation)
S2 SmcService; c:\Program Files\Symantec AntiVirus\Smc.exe [1864888 2009-09-23] (Symantec Corporation)
S3 smstsmgr; C:\WINDOWS\system32\CCM\TSManager.exe [246624 2009-09-18] (Microsoft Corporation)
S4 SNAC; c:\Program Files\Symantec AntiVirus\SNAC.EXE [341320 2009-09-23] (Symantec Corporation)
S2 SUService; c:\Program Files\Lenovo\System Update\SUService.exe [28672 2011-04-18] (Lenovo Group Limited)
R2 Symantec AntiVirus; c:\Program Files\Symantec AntiVirus\Rtvscan.exe [2477304 2009-09-23] (Symantec Corporation)
S2 TpKmpSVC; C:\WINDOWS\system32\TpKmpSVC.exe [32768 2006-06-29] ()
S2 TVT Backup Protection Service; C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe [520192 2008-05-13] ()
S2 TVT Scheduler; C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe [1155072 2008-05-13] (Lenovo Group Limited)
S2 UNS; C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2058776 2009-02-12] (Intel Corporation)
S2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"
S2 SessionLauncher; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\DX9\SessionLauncher.exe [x]
 
==================== Drivers (Whitelisted) ====================
 
S1 ANC; C:\Windows\System32\drivers\ANC.SYS [11520 2005-09-28] (IBM Corp.)
S3 btaudio; C:\Windows\System32\drivers\btaudio.sys [534568 2009-02-16] (Broadcom Corporation.)
S3 BTDriver; C:\Windows\System32\DRIVERS\btport.sys [37160 2009-02-16] (Broadcom Corporation.)
S3 BTKRNL; C:\Windows\System32\DRIVERS\btkrnl.sys [991784 2009-02-16] (Broadcom Corporation.)
S3 BTWDNDIS; C:\Windows\System32\DRIVERS\btwdndis.sys [156816 2009-02-16] (Broadcom Corporation.)
S3 BTWUSB; C:\Windows\System32\Drivers\btwusb.sys [47272 2009-02-16] (Broadcom Corporation.)
S3 CnxtHdAudService; C:\Windows\System32\drivers\CHDAU32.sys [764416 2008-06-12] (Conexant Systems Inc.)
S3 COH_Mon; C:\WINDOWS\system32\Drivers\COH_Mon.sys [23888 2009-09-23] (Symantec Corporation)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5315 2005-05-17] (Cisco Systems, Inc.)
S2 CVPNDRVA; C:\WINDOWS\system32\Drivers\CVPNDRVA.sys [303735 2005-11-04] (Cisco Systems, Inc.)
S3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [110080 2005-06-29] (Deterministic Networks, Inc.)
S3 e1yexpress; C:\Windows\System32\DRIVERS\e1y5132.sys [243856 2008-06-13] (Intel Corporation)
S1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-08-26] (Symantec Corporation)
S3 es1371; C:\Windows\System32\drivers\es1371mp.sys [40704 2001-08-17] (Creative Technology Ltd.)
S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [30976 2013-09-21] ()
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2008-10-28] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2008-10-28] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2008-10-28] (HP)
S3 HSFHWAZL; C:\Windows\System32\DRIVERS\HSFHWAZL.sys [210560 2008-04-09] (Conexant Systems, Inc.)
S3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [985472 2008-04-09] (Conexant Systems, Inc.)
S1 IBMTPCHK; C:\WINDOWS\system32\Drivers\IBMBLDID.sys [4224 2008-05-12] ()
S3 motport; C:\Windows\System32\DRIVERS\motport.sys [23680 2007-06-18] (Motorola)
S3 NAVENG; C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20130911.004\NAVENG.SYS [93272 2013-08-28] (Symantec Corporation)
S3 NAVEX15; C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20130911.004\NAVEX15.SYS [1612376 2013-08-28] (Symantec Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 NETw5x32; C:\Windows\System32\DRIVERS\NETw5x32.sys [4202496 2009-03-04] (Intel Corporation)
S2 PMEM; C:\WINDOWS\SYSTEM32\DRIVERS\PMEMNT.SYS [7012 2007-10-25] (Microsoft Corporation)
S3 prepdrvr; C:\WINDOWS\system32\CCM\prepdrv.sys [20848 2009-09-18] (Microsoft Corporation)
S2 s24trans; C:\Windows\System32\DRIVERS\s24trans.sys [11904 2008-08-13] (Intel Corporation)
S3 smsmdd; C:\Windows\System32\DRIVERS\smsmdm.sys [12448 2008-10-20] (Microsoft Corporation)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [9598080 2007-02-16] ()
S1 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [421424 2009-09-23] (Symantec Corporation)
S1 SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [281648 2009-09-23] (Symantec Corporation)
S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [320560 2009-09-23] (Symantec Corporation)
S1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [43696 2009-09-23] (Symantec Corporation)
S3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT.SYS [124976 2009-10-28] (Symantec Corporation)
R0 Symmpi; C:\Windows\System32\DRIVERS\symmpi.sys [104320 2007-09-20] (LSI Corporation)
S3 SYMREDRV; C:\Windows\System32\Drivers\SYMREDRV.SYS [26416 2009-09-23] (Symantec Corporation)
S1 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.SYS [188080 2009-09-23] (Symantec Corporation)
S4 SysPlant; C:\Windows\SYSTEM32\Drivers\SysPlant.sys [92488 2009-09-23] (Symantec Corporation)
S3 Teefer2; C:\Windows\System32\DRIVERS\teefer2.sys [50064 2009-09-23] (Symantec Corporation)
S1 TPHKDRV; C:\Windows\System32\DRIVERS\TPHKDRV.sys [17844 2008-05-12] (Lenovo Group Limited)
R3 tpm; C:\Windows\System32\DRIVERS\tpm.sys [13824 2008-03-26] (Intel Corporation)
S1 TPPWRIF; C:\Windows\System32\drivers\Tppwrif.sys [4442 2004-11-30] ()
S1 TSMAPIP; C:\Windows\System32\drivers\TSMAPIP.SYS [4608 2009-08-04] ()
S3 vmx_svga; C:\Windows\System32\DRIVERS\vmx_svga.sys [15744 2006-06-30] (VMware, Inc.)
S3 vsdatant; C:\WINDOWS\system32\vsdatant.sys [280344 2005-01-26] (Zone Labs LLC)
S1 WPS; C:\WINDOWS\system32\drivers\wpsdrvnt.sys [42312 2009-09-23] (Symantec Corporation)
S3 WpsHelper; C:\WINDOWS\system32\drivers\WpsHelper.sys [174056 2012-10-05] (Symantec Corporation)
S3 WSIMD; C:\Windows\System32\DRIVERS\wsimd.sys [57408 2008-02-08] (Atheros Communications, Inc.)
S3 60362804; No ImagePath
S3 idisw2km; system32\DRIVERS\idisw2km.sys [x]
S3 kbstuff; system32\DRIVERS\kbstuff5.sys [x]
U1 RCHelp; 
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U3 TrueSight; \??\C:\WINDOWS\system32\TrueSight.sys [x]
U1 WS2IFSL; 
U3 mbr; \??\c:\TEMP\mbr.sys [x]
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2013-09-22 22:31 - 2013-09-22 22:31 - 00000000 ____D C:\FRST
2013-09-22 22:29 - 2013-09-22 21:55 - 01088367 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\FRST.exe
2013-09-22 14:34 - 2013-09-22 14:33 - 00012778 _____ C:\Documents and Settings\Administrator\Desktop\attach.txt
2013-09-22 14:34 - 2013-09-22 14:31 - 00013379 _____ C:\Documents and Settings\Administrator\Desktop\dds.txt
2013-09-22 10:08 - 2013-09-22 09:43 - 00688992 ____R (Swearware) C:\Documents and Settings\Administrator\Desktop\dds.com
2013-09-21 22:32 - 2013-09-21 21:51 - 00003083 _____ C:\Documents and Settings\petersonm\Desktop\resetdma.vbs
2013-09-21 22:29 - 2013-09-21 22:29 - 00000208 _____ C:\WINDOWS\pfirewall.log
2013-09-21 22:28 - 2013-09-22 00:35 - 00012252 _____ C:\WINDOWS\setupapi.log
2013-09-21 22:28 - 2013-09-22 00:32 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-09-21 22:28 - 2013-09-22 00:32 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-09-21 22:28 - 2013-09-21 22:28 - 00000000 _____ C:\WINDOWS\Sti_Trace.log
2013-09-21 22:27 - 2013-09-21 22:27 - 00010524 _____ C:\WINDOWS\SchedLgU.Txt
2013-09-21 22:13 - 2013-09-21 21:51 - 00003083 _____ C:\Documents and Settings\Administrator\Desktop\resetdma.vbs
2013-09-21 11:16 - 2013-09-21 11:16 - 00000000 ____D C:\Program Files\HitmanPro
2013-09-21 11:02 - 2013-09-21 11:02 - 00017747 _____ C:\Documents and Settings\Administrator\Desktop\hijackthis.log
2013-09-21 11:00 - 2013-09-20 23:39 - 00388608 _____ (Trend Micro Inc.) C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
2013-09-20 23:48 - 2013-09-20 23:48 - 00000000 ____D C:\WINDOWS\pss
2013-09-17 07:47 - 2013-09-21 11:18 - 00030976 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2013-09-17 07:46 - 2013-09-17 07:46 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HitmanPro
2013-09-16 22:08 - 2013-09-22 00:41 - 00011327 _____ C:\WINDOWS\WindowsUpdate.log
2013-09-15 11:16 - 2013-09-15 10:57 - 07211664 _____ (Malwarebytes Corporation                                    ) C:\Documents and Settings\Administrator\Desktop\mbam-rules.exe
2013-09-15 11:16 - 2013-09-13 21:53 - 01990472 _____ C:\Documents and Settings\Administrator\Desktop\MGtools.exe
2013-09-15 10:30 - 2013-09-15 10:30 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2013-09-15 10:26 - 2013-09-15 10:26 - 00000784 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-15 10:25 - 2013-09-15 10:25 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
2013-09-15 10:24 - 2013-09-15 10:24 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-09-15 10:20 - 2013-09-15 10:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-15 10:20 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-09-15 04:06 - 2013-09-15 04:06 - 00002379 _____ C:\Documents and Settings\Administrator\Desktop\RKreport[0]_S_09152013_040603.txt
2013-09-14 11:26 - 2013-09-13 11:10 - 09186416 _____ (SurfRight B.V.) C:\Documents and Settings\Administrator\Desktop\HitmanPro.exe
2013-09-14 11:26 - 2013-09-13 11:08 - 02748256 _____ (Kaspersky Lab ZAO) C:\Documents and Settings\Administrator\Desktop\tdsskiller.exe
2013-09-14 11:25 - 2013-09-13 11:08 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Documents and Settings\Administrator\Desktop\mb.exe
2013-09-14 11:14 - 2013-09-15 10:14 - 00000000 ____D C:\Documents and Settings\Administrator\Desktop\RK_Quarantine
2013-09-14 11:14 - 2013-09-13 11:07 - 00918016 _____ C:\Documents and Settings\Administrator\Desktop\RogueKiller.exe
2013-09-13 22:01 - 2013-09-13 22:01 - 00000682 _____ C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
2013-09-13 22:01 - 2013-09-13 22:01 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2013-09-13 21:16 - 2013-09-13 11:03 - 03415256 _____ (Piriform Ltd) C:\Documents and Settings\Administrator\Desktop\ccsetup405_slim.exe
2013-09-12 22:51 - 2013-09-12 22:51 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.tmp
2013-09-12 21:19 - 2013-09-12 21:19 - 00000000 __SHD C:\Documents and Settings\Administrator\PrivacIE
2013-09-12 09:47 - 2013-09-12 09:47 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\ICAClient
2013-09-12 09:46 - 2013-09-12 09:46 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Adobe
2013-09-12 09:45 - 2013-09-12 09:45 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Apple Computer
2013-09-12 09:43 - 2013-09-12 09:43 - 00000803 _____ C:\Documents and Settings\Administrator\Start Menu\Programs\Internet Explorer.lnk
2013-09-12 09:43 - 2013-09-12 09:43 - 00000000 __SHD C:\Documents and Settings\Administrator\IETldCache
2013-09-12 09:43 - 2013-09-12 09:43 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Workshare
2013-09-02 23:32 - 2013-09-22 00:32 - 00000428 _____ C:\WINDOWS\Tasks\RNUpgradeHelperLogonPrompt_PetersonM.job
2013-09-02 23:32 - 2013-09-21 23:48 - 00000418 _____ C:\WINDOWS\Tasks\ReclaimerUpdateXML_PetersonM.job
2013-09-02 23:32 - 2013-09-11 19:58 - 00000422 _____ C:\WINDOWS\Tasks\ReclaimerUpdateFiles_PetersonM.job
 
==================== One Month Modified Files and Folders =======
 
2013-09-22 22:31 - 2013-09-22 22:31 - 00000000 ____D C:\FRST
2013-09-22 21:55 - 2013-09-22 22:29 - 01088367 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\FRST.exe
2013-09-22 14:33 - 2013-09-22 14:34 - 00012778 _____ C:\Documents and Settings\Administrator\Desktop\attach.txt
2013-09-22 14:31 - 2013-09-22 14:34 - 00013379 _____ C:\Documents and Settings\Administrator\Desktop\dds.txt
2013-09-22 11:47 - 2009-03-09 05:29 - 00509564 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-09-22 09:43 - 2013-09-22 10:08 - 00688992 ____R (Swearware) C:\Documents and Settings\Administrator\Desktop\dds.com
2013-09-22 00:47 - 2009-09-29 02:31 - 09046656 _____ C:\WINDOWS\system32\TPAPSLOG.LOG
2013-09-22 00:41 - 2013-09-16 22:08 - 00011327 _____ C:\WINDOWS\WindowsUpdate.log
2013-09-22 00:38 - 2011-07-18 18:33 - 00000892 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-22 00:36 - 2011-05-17 10:45 - 00000000 ____D C:\Program Files\Steam
2013-09-22 00:36 - 2009-09-29 02:49 - 05628480 _____ C:\WINDOWS\system32\ICAutoUpdate.log
2013-09-22 00:35 - 2013-09-21 22:28 - 00012252 _____ C:\WINDOWS\setupapi.log
2013-09-22 00:34 - 2011-12-30 07:49 - 00000994 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2068663165-295860962-636688714-65442UA.job
2013-09-22 00:34 - 2009-09-29 02:20 - 00000316 _____ C:\WINDOWS\Tasks\PMTask.job
2013-09-22 00:34 - 2009-09-28 11:11 - 00000000 ____D C:\Documents and Settings\petersonm\Tracing
2013-09-22 00:32 - 2013-09-21 22:28 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-09-22 00:32 - 2013-09-21 22:28 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-09-22 00:32 - 2013-09-02 23:32 - 00000428 _____ C:\WINDOWS\Tasks\RNUpgradeHelperLogonPrompt_PetersonM.job
2013-09-22 00:32 - 2011-07-18 18:33 - 00000888 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-22 00:32 - 2009-03-09 10:37 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-09-21 23:48 - 2013-09-02 23:32 - 00000418 _____ C:\WINDOWS\Tasks\ReclaimerUpdateXML_PetersonM.job
2013-09-21 22:29 - 2013-09-21 22:29 - 00000208 _____ C:\WINDOWS\pfirewall.log
2013-09-21 22:28 - 2013-09-21 22:28 - 00000000 _____ C:\WINDOWS\Sti_Trace.log
2013-09-21 22:27 - 2013-09-21 22:27 - 00010524 _____ C:\WINDOWS\SchedLgU.Txt
2013-09-21 22:21 - 2009-03-09 10:37 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2013-09-21 21:51 - 2013-09-21 22:32 - 00003083 _____ C:\Documents and Settings\petersonm\Desktop\resetdma.vbs
2013-09-21 21:51 - 2013-09-21 22:13 - 00003083 _____ C:\Documents and Settings\Administrator\Desktop\resetdma.vbs
2013-09-21 11:18 - 2013-09-17 07:47 - 00030976 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2013-09-21 11:16 - 2013-09-21 11:16 - 00000000 ____D C:\Program Files\HitmanPro
2013-09-21 11:02 - 2013-09-21 11:02 - 00017747 _____ C:\Documents and Settings\Administrator\Desktop\hijackthis.log
2013-09-21 10:58 - 2009-03-09 12:23 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-09-20 23:48 - 2013-09-20 23:48 - 00000000 ____D C:\WINDOWS\pss
2013-09-20 23:39 - 2013-09-21 11:00 - 00388608 _____ (Trend Micro Inc.) C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
2013-09-17 07:46 - 2013-09-17 07:46 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HitmanPro
2013-09-16 22:42 - 2012-05-25 11:16 - 00000000 ____D C:\WINDOWS\Out of the Park Baseball 13
2013-09-15 10:57 - 2013-09-15 11:16 - 07211664 _____ (Malwarebytes Corporation                                    ) C:\Documents and Settings\Administrator\Desktop\mbam-rules.exe
2013-09-15 10:30 - 2013-09-15 10:30 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2013-09-15 10:27 - 2013-09-15 10:20 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-15 10:26 - 2013-09-15 10:26 - 00000784 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-15 10:25 - 2013-09-15 10:25 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
2013-09-15 10:24 - 2013-09-15 10:24 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-09-15 10:14 - 2013-09-14 11:14 - 00000000 ____D C:\Documents and Settings\Administrator\Desktop\RK_Quarantine
2013-09-15 04:06 - 2013-09-15 04:06 - 00002379 _____ C:\Documents and Settings\Administrator\Desktop\RKreport[0]_S_09152013_040603.txt
2013-09-14 08:45 - 2011-09-03 17:37 - 00000000 ____D C:\WINDOWS\Minidump
2013-09-14 08:44 - 2009-03-09 10:37 - 00000000 ____D C:\Documents and Settings\Administrator
2013-09-13 22:01 - 2013-09-13 22:01 - 00000682 _____ C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
2013-09-13 22:01 - 2013-09-13 22:01 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2013-09-13 22:01 - 2010-08-30 17:26 - 00000000 ____D C:\Program Files\CCleaner
2013-09-13 21:53 - 2013-09-15 11:16 - 01990472 _____ C:\Documents and Settings\Administrator\Desktop\MGtools.exe
2013-09-13 21:12 - 2009-09-29 02:49 - 00000000 ____D C:\Documents and Settings\Administrator\Tracing
2013-09-13 11:10 - 2013-09-14 11:26 - 09186416 _____ (SurfRight B.V.) C:\Documents and Settings\Administrator\Desktop\HitmanPro.exe
2013-09-13 11:08 - 2013-09-14 11:26 - 02748256 _____ (Kaspersky Lab ZAO) C:\Documents and Settings\Administrator\Desktop\tdsskiller.exe
2013-09-13 11:08 - 2013-09-14 11:25 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Documents and Settings\Administrator\Desktop\mb.exe
2013-09-13 11:07 - 2013-09-14 11:14 - 00918016 _____ C:\Documents and Settings\Administrator\Desktop\RogueKiller.exe
2013-09-13 11:03 - 2013-09-13 21:16 - 03415256 _____ (Piriform Ltd) C:\Documents and Settings\Administrator\Desktop\ccsetup405_slim.exe
2013-09-12 22:51 - 2013-09-12 22:51 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.tmp
2013-09-12 22:51 - 2010-12-01 13:14 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2013-09-12 21:19 - 2013-09-12 21:19 - 00000000 __SHD C:\Documents and Settings\Administrator\PrivacIE
2013-09-12 09:47 - 2013-09-12 09:47 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\ICAClient
2013-09-12 09:47 - 2009-09-28 11:14 - 00000497 _____ C:\WINDOWS\SMSCFG.INI
2013-09-12 09:46 - 2013-09-12 09:46 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Adobe
2013-09-12 09:45 - 2013-09-12 09:45 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Apple Computer
2013-09-12 09:43 - 2013-09-12 09:43 - 00000803 _____ C:\Documents and Settings\Administrator\Start Menu\Programs\Internet Explorer.lnk
2013-09-12 09:43 - 2013-09-12 09:43 - 00000000 __SHD C:\Documents and Settings\Administrator\IETldCache
2013-09-12 09:43 - 2013-09-12 09:43 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Workshare
2013-09-12 09:43 - 2009-03-09 10:37 - 00000000 ___RD C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2013-09-11 22:43 - 2009-09-29 02:37 - 00000000 ____D C:\SWSHARE
2013-09-11 21:03 - 2009-09-28 11:08 - 00000000 ____D C:\Program Files\Symantec AntiVirus
2013-09-11 19:58 - 2013-09-02 23:32 - 00000422 _____ C:\WINDOWS\Tasks\ReclaimerUpdateFiles_PetersonM.job
2013-09-11 19:58 - 2011-12-30 07:49 - 00000942 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2068663165-295860962-636688714-65442Core.job
2013-09-05 00:39 - 2011-12-30 07:51 - 00002316 _____ C:\Documents and Settings\petersonm\Desktop\Google Chrome.lnk
2013-09-03 00:14 - 2012-07-11 09:18 - 00000000 ____D C:\Documents and Settings\petersonm\Desktop\Kristi School Stuff
2013-08-30 14:34 - 2011-04-23 17:06 - 00000000 ____D C:\Documents and Settings\petersonm\Application Data\Mozilla
2013-08-27 17:53 - 2009-09-29 02:36 - 00000000 ____D C:\Exchange
2013-08-26 21:54 - 2009-09-28 11:11 - 00000278 ___SH C:\Documents and Settings\petersonm\ntuser.ini
2013-08-26 21:54 - 2009-09-28 11:11 - 00000000 ____D C:\Documents and Settings\petersonm
 
==================== Bamital & volsnap Check =================
 
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
==================== End Of Log ============================

 

Attached Files



#12 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:02 AM

Posted 23 September 2013 - 01:01 PM

Hello mdpeterson42



I need you to download this script I have made for you --> Attached File  fixlist.txt   722bytes   3 downloads

It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)

Run FRST again but this time press the Fix button just once and wait.


When finished, it will make a log (fixlog.txt) next to FRST. Please copy and paste the content of this file to your reply.


NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#13 mdpeterson42

mdpeterson42
  • Topic Starter

  • Members
  • 75 posts
  • OFFLINE
  •  
  • Local time:07:02 AM

Posted 24 September 2013 - 12:40 AM

Here you go

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 23-09-2013
Ran by administrator at 2013-09-23 21:44:09 Run:1
Running from C:\Documents and Settings\Administrator\Desktop
Boot Mode: Safe Mode (minimal)
 
==============================================
 
Content of fixlist:
*****************
HKLM Group Policy restriction on software: 2.exe <====== ATTENTION
HKLM Group Policy restriction on software: psexesvc.exe <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <====== ATTENTION
 
 
*****************
 
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
 
==== End of Fixlog ====


#14 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:02 AM

Posted 24 September 2013 - 12:50 AM



Hello mdpeterson42

These are the programs I would like you to run next, if you have any problems with one of these just skip it and move on to the next one.

-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
-Junkware-Removal-Tool-

Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
When they are complete let me have the two reports and let me know how things are running.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#15 mdpeterson42

mdpeterson42
  • Topic Starter

  • Members
  • 75 posts
  • OFFLINE
  •  
  • Local time:07:02 AM

Posted 25 September 2013 - 11:01 AM

Hey gringo, here are the logs.  In addition, I got an error when I started JRT (I attached a screen capture), but JRT ran anyway without me clicking anything in the error window.  Computer seems a bit better (the scans are going faster it seems - JRT only took 45 minutes), but it still really laggy and freezes up often.

 

 

# AdwCleaner v3.005 - Report created 24/09/2013 at 09:34:07
# Updated 22/09/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : administrator - LA-petersonm-L
# Running from : C:\Documents and Settings\Administrator\Desktop\adwcleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Babylon
Folder Deleted : C:\Documents and Settings\All Users\Application Data\boost_interprocess
Folder Deleted : C:\Program Files\Search Results Toolbar
Folder Deleted : C:\Documents and Settings\petersonm\Local Settings\Application Data\Ilivid
Folder Deleted : C:\Documents and Settings\petersonm\Application Data\ilividtoolbarguid
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v8.0.6001.18702
 
 
*************************
 
AdwCleaner[R0].txt - [2432 octets] - [24/09/2013 09:18:52]
AdwCleaner[S0].txt - [2405 octets] - [24/09/2013 09:34:07]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2465 octets] ##########

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Microsoft Windows XP x86
Ran by administrator on Tue 09/24/2013 at 22:13:43.01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 09/24/2013 at 22:55:17.60
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Attached Files






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users