Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help with Exploit:Win32/Pdfjsc.ALC


  • This topic is locked This topic is locked
3 replies to this topic

#1 LetsBfrank

LetsBfrank

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:05:56 AM

Posted 12 March 2014 - 12:31 PM

Running Vista on an older HP laptop:

 

Prior scan with MSE found this. I selected to remove it, then followed up with TDSSkiler & kaspersky virus removal tool, no other threats found/removed. Computer became very slow & often has BSOD's, so I can only do most things in safe mode (with networking). Tried several (the ususal suggested) maleware removal options in addition to what I have mentioned: Hitmanpro, ESET, Rkill, Roguekiller, Malwarebytes, ComboFix, Rootkitbuster, Panda Cloud Cleaner, superantispyware, ccleaner, etc. - with some detection, but without success in removing anything. Always finds tracking cookies reported as malware: googleadservices.com, trend.com, doubleclick.net, revsci.net, atdmt.com, etc. to name a few, but cannot delete them permanently or prevent them from returning. Hitmanpro is shut down mid scan several times in safe mode & it only detects tracking cookies for googleadservices.com, doubleclick.net, atdmt.com, trade,com, etc. When run in normal mode, hitman causes BSOD's. They have been:

 

A device driver is attempting to corrupt the system and has been caught. The faulty driver currently on the kernel stack must be replaced with a working version

 

Technical information:

STOP: 0x000000C4 (0x000000B0, 0xA07C6008, 0x0000000C, 0x00000004)

 

I have prior minidump files for those BSOD's. I do not have a recover disk from HP for windows & if a system wipe & re-install is required, I will need instruction on what to do, including if I can salvage saved items on the computer (word docs, photos, etc.) without compromising the next installation.

 

That's why I am here now. Probably too late, but worth a try.

 

Just tried DDS in normal mode, but stalls & then generates BSOD with message about "Driver IRQL not less or equal" & the technical info is:

 

STOP: 0x000000D1 (0xBEEC5000, 0x000000FF, 0x00000000, 0xC4A45BB2)

mbr.sys- Address C4A45BB2 base at C4a44000, Datestamp 4cd665da

 

When Windows reboots, it gives me these messages:

Files that help describe the problem:

C:\Windows\Minidump\Mini031214-02.dmp

C:\Users\Tim\AppData\Local\temp\WER-72961-0.sysdata.xml

C:\Users\Tim\AppData\Local\temp\WER53F8.tmp.version.txt

 

 

Everytime it reboots, it gives a different WER.xml and txt message. I'm not sure how to include the other minidump files for you to look at.

 

Was finally able to run DDS in safe mode & this is what it generated:

 

 

DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 9.0.8112.16533  BrowserJavaVersion: 10.51.2
Run by Tim at 10:51:38 on 2014-03-12
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.2.1033.18.958.447 [GMT -6:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\atashost.exe
C:\Windows\System32\WerFault.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.ca/
uSearch Bar = Preserve
BHO: AutorunsDisabled - <orphaned>
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_bho.dll
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [hpqSRMon] c:\program files\hewlett-packard\digital imaging\bin\hpqSRMon.exe
mRunOnce: [Launcher] c:\windows\sminst\launcher.exe
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 64.59.184.13 64.59.190.242
TCP: Interfaces\{0EA05D9D-D53C-49F5-BA23-91E0DFE3BD4C} : DHCPNameServer = 64.59.184.13 64.59.190.242
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} -
LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\33.0.1750.146\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2011-4-10 43912]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\drivers\dc3d.sys [2011-8-1 45288]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648]
S1 MpKsl2690e890;MpKsl2690e890;c:\programdata\microsoft\microsoft antimalware\definition updates\{4d02b9b8-7891-49dd-b9b0-99d97fd58737}\MpKsl2690e890.sys [2014-3-11 39464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-15 21504]
S2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2014-3-11 418376]
S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2014-3-11 701512]
S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2011-8-31 227896]
S3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys [2014-3-10 43368]
S3 gfiutil;gfiutil;c:\windows\system32\drivers\gfiutil.sys [2014-3-10 24040]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-3-11 22856]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 65024]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
S3 PSKMAD;PSKMAD;c:\windows\system32\drivers\PSKMAD.sys [2014-3-11 47632]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-7-20 754856]
S4 59804776;59804776;c:\windows\system32\drivers\59804776.sys [2014-3-8 133208]
S4 70452188;70452188;c:\windows\system32\drivers\70452188.sys [2014-3-9 133208]
S4 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NLSSRV32.EXE [2012-10-10 69640]
.
=============== Created Last 30 ================
.
2014-03-12 06:40:20 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-03-12 05:47:28 107224 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-03-12 05:12:50 39464 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{4d02b9b8-7891-49dd-b9b0-99d97fd58737}\MpKsl2690e890.sys
2014-03-12 00:49:59 -------- d-----w- c:\program files\Tweaking.com
2014-03-11 22:10:51 -------- d-----w- c:\program files\CCleaner
2014-03-11 20:04:38 12872 ----a-w- c:\windows\system32\bootdelete.exe
2014-03-11 18:18:14 -------- d-----w- c:\users\tim\appdata\roaming\SUPERAntiSpyware.com
2014-03-11 18:12:15 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-11 18:12:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-03-11 15:00:21 47632 ----a-w- c:\windows\system32\drivers\PSKMAD.sys
2014-03-11 14:54:12 -------- d-----w- c:\program files\Panda Security
2014-03-11 13:33:28 7947048 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{4d02b9b8-7891-49dd-b9b0-99d97fd58737}\mpengine.dll
2014-03-11 05:14:11 -------- d-----w- c:\users\tim\appdata\roaming\Curiolab
2014-03-11 03:45:54 -------- d-----w- c:\users\tim\appdata\local\temp
2014-03-11 03:26:28 -------- d-----w- C:\$RECYCLE.BIN
2014-03-11 00:12:56 -------- d-----w- c:\users\tim\appdata\local\CrashDumps
2014-03-10 22:42:48 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-03-10 22:42:05 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-03-10 22:35:44 -------- d-----w- c:\windows\ERUNT
2014-03-10 21:24:23 -------- d-----w- C:\AdwCleaner
2014-03-10 19:21:44 -------- d-----w- c:\program files\COMODO
2014-03-10 17:22:02 -------- d-----w- c:\program files\HitmanPro
2014-03-10 13:27:14 43368 ----a-w- c:\windows\system32\drivers\gfiark.sys
2014-03-10 13:27:14 24040 ----a-w- c:\windows\system32\drivers\gfiutil.sys
2014-03-10 13:25:38 -------- d-----w- C:\VIPRERESCUE
2014-03-10 04:17:06 -------- d-----w- c:\windows\Downloaded Program Files
2014-03-10 01:22:11 -------- d-----w- c:\programdata\HitmanPro
2014-03-10 00:50:33 -------- d-----w- c:\users\tim\appdata\local\Google
2014-03-10 00:32:32 -------- d-----w- C:\SigAV_3FE894CC-AEEA-4230-B7AC-6048773F4730
2014-03-10 00:03:36 -------- d-----w- c:\users\tim\appdata\local\LogMeIn Rescue Applet
2014-03-09 17:00:12 -------- d-----w- c:\programdata\RegRun
2014-03-09 16:38:49 -------- d-----w- c:\users\tim\appdata\roaming\Malwarebytes
2014-03-09 16:38:36 -------- d-----w- c:\programdata\Malwarebytes
2014-03-09 12:05:23 133208 ----a-w- c:\windows\system32\drivers\70452188.sys
2014-03-09 04:10:54 133208 ----a-w- c:\windows\system32\drivers\59804776.sys
2014-03-08 18:42:34 -------- d-----w- c:\programdata\Kaspersky Lab
2014-03-07 19:45:54 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-07 19:42:39 158208 ----a-w- c:\windows\system32\imagehlp.dll
2014-03-07 19:42:34 2050560 ----a-w- c:\windows\system32\win32k.sys
2014-03-07 19:42:30 1248768 ----a-w- c:\windows\system32\msxml3.dll
2014-03-07 19:42:29 335360 ----a-w- c:\windows\system32\SysFxUI.dll
2014-03-07 19:42:28 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-03-07 19:42:28 130048 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-03-07 19:42:05 155648 ----a-w- c:\windows\system32\wscript.exe
2014-03-07 19:42:05 131072 ----a-w- c:\windows\system32\wshom.ocx
2014-03-07 19:42:00 36864 ----a-w- c:\windows\system32\wshcon.dll
2014-03-07 19:42:00 172032 ----a-w- c:\windows\system32\scrrun.dll
2014-03-07 19:42:00 135168 ----a-w- c:\windows\system32\cscript.exe
.
==================== Find3M  ====================
.
2014-02-05 08:56:17 1806848 ----a-w- c:\windows\system32\jscript9.dll
2014-02-05 08:50:39 1129472 ----a-w- c:\windows\system32\wininet.dll
2014-02-05 08:48:40 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2014-02-05 08:48:27 421376 ----a-w- c:\windows\system32\vbscript.dll
2014-02-05 08:47:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2014-01-19 07:32:23 231584 ------w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 10:53:32.92 ===============
 

 

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 29/06/2007 6:24:43 AM
System Uptime: 12/03/2014 10:45:34 AM (0 hours ago)
.
Motherboard: Quanta |  | 30B9
Processor: AMD Turion™ 64 X2 Mobile Technology TL-58 | Socket S1 | 1908/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 104 GiB total, 61.872 GiB free.
D: is FIXED (NTFS) - 112 GiB total, 111.578 GiB free.
E: is FIXED (NTFS) - 8 GiB total, 1.791 GiB free.
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP2175: 11/03/2014 7:30:36 AM - Windows Update
RP2176: 12/03/2014 12:31:04 AM - Installed Java 7 Update 51
.
==== Installed Programs ======================
.
 Update for Microsoft Office 2007 (KB2508958)
32 Bit HP CIO Components Installer
Activation Assistant for the 2007 Microsoft Office suites
Adobe Reader X (10.1.9)
Adobe Shockwave Player
Adobe SVG Viewer 3.0
BufferChm
C309a
C309n-s
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch
Canon Utilities ZoomBrowser EX
CCleaner
Conexant HD Audio
D4200
D4200_Help
Destinations
DeviceDiscovery
DeviceManagementQFolder
Dexterity Shared Components 10.0
dj_sf_ProductContext
dj_sf_software
dj_sf_software_req
DocProc
ESU for Microsoft Vista
eSupportQFolder
Fax
Google Chrome
Google Update Helper
GPBaseService2
Hewlett-Packard ACLM.NET v1.1.0.0
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library 32 bit components
HP Customer Experience Enhancements
HP Customer Participation Program 14.0
HP Deskjet 8.0 Software
HP Imaging Device Functions 14.0
HP Pavilion Webcam Driver for Vista v061.001.00005
HP Photo Creations
HP Photosmart C309a All-In-One Driver Software 14.0 Rel. 5
HP Photosmart Essential
HP Photosmart Essential 3.5
HP Photosmart Prem-Web  C309n-s All-in-One Driver Software 14.0 Rel. 6
HP Product Detection
HP Quick Launch Buttons
HP QuickPlay 3.2
HP Smart Web Printing 4.60
HP Solution Center 14.0
HP User Guide 0042
HP Wireless Assistant
HPDiagnosticAlert
HPPhotoGadget
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotosmartEssential
HPProductAssistant
HPSSupply
Internet Explorer (Enable DEP)
Java 7 Update 51
LightScribe  1.4.136.1
Malwarebytes Anti-Malware version 1.75.0.1300
MarketResearch
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft IntelliPoint 8.2
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Security Client
Microsoft Security Essentials
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSCU for Microsoft Vista
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.0
Network
NVIDIA Drivers
OCR Software by I.R.I.S. 14.0
Office (Enable DEP)
Panda Cloud Cleaner
PS_AIO_05_C309_Software_Min
PS_AIO_06_C309n-s_SW_Min
PSSWCORE
QLBCASL
QuickTransfer
Rhapsody
Rhapsody Player Engine
Roxio Activation Module
Roxio Creator Audio
Roxio Creator Basic v9
Roxio Creator Copy
Roxio Creator Data
Roxio Creator EasyArchive
Roxio Creator Tools
Roxio Express Labeler 3
Roxio MyDVD Basic v9
Scan
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2832407)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2861188)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2898855v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2901110v2)
Security Update for Microsoft Office 2007 System (KB2541012)
Security Update for Microsoft Office Excel 2007 (KB2541007)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Shop for HP Supplies
SmartWebPrinting
Soft Data Fax Modem with SmartCP
SolutionCenter
Status
Synaptics Pointing Device Driver
Toolbox
TrayApp
Tweaking.com - Windows Repair (All in One)
UnloadSupport
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
WebReg
.
==== Event Viewer Messages From Past Week ========
.
12/03/2014 10:50:45 AM, Error: Service Control Manager [7001]  - The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:  The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
12/03/2014 10:47:38 AM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  MpFilter spldr Wanarpv6
12/03/2014 10:47:38 AM, Error: Service Control Manager [7001]  - The Internet Connection Sharing (ICS) service depends on the Remote Access Connection Manager service which failed to start because of the following error:  The dependency service or group failed to start.
12/03/2014 10:47:38 AM, Error: Service Control Manager [7001]  - The Computer Browser service depends on the Server service which failed to start because of the following error:  The dependency service or group failed to start.
12/03/2014 10:47:19 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
12/03/2014 10:47:16 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
12/03/2014 10:47:06 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
12/03/2014 10:46:54 AM, Error: Microsoft-Windows-WLAN-AutoConfig [10000]  - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\bcmihvsrv.dll Error Code: 21
12/03/2014 10:46:48 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
12/03/2014 10:46:27 AM, Error: EventLog [6008]  - The previous system shutdown at 10:43:46 AM on 12/03/2014 was unexpected.
12/03/2014 10:29:59 AM, Error: Service Control Manager [7022]  - The KtmRm for Distributed Transaction Coordinator service hung on starting.
12/03/2014 10:28:08 AM, Error: Service Control Manager [7000]  - The Windows Font Cache Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
12/03/2014 10:27:50 AM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Font Cache Service service to connect.
12/03/2014 10:24:39 AM, Error: Service Control Manager [7001]  - The CyberLink Task Scheduler (CTS) service depends on the CyberLink Background Capture Service (CBCS) service which failed to start because of the following error:  After starting, the service hung in a start-pending state.
12/03/2014 10:24:38 AM, Error: Service Control Manager [7022]  - The CyberLink Background Capture Service (CBCS) service hung on starting.
12/03/2014 10:22:41 AM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Net Driver HPZ12 service to connect.
12/03/2014 10:22:41 AM, Error: Service Control Manager [7000]  - The Net Driver HPZ12 service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
12/03/2014 10:20:30 AM, Error: EventLog [6008]  - The previous system shutdown at 10:17:32 AM on 12/03/2014 was unexpected.
.
==== End Of File ===========================
 


Edited by LetsBfrank, 12 March 2014 - 12:55 PM.


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,713 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:56 AM

Posted 15 March 2014 - 08:08 PM

Greetings LetsBfrank and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that. :thumbup2:

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. While I review our situation please run these programs for me from Safe Mode if necessary.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for 32 bit systems and save it to your desktop
  • If you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one should
  • Double click the icon
  • Click Yes to the disclaimer
  • Make sure the Addition.txt box is checked
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of both in your reply
===================================================

Farbar's Service Scanner

--------------------
  • Please download Farbar Service Scanner, save it to your desktop, and run it.
  • Make sure the following options are checked:

Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Windows Defender
Other Services

  • Press Scan
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST results
  • Addition log
  • FSS log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,713 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:56 AM

Posted 19 March 2014 - 08:12 AM

Greetings,

===================================================

3 Day Bump

It has been more than 3 days since my last post.
  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,713 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:56 AM

Posted 21 March 2014 - 11:13 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users