Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

ZeroAccess.b!cfg & Artemis! Skilled user, will respond fast.


  • This topic is locked This topic is locked
2 replies to this topic

#1 Hedgeplay

Hedgeplay

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:56 PM

Posted 01 November 2014 - 04:07 PM

Hello.  Thanks for all the work you guys put in!!!

 

 

Please help me rid my box of these two nasties:  

  • Several months back got hit by ZeroAccess. Got the machine running but ZeroAccess remnants remain.
  • Started seeing Artemis! hits.
  • My drivers/etc/hosts file keeps getting written to zero bytes
  • Occasionally my MS IE Internet Options window will appear showing that my home page has just be reset to "about:blank"
  • Right-click on a web-page link and select Open in a new tab results in a tab open with just a blank display, the URL I clicked on to open does not get passed to the opened tab address bar.
  • Click on buttons that execute Javascript and nothing happens 
  • I accept all MS Important updates each day - ignoring some 'unimportant updates'
  • Deleted & reinstalled MS IE 10 - no impact/no improvement
  • Installed MS IE 11 - no improvement 

 

Thanks!  

 

As instructed fresh DDS pasted in below and Attach.txt file attached.  I also attached a view images showing Mcafee quarantine log info.

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 11.0.9600.17344  BrowserJavaVersion: 10.67.2
Run by jamesc1 at 15:23:55 on 2014-11-01
Microsoft Windows 7 Enterprise   6.1.7601.1.1252.1.1033.18.8142.4164 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
AV: McAfee VirusScan Enterprise *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee VirusScan Enterprise Antispyware Module *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
FW: McAfee Host Intrusion Prevention Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\vcsFPService.exe
c:\Program Files (x86)\Common Files\Juniper Networks\JUNS\dsAccessService.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbClientManager.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files (x86)\PC Backup\AgentService.exe
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files (x86)\DirectAccess Connectivity Assistant\DcaSvc.exe
C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe
C:\Program Files\Microsoft Forefront Identity Manager\2010\Password Reset Client Service\PwdMgmtProxy.exe
c:\Program Files (x86)\Common Files\Juniper Networks\JUNS\dsAccessService.exe
C:\Program Files (x86)\McAfee\Host Intrusion Prevention\HipMgmt.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
C:\HP\IT\DirectAccess\4to6\HPNat46Service.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McSACore.exe
C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Windows\system32\mfevtps.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Palm, Inc\novacomd\amd64\novacomd.exe
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\PROGRA~2\HEWLET~1\PCCOE3~1\OVCMS~1\radexecd.exe
C:\PROGRA~2\HEWLET~1\PCCOE3~1\OVCMS~1\radsched.exe
C:\PROGRA~2\HEWLET~1\PCCOE3~1\OVCMS~1\Radstgms.exe
C:\Windows\system32\locator.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\McAfee\Raptor\RaptorClient.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\RA2HP\HPRAService.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\Users\jamesc1\AppData\Local\Akamai\netsession_win.exe
C:\Users\jamesc1\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Hewlett-Packard\PC COE\COEMsgDisplay.exe
C:\Program Files (x86)\Hewlett-Packard\PC COE\Ida.exe
C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe
C:\Program Files (x86)\Hewlett-Packard\GetITIcon\GetITShell.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\DirectAccess Connectivity Assistant\DcaTray.exe
C:\Program Files (x86)\PC Backup\Agent.exe
C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
C:\Program Files (x86)\McAfee\Common Framework\McTray.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wlrmdr.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SnippingTool.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
uProxyOverride = <local>
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
EB: {2B4C4770-27FD-4A09-B17D-33CA580965FB} - <orphaned>
EB: Web Test Recorder 10.0: {3142c289-f319-47f5-a594-a827028714c9} - 
uRun: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
uRun: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office14\GROOVEMN.EXE
uRun: [ApplePhotoStreams] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 360 C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
uRun: [Uploader] C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRun: [Akamai NetSession Interface] "C:\Users\jamesc1\AppData\Local\Akamai\netsession_win.exe"
mRun: [COEMsgDisplay] c:\Program Files (x86)\Hewlett-Packard\PC COE\COEMsgDisplay.exe
mRun: [IDA] C:\Program Files (x86)\Hewlett-Packard\PC COE\IDA.EXE
mRun: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
mRun: [eepc_SmartClient] C:\Program Files (x86)\SmartClient\Smart.exe
mRun: [SafeBootTokenWatcher] "C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe"
mRun: [GetITIcon] C:\Program Files (x86)\Hewlett-Packard\GetITIcon\GetITShell.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [Communicator] "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
mRun: [DcaTray] C:\Program Files (x86)\DirectAccess Connectivity Assistant\DcaTray.exe
mRun: [AgentUiRunKey] "C:\Program Files (x86)\PC Backup\Agent.exe" -ni -sss -e http://localhost:16386/
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe"
mRun: [McAfeeUpdaterUI] "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
mRun: [DBAgent] "C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe" /WinStart
StartupFolder: C:\Users\jamesc1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hostsset - Copy.bat
uPolicies-Explorer: HideSCAHealth = dword:1
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: HideSCAHealth = dword:1
mPolicies-Explorer: NoWebServices = dword:1
mPolicies-Explorer: NoPublishingWizard = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Explorer: NoAutorun = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:4
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: dontdisplaylockeduserid = dword:1
mPolicies-System: legalnoticecaption = Terms of Use
mPolicies-System: legalnoticetext = This computing system is a company owned asset and provided for the exclusive use of authorized personnel for business purposes.  All information and data created, accessed, processed, or stored using this system (including personal information) are subject to monitoring, auditing, or review to the extent permitted by applicable law.  Unauthorized use or abuse of this system may lead to corrective action including termination of employment, civil and/or criminal penalties.
mPolicies-System: LogonType = dword:0
mPolicies-System: HideFastUserSwitching = dword:1
mPolicies-System: ReportControllerMissing = dword:0
mPolicies-System: DisableNT4Policy = dword:1
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {00000035-9593-4264-8B29-930B3E4EDCCD} - hxxps://www.rooms.hp.com/vRoom_Cab/WebHPVCInstall35.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect1262.cab
DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} - hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} - hxxps://www.icloud.com/system/iCloud.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab
DPF: {AB01FF2E-A848-410C-B47B-CB467C476AD9} - hxxps://digitalbadge.external.hp.com/hp/HPPKI.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://akamaicdn.webex.com/client/WBXclient-T28L10NSP12_CP1-16851/webex/ieatgpc1.cab
DPF: {EBF1BFCB-F60B-4DCB-9C96-E53C543CB645} - hxxp://qc2d.atlanta.hp.com/qcbin/ALM-Platform-Loader.11.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{E17DDC1B-DC9C-49DA-A368-055E4E3909A5} : DHCPNameServer = 10.0.0.1
TCP: Interfaces\{E17DDC1B-DC9C-49DA-A368-055E4E3909A5}\24F62672E672D496B65637 : DHCPNameServer = 10.0.0.1
TCP: Interfaces\{E17DDC1B-DC9C-49DA-A368-055E4E3909A5}\25F61637475627370234F6666656560284166756E6 : DHCPNameServer = 10.0.0.1
TCP: Interfaces\{E17DDC1B-DC9C-49DA-A368-055E4E3909A5}\4534343402649647E6563737 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{E17DDC1B-DC9C-49DA-A368-055E4E3909A5}\D4165796D2E4 : DHCPNameServer = 10.0.0.1
TCP: Interfaces\{EBF537B9-3978-495C-B2BC-D6F7C8FA7AE4} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{EBF537B9-3978-495C-B2BC-D6F7C8FA7AE4}\45343434 : DHCPNameServer = 4.2.2.2 4.2.2.3
TCP: Interfaces\{EBF537B9-3978-495C-B2BC-D6F7C8FA7AE4}\56C656D656E647F584F6573747F6E6 : DHCPNameServer = 4.2.2.2 8.8.8.8 4.2.2.1
TCP: Interfaces\{EBF537B9-3978-495C-B2BC-D6F7C8FA7AE4}\7457563747 : DHCPNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{EBF537B9-3978-495C-B2BC-D6F7C8FA7AE4}\8607 : DHCPNameServer = 16.110.135.52 16.110.135.51
TCP: Interfaces\{EBF537B9-3978-495C-B2BC-D6F7C8FA7AE4}\D4165796D2E4 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{EBF537B9-3978-495C-B2BC-D6F7C8FA7AE4}\D656E6370286169627023656E6475627 : DHCPNameServer = 192.168.1.254
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
Handler: qvp - {4BA78E3D-CA25-4BFF-B8F0-8A3359E4B520} - C:\Program Files (x86)\QlikView\QvProtocol\qvp.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - C:\Program Files (x86)\CoreFTP\pftpns.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
LSA: Notification Packages =  sbnp scecli
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
mASetup: {86E45973-5352-439F-A115-2E8EE4D40140} - "C:\Program Files (x86)\Common Files\Hewlett-Packard\ActSet\HpActSet.exe"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = about:blank
x64-mDefault_Page_URL = hxxp://athp.hp.com
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll
x64-Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe"
x64-Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
x64-Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
x64-Run: [HPRAService] C:\Program Files\RA2HP\HPRAService.exe
x64-Run: [McAfee Host Intrusion Prevention Tray] "C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe"
x64-RunOnce: [RaptorClient] "C:\Program Files\McAfee\Raptor\RaptorClient.exe" --run
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
x64-DPF: {AA570693-00E2-4907-B6F1-60A1199B030C} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - <orphaned>
x64-Handler: qvp - {4BA78E3D-CA25-4BFF-B8F0-8A3359E4B520} - C:\Program Files\QlikView\QvProtocol\qvp.dll
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 analytics.microsoft.com
Hosts: 127.0.0.1 metrics.bitdefender.com
Hosts: 127.0.0.1 metrics.mcafee.com
Hosts: 127.0.0.1  om.symantec.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\jamesc1\AppData\Roaming\Mozilla\Firefox\Profiles\ltvxjqgp.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Hewlett-Packard\HP Virtual Room Client Launcher Plugin\nphpvrl.dll
FF - plugin: C:\Program Files (x86)\HttpWatch\Firefox\components\nphttpwatchff.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\jamesc1\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: C:\Users\jamesc1\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\jamesc1\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2011-7-14 786296]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\drivers\mfewfpk.sys [2014-3-24 344176]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\System32\drivers\mfenlfk.sys [2014-7-14 78960]
R3 FireNfcp;McAfee Inc. FireNfcp;C:\Windows\System32\drivers\FireNfcp.sys [2014-7-14 53728]
R3 HipShieldK;McAfee Inc. HipShieldK;C:\Windows\System32\drivers\HipShieldK.sys [2014-7-14 200616]
R3 JNPRNA;Juniper Network Agent Miniport;C:\Windows\System32\drivers\jnprna6.sys [2014-6-30 522544]
R3 JnprVaMgr;Juniper Networks Virtual Adapter Manager Service;C:\Windows\System32\drivers\jnprvamgr.sys [2013-10-28 45352]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2014-3-24 311600]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\drivers\mfefirek.sys [2014-7-14 520056]
S3 btwampfl;Bluetooth AMP USB Filter;C:\Windows\System32\drivers\btwampfl.sys [2011-6-20 344616]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-6-20 39464]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2012-5-20 95928]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys [2011-3-28 174680]
S3 johci;JMicron 1394 Filter Driver;C:\Windows\System32\drivers\johci.sys [2011-3-28 26712]
S3 LV_Tracker;LV_Tracker;C:\Windows\System32\drivers\LV_Tracker64.sys [2013-8-2 54824]
S3 Mandiant_Tools;Mandiant_Tools;C:\ProgramData\Application Data\Time Service\mktools.sys [2012-10-26 25168]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\System32\drivers\mferkdet.sys [2014-3-24 108440]
S4 jnprTdi_801_41197;Juniper Networks TDI Filter Driver (jnprTdi_801_41197);C:\Windows\System32\drivers\jnprTdi_801_41197.sys [2014-6-30 108336]
.
=============== File Associations ===============
.
FileExt: .vbe: VBEFile=C:\Windows\SysWow64\WScript.exe "%1" %*
ShellExec: Opera.exe: open="C:\Program Files (x86)\Opera\Launcher.exe" "%1"
.
=============== Created Last 30 ================
.
2014-11-01 05:24:16 -------- d-----w- C:\Program Files (x86)\Foundstone Free Tools
2014-11-01 02:27:18 93 ----a-w- C:\Users\jamesc1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hostsset - Copy.bat
2014-10-31 20:17:46 -------- d-----w- C:\Win7Ent90
2014-10-31 19:01:58 -------- d-----w- C:\Users\jamesc1\AppData\Local\Akamai
2014-10-31 16:15:51 -------- d-----w- C:\Windows\ERUNT
2014-10-30 23:04:36 -------- d-----w- C:\Users\jamesc1\AppData\Roaming\EncryptStick
2014-10-30 18:08:33 -------- d-----w- C:\Windows\CheckSur
2014-10-30 05:07:42 -------- d-----w- C:\Program Files\CCleaner
2014-10-30 04:36:25 536576 ----a-w- C:\Windows\SysWow64\sqlite3.dll
2014-10-30 04:34:14 -------- d-----w- C:\AdwCleaner
2014-10-30 02:56:49 -------- d-----w- C:\FRST
2014-10-29 19:15:30 -------- d-----w- C:\dfae810b750fe6f8c94378c2acdd3401
2014-10-29 18:54:44 -------- d-----w- C:\Program Files (x86)\Free Window Registry Repair
2014-10-29 18:33:02 -------- d-----w- C:\Users\jamesc1\AppData\Local\NPE
2014-10-29 18:33:02 -------- d-----w- C:\ProgramData\Norton
2014-10-29 15:40:58 189912 ----a-w- C:\Windows\System32\mfevtps2.old
2014-10-28 07:24:00 -------- d-----w- C:\cygwin64
2014-10-28 07:16:03 -------- d-----w- C:\.deleted
2014-10-28 04:14:26 -------- d-----w- C:\Users\jamesc1\My Online Documents
2014-10-28 04:06:37 -------- d-----w- C:\ProgramData\Nero
2014-10-28 04:05:48 -------- d-----w- C:\Program Files (x86)\Seagate
2014-10-28 03:11:52 -------- d-----w- C:\Program Files\stinger
2014-10-28 01:21:43 1012656 ----a-w- C:\rkill.exe
2014-10-27 19:17:35 -------- d-----w- C:\Program Files\OCSetup
2014-10-26 02:17:10 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-10-26 00:27:45 -------- d-sh--w- C:\Users\jamesc1\AppData\Local\EmieUserList
2014-10-26 00:27:43 -------- d-sh--w- C:\Users\jamesc1\AppData\Local\EmieSiteList
2014-10-25 17:05:15 194048 ----a-w- C:\Windows\SysWow64\elshyph.dll
2014-10-23 17:21:58 215040 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\plugins\npatgpc.dll
2014-10-23 17:21:58 -------- d-----w- C:\Users\jamesc1\AppData\Local\WebEx
2014-10-16 00:07:34 3243008 ----a-w- C:\Windows\System32\msi.dll
2014-10-16 00:07:34 2364416 ----a-w- C:\Windows\SysWow64\msi.dll
2014-10-16 00:07:33 337408 ----a-w- C:\Windows\SysWow64\msihnd.dll
2014-10-16 00:07:33 1942016 ----a-w- C:\Windows\System32\authui.dll
2014-10-16 00:07:33 1806848 ----a-w- C:\Windows\SysWow64\authui.dll
2014-10-16 00:07:33 112568 ----a-w- C:\Windows\System32\consent.exe
2014-10-16 00:07:09 3201536 ----a-w- C:\Windows\System32\win32k.sys
2014-10-16 00:07:01 156824 ----a-w- C:\Windows\SysWow64\mscorier.dll
2014-10-16 00:07:00 1943696 ----a-w- C:\Windows\System32\dfshim.dll
2014-10-16 00:07:00 156312 ----a-w- C:\Windows\System32\mscorier.dll
2014-10-16 00:07:00 1131664 ----a-w- C:\Windows\SysWow64\dfshim.dll
2014-10-16 00:05:59 212480 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2014-10-16 00:05:59 157696 ----a-w- C:\Windows\SysWow64\winsta.dll
2014-10-16 00:05:59 150528 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2014-10-16 00:05:57 455168 ----a-w- C:\Windows\System32\winlogon.exe
2014-10-16 00:05:57 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2014-10-16 00:05:56 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2014-10-16 00:05:56 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2014-10-16 00:05:55 22016 ----a-w- C:\Windows\System32\credssp.dll
2014-10-16 00:05:55 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2014-10-16 00:05:54 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
2014-10-16 00:05:03 77312 ----a-w- C:\Windows\System32\packager.dll
2014-10-16 00:05:03 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2014-10-06 20:03:56 -------- d-----w- C:\Users\jamesc1\AppData\Local\Citrix
.
==================== Find3M  ====================
.
2014-11-01 04:51:04 129752 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-10-28 03:16:35 786296 ----a-w- C:\Windows\System32\drivers\mfehidk.sys
2014-10-28 03:16:35 189912 ----a-w- C:\Windows\System32\mfevtps.exe
2014-10-28 03:16:35 108440 ----a-w- C:\Windows\System32\drivers\mferkdet.sys
2014-10-01 16:11:26 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-10-01 16:11:16 93400 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-10-01 16:11:12 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-09-25 02:08:38 371712 ----a-w- C:\Windows\System32\qdvd.dll
2014-09-25 01:40:50 519680 ----a-w- C:\Windows\SysWow64\qdvd.dll
2014-09-22 06:42:39 278152 ------w- C:\Windows\System32\MpSigStub.exe
2014-09-19 17:49:03 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-09-12 20:41:25 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-12 20:41:25 699568 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-09-09 22:18:29 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-09-09 21:49:38 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-09-04 05:23:20 424448 ----a-w- C:\Windows\System32\rastls.dll
2014-09-04 05:04:15 372736 ----a-w- C:\Windows\SysWow64\rastls.dll
2014-08-23 02:07:00 404480 ----a-w- C:\Windows\System32\gdi32.dll
2014-08-23 01:45:55 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2014-08-12 06:17:08 53728 ----a-w- C:\Windows\System32\drivers\FireNfcp.sys
.
============= FINISH: 15:29:44.02 ===============
 
 

Attached Files



BC AdBot (Login to Remove)

 


m

#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,549 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:56 PM

Posted 06 November 2014 - 04:10 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/554301 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,549 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:56 PM

Posted 11 November 2014 - 04:15 PM

Hello again!

I haven't heard from you in 5 days. Therefore, I am going to assume that you no longer need our help, and close this topic.

If you do still need help, please send a Private Message to any Moderator within the next five days. Be sure to include a link to your topic in your Private Message.

Thank you for using Bleeping Computer, and have a great day!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users