Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan.Agent


  • Please log in to reply
16 replies to this topic

#1 Nici

Nici

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Minnesota
  • Local time:02:12 PM

Posted 19 August 2015 - 02:54 PM

Hope this is appropriate. Could not find anything in the rules about apologies. Been gone a while. Would like to extend my apology and thanx to all who answered the call on my last post, especially, Arachibutyrophobia. Sorry, I did not follow up. Unsure why, today. Did not mean to cause a ruckus either. Using Norton Identity safe, and Windows Defender.

 

Well, today my problem is something called Trojan.Agent. I ran malware bytes free addition after installing spybot search and destroy, and got the results of the Trojan. The Trojan went away after cleaning with malware bytes, but, it seems that if I run spybot for any reason, it returns. Unsure if spybot is, or has, the Trojan within it, "if" that can happen to a malware program.

Any Ideas?



BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,312 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:02:12 PM

Posted 19 August 2015 - 06:31 PM

Uninstall Spybot....its fallen out of favor.

 

Use CCleaner to remove Temporary files, program caches, cookies, logs, etc. Use the Default settings. No need to use the

Registry Cleaning Tool...risky. Pay close attention while installing and UNcheck offers of toolbars....especially Google.

After install, open CCleaner and run by clicking on the Run Cleaner button in the bottom right corner.

CCleaner - PC Optimization and Cleaning - Free Download

 

Download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  • download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message

 

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 Nici

Nici
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Minnesota
  • Local time:02:12 PM

Posted 20 August 2015 - 05:09 PM

Thank you Buddy15. Now, should I uninstall and reinstall a fresh copy of ccleaner from the link you posted, or, is it contaminated from the Trojan.Agent?



#4 buddy215

buddy215

  • Moderator
  • 13,312 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:02:12 PM

Posted 20 August 2015 - 05:22 PM

If you already have CCleaner installed, just run it. Then use the other programs to find and remove whatever the trojan may have installed and

any other adware and malware that may have been on your computer.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#5 Nici

Nici
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Minnesota
  • Local time:02:12 PM

Posted 20 August 2015 - 09:58 PM

Was unable to stop, or, pause Defender, but, ran the tool anyway.

# AdwCleaner v5.003 - Logfile created 20/08/2015 at 20:45:44
# Updated 20/08/2015 by Xplode
# Database : 2015-08-20.1 [Server]
# Operating system : Windows 8.1 Pro (x64)
# Username : Thezba - THEZBASPLACE
# Running from : C:\Users\Thezba\Downloads\AdwCleaner.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\TweakBit
[-] Folder Deleted : C:\ProgramData\TweakBit
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakBit
[#] Folder Deleted : C:\windows\hosts

***** [ Files ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****


*************************

:: Proxy settings cleared
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C17].txt - [819 bytes] ##########
---------------------------------------------------------------------------------------
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.7 (08.18.2015:1)
OS: Windows 8.1 Pro x64
Ran by Thezba on Thu 08/20/2015 at 20:51:01.95
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer



~~~ Files



~~~ Folders





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 08/20/2015 at 20:52:16.48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
------------------------------------------------------------------------------
C:\Program Files\Adware-Removal-Tool\ARTP3.exe MSIL/FakeTool.PS trojan cleaned by deleting - quarantined

#6 buddy215

buddy215

  • Moderator
  • 13,312 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:02:12 PM

Posted 21 August 2015 - 04:40 AM

Post the three lists mentioned below using CCleaner:

 

Open CCleaner and click on Tools. Choose Startups. On that page you will see a list of Windows Startups and at the top tabs for each browser and Scheduled Tasks.

At the bottom right of that page you will see a button when clicked will allow you to Copy and Paste the list of Windows Startups and Scheduled Tasks into your next

post. Please do that.

 

Open CCleaner and click on Tools. Choose Uninstall. On that page you will see a list of programs installed on your computer and at the bottom right of that page you

will see a button when clicked will allow you to Copy and Paste that list in your next post. Please do that.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#7 Nici

Nici
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Minnesota
  • Local time:02:12 PM

Posted 21 August 2015 - 05:12 PM

Browsers:

 

Yes Helper Bing Bar Helper Microsoft Corporation. C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll
Yes Helper Norton Identity Protection  C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\coIEPlg.dll
Yes Helper Norton Identity Protection  C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.11.42\coIEPlg.dll
Yes Toolbar Bing Bar Microsoft Corporation. "C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll"
Yes Toolbar Norton Identity Safe Toolbar  C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\coIEPlg.dll
Yes Toolbar Norton Identity Safe Toolbar  C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.11.42\coIEPlg.dll

---------------------------------------------------------------------------------

Startup:

 

Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
Yes HKCU:Run SpybotPostWindows10UpgradeReInstall Safer-Networking Ltd. "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
No HKLM:Run 331BigDog Vimicro "C:\Program Files (x86)\USB Camera\VM331STI.EXE"
Yes HKLM:Run BTMTrayAgent Microsoft Corporation rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
Yes HKLM:Run cAudioFilterAgent Conexant Systems, Inc. C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe
No HKLM:Run ForteConfig Fortemedia Inc C:\Program Files\Conexant\ForteConfig\fmapp.exe
No HKLM:Run LMCSSTART1 Lenovo Corporation "C:\Program Files\Lenovo\Communications Utility\lmcsctrl.exe" /initsubsysproc:
Yes HKLM:Run LMCSSTART2 Lenovo Corporation "C:\Program Files\Lenovo\Communications Utility\lmcsctrl.exe" /proxystart:
Yes HKLM:Run LMCSSTART3 Lenovo Corporation "C:\Program Files\Lenovo\Communications Utility\lmcsctrl.exe" /setcamplusdrop:
No HKLM:Run LnvMobHotspotClient  C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe
No HKLM:Run PasswordManager Lenovo Group Limited "C:\Program Files\Lenovo\Password Manager\password_manager.exe"
Yes HKLM:Run SmartAudio Conexant Systems, Inc. "C:\Program Files\CONEXANT\SAII\SACpl.exe" /t
Yes HKLM:Run TpShocks Lenovo. TpShocks.exe

----------------------------------------------------------------------------------------------------------------------------------

Tasks:

 

Yes Task Adobe Flash Player Updater Adobe Systems Incorporated C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Yes Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes Task HPCeeScheduleForThezba  C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForThezba (null)
No Task Optimize Start Menu Cache Files-S-1-5-21-4269329723-3529739061-3659076693-1001  
Yes Task Synaptics TouchPad Enhancements Synaptics Incorporated "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"


 



#8 Nici

Nici
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Minnesota
  • Local time:02:12 PM

Posted 21 August 2015 - 05:17 PM

Adobe AIR Adobe Systems Incorporated 4/21/2015  18.0.0.180
Adobe Flash Player 18 NPAPI Adobe Systems Incorporated 8/12/2015 8.85 MB 18.0.0.232
Belarc Advisor 8.4 Belarc Inc. 7/23/2015  8.4.0.0
Bing Bar Microsoft Corporation 8/9/2015 464 KB 7.1.355.0
CCleaner Piriform 7/13/2015  5.07
Conexant HD Audio Conexant 8/20/2015  8.65.56.52
DISH Anywhere Video Player DISH Anywhere 7/20/2015 57.7 MB 2.24.2
Dolby Digital Plus Home Theater Dolby Laboratories Inc 8/20/2015 2.75 MB 7.5.1.1
ESET Online Scanner v3  8/20/2015  
Integrated Camera Vimicro 7/18/2015  5.13.911.3
Intel® Management Engine Components Intel Corporation 3/27/2014  9.5.15.1730
Intel® Processor Graphics Intel Corporation 4/13/2015  10.18.10.3855
Intel® PROSet/Wireless Software for Bluetooth® Technology(patch version 17.0.1419.2) Intel Corporation 4/13/2015 37.7 MB 17.0.1405.0464
Intel® Smart Connect Technology Intel Corporation 3/27/2014 16.9 MB 4.2.40.2418
Intel® PROSet/Wireless Software Intel Corporation 5/20/2015 278 MB 17.14.0
Lenovo Auto Scroll Utility Lenovo 4/13/2015 500 KB 2.17
Lenovo Dependency Package Lenovo Group Limited 4/11/2015  1.6.36.00
Lenovo Peer Connect SDK Lenovo 7/30/2015 6.64 MB 1.0.0.7
Lenovo Power Management Driver Lenovo 5/10/2015 10.2 MB 1.67.10.17
Lenovo QuickControl Lenovo Group Limited 7/30/2015 11.5 MB 2.40
Lenovo Service Bridge Lenovo 7/1/2015  1.3.1.0
Lenovo Settings Dependency Package Lenovo Group Limited 8/20/2015 165 MB 2.3.3.42
Lenovo Solution Center Lenovo Group Limited 4/13/2015 39.7 MB 2.8.004.00
Lenovo System Update Lenovo 7/18/2015 16.3 MB 5.07.0003
Lenovo User Guide Lenovo Group Limited 3/27/2014 610 KB 1.0.0012.00
Lenovo Warranty Information Lenovo 3/27/2014 2.23 MB 1.0.0011.00
Malwarebytes Anti-Malware version 2.1.8.1057 Malwarebytes Corporation 8/4/2015 64.6 MB 2.1.8.1057
Microsoft Office Microsoft Corporation 3/27/2014 296 MB 15.0.4454.1510
Microsoft Silverlight Microsoft Corporation 8/11/2015 150 MB 5.1.40728.0
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 Microsoft Corporation 3/27/2014 13.8 MB 10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 Microsoft Corporation 3/27/2014 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 Microsoft Corporation 3/27/2014 20.5 MB 11.0.60610.1
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 Microsoft Corporation 3/27/2014 17.3 MB 11.0.60610.1
Norton Identity Safe Symantec Corporation 7/25/2015  2014.7.11.42
Realtek Card Reader Realtek Semiconductor Corp. 4/13/2015  6.3.9600.21260
SHAREit Lenovo Group Limited 7/30/2015 17.1 MB 2.1.15.0
Synaptics Pointing Device Driver Synaptics Incorporated 4/13/2015 46.4 MB 18.0.7.103
Thinkpad USB 3.0 Ethernet Adapter Driver Lenovo 3/27/2014  8.8.911.2013
ThinkVantage Active Protection System Lenovo 3/27/2014 9.05 MB 1.78.0.10
ThinkVantage Password Manager Lenovo Group Limited 4/30/2015 49.9 MB 4.70.2.0
Windows Driver Package - Intel Corporation (iaStorA) HDC  (08/01/2013 12.8.0.1016) Intel Corporation 3/27/2014  08/01/2013 12.8.0.1016
Windows Driver Package - Intel hdc  (07/25/2013 9.4.0.1023) Intel 3/27/2014  07/25/2013 9.4.0.1023
Windows Driver Package - Intel System  (07/25/2013 9.4.0.1023) Intel 3/27/2014  07/25/2013 9.4.0.1023
Windows Driver Package - Intel System  (08/21/2013 9.4.0.1027) Intel 3/27/2014  08/21/2013 9.4.0.1027
Windows Driver Package - Intel USB  (07/31/2013 9.4.0.1025) Intel 3/27/2014  07/31/2013 9.4.0.1025
Windows Driver Package - Lenovo 1.67.04.04 (11/07/2013 1.67.04.04) Lenovo 3/27/2014  11/07/2013 1.67.04.04
Windows Driver Package - Synaptics (SmbDrv) System  (02/06/2014 17.0.12.68) Synaptics 3/27/2014  02/06/2014 17.0.12.68
Windows Driver Package - Synaptics (SynTP) Mouse  (02/06/2014 17.0.12.68) Synaptics 3/27/2014  02/06/2014 17.0.12.68
 



#9 buddy215

buddy215

  • Moderator
  • 13,312 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:02:12 PM

Posted 21 August 2015 - 06:50 PM

Remove these Browser Startups: (Use CCleaner by clicking on each item to highlight and then on the right choose either Disable, Remove or Uninstall)

Yes Helper Bing Bar Helper Microsoft Corporation. C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll

Yes Toolbar Bing Bar Microsoft Corporation. "C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll"

 

Disable these Windows Startups:

Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
Yes HKCU:Run SpybotPostWindows10UpgradeReInstall Safer-Networking Ltd. "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"

 

Disable these Scheduled Tasks:

Yes Task Adobe Flash Player Updater Adobe Systems Incorporated C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Yes Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes Task HPCeeScheduleForThezba  C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForThezba (null)

 

Uninstall these programs:

Bing Bar Microsoft Corporation 8/9/2015 464 KB 7.1.355.0

 

Lenovo installed on some computers an unwanted piece of junk adware/ spyware. They got caught and issued a fix for finding and removing the junk.

Easy for you to run it. Your computer may or may not have the junk installed.

SuperFish Uninstall Instructions - Lenovo Support (US)


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#10 Nici

Nici
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Minnesota
  • Local time:02:12 PM

Posted 21 August 2015 - 07:56 PM

Was unable to find the first two keys in the startup list. Maybe missing because I uninstalled Bing first. Followed all other directions in order. No SuperFish files found.

Found these other tasks under 'scheduled tasks" Advanced menu: 

 

No Task AD RMS Rights Policy Template Management (Automated)   \Microsoft\Windows\Active Directory Rights Management Services Client
Yes Task AD RMS Rights Policy Template Management (Manual)   \Microsoft\Windows\Active Directory Rights Management Services Client
No Task Adobe Flash Player Updater Adobe Systems Incorporated C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe \
Yes Task AitAgent  aitagent /increment \Microsoft\Windows\Application Experience
Yes Task AnalyzeSystem   \Microsoft\Windows\Power Efficiency Diagnostics
No Task AUFirmwareInstall   \Microsoft\Windows\WindowsUpdate
No Task AUScheduledInstall   \Microsoft\Windows\WindowsUpdate
No Task AUSessionConnect   \Microsoft\Windows\WindowsUpdate
No Task Automatic-Workplace-Join Microsoft Corporation %SystemRoot%\System32\AutoWorkplace.exe join \Microsoft\Windows\Workplace Join
No Task Background Synchronization   \Microsoft\Windows\Offline Files
Yes Task Badge Update   \Microsoft\Windows\WS
Yes Task BindingWorkItemQueueHandler   \Microsoft\Windows\NetCfg
Yes Task CacheTask   \Microsoft\Windows\Wininet
No Task Calibration Loader   \Microsoft\Windows\WindowsColorSystem
No Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0) \
Yes Task CleanupTemporaryState Microsoft Corporation %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState \Microsoft\Windows\ApplicationData
Yes Task Consolidator Microsoft Corporation %SystemRoot%\System32\wsqmcons.exe \Microsoft\Windows\Customer Experience Improvement Program
No Task Data Integrity Scan   \Microsoft\Windows\Data Integrity Scan
Yes Task Diagnostics   \Microsoft\Windows\DiskFootprint
Yes Task FamilySafetyMonitor Microsoft Corporation %windir%\System32\wpcmon.exe \Microsoft\Windows\Shell
Yes Task FamilySafetyRefresh   \Microsoft\Windows\Shell
No Task FamilySafetyUpload   \Microsoft\Windows\Shell
Yes Task File History (maintenance mode)   \Microsoft\Windows\FileHistory
Yes Task ForceSynchronizeTime   \Microsoft\Windows\Time Synchronization
Yes Task GatherNetworkInfo  %windir%\system32\gatherNetworkInfo.vbs \Microsoft\Windows\NetTrace
No Task HiveUploadTask   \Microsoft\Windows\User Profile Service
No Task HPCeeScheduleForThezba  C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForThezba (null) \
No Task HybridDriveCachePrepopulate   \Microsoft\Windows\Sysmain
No Task HybridDriveCacheRebalance   \Microsoft\Windows\Sysmain
Yes Task Idle Maintenance   \Microsoft\Windows\TaskScheduler
Yes Task Idle Sync Maintenance Task   \Microsoft\Windows\SkyDrive
Yes Task IndexerAutomaticMaintenance   \Microsoft\Windows\Shell
Yes Task launchtrayprocess Microsoft Corporation %windir%\system32\GWX\GWX.exe /tasklaunch \Microsoft\Windows\Setup\gwx
Yes Task Lenovo Customer Feedback Program 64  "%ProgramFiles(x86)%\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe" \Lenovo
Yes Task Lenovo Customer Feedback Program 64 35  "%ProgramFiles(x86)%\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe" \Lenovo
Yes Task Lenovo Settings Power Microsoft Corporation "C:\windows\system32\rundll32.exe" "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor \Lenovo
No Task Logon Synchronization   \Microsoft\Windows\Offline Files
Yes Task Logon-5d Microsoft Corporation %windir%\system32\GWX\GWX.exe /event:7 \Microsoft\Windows\Setup\GWXTriggers
Yes Task LPRemove Microsoft Corporation %windir%\system32\lpremove.exe \Microsoft\Windows\MUI
Yes Task LSCHardwareScan LENOVO "C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe" -diag HWScan \Lenovo\LSC
Yes Task LSCHardwareScanPostpone LENOVO "C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe" -diag HWScan \Lenovo\LSC
Yes Task MachineUnlock-5d Microsoft Corporation %windir%\system32\GWX\GWX.exe /event:8 \Microsoft\Windows\Setup\GWXTriggers
Yes Task Maintenance Configurator   \Microsoft\Windows\TaskScheduler
Yes Task Manual Maintenance   \Microsoft\Windows\TaskScheduler
Yes Task Microsoft Compatibility Appraiser Microsoft Corporation %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly \Microsoft\Windows\Application Experience
Yes Task MNO Metadata Parser Microsoft Corporation %SystemRoot%\System32\MbaeParserTask.exe \Microsoft\Windows\Mobile Broadband Accounts
Yes Task MobilityManager   \Microsoft\Windows\Ras
Yes Task MRT_HB Microsoft Corporation C:\windows\system32\MRT.exe /EHB /Q \Microsoft\Windows\RemovalTools
Yes Task Norton Error Analyzer Symantec Corporation C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\SymErr.exe /analyze \Norton Identity Safe
Yes Task Norton Error Processor Symantec Corporation C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\SymErr.exe /submit \Norton Identity Safe
Yes Task Notifications Microsoft Corporation %windir%\System32\LocationNotifications.exe \Microsoft\Windows\Location
No Task Optimize Start Menu Cache Files-S-1-5-21-4269329723-3529739061-3659076693-1001   \
Yes Task OutOfIdle-5d Microsoft Corporation %windir%\system32\GWX\GWX.exe /event:6 \Microsoft\Windows\Setup\GWXTriggers
Yes Task OutOfSleep-5d Microsoft Corporation %windir%\system32\GWX\GWX.exe /event:9 \Microsoft\Windows\Setup\GWXTriggers
Yes Task Plug and Play Cleanup   \Microsoft\Windows\Plug and Play
No Task PolicyConverter Microsoft Corporation %windir%\system32\appidpolicyconverter.exe \Microsoft\Windows\AppID
Yes Task ProactiveScan   \Microsoft\Windows\Chkdsk
Yes Task ProgramDataUpdater Microsoft Corporation %windir%\system32\rundll32.exe invagent.dll,RunUpdate -noappraiser \Microsoft\Windows\Application Experience
No Task Property Definition Sync   \Microsoft\Windows\File Classification Infrastructure
Yes Task Proxy Microsoft Corporation %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations \Microsoft\Windows\Autochk
Yes Task QueueReporting Microsoft Corporation %windir%\system32\wermgr.exe -queuereporting \Microsoft\Windows\Windows Error Reporting
Yes Task refreshgwxconfig Microsoft Corporation %windir%\system32\GWX\GWXConfigManager.exe /RefreshConfig \Microsoft\Windows\Setup\gwx
Yes Task refreshgwxconfig-B Microsoft Corporation %windir%\system32\GWX\GWXConfigManager.exe /RefreshConfigAndContent \Microsoft\Windows\Setup\GWXTriggers
Yes Task refreshgwxconfigandcontent Microsoft Corporation %windir%\system32\GWX\GWXConfigManager.exe /RefreshConfigAndContent \Microsoft\Windows\Setup\gwx
Yes Task refreshgwxcontent Microsoft Corporation %windir%\system32\GWX\GWXConfigManager.exe /RefreshContent \Microsoft\Windows\Setup\gwx
Yes Task Regular Maintenance   \Microsoft\Windows\TaskScheduler
Yes Task Routine Maintenance Task   \Microsoft\Windows\SkyDrive
Yes Task Scheduled Start Microsoft Corporation C:\windows\system32\sc.exe start wuauserv \Microsoft\Windows\WindowsUpdate
Yes Task Scheduled Start With Network Microsoft Corporation C:\windows\system32\sc.exe start wuauserv \Microsoft\Windows\WindowsUpdate
Yes Task ScheduledDefrag Microsoft Corp. %windir%\system32\defrag.exe -c -h -o -$ \Microsoft\Windows\Defrag
Yes Task Secure-Boot-Update   \Microsoft\Windows\PI
Yes Task SilentCleanup Microsoft Corporation %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive% \Microsoft\Windows\DiskCleanup
Yes Task SmartScreenSpecific   \Microsoft\Windows\AppID
Yes Task SpaceAgentTask Microsoft Corporation %windir%\system32\SpaceAgent.exe \Microsoft\Windows\SpacePort
No Task SQM data sender   \Microsoft\Windows\IME
Yes Task Sqm-Tasks   \Microsoft\Windows\PI
Yes Task SR Microsoft Corporation %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation \Microsoft\Windows\SystemRestore
Yes Task StartComponentCleanup   \Microsoft\Windows\Servicing
Yes Task StartupAppTask Microsoft Corporation %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask \Microsoft\Windows\Application Experience
Yes Task Synaptics TouchPad Enhancements Synaptics Incorporated "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" \
Yes Task Sync Licenses   \Microsoft\Windows\WS
Yes Task SynchronizeTime Microsoft Corporation %windir%\system32\sc.exe start w32time task_started \Microsoft\Windows\Time Synchronization
Yes Task SynchronizeTimeZone Microsoft Corporation %windir%\system32\tzsync.exe \Microsoft\Windows\Time Zone
Yes Task Sysprep Generalize Drivers Microsoft Corporation %SystemRoot%\System32\drvinst.exe 6 \Microsoft\Windows\Plug and Play
Yes Task SystemSoundsService   \Microsoft\Windows\Multimedia
Yes Task SystemTask   \Microsoft\Windows\CertificateServicesClient
Yes Task Telemetry-4xd Microsoft Corporation %windir%\system32\GWX\GWX.exe /event:11 \Microsoft\Windows\Setup\GWXTriggers
Yes Task Time-5d Microsoft Corporation %windir%\system32\GWX\GWX.exe /event:10 \Microsoft\Windows\Setup\GWXTriggers
Yes Task Tpm-Maintenance   \Microsoft\Windows\TPM
Yes Task TVSUUpdateTask LENOVO "C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe" /CM -search C -action INSTALL -includerebootpackages 1,3,4 -noicon -noreboot -nolicense -defaultupdate \TVT
Yes Task UninstallDeviceTask Microsoft Corporation BthUdTask.exe $(Arg0) \Microsoft\Windows\Bluetooth
Yes Task UpdateLibrary  "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" \Microsoft\Windows\Windows Media Sharing
Yes Task UPnPHostConfig Microsoft Corporation sc.exe config upnphost start= auto \Microsoft\Windows\UPnP
Yes Task UserTask   \Microsoft\Windows\CertificateServicesClient
No Task UserTask-Roam   \Microsoft\Windows\CertificateServicesClient
Yes Task VerifiedPublisherCertStoreCheck Microsoft Corporation %windir%\system32\appidcertstorecheck.exe \Microsoft\Windows\AppID
Yes Task WIM-Hash-Management   \Microsoft\Windows\WOF
No Task WIM-Hash-Validation   \Microsoft\Windows\WOF
Yes Task Windows Defender Cache Maintenance Microsoft Corporation C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance \Microsoft\Windows\Windows Defender
Yes Task Windows Defender Cleanup Microsoft Corporation C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanup \Microsoft\Windows\Windows Defender
Yes Task Windows Defender Scheduled Scan Microsoft Corporation C:\Program Files\Windows Defender\MpCmdRun.exe Scan -ScheduleJob \Microsoft\Windows\Windows Defender
Yes Task Windows Defender Verification Microsoft Corporation C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerification \Microsoft\Windows\Windows Defender
Yes Task WinSAT   \Microsoft\Windows\Maintenance
Yes Task Work Folders Logon Synchronization   \Microsoft\Windows\Work Folders
Yes Task Work Folders Maintenance Work   \Microsoft\Windows\Work Folders
Yes Task WsSwapAssessmentTask Microsoft Corporation %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask \Microsoft\Windows\Sysmain
Yes Task WSTask   \Microsoft\Windows\WS
 



#11 buddy215

buddy215

  • Moderator
  • 13,312 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:02:12 PM

Posted 21 August 2015 - 09:00 PM

You can disable these:

Yes Task Lenovo Customer Feedback Program 64  "%ProgramFiles(x86)%\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe" \Lenovo
Yes Task Lenovo Customer Feedback Program 64 35  "%ProgramFiles(x86)%\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe" \Lenovo

 

Okay...looks good to me. If MBAM finds that item again, be sure to post the file path. Another suggestion is if you can actually locate the file you can have it scanned at

VirusTotal - Free Online Virus and Malware Scan by multiple security programs. MBAM's logs for previous scans would give you the location. Eset did remove something that it identified as a trojan.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#12 Nici

Nici
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Minnesota
  • Local time:02:12 PM

Posted 22 August 2015 - 12:06 PM

Will remove them. Just want to thank you for taking the time. This can be quite a daily task. Thank goodness for people like you, with the patience. Pretty thick hugh? Lol. Really though.
Thanx again.
Anything I can do for you?

#13 buddy215

buddy215

  • Moderator
  • 13,312 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:02:12 PM

Posted 22 August 2015 - 12:14 PM

Send a bit cooler weather..:) other than that...you're welcome and happy surfin'.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#14 Nici

Nici
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Minnesota
  • Local time:02:12 PM

Posted 23 August 2015 - 06:26 AM

It's pretty chilled here these days; 58 right now. Feel like I've been cheated out of the rest of my summer. Thanx again for your time; Now, how do I close this issue, or, just do nothing?



#15 buddy215

buddy215

  • Moderator
  • 13,312 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:02:12 PM

Posted 23 August 2015 - 06:54 AM

Do nothing....


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users