Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

is this a virus/malware/spyware?


  • Please log in to reply
10 replies to this topic

#1 t458

t458

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:36 AM

Posted 17 May 2016 - 10:04 AM

Hey everyone. what a great forum you have.

 

is this a sign/leftover/registry entry of a virus/malware/spyware?

 

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.com/search?q=hp%20assistat&form=WNSGPH&qs=SW&cvid=abee8ac32569465895bba270caef994f&pq=hp%20assistat&nclid=0ED39ADB9642D6A945440994DFD21348&ts=1462992234518&nclidts=1462992234&tsms=518

 

Thank you all.



BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,026 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:06:36 AM

Posted 17 May 2016 - 11:48 AM

Hello, very possible.. Lets do these now,

3Al62Pm.pngMiniToolBox
  • Please download MiniToolBox, save it to your desktop and run it.
  • Checkmark the following checkboxes:
    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List content of Hosts
    • List IP configuration
    • List Winsock Entries
    • List last 10 Event Viewer log
    • List Installed Programs
    • List Users, Partitions and Memory size.
  • Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run. Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
zcMPezJ.pngAdwCleaner
  • Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool. Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
lv0mVRW.pngJunkware Removal Tool
  • Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
cvMlKv6.pngESET Online Scanner
  • Click here to download the installer for ESET Online Scanner and save it to your Desktop.
  • Disable all your antivirus and antimalware software - see how to do that here.
  • Right click on esetsmartinstaller_enu.exe and select Run as Administrator.
  • Place a checkmark in YES, I accept the Terms of Use, then click Start. Wait for ESET Online Scanner to load its components.
  • Select Enable detection of potentially unwanted applications.
  • Click Advanced Settings, then place a checkmark in the following:
    • Remove found threats
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Click Start to begin scanning.
  • ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.
  • When the scan is done, click List threats (only available if ESET Online Scanner found something).
  • Click Export, then save the file to your desktop.
  • Click Back, then Finish to exit ESET Online Scanner.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 t458

t458
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:36 AM

Posted 17 May 2016 - 12:51 PM

Thank you for your kind help.

 

here is the data.

 

Mini toolbox result report:

 

 

MiniToolBox by Farbar  Version: 07-02-2016 01
Ran by Therios (administrator) on 17-05-2016 at 13:07:44
Running from "C:\Users\Therios\Downloads"
Microsoft Windows 10 Home  (X64)
Model: HP Pavilion x2 Detachable Manufacturer: HP
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========================= IE Proxy Settings: ==============================
 
Proxy is not enabled.
No Proxy Server is set.
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
 
========================= FF Proxy Settings: ==============================
 

"Reset FF Proxy Settings": Firefox Proxy settings were reset.
 
========================= Hosts content: =================================
========================= IP Configuration: ================================
 
Intel® Dual Band Wireless-AC 3165 = Wi-Fi (Connected)
Bluetooth Device (Personal Area Network) = Bluetooth Network Connection 3 (Media disconnected)
 

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
 
reset
set global
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 2" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Bluetooth Network Connection" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Bluetooth Network Connection 2" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Bluetooth Network Connection 3" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
 

popd
# End of IPv4 configuration
 
 
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : TABLET-JSTJM13J
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
 
Wireless LAN adapter Local Area Connection* 2:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : 08-D4-0C-4D-1A-99
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Wi-Fi:
 
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel® Dual Band Wireless-AC 3165
   Physical Address. . . . . . . . . : 08-D4-0C-4D-1A-98
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : ::fcf2:55e5:83f5:2328(Preferred)
   Temporary IPv6 Address. . . . . . : ::7005:e917:1c49:b8cd(Preferred)
   Link-local IPv6 Address . . . . . : fe80::fcf2:55e5:83f5:2328%4(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.0.5(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Tuesday, May 17, 2016 12:28:49 PM
   Lease Expires . . . . . . . . . . : Tuesday, May 17, 2016 1:58:49 PM
   Default Gateway . . . . . . . . . : 192.168.0.1
   DHCP Server . . . . . . . . . . . : 192.168.0.1
   DHCPv6 IAID . . . . . . . . . . . : 50910220
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1E-C5-23-0C-08-D4-0C-4D-1A-98
   DNS Servers . . . . . . . . . . . : 75.114.81.1
                                       75.114.81.2
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Ethernet adapter Bluetooth Network Connection 3:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network) #2
   Physical Address. . . . . . . . . : 08-D4-0C-4D-1A-9C
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter isatap.{2F684755-A178-44CE-ACC4-8E90721131A5}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Teredo Tunneling Pseudo-Interface:
 
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:9d38:90d7:2c48:3bd8:5257:e0b6(Preferred)
   Link-local IPv6 Address . . . . . : fe80::2c48:3bd8:5257:e0b6%18(Preferred)
   Default Gateway . . . . . . . . . :
   DHCPv6 IAID . . . . . . . . . . . : 301989888
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1E-C5-23-0C-08-D4-0C-4D-1A-98
   NetBIOS over Tcpip. . . . . . . . : Disabled
Server:  75-114-81-1.net.bhntampa.com
Address:  75.114.81.1
 
Name:    google.com
Addresses:  2607:f8b0:4002:805::200e
   74.125.21.138
   74.125.21.100
   74.125.21.102
   74.125.21.139
   74.125.21.113
   74.125.21.101
 

Pinging google.com [64.233.177.138] with 32 bytes of data:
Reply from 64.233.177.138: bytes=32 time=42ms TTL=42
Reply from 64.233.177.138: bytes=32 time=52ms TTL=42
 
Ping statistics for 64.233.177.138:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 42ms, Maximum = 52ms, Average = 47ms
Server:  75-114-81-1.net.bhntampa.com
Address:  75.114.81.1
 
Name:    yahoo.com
Addresses:  2001:4998:58:c02::a9
   2001:4998:c:a06::2:4008
   2001:4998:44:204::a7
   98.138.253.109
   98.139.183.24
   206.190.36.45
 

Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=84ms TTL=43
Reply from 98.139.183.24: bytes=32 time=65ms TTL=43
 
Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 65ms, Maximum = 84ms, Average = 74ms
 
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
  5...08 d4 0c 4d 1a 99 ......Microsoft Wi-Fi Direct Virtual Adapter
  4...08 d4 0c 4d 1a 98 ......Intel® Dual Band Wireless-AC 3165
 20...08 d4 0c 4d 1a 9c ......Bluetooth Device (Personal Area Network) #2
  1...........................Software Loopback Interface 1
 13...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
 18...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.0.1      192.168.0.5     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.0.0    255.255.255.0         On-link       192.168.0.5    281
      192.168.0.5  255.255.255.255         On-link       192.168.0.5    281
    192.168.0.255  255.255.255.255         On-link       192.168.0.5    281
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link       192.168.0.5    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link       192.168.0.5    281
===========================================================================
Persistent Routes:
  None
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  4    281 ::/64                    On-link
  1    306 ::1/128                  On-link
  4    281 ::7005:e917:1c49:b8cd/128
                                    On-link
  4    281 ::fcf2:55e5:83f5:2328/128
                                    On-link
 18    306 2001::/32                On-link
 18    306 2001:0:9d38:90d7:2c48:3bd8:5257:e0b6/128
                                    On-link
  4    281 fe80::/64                On-link
 18    306 fe80::/64                On-link
 18    306 fe80::2c48:3bd8:5257:e0b6/128
                                    On-link
  4    281 fe80::fcf2:55e5:83f5:2328/128
                                    On-link
  1    306 ff00::/8                 On-link
  4    281 ff00::/8                 On-link
 18    306 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================
 
Catalog5 01 C:\windows\SysWOW64\napinsp.dll [55808] (Microsoft Corporation)
Catalog5 02 C:\windows\SysWOW64\pnrpnsp.dll [70656] (Microsoft Corporation)
Catalog5 03 C:\windows\SysWOW64\pnrpnsp.dll [70656] (Microsoft Corporation)
Catalog5 04 C:\windows\SysWOW64\NLAapi.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog5 06 C:\windows\SysWOW64\winrnr.dll [23552] (Microsoft Corporation)
Catalog5 07 C:\windows\SysWOW64\wshbth.dll [51712] (Microsoft Corporation)
Catalog9 01 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 02 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 03 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 04 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 05 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 06 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 07 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 08 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 09 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 10 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 11 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 12 C:\windows\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [80896] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [31744] (Microsoft Corporation)
x64-Catalog5 07 C:\Windows\System32\wshbth.dll [63488] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 12 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (05/17/2016 12:29:01 PM) (Source: DptfPolicyLpmServiceHelper) (User: )
Description: DptfPolicyLpmServiceHelperWinMain:  CreateSharedMemory() failed.
 
Error: (05/17/2016 12:29:01 PM) (Source: DptfPolicyLpmServiceHelper) (User: )
Description: DptfPolicyLpmServiceHelperCreateSharedMemory:  CreateFileMapping() failed.Last error = [0x00000005]
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyCriticalService) (User: )
Description: DptfPolicyCriticalServiceServiceMain:  ServiceStart() failed.
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyCriticalService) (User: )
Description: DptfPolicyCriticalServiceServiceStart:  ConnectToDptfFrameworkDriver() failed.
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyLpmService) (User: )
Description: DptfPolicyLpmServiceServiceStart:  ConnectToDptfFrameworkDriver() failed.
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyLpmService) (User: )
Description: DptfPolicyLpmServiceConnectToDptfFrameworkDriver:  SetupDiEnumDeviceInterfaces() failed.Last error = [0x00000103]
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyCriticalService) (User: )
Description: DptfPolicyCriticalServiceConnectToDptfFrameworkDriver:  SetupDiEnumDeviceInterfaces() failed.Last error = [0x00000103]
 
Error: (05/17/2016 12:28:42 PM) (Source: DPTF) (User: )
Description: Intel® Dynamic Platform and Thermal FrameworkESIF(8.1.10605.221) TYPE: ERROR FUNC: EsifUpPm_EventCallback FILE: esif_uf_pm.c LINE: 284 TIME: 8109 ms
 
Fail to add participant TCPU in participant manager
 
Error: (05/17/2016 12:28:42 PM) (Source: DPTF) (User: )
Description: Intel® Dynamic Platform and Thermal FrameworkESIF(8.1.10605.221) TYPE: ERROR FUNC: EsifDspMgr_SelectDsp FILE: esif_uf_dspmgr.c LINE: 988 TIME: 8094 ms
 
No DSP selected for TCPU.
 
Error: (05/17/2016 12:28:42 PM) (Source: DPTF) (User: )
Description: Intel® Dynamic Platform and Thermal FrameworkESIF(8.1.10605.221) TYPE: ERROR FUNC: EsifUpPm_EventCallback FILE: esif_uf_pm.c LINE: 284 TIME: 8090 ms
 
Fail to add participant GEN3 in participant manager
 

System errors:
=============
Error: (05/17/2016 12:51:21 PM) (Source: Service Control Manager) (User: )
Description: The 1394 OHCI Compliant Host Controller service failed to start due to the following error:
%%1058
 
Error: (05/17/2016 12:28:18 PM) (Source: DCOM) (User: TABLET-JSTJM13J)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
 
Error: (05/17/2016 12:28:18 PM) (Source: DCOM) (User: TABLET-JSTJM13J)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
 
Error: (05/17/2016 12:28:13 PM) (Source: DCOM) (User: TABLET-JSTJM13J)
Description: {0002DF02-0000-0000-C000-000000000046}
 
Error: (05/17/2016 12:28:13 PM) (Source: Service Control Manager) (User: )
Description: The Sync Host_5f5d7 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (05/17/2016 12:28:13 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (05/17/2016 10:44:06 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (05/17/2016 10:38:12 AM) (Source: DCOM) (User: TABLET-JSTJM13J)
Description: "C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe" -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca5MicrosoftEdgeUnavailableUnavailable
 
Error: (05/17/2016 10:33:10 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (05/17/2016 10:24:20 AM) (Source: DCOM) (User: TABLET-JSTJM13J)
Description: {0002DF02-0000-0000-C000-000000000046}
 

Microsoft Office Sessions:
=========================
Error: (05/17/2016 12:29:01 PM) (Source: DptfPolicyLpmServiceHelper)(User: )
Description: DptfPolicyLpmServiceHelperWinMain:  CreateSharedMemory() failed.
 
Error: (05/17/2016 12:29:01 PM) (Source: DptfPolicyLpmServiceHelper)(User: )
Description: DptfPolicyLpmServiceHelperCreateSharedMemory:  CreateFileMapping() failed.Last error = [0x00000005]
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyCriticalService)(User: )
Description: DptfPolicyCriticalServiceServiceMain:  ServiceStart() failed.
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyCriticalService)(User: )
Description: DptfPolicyCriticalServiceServiceStart:  ConnectToDptfFrameworkDriver() failed.
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyLpmService)(User: )
Description: DptfPolicyLpmServiceServiceStart:  ConnectToDptfFrameworkDriver() failed.
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyLpmService)(User: )
Description: DptfPolicyLpmServiceConnectToDptfFrameworkDriver:  SetupDiEnumDeviceInterfaces() failed.Last error = [0x00000103]
 
Error: (05/17/2016 12:28:43 PM) (Source: DptfPolicyCriticalService)(User: )
Description: DptfPolicyCriticalServiceConnectToDptfFrameworkDriver:  SetupDiEnumDeviceInterfaces() failed.Last error = [0x00000103]
 
Error: (05/17/2016 12:28:42 PM) (Source: DPTF)(User: )
Description: Intel® Dynamic Platform and Thermal FrameworkESIF(8.1.10605.221) TYPE: ERROR FUNC: EsifUpPm_EventCallback FILE: esif_uf_pm.c LINE: 284 TIME: 8109 ms
 
Fail to add participant TCPU in participant manager
 
Error: (05/17/2016 12:28:42 PM) (Source: DPTF)(User: )
Description: Intel® Dynamic Platform and Thermal FrameworkESIF(8.1.10605.221) TYPE: ERROR FUNC: EsifDspMgr_SelectDsp FILE: esif_uf_dspmgr.c LINE: 988 TIME: 8094 ms
 
No DSP selected for TCPU.
 
Error: (05/17/2016 12:28:42 PM) (Source: DPTF)(User: )
Description: Intel® Dynamic Platform and Thermal FrameworkESIF(8.1.10605.221) TYPE: ERROR FUNC: EsifUpPm_EventCallback FILE: esif_uf_pm.c LINE: 284 TIME: 8090 ms
 
Fail to add participant GEN3 in participant manager
 

CodeIntegrity Errors:
===================================
  Date: 2016-05-16 20:46:19.130
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-11 17:26:24.797
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-11 16:05:54.755
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-11 15:59:41.137
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-11 13:54:26.758
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-11 13:48:16.092
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-11 13:25:30.379
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-11 13:10:07.542
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-11 13:10:07.134
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-11 12:58:12.671
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 

=========================== Installed Programs ============================
 
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.9.159 - Adobe Systems, Inc.)
AutoHotkey 1.1.23.05 (HKLM\...\AutoHotkey) (Version: 1.1.23.05 - Lexikos)
DisableMSDefender (HKLM\...\{74FE39A0-FB76-47CD-84BA-91E2BBB17EF2}) (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Dropbox (HKLM-x32\...\Dropbox) (Version: 3.20.1 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.41.1 - Dropbox, Inc.) Hidden
Energy Star (HKLM\...\{465CA2B6-98AF-4E77-BE22-A908C34BB9EC}) (Version: 1.0.9 - Hewlett-Packard Company)
Freeplane (HKLM\...\{D3941722-C4DD-4509-88C4-0E87F675A859}_is1) (Version: 1.3.15 - Open source)
Google Drive (HKLM-x32\...\{D7269C20-B3CE-4CD0-8E88-3D307D3BD41A}) (Version: 1.29.2074.1528 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.30.3 - Google Inc.) Hidden
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP)
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.8305.5282 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{61EB474B-67A6-47F4-B1B7-386851BAB3D0}) (Version: 8.0.29.6 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{D7D5F438-26EF-45AB-AB89-C476FBCF8584}) (Version: 12.4.18.7 - Hewlett-Packard Company)
Intel® Chipset Device Software (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel® Corporation) Hidden
Intel® Driver Update Utility 2.5 (HKLM-x32\...\{8EF465B2-1D08-4CA2-8ACC-1911B573725D}) (Version: 2.5.0.22 - Intel) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1167 - Intel Corporation)
Intel® PRO/Wireless Driver (HKLM\...\{07a12c6f-97c2-4a0e-9dd6-50ffc08ff551}) (Version: 18.20.0000.3210 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4312 - Intel Corporation)
Intel® Product Improvement Program (HKLM-x32\...\{5859045D-9DED-4776-9930-C9461AB2FF12}) (Version: 2.1.27.3 - Intel) Hidden
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.63.1519.7 - Intel Corporation)
Intel® Virtual Buttons (HKLM-x32\...\1992736F-C90A-481C-B21B-EE34CAD07387) (Version: 1.1.0.21 - Intel Corporation)
Intel® Wireless Bluetooth® (HKLM-x32\...\{EB14CEF0-8F59-47A3-B965-D0C0D6AC0DA3}) (Version: 18.1.1605.3087 - Intel Corporation)
Intel® Driver Update Utility (HKLM-x32\...\{aa1dec3b-dc4b-4db0-8c18-9157457eff1f}) (Version: 2.5.0.22 - Intel)
Intel® Integrated Sensor Solution (HKLM-x32\...\{755abcd0-2942-482b-a27d-22921a5849f0}) (Version: 3.0.14.3056 - Intel Corporation)
Intel® Software Guard Extensions Platform Software (HKLM\...\{D6CE0772-080E-45D4-8CB0-AB2AB9710DFE}) (Version: 1.1.28151.80 - Intel Corporation)
ISS_Drivers_x64 (HKLM\...\{7E28859E-AD3D-4FC2-8D70-E345F8C87722}) (Version: 3.0.14.3056 - Intel Corporation) Hidden
Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4693.1005 - Microsoft Corporation)
Microsoft OneNote Home and Student 2016 - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 16.0.6769.2040 - Microsoft Corporation)
Mozilla Firefox 46.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 46.0.1 (x86 en-US)) (Version: 46.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 46.0.1 - Mozilla)
Norton Security (HKLM-x32\...\NS) (Version: 22.6.0.142 - Symantec Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.6729.1019 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.6729.1019 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.6729.1019 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics ClickPad Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.25.4 - Synaptics Incorporated)
WhatsApp (HKCU\...\WhatsApp) (Version: 0.2.684 - WhatsApp)
XMind 7 (Update 1) (v3.6.1) (HKLM-x32\...\XMind_is1) (Version: 3.6.1.201512240104 - XMind Ltd.)
 
========================= Memory info: ===================================
 
Percentage of memory in use: 62%
Total physical RAM: 4005.2 MB
Available physical RAM: 1496.62 MB
Total Virtual: 5413.2 MB
Available Virtual: 2370.22 MB
 
========================= Partitions: =====================================
 
1 Drive c: () (Fixed) (Total:118.3 GB) (Free:34.13 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\TABLET-JSTJM13J
 
Administrator            DefaultAccount           Guest                   
Therios                 
 

**** End of log ****

 

 

This is the previous lgo ofadw cleaner before it cleaned the key:

 

​# AdwCleaner v5.117 - Logfile created 16/05/2016 at 21:46:10
# Updated 15/05/2016 by Xplode
# Database : 2016-05-15.2 [Server]
# Operating system : Windows 10 Home  (X64)
# Username : Therios - TABLET-JSTJM13J
# Running from : C:\Users\Therios\Downloads\adwcleaner_5.117.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.com/search?q=hp%20assistat&form=WNSGPH&qs=SW&cvid=abee8ac32569465895bba270caef994f&pq=hp%20assistat&nclid=0ED39ADB9642D6A945440994DFD21348&ts=1462992234518&nclidts=1462992234&tsms=518

***** [ Web browsers ] *****


*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [994 bytes] - [16/05/2016 21:46:10]
C:\AdwCleaner\AdwCleaner[S1].txt - [1049 bytes] - [16/05/2016 21:44:50]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1139 bytes] ##########
 

 

 

From JRT:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 10 Home x64
Ran by Therios (Administrator) on Tue 05/17/2016 at 13:11:32.13
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 5

Successfully deleted: C:\ProgramData\Start Menu\Programs\search.lnk (Shortcut)
Successfully deleted: C:\windows\prefetch\DRIVERUPDATEUI.EXE-76F67FE2.pf (File)
Successfully deleted: C:\windows\prefetch\FREEPLANE-SETUP-1.3.15.TMP-CA020E67.pf (File)
Successfully deleted: C:\windows\prefetch\FREEPLANE.EXE-F35D960F.pf (File)
Successfully deleted: C:\windows\prefetch\SETUPONENOTEFREERETAIL.X64.EN-4BE7E53C.pf (File)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 05/17/2016 at 13:12:32.81
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

im going to run eset right now.

 

Once again thank you very much.



#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,026 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:06:36 AM

Posted 17 May 2016 - 01:34 PM

Ok Eset will take a while, I'll look back
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 DanieI

DanieI

  • Banned
  • 109 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:36 AM

Posted 17 May 2016 - 01:46 PM

Download Zemana AntiMalware Free and run a Deep Scan to see if you have any malware/viruses installed. As you scan, each file that is found malicious will be listed and on the side it will say either "Delete" or "Quarantine". Whenever you see a new malware, click on "Quarantine" or "Delete" and select "Delete". You want Zemana AntiMalware Free to delete all the malware, not just stop you from using it harmfully. When the scan is over, it should give you the option to delete/quarantine the malware it found. Do it. You want to delete all the malware. Zemana AntiMalware Free also does scan your registry files, so it scans your entire computer, in and out, every nook and cranny for malware - and the best part - it's free.

 

Download: https://www.bleepingcomputer.com/download/zemana-antimalware/

 

To get the full version for free:

https://www.youtube.com/watch?v=N3v6nVd4Q8I



#6 t458

t458
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:36 AM

Posted 17 May 2016 - 01:59 PM

Ok Eset will take a while, I'll look back

finished scanning with eset. no threats found.



#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,026 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:06:36 AM

Posted 17 May 2016 - 02:17 PM

Appears it is not malware.. Lets' double check..

To get a second opinion, submit it to one of the following online services that analyzes suspicious files:In the "File to Scan" (Upload or Submit) box, browse to the location of the suspicious file(s) and submit (upload) it for scanning/analysis. If you get a message saying "File has already been analyzed", click Reanalyze or Scan again.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 t458

t458
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:36 AM

Posted 17 May 2016 - 02:37 PM

thanks again, but how can i submit a registry key?



#9 Didier Stevens

Didier Stevens

  • BC Advisor
  • 2,672 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:36 PM

Posted 21 May 2016 - 12:54 PM

I'm inclined to think it's not malware related, but linked to Cortana on Windows 10.

 

I searched for the elements in the registry entry you mentioned, and came up with this:

 

hp%20assistat: the %20 is a space character encoded for URLs. So this translates to "hp assistat". Notice the typo: assistat in stead of assistant. You have an HP machine with HP assistance software installed.

WNSGPH: this is linked to Cortana.

The following are timestamps:

1462992234518

1462992234

518

In GMT that's: Wed, 11 May 2016 18:43:54.518 GMT

 

It could be that it was cleaned because it is considered potentially unwanted software.


Edited by Didier Stevens, 21 May 2016 - 12:54 PM.

Didier Stevens
http://blog.DidierStevens.com
http://DidierStevensLabs.com

SANS ISC Handler
Microsoft MVP 2011-2016 Consumer Security, Windows Insider MVP 2016-2018
MVP_Horizontal_BlueOnly.png

 

If you send me messages, per Bleeping Computer's Forum policy, I will not engage in a conversation, but try to answer your question in the relevant forum post. If you don't want this, don't send me messages.

 

Stevens' law: "As an online security discussion grows longer, the probability of a reference to BadUSB approaches 1.0"


#10 t458

t458
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:36 AM

Posted 23 May 2016 - 11:57 AM

Boopme and Didier Stevens thank you so much for your kind help. It is actually a false positive. Thank you so much for helping me out. You have a great forum. Thank you.

 

Best regards. 



#11 Didier Stevens

Didier Stevens

  • BC Advisor
  • 2,672 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:36 PM

Posted 23 May 2016 - 01:34 PM

You're welcome.

Didier Stevens
http://blog.DidierStevens.com
http://DidierStevensLabs.com

SANS ISC Handler
Microsoft MVP 2011-2016 Consumer Security, Windows Insider MVP 2016-2018
MVP_Horizontal_BlueOnly.png

 

If you send me messages, per Bleeping Computer's Forum policy, I will not engage in a conversation, but try to answer your question in the relevant forum post. If you don't want this, don't send me messages.

 

Stevens' law: "As an online security discussion grows longer, the probability of a reference to BadUSB approaches 1.0"





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users