Jump to content

Recommended Posts

Got the known problem with mediashifting.

This is my malwarebyte results. Although it can find them after running it again (after a restart of course), mediashifting is still there :(

Thank you.

Malwarebytes Anti-Malware 1.60.1.1000

www.malwarebytes.org

Database version: v2012.02.06.05

Windows 7 Service Pack 1 x86 NTFS

Internet Explorer 9.0.8112.16421

Toumazis :: TOUMAZIS-PC [administrator]

11/02/2012 10:05:35 πμ

mbam-log-2012-02-11 (10-09-28).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 258980

Time elapsed: 3 minute(s), 45 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 1

C:\Windows\System32\ofcservice.dll (Rootkit.0Access) -> No action taken.

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 7

C:\Windows\System32\ofcservice.dll (Rootkit.0Access) -> No action taken.

C:\Windows\System32\tdrpman.dll (Rootkit.0Access) -> No action taken.

C:\Users\Toumazis\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> No action taken.

C:\Users\UpdatusUser\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> No action taken.

C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> No action taken.

C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> No action taken.

C:\Windows\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> No action taken.

(end)

Link to post
Share on other sites

Hello and :welcome:

Unfortunately you have a nasty rootkit infection. Please read the following information first.

BACKDOOR WARNING

------------------------------

One or more of the identified infections is known to use a backdoor.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would advice you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the infection has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you decide to go through with the cleanup, please proceed with the following steps.

COMBOFIX

---------------

Please download ComboFix from one of these locations:


Bleepingcomputer
ForoSpyware

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista, ComboFix will continue it's malware removal procedures.

Query_RC.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC_successful.gif

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\Combofix.txt in your next reply.

Link to post
Share on other sites

Thank you vary much for the reply. Here is the combofix.txt

ComboFix 12-02-10.03 - Toumazis 11/02/2012 21:07:51.1.4 - x86

Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3191.2270 [GMT 2:00]

Running from: c:\users\Toumazis\Downloads\ComboFix.exe

AV: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}

SP: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\hpeD778.dll

c:\users\Toumazis\AppData\Local\ade2b215\U

c:\users\Toumazis\AppData\Local\ade2b215\U\00000001.@

c:\users\Toumazis\AppData\Local\ade2b215\U\000000c0.@

c:\users\Toumazis\AppData\Local\ade2b215\U\000000cb.@

c:\users\Toumazis\AppData\Local\ade2b215\U\000000cf.@

c:\users\Toumazis\AppData\Local\ade2b215\U\80000000.@

c:\users\Toumazis\AppData\Local\ade2b215\U\800000c0.@

c:\users\Toumazis\AppData\Local\ade2b215\U\800000cb.@

c:\users\Toumazis\AppData\Local\ade2b215\U\800000cf.@

c:\users\Toumazis\AppData\Local\ade2b215\X

c:\windows\$NtUninstallKB57352$

c:\windows\$NtUninstallKB57352$\2917315093\@

c:\windows\$NtUninstallKB57352$\2917315093\L\xadqgnnk

c:\windows\$NtUninstallKB57352$\2917315093\loader.tlb

c:\windows\$NtUninstallKB57352$\2917315093\U\@00000001

c:\windows\$NtUninstallKB57352$\2917315093\U\@000000c0

c:\windows\$NtUninstallKB57352$\2917315093\U\@000000cb

c:\windows\$NtUninstallKB57352$\2917315093\U\@000000cf

c:\windows\$NtUninstallKB57352$\2917315093\U\@80000000

c:\windows\$NtUninstallKB57352$\2917315093\U\@800000c0

c:\windows\$NtUninstallKB57352$\2917315093\U\@800000cb

c:\windows\$NtUninstallKB57352$\2917315093\U\@800000cf

c:\windows\$NtUninstallKB57352$\3184389296

c:\windows\system32\

c:\windows\system32\c_00805.nls

c:\windows\system32\dds_log_trash.cmd

c:\windows\system32\QPCapSvc.dll

c:\windows\system32\regobj.dll

c:\windows\system32\roboot.exe

.

Infected copy of c:\windows\system32\drivers\netbt.sys was found and disinfected

Restored copy from - The cat found it :)

c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe . . . is infected!!

c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe . . . was deleted!! You should re-install the program it pertains to

.

Infected copy of c:\program files\Google\Update\GoogleUpdate.exe was found and disinfected

Restored copy from - c:\program files\Google\Update\

.

Infected copy of c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe was found and disinfected

Restored copy from - c:\program files\Google\Common\Google Updater\

.

Infected copy of c:\program files\TeamViewer\Version7\TeamViewer_Service.exe was found and disinfected

Restored copy from - c:\program files\TeamViewer\Version7\

.

.

((((((((((((((((((((((((( Files Created from 2012-01-11 to 2012-02-11 )))))))))))))))))))))))))))))))

.

.

2012-02-11 19:16 . 2012-02-11 19:17 -------- d-----w- c:\users\Toumazis\AppData\Local\temp

2012-02-11 19:16 . 2012-02-11 19:16 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2012-02-11 19:16 . 2012-02-11 19:16 -------- d-----w- c:\users\Toumazis.Toumazis-PC\AppData\Local\temp

2012-02-11 19:16 . 2012-02-11 19:16 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-02-11 19:16 . 2012-02-11 19:16 -------- d-----w- c:\users\Admin\AppData\Local\temp

2012-02-11 19:16 . 2012-02-11 19:16 -------- d-----w- c:\users\Admin.Toumazis-PC\AppData\Local\temp

2012-02-11 19:04 . 2010-11-20 08:39 187904 ----a-w- c:\windows\system32\drivers\netbt.sys

2012-02-06 21:03 . 2012-02-06 21:03 237 ----a-w- C:\user.js

2012-02-06 21:03 . 2012-02-06 21:03 -------- d-----w- c:\program files\BabylonToolbar

2012-02-06 21:03 . 2012-02-06 21:03 -------- d-----w- c:\users\Toumazis\AppData\Local\Babylon

2012-02-06 21:03 . 2012-02-06 21:03 -------- d-----w- c:\users\Toumazis\AppData\Roaming\Babylon

2012-02-06 21:03 . 2012-02-06 21:03 -------- d-----w- c:\programdata\Babylon

2012-02-06 21:03 . 2012-02-06 21:07 -------- d-----w- c:\users\Toumazis\AppData\Roaming\Systweak

2012-01-19 14:44 . 2009-08-19 20:50 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll

2012-01-19 14:43 . 2012-01-03 17:42 112056 ----a-w- c:\windows\system32\acaptuser32.dll

2012-01-14 12:04 . 2012-01-14 12:04 0 ---ha-w- c:\users\Toumazis\AppData\Local\BIT8C95.tmp

2012-01-12 22:04 . 2011-11-17 05:41 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys

2012-01-12 22:04 . 2011-11-17 05:41 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys

2012-01-12 22:04 . 2011-11-17 05:39 369352 ----a-w- c:\windows\system32\drivers\cng.sys

2012-01-12 22:04 . 2011-11-17 05:35 314880 ----a-w- c:\windows\system32\webio.dll

2012-01-12 22:04 . 2011-11-17 05:34 15872 ----a-w- c:\windows\system32\sspisrv.dll

2012-01-12 22:04 . 2011-11-17 05:34 100352 ----a-w- c:\windows\system32\sspicli.dll

2012-01-12 22:04 . 2011-11-17 05:34 224768 ----a-w- c:\windows\system32\schannel.dll

2012-01-12 22:04 . 2011-11-17 05:34 22016 ----a-w- c:\windows\system32\secur32.dll

2012-01-12 22:04 . 2011-11-17 05:32 1038848 ----a-w- c:\windows\system32\lsasrv.dll

2012-01-12 22:04 . 2011-11-17 05:29 22528 ----a-w- c:\windows\system32\lsass.exe

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-02-06 21:36 . 2011-11-06 18:17 417440 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-02-06 21:36 . 2011-03-15 21:24 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-01-12 00:19 . 2012-01-12 00:19 4448256 ----a-w- c:\windows\system32\GPhotos.scr

2012-01-07 09:10 . 2010-04-29 09:47 499712 ----a-w- c:\windows\system32\msvcp71.dll

2012-01-07 09:10 . 2010-04-29 09:47 348160 ----a-w- c:\windows\system32\msvcr71.dll

2011-12-16 15:32 . 2011-12-16 15:32 637848 ----a-w- c:\windows\system32\npdeployJava1.dll

2011-12-16 15:32 . 2010-08-22 17:23 567184 ----a-w- c:\windows\system32\deployJava1.dll

2011-12-10 13:24 . 2010-08-22 18:18 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-11-24 04:25 . 2011-12-16 15:10 2342912 ----a-w- c:\windows\system32\win32k.sys

2011-11-21 10:47 . 2011-12-23 15:16 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7925898D-831A-4715-83D0-0B3719FDE7C6}\mpengine.dll

2011-11-19 14:01 . 2012-01-12 05:31 67072 ----a-w- c:\windows\system32\packager.dll

2011-11-17 05:38 . 2012-01-12 05:31 1288472 ----a-w- c:\windows\system32\ntdll.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2012-01-03 40376]

"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2012-01-03 640440]

"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]

"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1313640]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 3080264]

"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-05 59240]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\System32\acaptuser32.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]

2010-11-12 10:13 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]

2011-11-01 21:25 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2011-09-22 962560]

R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-01-31 158856]

R2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2352640]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-02-06 253600]

R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]

R3 DivioUSBDCam;Crypto Smart PLUS USB Camera;c:\windows\system32\DRIVERS\pcam.sys [2000-03-31 159672]

R3 esihdrv;esihdrv;c:\users\Toumazis\AppData\Local\Temp\esihdrv.sys [x]

R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]

R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [2009-11-19 98672]

R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [2009-11-19 14960]

R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [2009-11-19 124016]

R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [2009-11-19 117872]

R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [2009-11-19 25456]

R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [2009-11-19 113904]

R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [2009-11-19 123504]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-22 1343400]

S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]

S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2011-08-09 163424]

S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]

S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]

S2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-11 2984832]

S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2011-05-18 40320]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]

.

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

PEVSystemStart

upnp

s3savagenb

NtMtlFax

.

Contents of the 'Scheduled Tasks' folder

.

2012-02-06 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2011-11-06 21:36]

.

2010-08-22 c:\windows\Tasks\Install.job

- c:\windows\System32\Adobe\Shockwave 11\nssstub.exe [2010-08-22 16:29]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://search.babylon.com/?AF=108298&babsrc=HP_ss&mntrId=a018f0b40000000000000025221c6f9e

uDefault_Search_URL = hxxp://www.google.com/ie

uInternet Settings,ProxyOverride = =

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.10.254

FF - ProfilePath - c:\users\Toumazis\AppData\Roaming\Mozilla\Firefox\Profiles\pvzoju9u.default\

FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/|https://mail.google.com/mail/?shva=1#inbox|http://www.facebook.com/|http://www.youtube.com/

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108298

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - a018f0b40000000000000025221c6f9e

FF - user.js: extensions.BabylonToolbar_i.hardId - a018f0b40000000000000025221c6f9e

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15376

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1723:03

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'lsass.exe'(528)

c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

.

- - - - - - - > 'Explorer.exe'(1572)

c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\nvvsvc.exe

c:\program files\NVIDIA Corporation\Display\nvxdsync.exe

c:\windows\system32\nvvsvc.exe

c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Canon\IJPLM\IJPLMSVC.EXE

c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

c:\program files\Microsoft\BingBar\SeaPort.EXE

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\windows\system32\WUDFHost.exe

c:\windows\system32\taskhost.exe

c:\windows\system32\conhost.exe

c:\program files\TeamViewer\Version7\TeamViewer.exe

c:\program files\TeamViewer\Version7\tv_w32.exe

c:\program files\Microsoft IntelliPoint\dpupdchk.exe

c:\program files\NVIDIA Corporation\Display\nvtray.exe

c:\program files\iPod\bin\iPodService.exe

c:\windows\system32\sppsvc.exe

c:\program files\Windows Media Player\wmpnetwk.exe

.

**************************************************************************

.

Completion time: 2012-02-11 21:22:09 - machine was rebooted

ComboFix-quarantined-files.txt 2012-02-11 19:22

.

Pre-Run: 291.239.870.464 bytes free

Post-Run: 291.169.017.856 bytes free

.

- - End Of File - - 9CD34411A704D3C16715E6030160346D

Link to post
Share on other sites

No rootkit message this time.

Also i should mention that NOD32 that says is running, Since the rootkit infection it has not been working

Thank you very much for the support

ComboFix 12-02-10.03 - Toumazis 11/02/2012 22:28:52.2.4 - x86

Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3191.1028 [GMT 2:00]

Running from: c:\users\Toumazis\Downloads\ComboFix.exe

AV: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}

SP: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2012-01-11 to 2012-02-11 )))))))))))))))))))))))))))))))

.

.

2012-02-11 20:36 . 2012-02-11 20:36 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2012-02-11 20:36 . 2012-02-11 20:36 -------- d-----w- c:\users\Toumazis.Toumazis-PC\AppData\Local\temp

2012-02-11 20:36 . 2012-02-11 20:36 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-02-11 20:36 . 2012-02-11 20:36 -------- d-----w- c:\users\Admin\AppData\Local\temp

2012-02-11 20:36 . 2012-02-11 20:36 -------- d-----w- c:\users\Admin.Toumazis-PC\AppData\Local\temp

2012-02-11 19:16 . 2012-02-11 20:36 -------- d-----w- c:\users\Toumazis\AppData\Local\temp

2012-02-11 19:04 . 2010-11-20 08:39 187904 ----a-w- c:\windows\system32\drivers\netbt.sys

2012-02-06 21:03 . 2012-02-06 21:03 237 ----a-w- C:\user.js

2012-02-06 21:03 . 2012-02-06 21:03 -------- d-----w- c:\program files\BabylonToolbar

2012-02-06 21:03 . 2012-02-06 21:03 -------- d-----w- c:\users\Toumazis\AppData\Local\Babylon

2012-02-06 21:03 . 2012-02-06 21:03 -------- d-----w- c:\users\Toumazis\AppData\Roaming\Babylon

2012-02-06 21:03 . 2012-02-06 21:03 -------- d-----w- c:\programdata\Babylon

2012-02-06 21:03 . 2012-02-06 21:07 -------- d-----w- c:\users\Toumazis\AppData\Roaming\Systweak

2012-01-19 14:44 . 2009-08-19 20:50 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll

2012-01-19 14:43 . 2012-01-03 17:42 112056 ----a-w- c:\windows\system32\acaptuser32.dll

2012-01-14 12:04 . 2012-01-14 12:04 0 ---ha-w- c:\users\Toumazis\AppData\Local\BIT8C95.tmp

2012-01-12 22:04 . 2011-11-17 05:41 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys

2012-01-12 22:04 . 2011-11-17 05:41 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys

2012-01-12 22:04 . 2011-11-17 05:39 369352 ----a-w- c:\windows\system32\drivers\cng.sys

2012-01-12 22:04 . 2011-11-17 05:35 314880 ----a-w- c:\windows\system32\webio.dll

2012-01-12 22:04 . 2011-11-17 05:34 15872 ----a-w- c:\windows\system32\sspisrv.dll

2012-01-12 22:04 . 2011-11-17 05:34 100352 ----a-w- c:\windows\system32\sspicli.dll

2012-01-12 22:04 . 2011-11-17 05:34 224768 ----a-w- c:\windows\system32\schannel.dll

2012-01-12 22:04 . 2011-11-17 05:34 22016 ----a-w- c:\windows\system32\secur32.dll

2012-01-12 22:04 . 2011-11-17 05:32 1038848 ----a-w- c:\windows\system32\lsasrv.dll

2012-01-12 22:04 . 2011-11-17 05:29 22528 ----a-w- c:\windows\system32\lsass.exe

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-02-06 21:36 . 2011-11-06 18:17 417440 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-02-06 21:36 . 2011-03-15 21:24 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-01-12 00:19 . 2012-01-12 00:19 4448256 ----a-w- c:\windows\system32\GPhotos.scr

2012-01-07 09:10 . 2010-04-29 09:47 499712 ----a-w- c:\windows\system32\msvcp71.dll

2012-01-07 09:10 . 2010-04-29 09:47 348160 ----a-w- c:\windows\system32\msvcr71.dll

2011-12-16 15:32 . 2011-12-16 15:32 637848 ----a-w- c:\windows\system32\npdeployJava1.dll

2011-12-16 15:32 . 2010-08-22 17:23 567184 ----a-w- c:\windows\system32\deployJava1.dll

2011-12-10 13:24 . 2010-08-22 18:18 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-11-24 04:25 . 2011-12-16 15:10 2342912 ----a-w- c:\windows\system32\win32k.sys

2011-11-21 10:47 . 2011-12-23 15:16 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7925898D-831A-4715-83D0-0B3719FDE7C6}\mpengine.dll

2011-11-19 14:01 . 2012-01-12 05:31 67072 ----a-w- c:\windows\system32\packager.dll

2011-11-17 05:38 . 2012-01-12 05:31 1288472 ----a-w- c:\windows\system32\ntdll.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2012-01-03 40376]

"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2012-01-03 640440]

"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]

"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1313640]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 3080264]

"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-05 59240]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\System32\acaptuser32.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]

2010-11-12 10:13 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]

2011-11-01 21:25 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2011-09-22 962560]

R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]

R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]

R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-01-31 158856]

R2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2352640]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-02-06 253600]

R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]

R3 DivioUSBDCam;Crypto Smart PLUS USB Camera;c:\windows\system32\DRIVERS\pcam.sys [2000-03-31 159672]

R3 esihdrv;esihdrv;c:\users\Toumazis\AppData\Local\Temp\esihdrv.sys [x]

R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]

R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [2009-11-19 98672]

R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [2009-11-19 14960]

R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [2009-11-19 124016]

R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [2009-11-19 117872]

R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [2009-11-19 25456]

R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [2009-11-19 113904]

R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [2009-11-19 123504]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-22 1343400]

S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]

S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2011-08-09 163424]

S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]

S2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-11 2984832]

S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2011-05-18 40320]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]

.

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

PEVSystemStart

upnp

s3savagenb

NtMtlFax

.

Contents of the 'Scheduled Tasks' folder

.

2012-02-06 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2011-11-06 21:36]

.

2010-08-22 c:\windows\Tasks\Install.job

- c:\windows\System32\Adobe\Shockwave 11\nssstub.exe [2010-08-22 16:29]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://search.babylon.com/?AF=108298&babsrc=HP_ss&mntrId=a018f0b40000000000000025221c6f9e

uDefault_Search_URL = hxxp://www.google.com/ie

uInternet Settings,ProxyOverride = =

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.10.254

FF - ProfilePath - c:\users\Toumazis\AppData\Roaming\Mozilla\Firefox\Profiles\pvzoju9u.default\

FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/|https://mail.google.com/mail/?shva=1#inbox|http://www.facebook.com/|http://www.youtube.com/

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108298

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - a018f0b40000000000000025221c6f9e

FF - user.js: extensions.BabylonToolbar_i.hardId - a018f0b40000000000000025221c6f9e

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15376

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1723:03

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'lsass.exe'(528)

c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

.

- - - - - - - > 'Explorer.exe'(4136)

c:\program files\TeamViewer\Version7\tv_w32.dll

c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

.

Completion time: 2012-02-11 22:37:32

ComboFix-quarantined-files.txt 2012-02-11 20:37

ComboFix2.txt 2012-02-11 19:22

.

Pre-Run: 290.699.288.576 bytes free

Post-Run: 290.403.430.400 bytes free

.

- - End Of File - - AD0ADB245DA2CE498DC9EEA2D58D0F32

Link to post
Share on other sites

Good to hear that! :)

We need to see some information about what is happening in your machine. Please perform the following scan:

  • Download DDS by sUBs from one of the following links. Save it to your desktop.

    [*]Double click on the DDS icon, allow it to run.

    [*]A small box will open, with an explaination about the tool. No input is needed, the scan is running.

    [*]Notepad will open with the results.

    [*]Follow the instructions that pop up for posting the results.

    [*]Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

Link to post
Share on other sites

DDS.txt

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.2.0

Run by Toumazis at 23:12:08 on 2012-02-11

Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3191.1479 [GMT 2:00]

.

AV: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}

SP: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\Microsoft\BingBar\SeaPort.EXE

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Windows\system32\WUDFHost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskhost.exe

C:\Program Files\TeamViewer\Version7\TeamViewer.exe

C:\Program Files\TeamViewer\Version7\tv_w32.exe

C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Program Files\Microsoft IntelliType Pro\itype.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\FileHippo.com\UpdateChecker.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files\iTunes\iTunes.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe

C:\Windows\system32\conhost.exe

C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\WUDFHost.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\ATH.exe

C:\Windows\system32\conhost.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe

C:\Windows\system32\conhost.exe

C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe

C:\Windows\Explorer.exe

C:\Program Files\Mozilla Firefox 4.0 Beta 3\firefox.exe

C:\Program Files\Mozilla Firefox 4.0 Beta 3\plugin-container.exe

C:\Program Files\Microsoft Office\Office12\WINWORD.EXE

C:\Program Files\Microsoft Office\Office12\EXCEL.EXE

C:\Windows\system32\vssvc.exe

C:\Windows\System32\svchost.exe -k swprv

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://search.babylon.com/?AF=108298&babsrc=HP_ss&mntrId=a018f0b40000000000000025221c6f9e

uDefault_Search_URL = hxxp://www.google.com/ie

uInternet Settings,ProxyOverride = =

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - c:\program files\babylontoolbar\babylontoolbar\1.5.3.17\bh\BabylonToolbar.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - No File

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll

BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll

BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll

TB: {8dcb7100-df86-4384-8842-8fa844297b3f} - No File

TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - c:\program files\babylontoolbar\babylontoolbar\1.5.3.17\BabylonToolbarTlbr.dll

uRun: [FileHippo.com] "c:\program files\filehippo.com\UpdateChecker.exe" /background

uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun

mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"

mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"

mRun: [intelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"

mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"

mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice

mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe

mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: PromptOnSecureDesktop = 0 (0x0)

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3}

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC}

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab

TCP: DhcpNameServer = 192.168.10.254

TCP: Interfaces\{00B44CBF-27F4-46F3-90EB-7E36BAADE4F8} : DhcpNameServer = 192.168.10.254

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

AppInit_DLLs: c:\windows\system32\acaptuser32.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\users\toumazis\appdata\roaming\mozilla\firefox\profiles\pvzoju9u.default\

FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/|https://mail.google.com/mail/?shva=1#inbox|http://www.facebook.com/|http://www.youtube.com/

FF - plugin: c:\program files\adobe\acrobat 9.0\acrobat\air\nppdf32.dll

FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\google\picasa3\npPicasa3.dll

FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll

FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll

FF - plugin: c:\program files\microsoft silverlight\5.0.61118.0\npctrlui.dll

FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll

FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll

FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_160.dll

.

---- FIREFOX POLICIES ----

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108298

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - a018f0b40000000000000025221c6f9e

FF - user.js: extensions.BabylonToolbar_i.hardId - a018f0b40000000000000025221c6f9e

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15376

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1723:03:26

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

============= SERVICES / DRIVERS ===============

.

R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2011-8-9 163424]

R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-9-8 2214504]

R2 TeamViewer7;TeamViewer 7;c:\program files\teamviewer\version7\TeamViewer_Service.exe [2011-12-14 2984832]

R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2011-9-22 962560]

S2 gupdate;Google Update Service (gupdate);"c:\program files\google\update\googleupdate.exe" /svc --> c:\program files\google\update\GoogleUpdate.exe [?]

S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\sony ericsson\sony ericsson pc suite\SupServ.exe [2011-1-19 90112]

S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-1-31 158856]

S2 TeamViewer6;TeamViewer 6;c:\program files\teamviewer\version6\TeamViewer_Service.exe [2011-8-30 2352640]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2011-11-6 253600]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]

S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-2-28 183560]

S3 DivioUSBDCam;Crypto Smart PLUS USB Camera;c:\windows\system32\drivers\pcam.sys [2011-2-13 159672]

S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-8-22 39264]

S3 gupdatem;Google Update Service (gupdatem);"c:\program files\google\update\googleupdate.exe" /medsvc --> c:\program files\google\update\GoogleUpdate.exe [?]

S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-4-18 15872]

S3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\drivers\s1039bus.sys [2011-1-19 98672]

S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\drivers\s1039mdfl.sys [2011-1-19 14960]

S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\drivers\s1039mdm.sys [2011-1-19 124016]

S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1039mgmt.sys [2011-1-19 117872]

S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1039nd5.sys [2011-1-19 25456]

S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\drivers\s1039obex.sys [2011-1-19 113904]

S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1039unic.sys [2011-1-19 123504]

S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-4-18 52224]

S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-8-22 1343400]

.

=============== Created Last 30 ================

.

2012-02-11 20:36:42 -------- d-sh--w- C:\$RECYCLE.BIN

2012-02-11 19:16:12 -------- d-----w- c:\users\toumazis\appdata\local\temp

2012-02-11 19:04:15 187904 ----a-w- c:\windows\system32\drivers\netbt.sys

2012-02-11 19:01:07 98816 ----a-w- c:\windows\sed.exe

2012-02-11 19:01:07 518144 ----a-w- c:\windows\SWREG.exe

2012-02-11 19:01:07 256000 ----a-w- c:\windows\PEV.exe

2012-02-11 19:01:07 208896 ----a-w- c:\windows\MBR.exe

2012-02-06 21:03:26 -------- d-----w- c:\program files\BabylonToolbar

2012-02-06 21:03:20 -------- d-----w- c:\users\toumazis\appdata\local\Babylon

2012-02-06 21:03:19 -------- d-----w- c:\users\toumazis\appdata\roaming\Babylon

2012-02-06 21:03:19 -------- d-----w- c:\programdata\Babylon

2012-02-06 21:03:14 -------- d-----w- c:\users\toumazis\appdata\roaming\Systweak

2012-01-19 14:44:02 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll

2012-01-19 14:43:02 112056 ----a-w- c:\windows\system32\acaptuser32.dll

2012-01-14 12:04:04 0 ---ha-w- c:\users\toumazis\appdata\local\BIT8C95.tmp

2012-01-12 22:04:45 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys

2012-01-12 22:04:45 369352 ----a-w- c:\windows\system32\drivers\cng.sys

2012-01-12 22:04:45 314880 ----a-w- c:\windows\system32\webio.dll

2012-01-12 22:04:45 22528 ----a-w- c:\windows\system32\lsass.exe

2012-01-12 22:04:45 224768 ----a-w- c:\windows\system32\schannel.dll

2012-01-12 22:04:45 22016 ----a-w- c:\windows\system32\secur32.dll

2012-01-12 22:04:45 15872 ----a-w- c:\windows\system32\sspisrv.dll

2012-01-12 22:04:45 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys

2012-01-12 22:04:45 1038848 ----a-w- c:\windows\system32\lsasrv.dll

2012-01-12 22:04:45 100352 ----a-w- c:\windows\system32\sspicli.dll

.

==================== Find3M ====================

.

2012-02-06 21:36:41 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-02-06 21:36:41 417440 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-01-12 00:19:16 4448256 ----a-w- c:\windows\system32\GPhotos.scr

2012-01-07 09:10:07 499712 ----a-w- c:\windows\system32\msvcp71.dll

2012-01-07 09:10:07 348160 ----a-w- c:\windows\system32\msvcr71.dll

2011-12-16 15:32:21 637848 ----a-w- c:\windows\system32\npdeployJava1.dll

2011-12-16 15:32:21 567184 ----a-w- c:\windows\system32\deployJava1.dll

2011-12-10 13:24:06 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-11-24 04:25:27 2342912 ----a-w- c:\windows\system32\win32k.sys

2011-11-19 14:01:00 67072 ----a-w- c:\windows\system32\packager.dll

2011-11-17 05:38:39 1288472 ----a-w- c:\windows\system32\ntdll.dll

.

============= FINISH: 23:12:18,45 ===============

Link to post
Share on other sites

Attach .txt

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-08-26.01)

.

Microsoft Windows 7 Ultimate

Boot Device: \Device\HarddiskVolume1

Install Date: 23/08/2010 2:22:52 pµ

System Uptime: 11/02/2012 9:16:55 µµ (2 hours ago)

.

Motherboard: ASRock | | H55M Pro

Processor: Intel® Core i5 CPU 660 @ 3.33GHz | CPUSocket | 3334/133mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 467 GiB total, 270,548 GiB free.

D: is CDROM ()

E: is CDROM ()

G: is FIXED (NTFS) - 466 GiB total, 17,797 GiB free.

H: is FIXED (FAT32) - 298 GiB total, 6,815 GiB free.

I: is Removable

K: is FIXED (NTFS) - 464 GiB total, 168,263 GiB free.

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP568: 06/02/2012 10:49:09 µµ - Installed STOPzilla. Available with Windows Installer version 1.2 and later.

RP570: 06/02/2012 10:55:14 µµ - StopZILLA! Restore Point.

RP572: 06/02/2012 10:57:12 µµ - StopZILLA! Restore Point.

RP574: 06/02/2012 10:59:56 µµ - StopZILLA! Restore Point.

RP575: 06/02/2012 11:30:43 µµ - Removed STOPzilla. Available with Windows Installer version 1.2 and later.

RP576: 06/02/2012 11:40:09 µµ - Installed Google Earth.

RP577: 11/02/2012 9:01:14 µµ - ComboFix created restore point

.

==== Installed Programs ======================

.

Update for Microsoft Office 2007 (KB2508958)

Adobe Acrobat 9 Pro Extended - English, Français, Deutsch

Adobe Acrobat 9.5.0 - CPSID_83708

Adobe Anchor Service CS4

Adobe Bridge CS4

Adobe CMaps CS4

Adobe Color - Photoshop Specific CS4

Adobe Color EU Extra Settings CS4

Adobe Color JA Extra Settings CS4

Adobe Color NA Recommended Settings CS4

Adobe Color Video Profiles CS CS4

Adobe CSI CS4

Adobe Default Language CS4

Adobe Device Central CS4

Adobe Drive CS4

Adobe ExtendScript Toolkit CS4

Adobe Extension Manager CS4

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Fonts All

Adobe Linguistics CS4

Adobe Media Player

Adobe Output Module

Adobe PDF Library Files CS4

Adobe Photoshop CS4

Adobe Photoshop CS4 Support

Adobe Search for Help

Adobe Service Manager Extension

Adobe Setup

Adobe Shockwave Player 11.6

Adobe Type Support CS4

Adobe Update Manager CS4

Adobe WinSoft Linguistics Plugin

Adobe XMP Panels CS4

AdobeColorCommonSetCMYK

AdobeColorCommonSetRGB

Apple Application Support

Apple Mobile Device Support

Apple Software Update

ArcGIS Desktop

AutoCad DXF to Shapefile Converter

Babylon toolbar on IE

Bing Bar Platform

Bonjour

Canon MP Navigator EX 1.0

Canon MP610 series

Canon MP610 series User Registration

Canon Utilities Easy-PhotoPrint EX

CCleaner

CD-LabelPrint

Connect

D3DX10

Defraggler

EasyGPS 4.13

ESET NOD32 Antivirus

ESET Online Scanner v3

FileHippo.com Update Checker

Google Chrome

Google Earth

Google Toolbar for Internet Explorer

Google Update Helper

iCloud

iTunes

Java 6 Update 22

Java 6 Update 26

Java 7 Update 2

JDownloader

Junk Mail filter update

kuler

Malwarebytes Anti-Malware version 1.60.1.1000

MapWinGIS ActiveX Control

Mesh Runtime

Messenger Companion

Microsoft .NET Framework 4 Client Profile

Microsoft Application Error Reporting

Microsoft IntelliPoint 8.2

Microsoft IntelliType Pro 8.2

Microsoft Office 2007 Service Pack 3 (SP3)

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Enterprise 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office File Validation Add-In

Microsoft Office Groove MUI (English) 2007

Microsoft Office Groove Setup Metadata MUI (English) 2007

Microsoft Office InfoPath MUI (English) 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook Connector

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Search Enhancement Pack

Microsoft Silverlight

MobileMe Control Panel

Mozilla Firefox 11.0 (x86 en-US)

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

NVIDIA Control Panel 275.33

NVIDIA Graphics Driver 275.33

NVIDIA Install Application

NVIDIA Update 1.3.5

NVIDIA Update Components

PDF Settings CS4

Photoshop Camera Raw

Picasa 3

Pidgin

PIXMA Extended Survey Program

Python 2.4.1

QuickTime

RealNetworks - Microsoft Visual C++ 2008 Runtime

RealPlayer

RealUpgrade 1.0

RealUpgrade 1.1

Recuva

Registry Easy v5.6

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition

Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition

Skype Click to Call

Skype™ 5.8

Suite Shared Configuration CS4

swMSM

TeamViewer 6

TeamViewer 7

Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft Office 2007 Help for Common Features (KB963673)

Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2596686) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition

Update for Microsoft Office Access 2007 Help (KB963663)

Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition

Update for Microsoft Office Excel 2007 Help (KB963678)

Update for Microsoft Office Infopath 2007 Help (KB963662)

Update for Microsoft Office OneNote 2007 Help (KB963670)

Update for Microsoft Office Outlook 2007 Help (KB963677)

Update for Microsoft Office Powerpoint 2007 Help (KB963669)

Update for Microsoft Office Publisher 2007 Help (KB963667)

Update for Microsoft Office Script Editor Help (KB963671)

Update for Microsoft Office Word 2007 Help (KB963665)

VLC media player 1.1.11

Windows Live Communications Platform

Windows Live Essentials Beta

Windows Live Family Safety

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Mail

Windows Live Messenger

Windows Live Messenger Companion Core

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Common Beta

Windows Live Photo Gallery Beta

Windows Live PIMT Platform

Windows Live Remote Client

Windows Live Remote Client Resources

Windows Live Remote Service

Windows Live Remote Service Resources

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live Sync Beta

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

Windows Media Player Firefox Plugin

WinRAR 4.10 (32-bit)

WinSoftME

Your Uninstaller! 7

.

==== Event Viewer Messages From Past Week ========

.

11/02/2012 9:23:23 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

11/02/2012 9:19:55 pµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

11/02/2012 9:19:32 pµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

11/02/2012 9:19:31 µµ, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The system cannot find the file specified.

11/02/2012 9:19:29 pµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

11/02/2012 9:19:29 pµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

11/02/2012 9:19:29 pµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

11/02/2012 9:19:29 pµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

11/02/2012 9:17:24 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

11/02/2012 9:17:15 µµ, Error: Service Control Manager [7023] - The Magictuneengine service terminated with the following error: The specified module could not be found.

11/02/2012 9:17:13 µµ, Error: Service Control Manager [7023] - The Pdlndqll service terminated with the following error: The specified module could not be found.

11/02/2012 9:17:12 µµ, Error: Service Control Manager [7023] - The MXOFX service terminated with the following error: The specified module could not be found.

11/02/2012 9:17:12 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

11/02/2012 9:17:12 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

11/02/2012 9:12:19 µµ, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

11/02/2012 9:06:44 µµ, Error: Service Control Manager [7034] - The Sony Ericsson OMSI download service service terminated unexpectedly. It has done this 1 time(s).

11/02/2012 9:06:44 µµ, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

11/02/2012 9:05:41 µµ, Error: Service Control Manager [7023] - The Pdlndqll service terminated with the following error: The specified module could not be found.

11/02/2012 9:05:41 µµ, Error: Service Control Manager [7023] - The MXOFX service terminated with the following error: The specified module could not be found.

11/02/2012 9:05:41 µµ, Error: Service Control Manager [7023] - The Magictuneengine service terminated with the following error: The specified module could not be found.

11/02/2012 9:05:41 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

11/02/2012 9:05:40 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

11/02/2012 9:05:40 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

11/02/2012 9:05:40 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

11/02/2012 9:03:05 µµ, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

11/02/2012 9:03:04 µµ, Error: Service Control Manager [7034] - The Sony Ericsson OMSI download service service terminated unexpectedly. It has done this 1 time(s).

11/02/2012 9:00:49 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

11/02/2012 8:56:32 µµ, Error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).

11/02/2012 8:52:53 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

11/02/2012 8:51:07 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

11/02/2012 8:51:05 µµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

11/02/2012 8:51:05 µµ, Error: Service Control Manager [7023] - The MXOFX service terminated with the following error: The specified module could not be found.

11/02/2012 8:51:05 µµ, Error: Service Control Manager [7023] - The Magictuneengine service terminated with the following error: The specified module could not be found.

11/02/2012 8:51:05 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

11/02/2012 8:51:05 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

11/02/2012 8:51:05 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

11/02/2012 12:12:46 µµ, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.

11/02/2012 12:12:36 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

11/02/2012 12:12:18 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

11/02/2012 12:12:14 µµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

11/02/2012 12:12:14 µµ, Error: Service Control Manager [7023] - The MXOFX service terminated with the following error: The specified module could not be found.

11/02/2012 12:12:14 µµ, Error: Service Control Manager [7023] - The Magictuneengine service terminated with the following error: The specified module could not be found.

11/02/2012 12:12:14 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

11/02/2012 12:12:14 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

11/02/2012 12:12:14 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

11/02/2012 10:36:09 µµ, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

11/02/2012 10:33:18 µµ, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

11/02/2012 10:28:46 µµ, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

11/02/2012 10:28:45 µµ, Error: Service Control Manager [7034] - The Sony Ericsson OMSI download service service terminated unexpectedly. It has done this 1 time(s).

11/02/2012 10:27:41 µµ, Error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).

11/02/2012 10:11:36 pµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

11/02/2012 10:11:26 pµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

11/02/2012 10:11:22 pµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

11/02/2012 10:11:22 pµ, Error: Service Control Manager [7023] - The MXOFX service terminated with the following error: The specified module could not be found.

11/02/2012 10:11:22 pµ, Error: Service Control Manager [7023] - The Magictuneengine service terminated with the following error: The specified module could not be found.

11/02/2012 10:11:22 pµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

11/02/2012 10:11:22 pµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

11/02/2012 10:11:22 pµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

10/02/2012 9:26:03 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

10/02/2012 9:25:42 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

10/02/2012 9:25:39 µµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

10/02/2012 9:25:39 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

10/02/2012 9:25:39 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

10/02/2012 9:25:39 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

09/02/2012 12:29:30 pµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

09/02/2012 12:28:44 pµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

09/02/2012 12:28:42 pµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

09/02/2012 12:28:42 pµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

09/02/2012 12:28:42 pµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

09/02/2012 12:28:42 pµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

08/02/2012 2:36:07 pµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

08/02/2012 2:35:46 pµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

08/02/2012 2:35:42 pµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

08/02/2012 2:35:42 pµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

08/02/2012 2:35:42 pµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

08/02/2012 2:35:42 pµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

08/02/2012 12:09:53 pµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

08/02/2012 12:08:00 pµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

08/02/2012 12:07:57 pµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

08/02/2012 12:07:57 pµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

08/02/2012 12:07:57 pµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

08/02/2012 12:07:57 pµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

08/02/2012 10:08:13 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

08/02/2012 10:07:56 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

08/02/2012 10:07:53 µµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

08/02/2012 10:07:53 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

08/02/2012 10:07:53 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

08/02/2012 10:07:53 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

07/02/2012 8:15:34 pµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

07/02/2012 8:09:34 pµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

07/02/2012 8:09:31 pµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

07/02/2012 8:09:31 pµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

07/02/2012 8:09:31 pµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

07/02/2012 8:09:31 pµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

06/02/2012 9:58:24 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

06/02/2012 9:56:16 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

06/02/2012 9:56:13 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

06/02/2012 9:56:13 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

06/02/2012 9:56:13 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

06/02/2012 12:42:53 pµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

06/02/2012 12:42:43 pµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

06/02/2012 12:42:39 pµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

06/02/2012 12:42:38 pµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

06/02/2012 12:42:38 pµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

06/02/2012 12:32:23 pµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

06/02/2012 12:31:51 pµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

06/02/2012 12:31:47 pµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

06/02/2012 12:31:47 pµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

06/02/2012 12:31:47 pµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

06/02/2012 11:54:15 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

06/02/2012 11:54:00 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

06/02/2012 11:53:54 µµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

06/02/2012 11:53:54 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

06/02/2012 11:53:54 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

06/02/2012 11:53:54 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

06/02/2012 11:53:07 µµ, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

06/02/2012 11:53:07 µµ, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-2147467243.

06/02/2012 11:53:01 µµ, Error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).

06/02/2012 11:52:52 µµ, Error: Service Control Manager [7031] - The Windows Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

06/02/2012 11:52:50 µµ, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Event Log service, but this action failed with the following error: An instance of the service is already running.

06/02/2012 11:52:50 µµ, Error: Service Control Manager [7023] - The Windows Audio Endpoint Builder service terminated with the following error: The RPC server is unavailable.

06/02/2012 11:52:50 µµ, Error: Service Control Manager [7023] - The Function Discovery Provider Host service terminated with the following error: %%-2147467243

06/02/2012 11:52:50 µµ, Error: Service Control Manager [7001] - The Windows Audio service depends on the Windows Audio Endpoint Builder service which failed to start because of the following error: The operation completed successfully.

06/02/2012 11:52:50 µµ, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: %%-2147467243

06/02/2012 11:52:48 µµ, Error: srv [2000] - The server's call to a system service failed unexpectedly.

06/02/2012 11:52:48 µµ, Error: Service Control Manager [7023] - The Windows Update service terminated with the following error: %%-2147467243

06/02/2012 11:52:48 µµ, Error: Service Control Manager [7023] - The Server service terminated with the following error: Access is denied.

06/02/2012 11:52:48 µµ, Error: Service Control Manager [7001] - The Background Intelligent Transfer Service service depends on the COM+ Event System service which failed to start because of the following error: The operation completed successfully.

06/02/2012 11:52:40 µµ, Error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).

06/02/2012 11:52:37 µµ, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

06/02/2012 11:52:28 µµ, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Audio Endpoint Builder service, but this action failed with the following error: Circular service dependency was specified.

06/02/2012 11:52:28 µµ, Error: Service Control Manager [7019] - The Windows Audio Endpoint Builder service depends on a service in a group which starts later. Change the order in the service dependency tree to ensure that all services required to start this service are starting before this service is started.

06/02/2012 11:52:28 µµ, Error: Service Control Manager [7017] - Detected circular dependencies demand starting Windows Audio Endpoint Builder. Check the service dependency tree.

06/02/2012 11:52:07 µµ, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the Power service, but this action failed with the following error: A system shutdown has already been scheduled.

06/02/2012 11:52:07 µµ, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the Plug and Play service, but this action failed with the following error: A system shutdown has already been scheduled.

06/02/2012 11:52:07 µµ, Error: Service Control Manager [7031] - The Power service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.

06/02/2012 11:52:07 µµ, Error: Service Control Manager [7031] - The Plug and Play service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.

06/02/2012 11:52:07 µµ, Error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.

06/02/2012 11:52:04 µµ, Error: Service Control Manager [7031] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.

06/02/2012 11:52:04 µµ, Error: Service Control Manager [7031] - The DHCP Client service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.

06/02/2012 11:52:01 µµ, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.

06/02/2012 11:51:55 µµ, Error: Service Control Manager [7034] - The WinHTTP Web Proxy Auto-Discovery Service service terminated unexpectedly. It has done this 3 time(s).

06/02/2012 11:51:55 µµ, Error: Service Control Manager [7034] - The Network Store Interface Service service terminated unexpectedly. It has done this 3 time(s).

06/02/2012 11:51:55 µµ, Error: Service Control Manager [7034] - The Network List Service service terminated unexpectedly. It has done this 3 time(s).

06/02/2012 11:51:55 µµ, Error: Service Control Manager [7034] - The COM+ Event System service terminated unexpectedly. It has done this 3 time(s).

06/02/2012 11:51:52 µµ, Error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s).

06/02/2012 11:51:50 µµ, Error: Service Control Manager [7031] - The Windows Event Log service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

06/02/2012 11:51:50 µµ, Error: Service Control Manager [7031] - The Windows Audio service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

06/02/2012 11:51:50 µµ, Error: Service Control Manager [7031] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.

06/02/2012 11:51:50 µµ, Error: Service Control Manager [7031] - The HomeGroup Provider service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

06/02/2012 11:51:50 µµ, Error: Service Control Manager [7031] - The DHCP Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

06/02/2012 11:50:53 µµ, Error: Service Control Manager [7031] - The Windows Modules Installer service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.

06/02/2012 11:47:05 µµ, Error: Service Control Manager [7031] - The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

06/02/2012 11:46:51 µµ, Error: Service Control Manager [7031] - The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

06/02/2012 11:46:21 µµ, Error: Service Control Manager [7034] - The PIXMA Extended Survey Program service terminated unexpectedly. It has done this 1 time(s).

06/02/2012 11:45:28 µµ, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

06/02/2012 11:34:05 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

06/02/2012 11:33:28 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

06/02/2012 11:33:25 µµ, Error: Service Control Manager [7023] - The Safety Settings Service service terminated with the following error: The specified module could not be found.

06/02/2012 11:33:25 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

06/02/2012 11:33:25 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

06/02/2012 11:33:25 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

06/02/2012 11:25:21 µµ, Error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).

06/02/2012 10:54:26 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

06/02/2012 10:53:34 µµ, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: is3srv

06/02/2012 10:53:34 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

06/02/2012 10:53:30 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

06/02/2012 10:53:30 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

06/02/2012 10:53:30 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

05/02/2012 9:08:06 µµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

05/02/2012 8:57:34 µµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

05/02/2012 8:57:34 µµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

05/02/2012 8:57:34 µµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

05/02/2012 8:57:33 µµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

05/02/2012 11:20:31 µµ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk3\DR3.

05/02/2012 11:20:30 µµ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk3\DR3.

04/02/2012 6:18:21 pµ, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.

04/02/2012 6:17:08 pµ, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

04/02/2012 6:17:05 pµ, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

04/02/2012 6:17:05 pµ, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

04/02/2012 6:17:05 pµ, Error: Service Control Manager [7000] - The ESET Service service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

.

==== End Of File ===========================

Link to post
Share on other sites

Hi again,

Please download Farbar Service Scanner and run it on the computer with the issue.

  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update

    [*]Press "Scan".

    [*]It will create a log (FSS.txt) in the same directory the tool is run.

    [*]Please copy and paste the log to your reply.

Link to post
Share on other sites

Good afternoon

Farbar Service Scanner Version: 12-02-2012

Ran by Toumazis (administrator) on 12-02-2012 at 17:34:55

Running from "C:\Users\Toumazis\Downloads"

Microsoft Windows 7 Ultimate Service Pack 1 (X86)

Boot Mode: Normal

****************************************************************

Internet Services:

============

Connection Status:

==============

Localhost is accessible.

LAN connected.

Google IP is accessible.

Yahoo IP is accessible.

Windows Firewall:

=============

mpsdrv Service is not running. Checking service configuration:

The start type of mpsdrv service is OK.

The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:

Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist.

Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist.

Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist.

Firewall Disabled Policy:

==================

System Restore:

============

System Restore Disabled Policy:

========================

Security Center:

============

Windows Update:

============

File Check:

========

C:\Windows\system32\nsisvc.dll => MD5 is legit

C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit

C:\Windows\system32\dhcpcore.dll => MD5 is legit

C:\Windows\system32\Drivers\afd.sys => MD5 is legit

C:\Windows\system32\Drivers\tdx.sys => MD5 is legit

C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit

C:\Windows\system32\dnsrslvr.dll => MD5 is legit

C:\Windows\system32\mpssvc.dll => MD5 is legit

C:\Windows\system32\bfe.dll => MD5 is legit

C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit

C:\Windows\system32\SDRSVC.dll => MD5 is legit

C:\Windows\system32\vssvc.exe => MD5 is legit

C:\Windows\system32\wscsvc.dll => MD5 is legit

C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit

C:\Windows\system32\wuaueng.dll => MD5 is legit

C:\Windows\system32\qmgr.dll => MD5 is legit

C:\Windows\system32\es.dll => MD5 is legit

C:\Windows\system32\cryptsvc.dll => MD5 is legit

C:\Windows\system32\svchost.exe => MD5 is legit

C:\Windows\system32\rpcss.dll => MD5 is legit

**** End of log ****

Link to post
Share on other sites

Lets rebuild the firewall service. Afterwards, restart the computer and let me know how everything is running.

We Need to Run a Registry Script

  1. Press the Windows Logo in the lower left corner of your screen.
  2. In the 10-16-2011%204-33-46%20PM.png box, enter notepad and press Enter.
  3. Highlight the contents of the following codebox, and copy and paste that text into notepad.

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MpsSvc]
    "DisplayName"="@%SystemRoot%\\system32\\FirewallAPI.dll,-23090"
    "Group"="NetworkProvider"
    "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
    74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
    00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
    6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\
    00,65,00,4e,00,6f,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,00,00
    "Description"="@%SystemRoot%\\system32\\FirewallAPI.dll,-23091"
    "ObjectName"="NT Authority\\LocalService"
    "ErrorControl"=dword:00000001
    "Start"=dword:00000002
    "Type"=dword:00000020
    "DependOnService"=hex(7):6d,00,70,00,73,00,64,00,72,00,76,00,00,00,62,00,66,00,\
    65,00,00,00,00,00
    "ServiceSidType"=dword:00000003
    "RequiredPrivileges"=hex(7):53,00,65,00,41,00,73,00,73,00,69,00,67,00,6e,00,50,\
    00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,00,65,00,6e,00,50,00,\
    72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,75,\
    00,64,00,69,00,74,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\
    00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,\
    00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
    53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,\
    00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,\
    65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,\
    00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,\
    6e,00,63,00,72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,\
    00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
    00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MpsSvc\Parameters]
    "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
    00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
    6d,00,70,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
    "ServiceDllUnloadOnStop"=dword:00000001

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MpsSvc\Parameters\PortKeywords]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MpsSvc\Security]
    "Security"=hex:01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,30,00,00,00,02,\
    00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
    00,00,02,00,84,00,05,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
    05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
    20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
    00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,00,00,28,00,15,00,\
    00,00,01,06,00,00,00,00,00,05,50,00,00,00,49,59,9d,77,91,56,e5,55,dc,f4,e2,\
    0e,a7,8b,eb,ca,7b,42,13,56,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\
    00,00,00,05,12,00,00,00


  4. Select File -> Save.
  5. Press the Desktop button on the left side of the save dialog.
  6. In the 10-16-2011%204-37-58%20PM.png box, type in Fix.reg.
  7. Press 10-16-2011%204-36-39%20PM.png.
  8. Close Notepad.
  9. Double click 10-16-2011%204-34-48%20PM.png on your desktop.
  10. Press Yes if prompted by User Account Control.
  11. Press Yes, and then Ok, when prompted.
  12. Right click on 10-16-2011%204-34-48%20PM.png and choose Delete.
  13. Press Yes.

Link to post
Share on other sites

Good to hear that! :) Lets do one last scan just to be sure.

ESET ONLINE SCANNER

----------------------------

I'd like us to scan your machine with ESET OnlineScan

  1. Hold down Control and click on this link to open ESET OnlineScan in a new window.
  2. Click the esetonlinebtn.png button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

    1. Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the esetsmartinstaller_enu.png
      icon on your desktop.

    3. Check "YES, I accept the Terms of Use."
    4. Click the Start button.
    5. Accept any security warnings from your browser.
    6. Under scan settings, check "Scan Archives" and "Remove found threats"
    7. Click Advanced settings and select the following:
      • Scan potentially unwanted applications
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth technology

[*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.

[*]When the scan completes, click List Threats

[*]Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

[*]Click the Back button.

[*]Click the Finish button.

Link to post
Share on other sites

  • 1 month later...
  • 1 month later...
  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.