billbradshaw, on 27 July 2011 - 04:47 AM, said:
I just spent a few days making logs for Broni over at the "Am I infected, What do i do?" forum.
Most of the AV or anti spyware programs dont work.
They will install and update. But none of them will finish a scan. I got malwarebites to work once. the results are on the thread in the other section.
I use Vista x86 or 32bit
The symptoms ive noticed so far are mostly redirecting me on searches. Usually 5 times per search.
no AV program will scan. ( It will install update and start a scan, but then it closes and destroys the file for opening the app. so i have to reinstall it.
now and then i think i disconnect from the internet for 10 15 seconds at a time.
My google chrome wont open any more.
every thing else seems to work so far.
Here is a link to the thread with all the logs so far. Please help. I dont have my vista disc so i cant just wipe it.
.........Thread with broni, containing Logs......
Redirect says 100Ksearches.com redirect.
I noticed other people have this.
Please read over the link to my other thread on this forum. it has much information.
A couple other things ive noticed.
My computer crashes if left on for a few hours unatended,
Sometimes when i click on web pages it will ask to view over a secure network when it shouldnt.
and on of the programs i use for work stopped working. one of the only programs i use.
I tried to run GMER but it crashes and then i cant remove the file from my computer. it says i dont have permission.
Here are the DDS Log Files.
DDS:
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.19019
Run by julio at 2:37:24 on 2011-08-11
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1021.422 [GMT -7:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
"\\.\globalroot\Device\svchost.exe\svchost.exe"
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\System32\rundll32.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Logitech\Logitech Vid\Vid.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [Logitech Vid] "c:\program files\logitech\logitech vid\vid.exe" -bootmode
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DU Meter] c:\program files\du meter\DUMeter.exe
uRun: [SpywareTerminatorUpdate] "c:\program files\spyware terminator\SpywareTerminatorUpdate.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Google Update] "c:\users\julio\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Windows Phone Device Manager] %SystemRoot%\WPDeviceManager\WPDeviceManager.exe /Minimized
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [SNM] c:\program files\spynomore\SNM.exe /startup
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.55 68.105.28.11 68.105.29.11
TCP: Interfaces\{28C04470-6D89-4C9F-BE51-1F6AD84C586B} : DhcpNameServer = 192.168.1.55 68.105.28.11 68.105.29.11
TCP: Interfaces\{C49132D5-05B5-4CFF-84BB-EDD6EB01F696} : DhcpNameServer = 192.168.1.1
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Hosts: 192.168.1.103 developerservices.windowsphone.com
============= SERVICES / DRIVERS ===============
.
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-7-19 142592]
R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 52\starwind\StarWindServiceAE.exe [2009-12-23 370688]
R3 b57nd60x;%SvcDispName%;c:\windows\system32\drivers\b57nd60x.sys [2010-11-15 179712]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;"c:\program files\emsisoft anti-malware\a2service.exe" --> c:\program files\emsisoft anti-malware\a2service.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe --> c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [?]
S2 IMFservice;IMF Service;c:\program files\iobit\iobit malware fighter\imfsrv.exe --> c:\program files\iobit\iobit malware fighter\IMFsrv.exe [?]
S2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;"c:\program files\nvidia corporation\performance drivers\nvpdsvc.exe" --> c:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-7-7 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-7-7 8456]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-7-7 16472]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-7-7 11104]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-07-27 22:32:50 1152 ----a-w- c:\windows\system32\windrv.sys
2011-07-27 22:31:34 -------- d-----w- c:\users\julio\appdata\roaming\GetRightToGo
2011-07-24 07:54:09 -------- d-----w- c:\programdata\Avira
2011-07-24 06:32:18 -------- d-----w- c:\programdata\AVAST Software
2011-07-24 06:32:18 -------- d-----w- c:\program files\AVAST Software
2011-07-22 08:48:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-20 11:42:16 56400 ----a-w- c:\windows\system32\drivers\tmrkb.sys
2011-07-20 11:42:16 190032 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-07-20 11:32:06 -------- d-sh--w- C:\$RECYCLE.BIN
2011-07-20 11:13:59 -------- d-s---w- C:\cf8951c
2011-07-20 11:12:37 -------- d-s---w- C:\cf5032c
2011-07-20 10:44:34 -------- d-s---w- C:\cf6080c
2011-07-20 10:36:37 -------- d-----w- c:\programdata\IObit
2011-07-20 07:45:08 -------- d-----w- c:\users\julio\appdata\roaming\QuickScan
2011-07-20 00:11:59 -------- d-----w- c:\users\julio\appdata\roaming\SUPERAntiSpyware.com
2011-07-20 00:11:59 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-07-19 23:59:27 -------- d-----w- c:\programdata\Kaspersky Lab
2011-07-19 23:20:07 -------- d-----w- c:\program files\Mb av
2011-07-19 12:54:28 98816 ----a-w- c:\windows\sed.exe
2011-07-19 12:54:28 518144 ----a-w- c:\windows\SWREG.exe
2011-07-19 12:54:28 256000 ----a-w- c:\windows\PEV.exe
2011-07-19 12:54:28 208896 ----a-w- c:\windows\MBR.exe
2011-07-19 12:54:22 -------- d-s---w- C:\cf5234c
2011-07-19 12:53:31 -------- d-s---w- C:\cf
2011-07-19 11:46:12 -------- d-----w- c:\users\julio\appdata\roaming\IObit
2011-07-19 11:45:49 -------- d-----w- c:\program files\IObit
2011-07-19 11:15:46 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-07-19 11:15:44 -------- d-----w- c:\users\julio\appdata\roaming\Spyware Terminator
2011-07-19 11:15:37 -------- d-----w- c:\programdata\Spyware Terminator
2011-07-19 10:57:58 -------- d-----w- c:\users\julio\appdata\roaming\Malwarebytes
2011-07-19 10:57:49 -------- d-----w- c:\programdata\Malwarebytes
2011-07-19 10:03:45 -------- d-----w- c:\program files\common files\iS3
2011-07-19 10:03:44 -------- d-----w- c:\programdata\STOPzilla!
2011-07-19 08:12:37 -------- d-----w- c:\program files\DAMN NFO Viewer
2011-07-16 10:04:18 7074640 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{fa57970b-cf0f-4c3e-832b-37264ebb97a5}\mpengine.dll
.
==================== Find3M ====================
.
2011-06-20 08:46:51 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-25 02:14:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-15 01:25:04 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2011-05-15 01:24:57 82432 ----a-w- c:\windows\system32\axaltocm.dll
.
============= FINISH: 2:37:51.34 ===============
Thank you guys for your help. Hopefully you can help me solve this.