Jump to content

davemanster

Members
  • Posts

    1
  • Joined

  • Last visited

Posts posted by davemanster

  1. I have Ran TDDSKiller with no infections found

    So far on every attempt to run ComboFix I get a warning that the recycle bin is corrupted. I then boot into safe mode and delete $RECYCLE.BIN then the problem is solved. Until I attempt to run ComboFix again. Then the problem returns.

    I have local network access, but no Internet access.

    I have been browsing around looking for help, and these are some of the commonly requested logs that I was able to get.

    MBAM Log

    Malwarebytes' Anti-Malware 1.51.2.1300

    www.malwarebytes.org

    Database version: 7622

    Windows 6.0.6001 Service Pack 1 (Safe Mode)

    Internet Explorer 7.0.6001.18000

    6/7/2012 3:02:45 PM

    mbam-log-2012-06-07 (15-02-45).txt

    Scan type: Full scan (C:\|D:\|)

    Objects scanned: 304125

    Time elapsed: 34 minute(s), 54 second(s)

    Memory Processes Infected: 0

    Memory Modules Infected: 0

    Registry Keys Infected: 0

    Registry Values Infected: 0

    Registry Data Items Infected: 0

    Folders Infected: 0

    Files Infected: 0

    Memory Processes Infected:

    (No malicious items detected)

    Memory Modules Infected:

    (No malicious items detected)

    Registry Keys Infected:

    (No malicious items detected)

    Registry Values Infected:

    (No malicious items detected)

    Registry Data Items Infected:

    (No malicious items detected)

    Folders Infected:

    (No malicious items detected)

    Files Infected:

    (No malicious items detected)

    Security Check Log

    Results of screen317's Security Check version 0.99.41

    Windows Vista Service Pack 1 x86 (UAC is enabled)

    Out of date service pack!!

    Internet Explorer 7 Out of date!

    ``````````````Antivirus/Firewall Check:``````````````

    Windows Security Center service is not running! This report may not be accurate!

    WMI entry may not exist for antivirus; attempting automatic update.

    `````````Anti-malware/Other Utilities Check:`````````

    Out of date HijackThis installed!

    Spybot - Search & Destroy

    SUPERAntiSpyware

    Malwarebytes Anti-Malware version 1.61.0.1400

    HijackThis 2.0.2

    CCleaner

    Java 6 Update 7

    Java version out of date!

    Adobe Reader 8 Adobe Reader out of date!

    Adobe Reader X KB403742.. Adobe Reader out of Date!

    ````````Process Check: objlist.exe by Laurent````````

    Malwarebytes Anti-Malware mbam.exe

    `````````````````System Health check`````````````````

    Total Fragmentation on Drive C: 1 %

    ````````````````````End of Log``````````````````````

    FSS Log

    Farbar Service Scanner Version: 09-06-2012

    Ran by josh (administrator) on 12-06-2012 at 13:13:48

    Running from "\\MAINPC\Users\Public"

    Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86)

    Boot Mode: Nerwork

    ****************************************************************

    Internet Services:

    ============

    Connection Status:

    ==============

    Attempt to access Local Host IP returned error: Localhost is blokked: Other errors

    LAN connected.

    Attempt to access Google IP returned error: Other errors

    Attempt to access Google.com returned error: Other errors

    Attempt to access Yahoo IP returned error: Other errors

    Attempt to access Yahoo.com returned error: Other errors

    Windows Firewall:

    =============

    mpsdrv Service is not running. Checking service configuration:

    The start type of mpsdrv service is OK.

    The ImagePath of mpsdrv service is OK.

    MpsSvc Service is not running. Checking service configuration:

    Checking Start type: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.

    Checking ImagePath: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.

    Checking ServiceDll: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.

    Firewall Disabled Policy:

    ==================

    System Restore:

    ============

    SDRSVC Service is not running. Checking service configuration:

    The start type of SDRSVC service is OK.

    The ImagePath of SDRSVC service is OK.

    The ServiceDll of SDRSVC service is OK.

    VSS Service is not running. Checking service configuration:

    The start type of VSS service is OK.

    The ImagePath of VSS service is OK.

    System Restore Disabled Policy:

    ========================

    Security Center:

    ============

    wscsvc Service is not running. Checking service configuration:

    The start type of wscsvc service is OK.

    The ImagePath of wscsvc: "%SystemRoot%\System32\svchost.exe -k netsvcs".

    The ServiceDll of wscsvc service is OK.

    Windows Update:

    ============

    wuauserv Service is not running. Checking service configuration:

    The start type of wuauserv service is OK.

    The ImagePath of wuauserv service is OK.

    The ServiceDll of wuauserv service is OK.

    BITS Service is not running. Checking service configuration:

    The start type of BITS service is OK.

    The ImagePath of BITS service is OK.

    The ServiceDll of BITS service is OK.

    EventSystem Service is not running. Checking service configuration:

    The start type of EventSystem service is OK.

    The ImagePath of EventSystem service is OK.

    The ServiceDll of EventSystem service is OK.

    Windows Autoupdate Disabled Policy:

    ============================

    Windows Defender:

    ==============

    WinDefend Service is not running. Checking service configuration:

    The start type of WinDefend service is set to Demand. The default start type is Auto.

    The ImagePath of WinDefend service is OK.

    The ServiceDll of WinDefend service is OK.

    File Check:

    ========

    C:\Windows\system32\nsisvc.dll => MD5 is legit

    C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit

    C:\Windows\system32\dhcpcsvc.dll

    [2008-05-21 16:29] - [2008-01-19 03:34] - 0204288 ____A (Microsoft Corporation) 43A988A9C10333476CB5FB667CBD629D

    C:\Windows\system32\Drivers\afd.sys

    [2012-03-12 11:10] - [2011-04-21 09:16] - 0273408 ____A (Microsoft Corporation) 48EB99503533C27AC6135648E5474457

    C:\Windows\system32\Drivers\tdx.sys => MD5 is legit

    C:\Windows\system32\Drivers\tcpip.sys

    [2012-03-12 11:07] - [2010-06-16 11:55] - 0902032 ____A (Microsoft Corporation) 6216A954ED7045B62880A92D6C9B9FC7

    C:\Windows\system32\dnsrslvr.dll

    [2012-03-12 11:10] - [2011-03-02 10:49] - 0086528 ____A (Microsoft Corporation) 4805D9A6D281C7A7DEFD9094DEC6AF7D

    C:\Windows\system32\mpssvc.dll

    [2008-05-21 16:30] - [2008-01-19 03:34] - 0393216 ____A (Microsoft Corporation) D1639BA315B0D79DEC49A4B0E1FB929B

    C:\Windows\system32\bfe.dll

    [2012-03-12 11:07] - [2010-06-16 11:09] - 0328704 ____A (Microsoft Corporation) D3E6D78285529962349A7F1617035938

    C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit

    C:\Windows\system32\SDRSVC.dll => MD5 is legit

    C:\Windows\system32\vssvc.exe

    [2008-05-21 16:30] - [2008-01-19 03:33] - 1054720 ____A (Microsoft Corporation) D5FB73D19C46ADE183F968E13F186B23

    C:\Windows\system32\wscsvc.dll

    [2008-05-21 16:29] - [2008-01-19 03:37] - 0061440 ____A (Microsoft Corporation) 683DD16B590372F2C9661D277F35E49C

    C:\Windows\system32\wbem\WMIsvc.dll

    [2008-05-21 16:29] - [2008-01-19 03:36] - 0161792 ____A (Microsoft Corporation) 00B79A7C984678F24CF052E5BEB3A2F5

    C:\Windows\system32\wuaueng.dll => MD5 is legit

    C:\Windows\system32\qmgr.dll

    [2008-05-21 16:30] - [2008-01-19 03:36] - 0758272 ____A (Microsoft Corporation) 02ED7B4DBC2A3232A389106DA7515C3D

    C:\Windows\system32\es.dll

    [2008-08-14 15:41] - [2008-04-18 01:48] - 0269312 ____A (Microsoft Corporation) 3CB3343D720168B575133A0A20DC2465

    C:\Windows\system32\cryptsvc.dll

    [2008-05-21 16:28] - [2008-01-19 03:34] - 0128000 ____A (Microsoft Corporation) 6DE363F9F99334514C46AEC02D3E3678

    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit

    C:\Windows\system32\svchost.exe => MD5 is legit

    C:\Windows\system32\rpcss.dll

    [2009-08-15 15:48] - [2009-03-03 00:39] - 0551424 ____A (Microsoft Corporation) 301AE00E12408650BADDC04DBC832830

    **** End of log ****

    HijackThis log

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 3:28:02 AM, on 6/12/2012

    Platform: Windows Vista SP1 (WinNT 6.00.1905)

    MSIE: Internet Explorer v7.00 (7.00.6001.18639)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Logitech\SetPoint\KEM.exe

    C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe

    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

    C:\Windows\System32\mobsync.exe

    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE

    C:\Windows\RtHDVCpl.exe

    C:\Windows\System32\rundll32.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    C:\Windows\System32\SysMonitor.exe

    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe

    C:\Windows\System32\rundll32.exe

    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac

    C:\Windows\ehome\ehtray.exe

    C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe

    C:\Program Files\Skype\Phone\Skype.exe

    C:\Program Files\Windows Sidebar\sidebar.exe

    C:\Windows\ehome\ehmsas.exe

    C:\Windows\system32\wbem\unsecapp.exe

    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE

    C:\Windows\system32\taskmgr.exe

    \MAINPC\Users\Public\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.100:80

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O1 - Hosts: ::1 localhost

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [setPoint] C:\Program Files\Logitech\SetPoint\KEM.EXE

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe -s

    O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

    O4 - HKLM\..\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

    O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

    O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup

    O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Windows\system32\SysMonitor.exe

    O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe

    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"

    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

    O4 - HKCU\..\Run: [Djykh] rundll32 "C:\Users\josh\AppData\Roaming\rasmanp.dll",NOEHO

    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"

    O4 - HKCU\..\Run: [speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup

    O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun

    O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

    O4 - Global Startup: Empowering Technology Launcher.lnk = ?

    O4 - Global Startup: hpoddt01.exe.lnk = ?

    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll

    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O13 - Gopher Prefix:

    O16 - DPF: Cab1 - https://registration.rr.com/RegHelper.cab

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab

    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{1C2B8C46-71C8-4D3F-BF01-803E1143AC2B}: NameServer = 8.8.8.8,192.168.1.1

    O17 - HKLM\System\CS1\Services\Tcpip\..\{1C2B8C46-71C8-4D3F-BF01-803E1143AC2B}: NameServer = 8.8.8.8,192.168.1.1

    O17 - HKLM\System\CS2\Services\Tcpip\..\{1C2B8C46-71C8-4D3F-BF01-803E1143AC2B}: NameServer = 8.8.8.8,192.168.1.1

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE

    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

    O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)

    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

    --

    End of file - 10369 bytes

    Thanks for any and all assistance!

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.