PDA

View Full Version : problems with vista help required



mjd59
2012-12-07, 22:00
i am coming across greyboxs not letting me update security or vist certain web pages . think redirect browser an maybe running older version , possable malware ??? help .

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 7.0.6000.16982
Run by fido at 7:27:18 on 2012-12-08
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.1.1033.18.3316.1946 [GMT -8:00]
.
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\AMT\atchk.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_5_502_110_ActiveX.exe
C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\System32\svchost.exe -k wdisvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [atchk] "c:\program files\intel\amt\atchk.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
StartupFolder: c:\users\fido\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.11.0.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{47B72BCD-B410-4D07-8519-46E98618273F} : DHCPNameServer = 192.168.0.1
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-12-8 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-12-8 1369624]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2012-12-8 168384]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2012-12-7 2521880]
.
=============== Created Last 30 ================
.
2012-12-08 13:48:19 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-12-08 13:48:11 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-12-08 13:48:04 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-12-08 11:03:57 268800 ----a-w- c:\windows\system32\es.dll
2012-12-08 10:27:31 229888 ----a-w- c:\windows\system32\msshsq.dll
2012-12-08 10:17:52 -------- d-----w- c:\users\fido\appdata\local\Deployment
2012-12-08 10:17:52 -------- d-----w- c:\users\fido\appdata\local\Apps
2012-12-08 10:01:18 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{bb5b9871-8949-47fa-9e4a-941a7d8098d2}\mpengine.dll
2012-12-08 08:47:41 -------- d-----w- c:\users\fido\New Folder
2012-12-08 08:27:34 -------- d-----w- c:\windows\pss
2012-12-08 08:10:02 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-12-08 08:02:19 -------- d-----w- c:\program files\Microsoft Security Client
2012-12-08 07:47:47 96760 ----a-w- c:\windows\system32\dfshim.dll
2012-12-08 07:47:43 41984 ----a-w- c:\windows\system32\netfxperf.dll
2012-12-08 07:47:41 83968 ----a-w- c:\windows\system32\mscories.dll
2012-12-08 07:47:41 282112 ----a-w- c:\windows\system32\mscoree.dll
2012-12-08 07:47:41 158720 ----a-w- c:\windows\system32\mscorier.dll
2012-12-08 07:30:50 -------- d-----w- c:\program files\SystemRequirementsLab
2012-12-08 07:26:11 -------- d-----w- c:\program files\GUMDA57.tmp
2012-12-08 07:25:05 -------- d-----w- c:\users\fido\appdata\local\Google
2012-12-08 07:24:45 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-08 07:24:45 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-07 16:10:53 72704 ----a-w- c:\windows\system32\fontsub.dll
2012-12-07 16:10:53 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-07 16:10:53 289792 ----a-w- c:\windows\system32\atmfd.dll
2012-12-07 16:10:53 24064 ----a-w- c:\windows\system32\lpk.dll
2012-12-07 16:10:53 156672 ----a-w- c:\windows\system32\t2embed.dll
2012-12-07 16:10:53 10240 ----a-w- c:\windows\system32\dciman32.dll
2012-12-07 16:08:13 61440 ----a-w- c:\windows\system32\winipsec.dll
2012-12-07 16:08:13 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2012-12-07 16:08:13 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2012-12-07 16:08:13 272896 ----a-w- c:\windows\system32\polstore.dll
2012-12-07 16:06:57 84992 ----a-w- c:\windows\system32\drivers\srvnet.sys
2012-12-07 16:06:56 306688 ----a-w- c:\windows\system32\drivers\srv.sys
2012-12-07 16:06:20 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2012-12-07 16:06:20 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2012-12-07 16:06:20 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2012-12-07 16:05:45 87040 ----a-w- c:\windows\system32\msoert2.dll
2012-12-07 16:05:45 707072 ----a-w- c:\program files\common files\system\wab32.dll
2012-12-07 16:05:45 41984 ----a-w- c:\program files\windows mail\wabimp.dll
2012-12-07 16:05:45 39424 ----a-w- c:\windows\system32\ACCTRES.dll
2012-12-07 16:05:45 205824 ----a-w- c:\windows\system32\msoeacct.dll
2012-12-07 16:05:45 1098752 ----a-w- c:\program files\common files\system\wab32res.dll
2012-12-07 16:05:44 2836992 ----a-w- c:\program files\windows mail\MSOERES.dll
2012-12-07 16:05:44 1614848 ----a-w- c:\program files\windows mail\msoe.dll
2012-12-07 16:05:42 397312 ----a-w- c:\program files\windows mail\WinMail.exe
2012-12-07 16:05:41 81408 ----a-w- c:\program files\windows mail\oeimport.dll
2012-12-07 16:05:41 24064 ----a-w- c:\program files\common files\system\DirectDB.dll
2012-12-07 16:04:50 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2012-12-07 16:04:50 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2012-12-07 16:04:50 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2012-12-07 16:04:50 19968 ----a-w- c:\windows\system32\ARP.EXE
2012-12-07 16:04:50 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2012-12-07 16:04:50 15360 ----a-w- c:\windows\system32\netevent.dll
2012-12-07 16:04:50 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2012-12-07 16:04:50 103936 ----a-w- c:\windows\system32\netiohlp.dll
2012-12-07 16:04:50 10240 ----a-w- c:\windows\system32\finger.exe
2012-12-07 16:03:55 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
2012-12-07 16:03:55 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
2012-12-07 16:03:54 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
2012-12-07 16:03:54 24064 ----a-w- c:\windows\system32\wtsapi32.dll
2012-12-07 16:03:52 542720 ----a-w- c:\windows\system32\sysmain.dll
2012-12-07 16:03:20 194560 ----a-w- c:\windows\system32\WebClnt.dll
2012-12-07 16:03:20 110080 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2012-12-07 16:02:47 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2012-12-07 16:02:46 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2012-12-07 16:02:46 502272 ----a-w- c:\windows\system32\wlansvc.dll
2012-12-07 16:02:46 47104 ----a-w- c:\windows\system32\wlanapi.dll
2012-12-07 16:02:46 297984 ----a-w- c:\windows\system32\wlansec.dll
2012-12-07 16:02:46 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2012-12-07 16:02:04 2048 ----a-w- c:\windows\system32\msxml6r.dll
2012-12-07 16:02:04 2048 ----a-w- c:\windows\system32\msxml3r.dll
2012-12-07 16:02:04 1406464 ----a-w- c:\windows\system32\msxml6.dll
2012-12-07 16:02:04 1260032 ----a-w- c:\windows\system32\msxml3.dll
2012-12-07 16:01:21 997912 ----a-w- c:\windows\system32\igxpun.exe
2012-12-07 16:01:21 -------- d-----w- c:\windows\system32\x64
2012-12-07 16:00:39 216576 ----a-w- c:\windows\system32\msv1_0.dll
2012-12-07 16:00:02 58368 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2012-12-07 16:00:02 211968 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-12-07 16:00:02 102400 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-12-07 15:59:32 49664 ----a-w- c:\windows\system32\csrsrv.dll
2012-12-07 15:59:31 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-12-07 15:58:59 98816 ----a-w- c:\windows\system32\mfps.dll
2012-12-07 15:58:59 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2012-12-07 15:58:59 2855424 ----a-w- c:\windows\system32\mf.dll
2012-12-07 15:58:59 24576 ----a-w- c:\windows\system32\mfpmp.exe
2012-12-07 15:58:59 2048 ----a-w- c:\windows\system32\mferror.dll
2012-12-07 15:58:18 3502480 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-12-07 15:58:18 3468168 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-12-07 15:56:45 376832 ----a-w- c:\windows\system32\winhttp.dll
2012-12-07 15:56:11 434176 ----a-w- c:\windows\system32\vbscript.dll
2012-12-07 15:55:36 71680 ----a-w- c:\windows\system32\atl.dll
2012-12-07 15:54:34 297472 ----a-w- c:\windows\system32\gdi32.dll
2012-12-07 15:54:04 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2012-12-07 15:54:04 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-12-07 15:52:05 374456 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2012-12-07 15:51:38 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2012-12-07 15:51:38 30208 ----a-w- c:\windows\system32\xolehlp.dll
2012-12-07 15:51:06 156160 ----a-w- c:\windows\system32\wkssvc.dll
2012-12-07 15:50:31 116736 ----a-w- c:\windows\system32\aaclient.dll
2012-12-07 15:50:30 36352 ----a-w- c:\windows\system32\tsgqec.dll
2012-12-07 15:50:30 1871872 ----a-w- c:\windows\system32\mstscax.dll
2012-12-07 15:49:55 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2012-12-07 15:48:54 414208 ----a-w- c:\windows\system32\msscp.dll
2012-12-07 15:47:43 713728 ----a-w- c:\windows\system32\timedate.cpl
2012-12-07 15:47:10 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
2012-12-07 15:46:41 86016 ----a-w- c:\windows\system32\icfupgd.dll
2012-12-07 15:46:41 63488 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2012-12-07 15:46:41 61952 ----a-w- c:\windows\system32\cmifw.dll
2012-12-07 15:46:41 396800 ----a-w- c:\windows\system32\MPSSVC.dll
2012-12-07 15:46:41 392192 ----a-w- c:\windows\system32\FirewallAPI.dll
2012-12-07 15:46:41 16896 ----a-w- c:\windows\system32\wfapigp.dll
2012-12-07 15:45:41 23040 ----a-w- c:\program files\movie maker\WMM2EXT.dll
2012-12-07 15:45:41 150016 ----a-w- c:\program files\movie maker\MOVIEMK.exe
2012-12-07 15:45:41 10922496 ----a-w- c:\program files\movie maker\MOVIEMK.dll
2012-12-07 15:45:40 195072 ----a-w- c:\program files\movie maker\WMM2AE.dll
2012-12-07 15:43:14 2048 ----a-w- c:\windows\system32\tzres.dll
2012-12-07 15:42:34 696832 ----a-w- c:\windows\system32\localspl.dll
2012-12-07 15:42:06 21560 ----a-w- c:\windows\system32\drivers\atapi.sys
2012-12-07 15:42:05 45112 ----a-w- c:\windows\system32\drivers\pciidex.sys
2012-12-07 15:42:05 211000 ----a-w- c:\windows\system32\drivers\volsnap.sys
2012-12-07 15:42:05 15928 ----a-w- c:\windows\system32\drivers\pciide.sys
2012-12-07 15:42:05 154624 ----a-w- c:\windows\system32\drivers\nwifi.sys
2012-12-07 15:42:05 109624 ----a-w- c:\windows\system32\drivers\ataport.sys
2012-12-07 15:41:43 104448 ----a-w- c:\windows\system32\DWWIN.EXE
2012-12-07 15:41:19 2923520 ----a-w- c:\windows\explorer.exe
2012-12-07 15:40:24 171520 ----a-w- c:\windows\system32\wintrust.dll
2012-12-07 15:39:51 7680 ----a-w- c:\windows\system32\lsass.exe
2012-12-07 15:39:51 72704 ----a-w- c:\windows\system32\secur32.dll
2012-12-07 15:39:51 494592 ----a-w- c:\windows\system32\kerberos.dll
2012-12-07 15:39:51 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-12-07 15:39:51 175104 ----a-w- c:\windows\system32\wdigest.dll
2012-12-07 15:39:51 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2012-12-07 15:39:50 272384 ----a-w- c:\windows\system32\schannel.dll
2012-12-07 15:39:22 24064 ----a-w- c:\windows\system32\netcfg.exe
2012-12-07 15:35:40 1585664 ----a-w- c:\windows\system32\setupapi.dll
2012-12-07 15:34:18 549888 ----a-w- c:\windows\system32\rpcss.dll
2012-12-07 15:34:17 654336 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2012-12-07 15:34:17 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2012-12-07 15:34:17 501760 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2012-12-07 15:34:17 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2012-12-07 15:34:17 24576 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2012-12-07 15:34:17 130560 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2012-12-07 15:34:16 97280 ----a-w- c:\windows\system32\iasrecst.dll
2012-12-07 15:34:16 53248 ----a-w- c:\windows\system32\iasads.dll
2012-12-07 15:34:16 37888 ----a-w- c:\windows\system32\iasdatastore.dll
2012-12-07 15:34:16 158720 ----a-w- c:\windows\system32\sdohlp.dll
2012-12-07 15:33:46 62464 ----a-w- c:\windows\system32\l3codeca.acm
2012-12-07 15:33:46 220672 ----a-w- c:\windows\system32\l3codecp.acm
2012-12-07 15:32:51 815104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-12-07 15:32:51 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2012-12-07 15:32:51 22016 ----a-w- c:\windows\system32\netiougc.exe
2012-12-07 15:32:51 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2012-12-07 15:32:51 179712 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-12-07 15:32:51 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2012-12-07 15:32:51 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2012-12-07 15:32:08 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2012-12-07 15:31:46 9728 ----a-w- c:\windows\system32\LAPRXY.DLL
2012-12-07 15:31:46 223232 ----a-w- c:\windows\system32\WMASF.DLL
2012-12-07 15:31:46 2048 ----a-w- c:\windows\system32\asferror.dll
2012-12-07 15:31:25 25600 ----a-w- c:\windows\system32\amxread.dll
2012-12-07 15:31:24 14848 ----a-w- c:\windows\system32\apilogen.dll
2012-12-07 15:30:56 33280 ----a-w- c:\windows\system32\slwmi.dll
2012-12-07 15:30:56 268288 ----a-w- c:\windows\system32\mcbuilder.exe
2012-12-07 15:30:56 223232 ----a-w- c:\windows\system32\SLC.dll
2012-12-07 15:30:55 57856 ----a-w- c:\windows\system32\SLUINotify.dll
2012-12-07 15:30:55 566784 ----a-w- c:\windows\system32\SLCommDlg.dll
2012-12-07 15:30:55 39936 ----a-w- c:\windows\system32\slcinst.dll
2012-12-07 15:30:55 351232 ----a-w- c:\windows\system32\SLUI.exe
2012-12-07 15:30:55 2605568 ----a-w- c:\windows\system32\SLsvc.exe
2012-12-07 15:30:55 186368 ----a-w- c:\windows\system32\SLLUA.exe
2012-12-07 15:30:27 712192 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-12-07 15:30:27 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-12-07 15:30:26 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-12-07 15:29:56 97792 ----a-w- c:\windows\system32\cabview.dll
2012-12-07 15:29:06 320000 ----a-w- c:\windows\system32\drivers\csc.sys
2012-12-07 15:29:06 105984 ----a-w- c:\windows\system32\CscMig.dll
2012-12-07 15:29:03 61440 ----a-w- c:\windows\system32\ntprint.exe
2012-12-07 15:29:03 220160 ----a-w- c:\windows\system32\ntprint.dll
2012-12-07 15:29:02 1984512 ----a-w- c:\windows\system32\authui.dll
2012-12-07 15:29:02 120320 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-12-07 15:29:02 10240 ----a-w- c:\windows\system32\dhcpcmonitor.dll
2012-12-07 15:29:01 8138240 ----a-w- c:\windows\system32\ssBranded.scr
2012-12-07 15:29:01 69632 ----a-w- c:\windows\system32\sendmail.dll
2012-12-07 15:28:16 441856 ----a-w- c:\windows\system32\win32spl.dll
2012-12-07 15:28:16 37376 ----a-w- c:\windows\system32\printcom.dll
2012-12-07 15:27:54 2031104 ----a-w- c:\windows\system32\win32k.sys
2012-12-07 15:27:33 14848 ----a-w- c:\windows\system32\wshrm.dll
2012-12-07 15:27:33 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2012-12-07 15:27:22 2565432 ---ha-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2012-12-07 15:27:16 6812136 ---ha-w- c:\programdata\microsoft\windows defender\definition updates\{d6b8f43e-ebcc-4c70-854f-aaa24a31a9f8}\mpengine.dll
2012-12-07 15:27:15 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-12-07 15:26:50 43520 ----a-w- c:\windows\system32\msdxm.tlb
2012-12-07 15:26:50 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2012-12-07 15:26:50 18432 ----a-w- c:\windows\system32\amcompat.tlb
2012-12-07 15:26:14 435712 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2012-12-07 15:26:14 431104 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2012-12-07 15:26:14 312320 ----a-w- c:\windows\system32\msdrm.dll
2012-12-07 15:26:14 154624 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2012-12-07 15:26:14 154112 ----a-w- c:\windows\system32\secproc_ssp.dll
2012-12-07 15:26:13 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2012-12-07 15:26:13 515584 ----a-w- c:\windows\system32\RMActivate.exe
2012-12-07 15:26:13 473088 ----a-w- c:\windows\system32\secproc_isv.dll
2012-12-07 15:26:13 472576 ----a-w- c:\windows\system32\secproc.dll
2012-12-07 15:25:51 66048 ----a-w- c:\program files\windows sidebar\sbdrop.dll
2012-12-07 15:25:51 1232896 ----a-w- c:\program files\windows sidebar\sidebar.exe
2012-12-07 15:25:51 11776 ----a-w- c:\windows\system32\sbunattend.exe
2012-12-07 15:25:27 83968 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-12-07 15:25:27 24576 ----a-w- c:\windows\system32\dnscacheugc.exe
2012-12-07 15:25:19 53760 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2012-12-07 15:24:37 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2012-12-07 15:24:36 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2012-12-07 15:24:35 1686528 ----a-w- c:\windows\system32\gameux.dll
2012-12-07 15:23:58 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2012-12-07 15:23:58 94720 ----a-w- c:\windows\system32\logagent.exe
2012-12-07 15:23:25 765952 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2012-12-07 15:23:12 84480 ----a-w- c:\windows\system32\INETRES.dll
2012-12-07 15:23:12 737792 ----a-w- c:\windows\system32\inetcomm.dll
2012-12-07 15:22:49 60928 ----a-w- c:\windows\system32\msasn1.dll
2012-12-07 15:22:29 1645568 ----a-w- c:\windows\system32\connect.dll
2012-12-07 15:22:13 5120 ----a-w- c:\windows\system32\wmi.dll
2012-12-07 15:22:13 152576 ----a-w- c:\windows\system32\imagehlp.dll
2012-12-07 15:22:13 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-12-07 15:21:56 788992 ----a-w- c:\windows\system32\rpcrt4.dll
2012-12-07 15:21:17 396800 ----a-w- c:\windows\system32\drivers\http.sys
2012-12-07 15:21:17 31232 ----a-w- c:\windows\system32\httpapi.dll
2012-12-07 15:21:17 24064 ----a-w- c:\windows\system32\nshhttp.dll
2012-12-07 15:19:51 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-12-07 15:19:39 974336 ----a-w- c:\windows\system32\crypt32.dll
2012-12-07 15:19:28 274432 ----a-w- c:\windows\system32\raschap.dll
2012-12-07 15:19:28 232960 ----a-w- c:\windows\system32\rastls.dll
2012-12-07 15:19:10 321536 ----a-w- c:\windows\system32\WSDApi.dll
2012-12-07 15:17:48 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2012-12-07 15:17:24 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2012-12-07 15:17:24 7680 ----a-w- c:\windows\system32\spwmp.dll
2012-12-07 15:17:23 4096 ----a-w- c:\windows\system32\msdxm.ocx
2012-12-07 15:17:23 4096 ----a-w- c:\windows\system32\dxmasf.dll
2012-12-07 15:17:23 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2012-12-07 15:17:23 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2012-12-07 15:17:23 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2012-12-07 15:17:21 311296 ----a-w- c:\windows\system32\unregmp2.exe
2012-12-07 15:17:21 1418240 ----a-w- c:\program files\windows media player\setup_wm.exe
2012-12-07 14:07:22 920344 ----a-w- c:\windows\system32\mesoludlg.exe
2012-12-07 14:07:22 319456 ----a-w- c:\windows\system32\difxapi.dll
2012-12-07 14:07:22 -------- d-----w- c:\windows\system32\Lang
2012-12-07 14:07:22 -------- d-----w- c:\program files\common files\postureAgent
2012-12-07 14:05:43 39288 ----a-w- c:\windows\system32\NicInE6.dll
2012-12-07 14:05:42 28536 ----a-w- c:\windows\system32\NicCo6.dll
2012-12-07 14:05:42 228224 ----a-w- c:\windows\system32\drivers\e1e6032.sys
2012-12-07 14:05:40 179048 ----a-w- c:\windows\system32\e1000msg.dll
2012-12-07 14:05:40 154496 ----a-w- c:\windows\system32\Prounstl.exe
2012-12-07 14:03:08 -------- d-----w- c:\windows\system32\vmm32
2012-12-07 14:03:08 -------- d-----w- c:\program files\Dell
2012-12-07 14:00:58 -------- d-sh--w- c:\windows\Installer
2012-12-07 13:58:01 -------- d-----w- c:\users\fido\appdata\local\VirtualStore
2012-12-07 13:43:45 -------- d-----w- c:\windows\Panther
2012-12-07 13:43:09 -------- d-----w- c:\windows\system32\OEM
2012-12-07 13:30:22 -------- d-----w- C:\Windows.old
2012-12-07 03:55:40 -------- d-----w- C:\DellMPv3.1.1
2012-12-07 02:42:34 -------- d-----w- C:\temp
2012-12-07 01:06:19 -------- d-----w- C:\PerfLogs
2012-12-06 13:34:19 -------- d-----w- C:\inetpub
2012-12-06 01:15:11 -------- d-----w- C:\Intel
2012-12-06 01:12:09 -------- d-----w- C:\dell
2012-12-06 00:14:07 -------- d-sh--w- C:\Boot
.
==================== Find3M ====================
.
2012-12-07 16:09:46 72704 ----a-w- c:\windows\system32\admparse.dll
2012-12-07 16:09:45 832512 ----a-w- c:\windows\system32\wininet.dll
2012-12-07 16:09:45 52736 ----a-w- c:\windows\apppatch\iebrshim.dll
2012-12-07 16:09:42 389120 ----a-w- c:\windows\system32\html.iec
2012-12-07 16:09:41 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-12-07 16:09:41 48128 ----a-w- c:\windows\system32\mshtmler.dll
2012-12-07 16:09:40 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2012-12-07 16:09:38 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-07 16:09:37 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2012-12-07 16:09:35 56320 ----a-w- c:\windows\system32\iesetup.dll
2012-12-07 15:38:53 1808896 ----a-w- c:\windows\system32\NlsLexicons0046.dll
2012-12-07 15:35:25 5632 ----a-w- c:\windows\system32\drivers\en-us\sermouse.sys.mui
2012-12-07 15:31:25 40960 ----a-w- c:\windows\apppatch\apihex86.dll
2012-12-07 15:24:37 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2012-12-07 15:24:37 2143744 ----a-w- c:\windows\apppatch\AcGenral.dll
2012-12-07 15:24:36 537600 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-12-07 15:24:36 449024 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2012-12-07 15:24:36 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
.
============= FINISH: 7:27:32.13 ===============



aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-12-08 07:30:11
-----------------------------
07:30:11.003 OS Version: Windows 6.0.6000
07:30:11.003 Number of processors: 2 586 0xF0B
07:30:11.003 ComputerName: FIDO-PC UserName: fido
07:30:11.877 Initialize success
07:33:47.516 AVAST engine defs: 12120700
07:43:00.645 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
07:43:00.660 Disk 0 Vendor: ST380815AS 4.ADA Size: 76293MB BusType: 3
07:43:00.676 Disk 0 MBR read successfully
07:43:00.676 Disk 0 MBR scan
07:43:00.676 Disk 0 Windows VISTA default MBR code
07:43:00.692 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76291 MB offset 2048
07:43:00.707 Disk 0 scanning sectors +156246016
07:43:00.785 Disk 0 scanning C:\Windows\system32\drivers
07:43:11.846 Service scanning
07:43:21.798 Service MpKsl6041ee77 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BB5B9871-8949-47FA-9E4A-941A7D8098D2}\MpKsl6041ee77.sys **LOCKED** 32
07:43:37.554 Modules scanning
07:43:44.138 Disk 0 trace - called modules:
07:43:44.169 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll pciide.sys PCIIDEX.SYS atapi.sys
07:43:44.184 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84df1ad8]
07:43:44.184 3 ntkrnlpa.exe[818b07e2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x848a48b8]
07:43:44.684 AVAST engine scan C:\Windows
07:43:46.478 AVAST engine scan C:\Windows\system32
07:46:18.968 AVAST engine scan C:\Windows\system32\drivers
07:46:33.600 AVAST engine scan C:\Users\fido
07:47:03.406 AVAST engine scan C:\ProgramData
07:47:14.794 Scan finished successfully
07:47:15.200 Disk 0 MBR has been saved successfully to "C:\Users\fido\Documents\dds\MBR.dat"
07:47:15.216 The log file has been saved successfully to "C:\Users\fido\Documents\dds\aswMBR.txt"
07:47:27.134 Disk 0 MBR has been saved successfully to "C:\Users\fido\Desktop\MBR.dat"
07:47:27.134 The log file has been saved successfully to "C:\Users\fido\Desktop\aswMBR.txt"

shelf life
2012-12-12, 23:51
hi mjd59,

Your post is a few days old. If you still need help simply reply back.

mjd59
2012-12-13, 22:45
sorry i have being off line for a few days .

shelf life
2012-12-14, 01:39
ok. We will get two downloads to run. The first is called tdsskiller, the second is combofix.

Please download tdsskiller to your desktop:
TDSSkiller. exe (http://support.kaspersky.com/downloads/utils/tdsskiller.exe)

Right Click the icon and select "run as admin" then click on Change Parameters. Check the option: Detect TDLFS file system, then click ok and Start Scan

Once the scan is done you will find a .txt file in your root drive Local Disk, usually (C) labeled as: TDSSKILLER.2.8.13.0_15.10.2012_17.34.06_log.txt (version,date time) Please post the log.

Combofix requires you read a short guide first before downloading. Read through the guide then apply the directions on your own machine.

The guide and links are here. (http://www.bleepingcomputer.com/combofix/how-to-use-combofix)

Please copy/paste the log file in your reply.

mjd59
2012-12-14, 21:41
here are the logs ,hope they are what you requested

shelf life
2012-12-14, 22:41
Not much there to worry about. I would update IE. This may solve some web page problems. Have you been to Windows Updates recently or is your machine set up for auto updating Windows?

You should be running the latest IE for Vista which I think is IE 9.0
Are you a admin account on the machine?

mjd59
2012-12-16, 18:44
yes i am the only user ,which is an admin account operated under U.A.C. I am having problems updating .NET Framework 3.5 vista S.P.1 along with microsoft security essentails. I hope my S&D updates are installing the program says all is well . I have tryed updating I.E. but cannot seem to install the latest edition . I do not know if it is a configaration issue or if as i suspected a viral or hacker issue as i have had numerous issues with my network connection . before i did a clean vista reimage i could not configure some areas of the network . and when reviewing recent items on the start screen i was finding programs had been run in media player .I had a feeling that my internet connection was being controlled by outside influences when i reported this to my I.S.P they tried to isolate the modem over a 12 hour period only to inform me that they could not connect to my modem ,and that i must have turned off the power . If you think i have no issues with maleware may i thank you for your time , you guys do a wonderfull job ,and hope i will not be needing your services in the near future
thanks
mick

shelf life
2012-12-16, 22:44
Since you are having problems with MS Security Essentials I would uninstall it via the add/remove programs panel then download another application, there are several others that have free versions. If its not updating then it will soon be worthless and may even have other issues also. I would get a functional AV app on your machine.
I can provide links to other free AV.
I dont recognize any malware in the logs you posted. Another antimalware you may want to install is Malwarebytes. Also a free version. (http://www.malwarebytes.org/products/malwarebytes_free/)

You can also attempt a online scan with Eset. I say attempt because of your IE version, may work ok.

ESET online scanner:
Eset. (http://www.eset.com/onlinescan/)

Use Internet Explorer
check "YES" to accept terms
click start button
allow the ActiveX component to install
click the start button. the Scanner will update.
check both "Remove found threats" and "Scan archives" Leave the defaults checked under Advanced settings
click scan. When it completes click "List found threats"
click "Export to text file.." and save it to your desktop. Post the saved log.
Click "back" and "finish"

A good source (http://www.chicagotech.net/vista/vistaconnection.htm) for Vista connectivity issues.

mjd59
2012-12-17, 11:37
eset found this
C:\Users\fido\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7FUG9HVX\VideoDownloadConvert[1].exe Win32/AdInstaller application cleaned by deleting - quarantined


i will keep trying to update I.E. any more trouble i will submit a new help ticket.

again thanks for your help .

shelf life
2012-12-18, 02:37
Thats not much of a find. Are you trying to update IE via Windows Update?
Try this Link. (http://windows.microsoft.com/en-US/internet-explorer/downloads/ie-9/worldwide-languages)