This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]Would Love To "heal" My Computer, Need Help

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hey, i've been having some issues with my computer for awhile. There's certain files like NTUSER that i can't delete, among others. Some files replicate themselves after i delete them. I think i've been hijacked.

i once had a 'problem' disguised as system32, and i think i have that on this computer too, but am scared to delete the wrong thing….

Really slow startup times, slow processing, and frequent freezes, ect…

and i repeatedly have to repair registry problems. I scan for spyware (adAware, spybot, ect…) but it doesn't seem to 'fix' much.

I hope someone can translate this for me, so i can make my computer well again. I definately canot afford a new one….

_william chorm

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~

here's the hijackthis logfile….


Logfile of HijackThis v1.99.1
Scan saved at 1:04:31 PM, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\scvhost32.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\compaq\Desktop\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SVCHost Protocol32] scvhost32.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\RunServices: [SVCHost Protocol32] scvhost32.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Unknown owner - C:\Program Files\HPQ\SHARED\HPQWMI.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~

and here's the startup list….



StartupList report, 7/15/2007, 1:10:00 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\compaq\Desktop\Temp\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\scvhost32.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\compaq\Desktop\Temp\HijackThis.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SmcService = C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
IntelliPoint = "C:\Program Files\Microsoft IntelliPoint\point32.exe"
IgfxTray = C:\WINDOWS\system32\igfxtray.exe
AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
SVCHost Protocol32 = scvhost32.exe
SpywareTerminator = "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
NeroFilterCheck = C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
SsAAD.exe = C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

SVCHost Protocol32 = scvhost32.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} = "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
BitTorrent = "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
SITEguard BHO - C:\Program Files\STOPzilla!\SZSG.dll - {1827766B-9F49-4854-8034-F6EE26FCB1EC}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - (no file) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}
(no name) - C:\Program Files\STOPzilla!\SZIEBHO.dll - {E3215F20-3212-11D6-9F8B-00D0B743919D}

————————————————–

Enumerating Task Scheduler jobs:

Symantec NetDetect.job
Uniblue SpeedUpMyPC Nag.job
Uniblue SpeedUpMyPC.job
Uniblue SpyEraser Nag.job
Uniblue SpyEraser.job

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

————————————————–
End of report, 5,654 bytes
Report generated in 0.297 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hello ichorm and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem.


A. Please rename the Temp folder on your desk to HJT


B. Please download this file - combofix.exe by sUBs
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
hey Trevruen,

i appreciate this….

here's the log from combofix…

~~~~~~~~~~~~~~~~~~~~~~

"compaq" - 2007-07-15 17:14:16 - ComboFix 07-07-16.4 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\hosts


((((((((((((((((((((((((( Files Created from 2007-06-16 to 2007-07-16 )))))))))))))))))))))))))))))))


2007-07-15 17:13 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-15 13:50 63 –a—— C:\WINDOWS\system\SysSD.dll
2007-07-15 13:48 1,044,480 –a—— C:\WINDOWS\system32\VchReg.dll
2007-07-15 13:48 d——– C:\Program Files\SpywareDetector
2007-07-15 13:39 d——– C:cc31c23a562bfe8b64dd523e7
2007-07-15 12:59 218,112 –a—— C:\Temp\HijackThis.exe
2007-07-13 22:14 3,030 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2007-07-13 17:11 d——– C:\Program Files\Common Files\xing shared
2007-07-13 16:43 3,590 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2007-07-10 19:16 13,015 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2007-07-10 19:12 2,951 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2007-07-08 21:32 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Ahead
2007-07-05 23:11 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-05 23:11 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-05 23:11 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-06-16 09:31 d——– C:\stuff


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-15 21:22:28 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Azureus
2007-07-15 20:01:01 ——– d—–w C:\Program Files\Microsoft Works
2007-07-15 18:02:32 ——– d—–w C:\Program Files\Spyware Terminator
2007-07-15 18:00:47 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Spyware Terminator
2007-07-14 05:14:21 685,944 —-a-w C:\WINDOWS\system32\SpoonUninstall.exe
2007-07-14 00:15:39 8,854 —-a-w C:\WINDOWS\mozver.dat
2007-07-14 00:13:34 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Real
2007-07-14 00:10:50 ——– d—–w C:\Program Files\Common Files\Real
2007-07-10 14:50:58 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\BitTorrent
2007-07-01 18:00:55 135,936 —-a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-06-24 05:23:42 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\uTorrent
2007-06-24 01:13:59 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Uniblue
2007-06-24 01:13:48 ——– d—–w C:\Program Files\Uniblue
2007-06-24 00:52:47 ——– d—–w C:\Program Files\Mozilla Thunderbird
2007-06-13 20:13:22 ——– d—–w C:\Program Files\Azureus
2007-06-11 05:31:49 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Ahead
2007-06-10 18:41:24 ——– d—–w C:\Program Files\Common Files\Ahead
2007-06-10 18:38:49 ——– d—–w C:\Program Files\Nero
2007-06-10 18:29:58 ——– d—–w C:\Program Files\Ahead
2007-06-10 18:20:05 ——– d—–w C:\Program Files\PowerISO
2007-06-08 07:25:31 ——– d—–w C:\Program Files\STOPzilla!
2007-06-08 05:29:48 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\.wyzo
2007-06-08 04:46:18 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\STOPzilla!
2007-06-08 03:13:09 ——– d—–w C:\Program Files\Common Files\iS3
2007-06-08 02:52:24 ——– d—–w C:\Program Files\uTorrent
2007-06-08 00:40:01 ——– d—–w C:\Program Files\BitTorrent
2007-06-06 07:27:28 217,088 —-a-r C:\WINDOWS\system32\SZBase5.dll
2007-06-05 17:22:08 ——– d—–w C:\Program Files\Audacity
2007-06-05 17:12:34 ——– d—–w C:\Program Files\DVD Shrink
2007-06-02 15:55:46 ——– d—–w C:\Program Files\Hewlett-Packard
2007-06-02 15:53:07 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-05-30 18:12:28 126,976 —-a-r C:\WINDOWS\system32\IS3HTUI5.dll
2007-05-30 18:12:20 294,912 —-a-r C:\WINDOWS\system32\IS3DBA5.dll
2007-05-30 18:11:28 372,736 —-a-r C:\WINDOWS\system32\IS3UI5.dll
2007-05-30 18:11:14 69,632 —-a-r C:\WINDOWS\system32\IS3Hks5.dll
2007-05-30 18:10:56 23,040 —-a-r C:\WINDOWS\system32\IS3XDat5.dll
2007-05-30 18:10:36 184,320 —-a-r C:\WINDOWS\system32\IS3Win325.dll
2007-05-30 18:10:16 94,208 —-a-r C:\WINDOWS\system32\IS3Inet5.dll
2007-05-30 18:10:02 90,112 —-a-r C:\WINDOWS\system32\IS3Svc5.dll
2007-05-30 18:09:36 626,688 —-a-r C:\WINDOWS\system32\IS3Base5.dll
2007-05-19 16:11:21 ——– d—–w C:\Program Files\Microsoft AntiSpyware
2004-08-04 12:00:00 73,728 –sha-w C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
2004-08-04 12:00:00 590,848 –sh–r C:\WINDOWS\system32\scvhost32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-11-03 14:17 54248 –a—— C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1827766B-9F49-4854-8034-F6EE26FCB1EC}]
2007-06-06 00:35 275904 -ra—— C:\Program Files\STOPzilla!\SZSG.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\PROGRA~1\SPYBOT~1\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E3215F20-3212-11D6-9F8B-00D0B743919D}]
2007-06-06 00:35 177600 -ra—— C:\Program Files\STOPzilla!\SZIEBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2003-05-15 16:41]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-05-14 09:09]
"AVG7_EMC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" [2007-06-26 18:09]
"SVCHost Protocol32"="scvhost32.exe" [2004-08-04 05:00 C:\WINDOWS\system32\scvhost32.exe]
"SpywareTerminator"="C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe" [2007-07-01 11:00]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-13 17:08]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-09-27 07:59]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-03-01 16:11]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"SVCHost Protocol32"=scvhost32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
C:\WINDOWS\system32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r


Contents of the 'Scheduled Tasks' folder
2005-07-07 16:38:50 C:\WINDOWS\tasks\Symantec NetDetect.job
2007-07-14 08:42:07 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
2007-06-24 00:40:35 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
2007-07-14 08:42:13 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
2007-06-24 01:25:41 C:\WINDOWS\tasks\Uniblue SpyEraser.job

**************************************************************************

catchme 0.3.1017 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-15 17:16:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000007d
"TracesSuccessful"=dword:00000062

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"AutoRestartShell"=dword:00000000

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-15 17:17:09
C:\ComboFix-quarantined-files.txt … 2007-07-15 17:17

— E O F —


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

and here's the newest hjt log

Logfile of HijackThis v1.99.1
Scan saved at 17:20, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\scvhost32.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SVCHost Protocol32] scvhost32.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\RunServices: [SVCHost Protocol32] scvhost32.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Unknown owner - C:\Program Files\HPQ\SHARED\HPQWMI.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~

i renamed the temp file to hjt, i just hope i renamed the right 'temp' file as i have a few.

cheers,

-Will
hey Trevruen,

i appreciate this….

here's the log from combofix…

~~~~~~~~~~~~~~~~~~~~~~

"compaq" - 2007-07-15 17:14:16 - ComboFix 07-07-16.4 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\hosts


((((((((((((((((((((((((( Files Created from 2007-06-16 to 2007-07-16 )))))))))))))))))))))))))))))))


2007-07-15 17:13 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-15 13:50 63 –a—— C:\WINDOWS\system\SysSD.dll
2007-07-15 13:48 1,044,480 –a—— C:\WINDOWS\system32\VchReg.dll
2007-07-15 13:48 d——– C:\Program Files\SpywareDetector
2007-07-15 13:39 d——– C:cc31c23a562bfe8b64dd523e7
2007-07-15 12:59 218,112 –a—— C:\Temp\HijackThis.exe
2007-07-13 22:14 3,030 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2007-07-13 17:11 d——– C:\Program Files\Common Files\xing shared
2007-07-13 16:43 3,590 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2007-07-10 19:16 13,015 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2007-07-10 19:12 2,951 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2007-07-08 21:32 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Ahead
2007-07-05 23:11 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-05 23:11 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-05 23:11 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-06-16 09:31 d——– C:\stuff


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-15 21:22:28 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Azureus
2007-07-15 20:01:01 ——– d—–w C:\Program Files\Microsoft Works
2007-07-15 18:02:32 ——– d—–w C:\Program Files\Spyware Terminator
2007-07-15 18:00:47 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Spyware Terminator
2007-07-14 05:14:21 685,944 —-a-w C:\WINDOWS\system32\SpoonUninstall.exe
2007-07-14 00:15:39 8,854 —-a-w C:\WINDOWS\mozver.dat
2007-07-14 00:13:34 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Real
2007-07-14 00:10:50 ——– d—–w C:\Program Files\Common Files\Real
2007-07-10 14:50:58 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\BitTorrent
2007-07-01 18:00:55 135,936 —-a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-06-24 05:23:42 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\uTorrent
2007-06-24 01:13:59 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Uniblue
2007-06-24 01:13:48 ——– d—–w C:\Program Files\Uniblue
2007-06-24 00:52:47 ——– d—–w C:\Program Files\Mozilla Thunderbird
2007-06-13 20:13:22 ——– d—–w C:\Program Files\Azureus
2007-06-11 05:31:49 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Ahead
2007-06-10 18:41:24 ——– d—–w C:\Program Files\Common Files\Ahead
2007-06-10 18:38:49 ——– d—–w C:\Program Files\Nero
2007-06-10 18:29:58 ——– d—–w C:\Program Files\Ahead
2007-06-10 18:20:05 ——– d—–w C:\Program Files\PowerISO
2007-06-08 07:25:31 ——– d—–w C:\Program Files\STOPzilla!
2007-06-08 05:29:48 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\.wyzo
2007-06-08 04:46:18 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\STOPzilla!
2007-06-08 03:13:09 ——– d—–w C:\Program Files\Common Files\iS3
2007-06-08 02:52:24 ——– d—–w C:\Program Files\uTorrent
2007-06-08 00:40:01 ——– d—–w C:\Program Files\BitTorrent
2007-06-06 07:27:28 217,088 —-a-r C:\WINDOWS\system32\SZBase5.dll
2007-06-05 17:22:08 ——– d—–w C:\Program Files\Audacity
2007-06-05 17:12:34 ——– d—–w C:\Program Files\DVD Shrink
2007-06-02 15:55:46 ——– d—–w C:\Program Files\Hewlett-Packard
2007-06-02 15:53:07 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-05-30 18:12:28 126,976 —-a-r C:\WINDOWS\system32\IS3HTUI5.dll
2007-05-30 18:12:20 294,912 —-a-r C:\WINDOWS\system32\IS3DBA5.dll
2007-05-30 18:11:28 372,736 —-a-r C:\WINDOWS\system32\IS3UI5.dll
2007-05-30 18:11:14 69,632 —-a-r C:\WINDOWS\system32\IS3Hks5.dll
2007-05-30 18:10:56 23,040 —-a-r C:\WINDOWS\system32\IS3XDat5.dll
2007-05-30 18:10:36 184,320 —-a-r C:\WINDOWS\system32\IS3Win325.dll
2007-05-30 18:10:16 94,208 —-a-r C:\WINDOWS\system32\IS3Inet5.dll
2007-05-30 18:10:02 90,112 —-a-r C:\WINDOWS\system32\IS3Svc5.dll
2007-05-30 18:09:36 626,688 —-a-r C:\WINDOWS\system32\IS3Base5.dll
2007-05-19 16:11:21 ——– d—–w C:\Program Files\Microsoft AntiSpyware
2004-08-04 12:00:00 73,728 –sha-w C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
2004-08-04 12:00:00 590,848 –sh–r C:\WINDOWS\system32\scvhost32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-11-03 14:17 54248 –a—— C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1827766B-9F49-4854-8034-F6EE26FCB1EC}]
2007-06-06 00:35 275904 -ra—— C:\Program Files\STOPzilla!\SZSG.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\PROGRA~1\SPYBOT~1\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E3215F20-3212-11D6-9F8B-00D0B743919D}]
2007-06-06 00:35 177600 -ra—— C:\Program Files\STOPzilla!\SZIEBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2003-05-15 16:41]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-05-14 09:09]
"AVG7_EMC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" [2007-06-26 18:09]
"SVCHost Protocol32"="scvhost32.exe" [2004-08-04 05:00 C:\WINDOWS\system32\scvhost32.exe]
"SpywareTerminator"="C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe" [2007-07-01 11:00]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-13 17:08]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-09-27 07:59]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-03-01 16:11]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"SVCHost Protocol32"=scvhost32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
C:\WINDOWS\system32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r


Contents of the 'Scheduled Tasks' folder
2005-07-07 16:38:50 C:\WINDOWS\tasks\Symantec NetDetect.job
2007-07-14 08:42:07 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
2007-06-24 00:40:35 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
2007-07-14 08:42:13 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
2007-06-24 01:25:41 C:\WINDOWS\tasks\Uniblue SpyEraser.job

**************************************************************************

catchme 0.3.1017 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-15 17:16:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000007d
"TracesSuccessful"=dword:00000062

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"AutoRestartShell"=dword:00000000

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-15 17:17:09
C:\ComboFix-quarantined-files.txt … 2007-07-15 17:17

— E O F —


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

and here's the newest hjt log

Logfile of HijackThis v1.99.1
Scan saved at 17:20, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\scvhost32.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SVCHost Protocol32] scvhost32.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\RunServices: [SVCHost Protocol32] scvhost32.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Unknown owner - C:\Program Files\HPQ\SHARED\HPQWMI.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~

i renamed the temp file to hjt, i just hope i renamed the right 'temp' file as i have a few.

cheers,

-Will
A. Download AVG AntiSpyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG AntiSpyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete, run AVG AntiSpyware and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG AntiSpyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while AVG AntiSpyware is scanning, it may interfere with the scanning proccess:
  • Launch AVG AntiSpyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG AntiSpyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close AVG AntiSpyware and reboot your system back into Normal Mode and post the results of the report.
B. Now please run ComboFix again.


C. Run HijackThis again and produce a log.


D. Reports/Logs to post
  • AVG Report.txt
  • ComboFix.txt
  • HijackThis .log
hey thanks for this, by the by….

when i ran AVG Anti-spyware in safe mode, the first time it found and removed 93 things…. but it didn't create a logfile. SO i ran it again, along with AVG virus scan, ad-aware, registry booster, registry mechanic, spyware terminator, spybot and super anti-spyware…. but when i ran it a second time, aside from finding and removing 20 things, it didn't create a logfile.

So i ran it in normal mode, with the internet unplugged, and it found nothing….


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 23:58 7/15/2007

+ Scan result:



Nothing found.


::Report end

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

i tried to find a copy of what it removed, but cannot. It says it's removed 113 spywares to date.
i added the stopzilla logfile at the bottom…. it found two critical things.









~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

plus the combofix log….

"compaq" - 2007-07-16 0:03:34 - ComboFix 07-07-16.4 - Service Pack 2 NTFS


((((((((((((((((((((((((( Files Created from 2007-06-16 to 2007-07-16 )))))))))))))))))))))))))))))))


2007-07-15 18:18 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-15 18:10 d——– C:\WINDOWS\system32\SuperAdBlocker.com
2007-07-15 17:29 d——– C:\Program Files\SUPERAntiSpyware
2007-07-15 17:29 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-15 17:29 d——– C:\DOCUME~1\compaq\APPLIC~1\SUPERAntiSpyware.com
2007-07-15 17:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-15 17:13 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-15 13:50 63 –a—— C:\WINDOWS\system\SysSD.dll
2007-07-15 13:48 1,044,480 –a—— C:\WINDOWS\system32\VchReg.dll
2007-07-15 13:48 d——– C:\Program Files\SpywareDetector
2007-07-15 13:39 d——– C:\removal tool
2007-07-13 22:14 3,030 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2007-07-13 17:11 d——– C:\Program Files\Common Files\xing shared
2007-07-13 16:43 3,590 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2007-07-10 19:16 13,015 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2007-07-10 19:12 2,951 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2007-07-08 21:32 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Ahead
2007-07-05 23:11 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-05 23:11 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-05 23:11 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-06-16 09:31 d——– C:\stuff


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-16 03:13:25 ——– d—–w C:\Program Files\Spyware Terminator
2007-07-16 02:50:13 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Spyware Terminator
2007-07-16 01:10:51 9,372 —-a-w C:\WINDOWS\mozver.dat
2007-07-15 21:22:28 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Azureus
2007-07-15 20:01:01 ——– d—–w C:\Program Files\Microsoft Works
2007-07-14 05:14:21 685,944 —-a-w C:\WINDOWS\system32\SpoonUninstall.exe
2007-07-14 00:13:34 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Real
2007-07-14 00:10:50 ——– d—–w C:\Program Files\Common Files\Real
2007-07-10 14:50:58 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\BitTorrent
2007-07-01 18:00:55 135,936 —-a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-06-24 05:23:42 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\uTorrent
2007-06-24 01:13:59 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Uniblue
2007-06-24 01:13:48 ——– d—–w C:\Program Files\Uniblue
2007-06-24 00:52:47 ——– d—–w C:\Program Files\Mozilla Thunderbird
2007-06-13 20:13:22 ——– d—–w C:\Program Files\Azureus
2007-06-11 05:31:49 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Ahead
2007-06-10 18:41:24 ——– d—–w C:\Program Files\Common Files\Ahead
2007-06-10 18:38:49 ——– d—–w C:\Program Files\Nero
2007-06-10 18:29:58 ——– d—–w C:\Program Files\Ahead
2007-06-10 18:20:05 ——– d—–w C:\Program Files\PowerISO
2007-06-08 07:25:31 ——– d—–w C:\Program Files\STOPzilla!
2007-06-08 05:29:48 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\.wyzo
2007-06-08 04:46:18 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\STOPzilla!
2007-06-08 03:13:09 ——– d—–w C:\Program Files\Common Files\iS3
2007-06-08 02:52:24 ——– d—–w C:\Program Files\uTorrent
2007-06-08 00:40:01 ——– d—–w C:\Program Files\BitTorrent
2007-06-06 07:27:28 217,088 —-a-r C:\WINDOWS\system32\SZBase5.dll
2007-06-05 17:22:08 ——– d—–w C:\Program Files\Audacity
2007-06-05 17:12:34 ——– d—–w C:\Program Files\DVD Shrink
2007-06-02 15:55:46 ——– d—–w C:\Program Files\Hewlett-Packard
2007-06-02 15:53:07 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-05-30 18:12:28 126,976 —-a-r C:\WINDOWS\system32\IS3HTUI5.dll
2007-05-30 18:12:20 294,912 —-a-r C:\WINDOWS\system32\IS3DBA5.dll
2007-05-30 18:11:28 372,736 —-a-r C:\WINDOWS\system32\IS3UI5.dll
2007-05-30 18:11:14 69,632 —-a-r C:\WINDOWS\system32\IS3Hks5.dll
2007-05-30 18:10:56 23,040 —-a-r C:\WINDOWS\system32\IS3XDat5.dll
2007-05-30 18:10:36 184,320 —-a-r C:\WINDOWS\system32\IS3Win325.dll
2007-05-30 18:10:16 94,208 —-a-r C:\WINDOWS\system32\IS3Inet5.dll
2007-05-30 18:10:02 90,112 —-a-r C:\WINDOWS\system32\IS3Svc5.dll
2007-05-30 18:09:36 626,688 —-a-r C:\WINDOWS\system32\IS3Base5.dll
2007-05-19 16:11:21 ——– d—–w C:\Program Files\Microsoft AntiSpyware
2004-08-04 12:00:00 73,728 –sha-w C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
2004-08-04 12:00:00 590,848 –sh–r C:\WINDOWS\system32\scvhost32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-11-03 14:17 54248 –a—— C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1827766B-9F49-4854-8034-F6EE26FCB1EC}]
2007-06-06 00:35 275904 -ra—— C:\Program Files\STOPzilla!\SZSG.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\PROGRA~1\SPYBOT~1\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E3215F20-3212-11D6-9F8B-00D0B743919D}]
2007-06-06 00:35 177600 -ra—— C:\Program Files\STOPzilla!\SZIEBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2003-05-15 16:41]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-05-14 09:09]
"AVG7_EMC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" [2007-06-26 18:09]
"SVCHost Protocol32"="scvhost32.exe" [2004-08-04 05:00 C:\WINDOWS\system32\scvhost32.exe]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-07-01 11:00]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-13 17:08]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-09-27 07:59]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"SVCHost Protocol32"=scvhost32.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 05:29]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll –a—— 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
C:\WINDOWS\system32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r


Contents of the 'Scheduled Tasks' folder
2005-07-07 16:38:50 C:\WINDOWS\tasks\Symantec NetDetect.job
2007-07-14 08:42:07 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
2007-06-24 00:40:35 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
2007-07-14 08:42:13 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
2007-06-24 01:25:41 C:\WINDOWS\tasks\Uniblue SpyEraser.job

**************************************************************************

catchme 0.3.1017 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-16 00:10:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000077
"TracesSuccessful"=dword:00000071

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-16 0:14:25 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-16 00:14
C:\ComboFix2.txt … 2007-07-15 17:17

— E O F —

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

and the hijackthis log….

Logfile of HijackThis v1.99.1
Scan saved at 00:15, on 7/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\scvhost32.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\notepad.exe
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SVCHost Protocol32] scvhost32.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [SVCHost Protocol32] scvhost32.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Unknown owner - C:\Program Files\HPQ\SHARED\HPQWMI.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Information Registry enforcer 2007-07-16 00:09:31 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-07-16 00:09:31 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-16 00:09:31 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-16 00:09:30 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-16 00:09:30 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-16 00:09:30 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-16 00:06:31 Removed service: poof -
Block/Extraction Registry enforcer 2007-07-15 23:33:31 Deleted registry value DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2007-07-15 23:33:31 Detected malicious registry entry DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Block/Extraction Registry enforcer 2007-07-15 23:31:27 Deleted registry value DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2007-07-15 23:31:26 Detected malicious registry entry DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Information Internet Explorer 2007-07-15 23:30:11 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-15 23:30:11 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-15 23:30:07 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-15 23:30:07 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-15 23:30:07 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-15 23:30:05 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-15 22:25:41 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-15 22:25:38 Disabled service: messenger -
Block/Extraction Pop-up blocker 2007-07-15 21:20:37 Extracted package System Policies.DisableRegistryTools
Block/Extraction Registry enforcer 2007-07-15 21:20:34 Deleted registry value DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2007-07-15 21:20:34 Detected malicious registry entry DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Block/Extraction Registry enforcer 2007-07-15 21:17:20 Deleted registry value DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2007-07-15 21:17:20 Detected malicious registry entry DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Information Internet Explorer 2007-07-15 21:16:52 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-15 21:16:50 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-15 21:16:50 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-15 21:16:50 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-15 21:16:49 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-15 21:16:49 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-15 18:24:47 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-15 18:24:44 Disabled service: messenger -
Block/Extraction Registry enforcer 2007-07-15 18:19:30 Deleted registry value DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2007-07-15 18:19:30 Detected malicious registry entry DisableRegistryTools in hkus\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\policies\system
Information Internet Explorer 2007-07-15 18:03:54 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-15 18:03:54 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-15 18:03:54 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-15 18:03:53 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-15 18:03:52 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-15 18:03:51 Starting process watcher
Information Internet Explorer 2007-07-15 17:54:03 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-15 17:54:03 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-15 17:54:02 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-15 17:54:02 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-15 17:54:01 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-15 17:54:00 Starting process watcher
Information Registry enforcer 2007-07-15 17:29:28 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-15 16:45:08 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-07-15 16:45:08 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-15 16:45:08 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-15 16:45:07 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-15 16:45:07 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-15 16:45:06 Starting process watcher
Information Registry enforcer 2007-07-15 14:01:53 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-15 13:48:48 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-07-14 19:04:19 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-14 19:04:19 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-14 19:04:19 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-14 19:04:18 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-14 19:04:17 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-14 19:04:16 Starting process watcher
Information Internet Explorer 2007-07-14 10:34:59 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-14 10:34:59 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-14 10:34:59 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-14 10:34:58 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-14 10:34:58 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-14 10:34:57 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-14 04:03:09 Disabled service: messenger -
Information Internet Explorer 2007-07-14 03:56:55 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-14 03:56:55 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-14 03:56:54 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-14 03:56:54 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-14 03:56:53 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-14 03:56:52 Starting process watcher
Information Internet Explorer 2007-07-14 01:44:00 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-14 01:44:00 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-14 01:43:59 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-14 01:43:58 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-14 01:43:58 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-14 01:43:57 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-14 01:42:58 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-14 01:42:54 Disabled service: messenger -
Information Registry enforcer 2007-07-13 14:32:26 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-07-13 14:32:26 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-13 14:32:26 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-13 14:32:26 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-13 14:32:25 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-13 14:32:24 Starting process watcher
Information Registry enforcer 2007-07-13 12:04:41 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-07-13 12:04:41 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-13 12:04:41 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-13 12:04:41 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-13 12:04:40 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-13 12:04:40 Starting process watcher
Information Internet Explorer 2007-07-13 09:35:05 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-13 09:35:05 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-13 09:35:05 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-13 09:35:05 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-13 09:35:04 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-13 09:35:02 Starting process watcher
Information Internet Explorer 2007-07-12 19:05:24 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-12 19:05:24 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-12 19:05:23 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-12 19:05:23 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-12 19:05:22 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-12 19:05:21 Starting process watcher
Information Internet Explorer 2007-07-12 18:39:17 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-12 18:39:17 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-12 18:39:17 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-12 18:39:14 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-12 18:39:13 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-12 18:39:12 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-11 07:50:59 Disabled service: messenger -
Information Internet Explorer 2007-07-10 19:29:49 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-10 19:29:49 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-10 19:29:49 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-10 19:29:48 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-10 19:29:47 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-10 19:29:46 Starting process watcher
Information Internet Explorer 2007-07-10 19:19:11 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-10 19:19:11 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-10 19:19:10 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-10 19:19:10 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-10 19:19:10 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-10 19:19:09 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-10 19:18:03 Disabled service: messenger -
Information Internet Explorer 2007-07-10 07:41:14 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-10 07:41:14 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-10 07:41:12 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-10 07:41:12 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-10 07:41:12 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-10 07:41:11 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-09 22:56:34 Disabled service: messenger -
Information Registry enforcer 2007-07-09 08:03:49 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-07-09 08:03:49 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-09 08:03:48 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-09 08:03:47 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-09 08:03:45 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-09 08:03:43 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-09 07:56:21 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-09 07:56:18 Disabled service: messenger -
Information Internet Explorer 2007-07-09 07:17:52 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-09 07:17:52 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-09 07:17:52 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-09 07:17:50 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-09 07:17:50 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-09 07:17:49 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-08 23:31:56 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-08 23:31:55 Disabled service: messenger -
Information Internet Explorer 2007-07-08 00:16:14 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-08 00:16:12 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-08 00:16:05 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-08 00:16:04 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-08 00:16:03 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-08 00:16:02 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-07 18:51:46 Disabled service: messenger -
Information Internet Explorer 2007-07-06 16:13:05 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-06 16:13:05 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-06 16:13:05 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-06 16:13:04 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-06 16:13:04 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-06 16:13:02 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-05 23:41:34 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-05 23:41:30 Disabled service: messenger -
Information Internet Explorer 2007-07-05 23:08:53 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-05 23:08:52 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-05 23:08:52 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-05 23:08:51 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-05 23:08:51 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-05 23:08:50 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-05 22:38:46 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-05 22:38:44 Disabled service: messenger -
Information Internet Explorer 2007-07-05 17:55:57 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-05 17:55:57 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-05 17:55:57 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-05 17:55:56 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-05 17:55:55 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-05 17:55:55 Starting process watcher
Information Internet Explorer 2007-07-05 07:40:37 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-05 07:40:37 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-05 07:40:36 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-05 07:40:36 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-05 07:40:36 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-05 07:40:35 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-05 00:00:07 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-05 00:00:04 Disabled service: messenger -
Information Internet Explorer 2007-07-04 19:56:44 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-04 19:56:43 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-04 19:56:42 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-04 19:56:42 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-04 19:56:42 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-04 19:56:41 Starting process watcher
Information Registry enforcer 2007-07-04 19:22:17 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-07-04 19:22:17 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-04 19:22:17 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-04 19:22:16 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-04 19:22:16 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-04 19:22:15 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-04 07:29:57 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-04 07:29:56 Disabled service: messenger -
Information Internet Explorer 2007-07-03 17:24:16 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-03 17:24:15 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-03 17:24:14 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-03 17:24:12 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-03 17:24:12 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-03 17:24:08 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-03 07:17:17 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-03 07:17:14 Disabled service: messenger -
Information Internet Explorer 2007-07-03 07:11:22 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-03 07:11:21 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-03 07:11:20 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-03 07:11:19 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-03 07:11:19 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-03 07:11:18 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-02 23:54:21 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-02 23:54:16 Disabled service: messenger -
Information Internet Explorer 2007-07-02 23:25:05 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-02 23:25:05 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-02 23:25:05 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-02 23:25:05 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-02 23:25:03 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-02 23:25:02 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-02 13:21:07 Disabled service: messenger -
Warning/Detection Process enforcer 2007-07-02 09:42:03 Restricting process c:\program files\outlook express\msimn.exe
Information Internet Explorer 2007-07-02 03:00:11 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-07-02 03:00:10 Inspecting registered Explorer bars
Information Registry enforcer 2007-07-02 03:00:08 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-07-02 03:00:06 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-07-02 03:00:05 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-07-02 03:00:03 Starting process watcher
Block/Extraction NT Service enforcer 2007-07-01 21:29:43 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-07-01 21:29:40 Disabled service: messenger -
Information Registry enforcer 2007-06-30 16:49:26 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-06-30 16:49:25 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-30 16:49:25 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-30 16:49:25 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-30 16:49:24 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-30 16:49:22 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-30 07:30:39 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-30 07:30:36 Disabled service: messenger -
Information Registry enforcer 2007-06-30 07:17:53 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-06-30 07:17:52 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-30 07:17:52 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-30 07:17:52 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-30 07:17:51 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-30 07:17:50 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-29 22:59:55 Disabled service: messenger -
Information Registry enforcer 2007-06-29 17:17:47 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-06-29 17:17:47 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-29 17:17:47 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-29 17:17:47 Inspecting registered Browser Helper Objects (BHOs)
Information Registry enforcer 2007-06-29 17:17:47 Inspecting WinSock registry (LSP Chain)
Information Process enforcer 2007-06-29 17:17:45 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-29 14:55:20 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-29 14:55:18 Disabled service: messenger -
Information Internet Explorer 2007-06-29 09:42:16 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-29 09:42:16 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-29 09:42:16 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-29 09:42:15 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-29 09:42:15 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-29 09:42:15 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-29 00:15:16 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-29 00:15:10 Disabled service: messenger -
Information Registry enforcer 2007-06-28 23:55:40 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-06-28 23:55:40 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-28 23:55:40 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-28 23:55:39 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-28 23:55:38 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-28 23:55:37 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-26 18:36:31 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-26 18:36:26 Disabled service: messenger -
Information Registry enforcer 2007-06-26 18:06:44 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-06-26 18:06:44 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-26 18:06:44 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-26 18:06:43 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-26 18:06:43 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-26 18:06:42 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-24 23:41:03 Disabled service: messenger -
Information Internet Explorer 2007-06-24 14:14:24 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-24 14:14:23 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-24 14:14:23 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-24 14:14:23 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-24 14:14:22 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-24 14:14:21 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-23 22:59:46 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-23 22:59:42 Disabled service: messenger -
Information Internet Explorer 2007-06-23 22:25:49 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-23 22:25:48 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-23 22:25:47 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-23 22:25:39 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-23 22:25:37 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-23 22:25:35 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-23 22:24:24 Disabled service: messenger -
Information Internet Explorer 2007-06-23 17:28:41 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-23 17:28:41 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-23 17:28:40 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-23 17:28:40 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-23 17:28:39 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-23 17:28:38 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-20 18:58:40 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-20 18:58:38 Disabled service: messenger -
Information Internet Explorer 2007-06-20 18:53:15 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-20 18:53:15 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-20 18:53:14 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-20 18:53:13 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-20 18:53:13 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-20 18:53:10 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-20 18:40:05 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-20 18:39:59 Disabled service: messenger -
Information Internet Explorer 2007-06-20 11:47:13 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-20 11:47:12 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-20 11:47:12 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-20 11:47:12 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-20 11:47:12 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-20 11:47:11 Starting process watcher
Information Registry enforcer 2007-06-19 15:13:02 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-06-19 15:13:02 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-19 15:13:02 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-19 15:13:02 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-19 15:13:01 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-19 15:13:00 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-18 21:50:16 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-18 21:50:14 Disabled service: messenger -
Information Internet Explorer 2007-06-18 21:16:03 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-18 21:16:02 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-18 21:16:02 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-18 21:16:02 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-18 21:16:02 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-18 21:16:01 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-18 20:40:52 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-18 20:40:42 Disabled service: messenger -
Information Internet Explorer 2007-06-17 21:11:48 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-17 21:11:48 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-17 21:11:47 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-17 21:11:47 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-17 21:11:47 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-17 21:11:46 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-17 20:11:02 Disabled service: messenger -
Information Internet Explorer 2007-06-16 15:56:50 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-16 15:56:50 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-16 15:56:50 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-16 15:56:49 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-16 15:56:48 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-16 15:56:48 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-16 14:15:48 Disabled service: messenger -
Information Internet Explorer 2007-06-16 11:54:45 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-16 11:54:45 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-16 11:54:45 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-16 11:54:44 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-16 11:54:44 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-16 11:54:43 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-16 11:53:35 Disabled service: messenger -
Information Internet Explorer 2007-06-16 09:43:47 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-16 09:43:45 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-16 09:43:38 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-16 09:43:36 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-16 09:43:36 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-16 09:43:35 Starting process watcher
Information General 2007-06-16 09:12:01 Completed system scan.
Information General 2007-06-16 09:10:16 Started system scan.
Information Internet Explorer 2007-06-16 08:44:45 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-16 08:44:44 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-16 08:44:44 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-16 08:44:43 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-16 08:44:42 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-16 08:44:40 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-15 23:00:24 Disabled service: messenger -
Information Internet Explorer 2007-06-15 16:23:45 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-15 16:23:45 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-15 16:23:45 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-15 16:23:44 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-15 16:23:44 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-15 16:23:43 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-14 23:43:23 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-14 23:43:19 Disabled service: messenger -
Information Registry enforcer 2007-06-14 22:36:26 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-06-14 22:36:26 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-14 22:36:26 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-14 22:36:26 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-14 22:36:25 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-14 22:36:25 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-14 12:33:59 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-14 12:33:54 Disabled service: messenger -
Information Internet Explorer 2007-06-14 11:43:43 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-14 11:43:43 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-14 11:43:42 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-14 11:43:42 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-14 11:43:42 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-14 11:43:41 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-13 22:01:36 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-13 22:01:33 Disabled service: messenger -
Information Internet Explorer 2007-06-13 21:45:26 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-13 21:45:25 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-13 21:45:25 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-13 21:45:24 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-13 21:45:24 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-13 21:45:23 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-13 13:37:13 Disabled service: messenger -
Information Internet Explorer 2007-06-13 08:25:43 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-13 08:25:43 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-13 08:25:38 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-13 08:25:25 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-13 08:25:23 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-13 08:25:19 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-12 23:46:45 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-12 23:46:42 Disabled service: messenger -
Information Registry enforcer 2007-06-12 23:05:36 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-12 23:05:36 Inspecting WinSock registry (LSP Chain)
Information Internet Explorer 2007-06-12 23:05:36 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-12 23:05:36 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-12 23:05:35 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-12 23:05:34 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-12 23:04:04 Disabled service: messenger -
Block/Extraction Pop-up blocker 2007-06-12 23:03:12 Extracted package Registration
Block/Extraction File enforcer 2007-06-12 23:03:12 Extracted files: path, c:\temp\stopzilla! v3.1.0.7 + crack\activator.exe
Block/Extraction File enforcer 2007-06-12 23:03:12 Deleted file: c:\temp\stopzilla! v3.1.0.7 + crack\activator.exe
Block/Extraction File enforcer 2007-06-12 23:03:11 Quarantined file: c:\temp\stopzilla! v3.1.0.7 + crack\activator.exe
Block/Extraction File enforcer 2007-06-12 23:03:10 Extracted files: path, c:\program files\stopzilla!\swin32z.exe
Block/Extraction File enforcer 2007-06-12 23:03:10 Deleted file: c:\program files\stopzilla!\swin32z.exe
Block/Extraction File enforcer 2007-06-12 23:03:09 Quarantined file: c:\program files\stopzilla!\swin32z.exe
Information General 2007-06-12 22:38:22 Completed system scan.
Information General 2007-06-12 22:17:43 Started system scan.
Block/Extraction Pop-up blocker 2007-06-12 22:16:46 Extracted package VirusBurst
Block/Extraction Registry enforcer 2007-06-12 22:16:46 Extracted registry key HKUS\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\internet settings\zonemap\ranges
Block/Extraction Registry enforcer 2007-06-12 22:16:45 Extracting registry value hklm\software\licenses
Block/Extraction Registry enforcer 2007-06-12 22:16:44 Extracting registry value hklm\software\licenses
Block/Extraction Pop-up blocker 2007-06-12 22:16:43 Failed to extract package HitVirus
Block/Extraction Registry enforcer 2007-06-12 22:16:43 Extracted registry key hklm\software\classes\.key
Block/Extraction Pop-up blocker 2007-06-12 22:16:40 Extracted package Media-Codec
Block/Extraction Registry enforcer 2007-06-12 22:16:39 Extracted registry key hklm\software\microsoft\windows\currentversion\policies\explorer\run
Block/Extraction Registry enforcer 2007-06-12 22:16:39 Extracted registry key HKUS\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\internet settings\zonemap\ranges
Block/Extraction File enforcer 2007-06-12 22:16:34 Extracted files: path, c:\documents and settings\compaq\local settings\temporary internet files\content.ie5\spuv09an\pngfix[1].js
Block/Extraction File enforcer 2007-06-12 22:16:34 Deleted file: c:\documents and settings\compaq\local settings\temporary internet files\content.ie5\spuv09an\pngfix[1].js
Block/Extraction File enforcer 2007-06-12 22:16:33 Suppressed file: c:\documents and settings\compaq\local settings\temporary internet files\content.ie5\spuv09an\pngfix[1].js
Information General 2007-06-12 22:13:33 Completed system scan.
Information General 2007-06-12 22:08:32 Started system scan.
Information Internet Explorer 2007-06-12 22:05:38 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-12 22:05:38 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-12 22:05:36 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-12 22:05:33 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-12 22:05:32 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-12 22:05:30 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-12 22:02:33 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-12 22:02:31 Disabled service: messenger -
Information Registry enforcer 2007-06-12 14:58:10 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-06-12 14:58:08 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-12 14:58:08 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-12 14:58:08 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-12 14:58:07 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-12 14:58:07 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-12 08:46:05 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-12 08:46:04 Disabled service: messenger -
Information Internet Explorer 2007-06-12 08:32:49 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-12 08:32:48 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-12 08:32:42 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-12 08:32:41 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-12 08:32:39 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-12 08:32:37 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-12 00:22:44 Disabled service: messenger -
Information Internet Explorer 2007-06-11 22:24:13 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-11 22:24:13 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-11 22:24:13 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-11 22:24:12 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-11 22:24:12 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-11 22:24:10 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-11 17:39:12 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-11 17:39:08 Disabled service: messenger -
Information Registry enforcer 2007-06-11 16:28:23 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Internet Explorer 2007-06-11 16:28:23 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-11 16:28:23 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-11 16:28:22 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-11 16:28:22 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-11 16:28:21 Starting process watcher
Information Internet Explorer 2007-06-10 11:46:59 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-10 11:46:59 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-10 11:46:47 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-10 11:46:45 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-10 11:46:45 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-10 11:46:44 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-10 11:45:24 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-10 11:45:21 Disabled service: messenger -
Information Internet Explorer 2007-06-10 11:33:05 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-10 11:33:04 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-10 11:32:38 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-10 11:32:35 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-10 11:32:34 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-10 11:32:33 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-10 11:31:19 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-10 11:31:15 Disabled service: messenger -
Information Internet Explorer 2007-06-10 11:23:12 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2007-06-10 11:23:12 Inspecting registered Explorer bars
Information Registry enforcer 2007-06-10 11:23:12 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2007-06-10 11:23:11 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2007-06-10 11:23:10 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2007-06-10 11:23:10 Starting process watcher
Block/Extraction NT Service enforcer 2007-06-10 11:22:15 Disabled service: messenger -
Block/Extraction NT Service enforcer 2007-06-10 11:22:12 Disabled service: messenger -
Block/Extraction Pop-up blocker 2007-06-10 09:59:51 Failed to extract package SearchSquire
Block/Extraction Pop-up blocker 2007-06-10 09:59:47 Extracted package VirusBurst
Block/Extraction Registry enforcer 2007-06-10 09:59:47 Extracted registry key HKUS\S-1-5-21-1292428093-362288127-725345543-1004\software\microsoft\windows\currentversion\internet settings\zonemap\ranges
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.tomcoyote.org/Would_Love_heal_Computer_Need_Help_t81304.html

Collect::
C:\WINDOWS\system32\scvhost32.exe
C:\DOCUME~1\compaq\APPLIC~1\.wyzo

DirLook::
C:\stuff

File::
C:\WINDOWS\system32\scvhost32.exe
C:\DOCUME~1\compaq\APPLIC~1\.wyzo

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SVCHost Protocol32"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"SVCHost Protocol32"=-


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. Additonally, ComboFix will generate a zipped file on your desktop called Submit [Date Time].zip
Please submit this file to:

http://www.bleepingcomputer.com/submit-malware.php?channel=4


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
okay sir,

i assume you're a sir… you could be a ma'am, but it says 'trev'-erun…. my apologies if i am incorrect.

i sent the submit.zip file to bleeping computer, and here are the combofix/hijackthis logs.

Pretty exciting stuff. I feel like we're close…. it's like exorcising a demon. ha!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


"compaq" - 2007-07-16 8:50:38 - ComboFix 07-07-16.4 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\compaq\My Documents\Azureus Downloads\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\scvhost32.exe


((((((((((((((((((((((((( Files Created from 2007-06-16 to 2007-07-16 )))))))))))))))))))))))))))))))


2007-07-15 18:18 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-15 18:10 d——– C:\WINDOWS\system32\SuperAdBlocker.com
2007-07-15 17:29 d——– C:\Program Files\SUPERAntiSpyware
2007-07-15 17:29 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-15 17:29 d——– C:\DOCUME~1\compaq\APPLIC~1\SUPERAntiSpyware.com
2007-07-15 17:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-15 17:13 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-15 13:50 63 –a—— C:\WINDOWS\system\SysSD.dll
2007-07-15 13:48 1,044,480 –a—— C:\WINDOWS\system32\VchReg.dll
2007-07-15 13:48 d——– C:\Program Files\SpywareDetector
2007-07-15 13:39 d——– C:\removal tool
2007-07-13 22:14 3,030 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2007-07-13 17:11 d——– C:\Program Files\Common Files\xing shared
2007-07-13 16:43 3,590 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2007-07-10 19:16 13,015 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2007-07-10 19:12 2,951 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2007-07-08 21:32 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Ahead
2007-07-05 23:11 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-05 23:11 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-05 23:11 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-06-16 09:31 d——– C:\stuff


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-16 15:55:11 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Azureus
2007-07-16 08:28:05 9,372 —-a-w C:\WINDOWS\mozver.dat
2007-07-16 03:13:25 ——– d—–w C:\Program Files\Spyware Terminator
2007-07-16 02:50:13 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Spyware Terminator
2007-07-15 20:01:01 ——– d—–w C:\Program Files\Microsoft Works
2007-07-14 05:14:21 685,944 —-a-w C:\WINDOWS\system32\SpoonUninstall.exe
2007-07-14 00:13:34 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Real
2007-07-14 00:10:50 ——– d—–w C:\Program Files\Common Files\Real
2007-07-10 14:50:58 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\BitTorrent
2007-07-01 18:00:55 135,936 —-a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-06-24 05:23:42 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\uTorrent
2007-06-24 01:13:59 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Uniblue
2007-06-24 01:13:48 ——– d—–w C:\Program Files\Uniblue
2007-06-24 00:52:47 ——– d—–w C:\Program Files\Mozilla Thunderbird
2007-06-13 20:13:22 ——– d—–w C:\Program Files\Azureus
2007-06-11 05:31:49 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Ahead
2007-06-10 18:41:24 ——– d—–w C:\Program Files\Common Files\Ahead
2007-06-10 18:38:49 ——– d—–w C:\Program Files\Nero
2007-06-10 18:29:58 ——– d—–w C:\Program Files\Ahead
2007-06-10 18:20:05 ——– d—–w C:\Program Files\PowerISO
2007-06-08 07:25:31 ——– d—–w C:\Program Files\STOPzilla!
2007-06-08 05:29:48 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\.wyzo
2007-06-08 04:46:18 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\STOPzilla!
2007-06-08 03:13:09 ——– d—–w C:\Program Files\Common Files\iS3
2007-06-08 02:52:24 ——– d—–w C:\Program Files\uTorrent
2007-06-08 00:40:01 ——– d—–w C:\Program Files\BitTorrent
2007-06-06 07:27:28 217,088 —-a-r C:\WINDOWS\system32\SZBase5.dll
2007-06-05 17:22:08 ——– d—–w C:\Program Files\Audacity
2007-06-05 17:12:34 ——– d—–w C:\Program Files\DVD Shrink
2007-06-02 15:55:46 ——– d—–w C:\Program Files\Hewlett-Packard
2007-06-02 15:53:07 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-05-30 18:12:28 126,976 —-a-r C:\WINDOWS\system32\IS3HTUI5.dll
2007-05-30 18:12:20 294,912 —-a-r C:\WINDOWS\system32\IS3DBA5.dll
2007-05-30 18:11:28 372,736 —-a-r C:\WINDOWS\system32\IS3UI5.dll
2007-05-30 18:11:14 69,632 —-a-r C:\WINDOWS\system32\IS3Hks5.dll
2007-05-30 18:10:56 23,040 —-a-r C:\WINDOWS\system32\IS3XDat5.dll
2007-05-30 18:10:36 184,320 —-a-r C:\WINDOWS\system32\IS3Win325.dll
2007-05-30 18:10:16 94,208 —-a-r C:\WINDOWS\system32\IS3Inet5.dll
2007-05-30 18:10:02 90,112 —-a-r C:\WINDOWS\system32\IS3Svc5.dll
2007-05-30 18:09:36 626,688 —-a-r C:\WINDOWS\system32\IS3Base5.dll
2007-05-19 16:11:21 ——– d—–w C:\Program Files\Microsoft AntiSpyware
2004-08-04 12:00:00 73,728 –sha-w C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe


(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))


—- Directory of C:\stuff —-

C:\stuff\


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-11-03 14:17 54248 –a—— C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1827766B-9F49-4854-8034-F6EE26FCB1EC}]
2007-06-06 00:35 275904 -ra—— C:\Program Files\STOPzilla!\SZSG.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\PROGRA~1\SPYBOT~1\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E3215F20-3212-11D6-9F8B-00D0B743919D}]
2007-06-06 00:35 177600 -ra—— C:\Program Files\STOPzilla!\SZIEBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2003-05-15 16:41]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-05-14 09:09]
"AVG7_EMC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" [2007-06-26 18:09]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-07-01 11:00]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-13 17:08]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-09-27 07:59]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 05:29]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll –a—— 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
C:\WINDOWS\system32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r


Contents of the 'Scheduled Tasks' folder
2005-07-07 16:38:50 C:\WINDOWS\tasks\Symantec NetDetect.job
2007-07-14 08:42:07 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
2007-06-24 00:40:35 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
2007-07-14 08:42:13 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
2007-06-24 01:25:41 C:\WINDOWS\tasks\Uniblue SpyEraser.job

**************************************************************************

catchme 0.3.1017 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-16 08:58:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-16 9:02:06 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-16 09:01
C:\ComboFix2.txt … 2007-07-16 00:14
C:\ComboFix3.txt … 2007-07-15 17:17

— E O F —

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 09:07, on 7/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Unknown owner - C:\Program Files\HPQ\SHARED\HPQWMI.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
Please download F2Ts.exe from HERE
  • Copy/Paste/type the full path of the file/folder into the Path box, the one that contains the writing in red:

    C:\stuff

  • Click the Go button and wait for the result to be shown in the F2Ts-list.
  • Click the "Select F2Ts-list" button to select all the text in the F2Ts-list.
  • Hit [Ctrl] + C on your keyboard to copy the selected text to memory.
  • Paste the text in memory into your reply by hitting [Ctrl] + V
.
Copy/Paste/type the full path of the file/folder into the Path box, the one that contains the writing in red: this confuses me…. what file/folder? I put 'c:/stuff' into the path box, but it just says no version is available for this file…. please advise….
maybe it's just c:\ that you want? here it is anyway…. F2Ts version 1.1 (april 5, 2006) Date: 7/16/2007 1:41:21 PM F2Ts File-Properties of C:\stuff ——————————————————-F2Ts File-Properties of c:\stuff ——————————————————-F2Ts-list of c:\ ——————————————————- F–RH– $VAULT$.AVG F——– ComboFix F——– Documents and Settings F——– Feurio FARHS hiberfil.sys F——– hjt F——– Intel FARHS pagefile.sys F–R—- Program Files F——– QooBox F—-HS RECYCLER F——– removal tool F——– stuff F——– swsetup F—-HS System Volume Information F——– WAVE F——– WINDOWS –A—— AUTOEXEC.BAT —-RHS AVG7DB_F.DAT ——HS boot.ini –A—— ComboFix-quarantined-files.txt –A—— ComboFix.txt –A—— ComboFix2.txt –A—— ComboFix3.txt –A—— CONFIG.SYS ——HS dllimp_regmsft985 –ARHS hiberfil.sys –ARHS IO.SYS –ARHS MaxSecureSig.DB –ARHS MSDOS.SYS –ARHS NTDETECT.COM –ARHS ntldr –ARHS pagefile.sys Total number of folders: 17 Total number of files: 16 ——————————————————- lemme know….
1. Please try it this way C:\stuff\

2. Your logs look clean. :thumbup: I think it would be wise to do an in-depth check of your entire system just to make sure that no malware is still lurking:

Please do an online scan with Kaspersky Online Virus Scanner (Use Internet Explorer as your Browser)

Note: If you have used this particular scanner before, you MAY HAVE YO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component

Next Click on Free Virus Scanner, then Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Standard
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information into your next post.
Please also tell me how things are now running.

Regards

Trevuren
I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren
hey Trev, it took me awhile to d/l windows explorer to run Kaspersky, but i did and it said i had nothing…. now… that's fine, i feel better. My computer… it's about the same. and…. all these 'spywares', which i dilligently remove every week or so, with a host of removers, fixers, ect… seem to inevitably return. AVG anti-spyware removed 85 or 92 yesterday… and super antispyware removed another five…. it doesn't actually seem to go away. i feel like i'm cutting the lawn with scissors.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI