This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]Would Love To "heal" My Computer, Need Help

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

good morning,


i didn't run these in safemode. I hope that is okay.

this is the combofix log….


"compaq" - 2007-07-26 9:39:40 [GMT -7:00] - ComboFix 07-07-24.5 - Service Pack 2 NTFS
* Created a new restore point


((((((((((((((((((((((((( Files Created from 2007-06-26 to 2007-07-26 )))))))))))))))))))))))))))))))


2007-07-25 10:44 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-07-25 10:44 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-07-25 10:44 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-07-25 10:43 d——– C:\Program Files\DivX
2007-07-25 10:41 d——– C:\Program Files\Quintessential Player
2007-07-17 16:45 d—s—- C:\DOCUME~1\compaq\UserData
2007-07-17 08:46 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-17 08:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-16 23:04 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-07-16 15:49 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-15 18:18 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-15 18:10 d——– C:\WINDOWS\system32\SuperAdBlocker.com
2007-07-15 17:29 d——– C:\Program Files\SUPERAntiSpyware
2007-07-15 17:29 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-15 17:29 d——– C:\DOCUME~1\compaq\APPLIC~1\SUPERAntiSpyware.com
2007-07-15 17:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-15 17:13 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-15 13:50 63 –a—— C:\WINDOWS\system\SysSD.dll
2007-07-15 13:48 1,044,480 –a—— C:\WINDOWS\system32\VchReg.dll
2007-07-15 13:48 d——– C:\Program Files\SpywareDetector
2007-07-15 13:39 d——– C:\removal tool
2007-07-13 22:14 3,030 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2007-07-13 17:11 d——– C:\Program Files\Common Files\xing shared
2007-07-13 16:43 3,590 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2007-07-10 19:16 13,015 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2007-07-10 19:12 2,951 –a—— C:\WINDOWS\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2007-07-09 12:07 524,288 –a—— C:\WINDOWS\system32\DivXsm.exe
2007-07-09 12:07 3,596,288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-07-09 12:07 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-07-09 12:07 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-07-09 12:05 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-07-09 12:05 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-07-09 12:05 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-07-09 12:05 740,442 –a—— C:\WINDOWS\system32\DivX.dll
2007-07-09 12:05 73,728 –a—— C:\WINDOWS\system32\dpl100.dll
2007-07-09 12:05 593,920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2007-07-09 12:05 57,344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-07-09 12:05 53,248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2007-07-09 12:05 344,064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-07-09 12:05 294,912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-07-09 12:05 294,912 –a—— C:\WINDOWS\system32\dpu10.dll
2007-07-09 12:05 196,608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-07-09 12:05 124,472 –a—— C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-07-09 12:05 12,288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-08 21:32 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Ahead
2007-07-05 23:11 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-05 23:11 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-05 23:11 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-24 18:18:33 ——– d—–w C:\Program Files\STOPzilla!
2007-07-24 18:02:13 ——– d—–w C:\Program Files\Spyware Terminator
2007-07-24 18:01:01 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Spyware Terminator
2007-07-23 06:37:21 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Azureus
2007-07-16 08:28:05 9,372 —-a-w C:\WINDOWS\mozver.dat
2007-07-15 20:01:01 ——– d—–w C:\Program Files\Microsoft Works
2007-07-14 05:14:21 685,944 —-a-w C:\WINDOWS\system32\SpoonUninstall.exe
2007-07-14 00:13:34 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Real
2007-07-14 00:10:50 ——– d—–w C:\Program Files\Common Files\Real
2007-07-10 14:50:58 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\BitTorrent
2007-07-09 19:07:47 36,624 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-07-09 19:07:47 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-07-09 19:07:47 116,472 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-07-01 18:00:55 135,936 —-a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-06-24 01:13:59 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Uniblue
2007-06-24 01:13:48 ——– d—–w C:\Program Files\Uniblue
2007-06-24 00:52:47 ——– d—–w C:\Program Files\Mozilla Thunderbird
2007-06-13 20:13:22 ——– d—–w C:\Program Files\Azureus
2007-06-11 05:31:49 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\Ahead
2007-06-10 18:41:24 ——– d—–w C:\Program Files\Common Files\Ahead
2007-06-10 18:38:49 ——– d—–w C:\Program Files\Nero
2007-06-10 18:29:58 ——– d—–w C:\Program Files\Ahead
2007-06-10 18:20:05 ——– d—–w C:\Program Files\PowerISO
2007-06-08 05:29:48 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\.wyzo
2007-06-08 04:46:18 ——– d—–w C:\DOCUME~1\compaq\APPLIC~1\STOPzilla!
2007-06-08 00:40:01 ——– d—–w C:\Program Files\BitTorrent
2007-06-05 17:22:08 ——– d—–w C:\Program Files\Audacity
2007-06-05 17:12:34 ——– d—–w C:\Program Files\DVD Shrink
2007-06-02 15:55:46 ——– d—–w C:\Program Files\Hewlett-Packard
2007-06-02 15:53:07 ——– d–h–w C:\Program Files\InstallShield Installation Information
2004-08-04 12:00:00 73,728 –sha-w C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2003-05-15 16:41]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-05-14 09:09]
"AVG7_EMC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" [2007-06-26 18:09]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-13 17:08]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-03-01 16:11]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
C:\WINDOWS\system32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

R0 Teefer;Teefer for NT;C:\WINDOWS\system32\Drivers\Teefer.sys
R1 eabfiltr;EABFiltr;\??\C:\WINDOWS\system32\drivers\EABFiltr.sys
R1 Kbdclass;Keyboard Class Driver;C:\WINDOWS\system32\DRIVERS\kbdclass.sys
R1 Mouclass;Mouse Class Driver;C:\WINDOWS\system32\DRIVERS\mouclass.sys
R1 SASDIFSV;SASDIFSV;\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
R1 SCDEmu;SCDEmu;C:\WINDOWS\system32\drivers\SCDEmu.sys
R1 sp_rsdrv2;Spyware Terminator Driver 2;\??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI;C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
R1 wpsdrvnt;wpsdrvnt;\??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys
R2 CDRPDACC;Quinnware CDDA Driver (by InfinaDyne);\??\C:\Program Files\Quintessential Player\cdrpdacc.sys
R2 wg3n;SyGate for NT, wg3n;C:\WINDOWS\system32\Drivers\wg3n.sys
R2 wg4n;SyGate for NT, wg4n;C:\WINDOWS\system32\Drivers\wg4n.sys
R2 wg5n;SyGate for NT, wg5n;C:\WINDOWS\system32\Drivers\wg5n.sys
R2 wg6n;SyGate for NT, wg6n;C:\WINDOWS\system32\Drivers\wg6n.sys
R3 CAMCAUD;Conexant AMC 3D Environmental Audio;C:\WINDOWS\system32\drivers\camcaud.sys
R3 CAMCHALA;CAMCHALA;C:\WINDOWS\system32\drivers\camchal.sys
R3 Gpc;Generic Packet Classifier;C:\WINDOWS\system32\DRIVERS\msgpc.sys
R3 HidUsb;Microsoft HID Class Driver;C:\WINDOWS\system32\DRIVERS\hidusb.sys
R3 HSFHWICH;HSFHWICH;C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
R3 sdbus;sdbus;C:\WINDOWS\system32\DRIVERS\sdbus.sys
R3 tifm21;tifm21;C:\WINDOWS\system32\drivers\tifm21.sys
R3 w22n51;Intel® PRO/Wireless 2200 Adapter Driver;C:\WINDOWS\system32\DRIVERS\w22n51.sys
S0 szkg;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys
S3 eabusb;eabusb;\??\C:\WINDOWS\system32\drivers\eabusb.sys
S3 NETMDUSB;Net MD;C:\WINDOWS\system32\Drivers\NETMD033.sys
S3 SABProcEnum;SABProcEnum;\??\C:\PROGRA~1\MOZILL~1\SABProcEnum.sys
S3 SASENUM;SASENUM;\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
S3 SbcpHid;SbcpHid;\??\C:\WINDOWS\system32\Drivers\SbcpHid.sys

*Newly Created Service* - CDRPDACC

Contents of the 'Scheduled Tasks' folder
2005-07-07 16:38:50 C:\WINDOWS\tasks\Symantec NetDetect.job
2007-07-14 08:42:07 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
2007-06-24 00:40:35 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
2007-07-14 08:42:13 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
2007-06-24 01:25:41 C:\WINDOWS\tasks\Uniblue SpyEraser.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-26 09:42:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

C:\WINDOWS\system32\cmd.exe [3540] 0x850F3A50


scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-26 9:43:06
C:\ComboFix-quarantined-files.txt … 2007-07-26 09:42

— E O F —


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


this is a note to say thank you for your time


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


this is the hjt log


Logfile of HijackThis v1.99.1
Scan saved at 09:45, on 7/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Unknown owner - C:\Program Files\HPQ\SHARED\HPQWMI.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


this is the combofix quarantined files log (?)


2004-08-04 05:00	  590848	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\scvhost32.exe.vir
2007-01-30 12:20	  34504	–a——	C:\Qoobox\Quarantine\C\WINDOWS\hosts.vir


Folder PATH listing
Volume serial number is 40F7-AC4A
C:\QOOBOX
\—Quarantine
	+—C
	|   \—WINDOWS
	|	   |   hosts.vir
	|	   |   
	|	   \—system32
	|			   scvhost32.exe.vir
	|			   
	\—Registry_backups


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


cheers,

-Will
Both logs come up clean. The only thing is perhaps the program Spyware Terminator which used to be known for false positives but apparently , the problem has been fixed in the most current versions. It is no longer really on our "badboy" list.

Try the following, please:

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
• http://www.pchell.com/support/safemode.shtml
•
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI