This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] slow, choppy computer

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm sorry I did forget to ask for the log from Killbox.
It's located here .

C:\!KillBox\Logs\kb.log

_________________________________

Note: I could not remove looksmart from the add/remove list (i also removed a bunch of carp** from my add/remove list)


Do you mean it would not uninstall ?

___________________________________

I see you have used Combofix. When did you use it and for what specifically ?


___________________________________


I want to try one more scan based on what I see combofix found.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log



___________________________
Next reply:
  • I need to see the report from !killbox.
  • The report from S&D fix
  • Let me know about Combofix.


__________________________________
Pocket Killbox version 2.0.0.648
Running on Windows XP as J-Fisch(Administrator)
was started @ Sunday, July 20, 2008, 12:07 PM

# 1 [Delete on Reboot]
Path = C:\1AB.tmp


# 2 [Delete on Reboot]
Path = C:\Documents and Settings\J-Fisch\Desktop\J-Feezle\HWOE\ADSTechnologyInstall.exe


# 3 [Delete on Reboot]
Path = C:\Documents and Settings\J-Fisch\Desktop\J-Feezle\HWOE\New Folder (2)\Setup.exe


# 4 [Delete on Reboot]
Path = C:\Documents and Settings\J-Fisch\Local Settings\Temp\nstF2.tmp\Install.dll


# 5 [Delete on Reboot]
Path = C:\Documents and Settings\J-Fisch\My Documents\Downloads\Programs\Setup.exe


# 6 [Delete on Reboot]
Path = C:\Documents and Settings\J-Fisch\My Documents\Downloads\Programs\Setup_2.exe


# 7 [Delete on Reboot]
Path = C:\Documents and Settings\J-Fisch\My Documents\Downloads\Programs\Setup_3.exe


# 8 [Delete on Reboot]
Path = C:\Program Files\LookSmart Toolbar\tbu90\tbupdate.cab


# 9 [Delete on Reboot]
Path = C:\WINDOWS\minisetup55.exe


# 10 [Delete on Reboot]
Path = C:\WINDOWS\system32\CmarP1083.exe


# 11 [Delete on Reboot]
Path = C:\WINDOWS\system32\NNSKYA638.exe


# 12 [Delete on Reboot]
Path = C:\WINDOWS\system32\qwintodv.exe


I Rebooted @ 12:08:51 PM
Killbox Closed(Exit) @ 12:09:15 PM
__________________________________________________




Yeah, every time i clicked to uninstall it, it made a quick confirmation box apear then dissappear as if it was closing it out so i couldn't remove it




This is when i used combofix, (the previous time i asked for help) http://forums.whatthetech.com/Need_some_he…are_t86950.html







SDFix: Version 1.124

Run by [removed] on Fri 07/25/2008 at 01:01 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

No Trojan Files Found





Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-25 02:09:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,d8,91,1a,d3,18,9e,dd,fd,e0,53,50,4b,ef,34,a6,a5,d0,..
"hj34z0"=hex:bf,3d,71,65,5f,0f,46,3f,e7,68,b1,d1,44,42,52,5f,dc,ce,88,63,40,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:77,80,85,d9,9f,4f,74,a1,1f,c7,76,a7,36,77,8f,40,85,86,cc,f0,38,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:77,80,85,d9,9f,4f,74,a1,1f,c7,76,a7,36,77,8f,40,85,86,cc,f0,38,..

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000007e

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Disabled:bittorrent"
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"="C:\\Program Files\\BitTornado\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Run a DLL as an App"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files:
—————


Files with Hidden Attributes:

Fri 13 May 2005 217,073 A.SHR — "C:\WINDOWS\meta4.exe"
Mon 24 Oct 2005 66,560 A.SHR — "C:\WINDOWS\MOTA113.exe"
Thu 13 Oct 2005 422,400 A.SHR — "C:\WINDOWS\x2.64.exe"
Mon 7 Mar 2005 56 ..SHR — "C:\WINDOWS\system32\72C6F1F7B0.sys"
Fri 7 Oct 2005 308,224 A.SHR — "C:\WINDOWS\system32\avisynth.dll"
Thu 14 Jul 2005 27,648 A.SHR — "C:\WINDOWS\system32\AVSredirect.dll"
Sun 26 Jun 2005 616,448 A.SHR — "C:\WINDOWS\system32\cygwin1.dll"
Tue 21 Jun 2005 45,568 A.SHR — "C:\WINDOWS\system32\cygz.dll"
Sun 25 Jan 2004 70,656 A.SHR — "C:\WINDOWS\system32\i420vfw.dll"
Sun 29 Oct 2006 11,690 A.SH. — "C:\WINDOWS\system32\KGyGaAvL.sys"
Thu 27 Apr 2006 2,945,024 A.SHR — "C:\WINDOWS\system32\Smab.dll"
Mon 28 Feb 2005 240,128 A.SHR — "C:\WINDOWS\system32\x.264.exe"
Sun 25 Jan 2004 70,656 A.SHR — "C:\WINDOWS\system32\yv12vfw.dll"
Fri 29 Feb 2008 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 5 Aug 2004 4,348 ..SH. — "C:\Documents and Settings\All Users\DRMBACKUP\DRMv1.bak"
Sun 13 Jul 2008 35,329 A..H. — "C:\Documents and Settings\J-Fisch\Application Data\EHGammaLib2501.dll"
Sun 13 Jul 2008 88,576 A..H. — "C:\Documents and Settings\J-Fisch\Application Data\rbap550.dll"
Sun 13 Jul 2008 30,720 A..H. — "C:\Documents and Settings\J-Fisch\Application Data\RBInternetEncodings600.dll"
Sun 13 Jul 2008 39,936 A..H. — "C:\Documents and Settings\J-Fisch\Application Data\RBShell555.dll"
Wed 23 Aug 2006 72,192 ..SHR — "C:\Program Files\eRightSoft\SUPER\Setup.exe"
Sat 21 Jun 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Fri 29 Feb 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRMBACKUP\Cache\Indiv01.tmp"
Mon 13 Sep 2004 94,458 …H. — "C:\Program Files\Ahead\Nero PhotoShow\data\Nero PhotoShow Elite.exe"
Tue 4 Jun 2002 84,992 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll"
Tue 4 Jun 2002 44,032 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll"
Mon 9 Dec 2002 73,766 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll"
Mon 9 Dec 2002 65,575 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll"
Tue 4 Jun 2002 20,480 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll"
Mon 9 Dec 2002 176,165 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll"
Mon 9 Dec 2002 94,208 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll"
Mon 9 Dec 2002 217,127 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll"
Sat 3 Nov 2001 225,280 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll"
Tue 10 Apr 2001 225,280 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll"
Fri 20 Feb 2004 548,940 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll"
Mon 9 Dec 2002 102,439 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll"
Wed 7 May 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\BIT9.tmp"
Fri 30 Mar 2007 857 …HR — "C:\Documents and Settings\J-Fisch\Application Data\SecuROM\UserData\securom_v7_01.bak"
Wed 9 Jan 2008 506 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic30.tmp"
Wed 9 Jan 2008 417 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\ticA.tmp"
Fri 13 Jul 2007 493,201 A..H. — "C:\Documents and Settings\J-Fisch\Desktop\J-Feezle\HWOE\New Folder (2)\Character - Mitsuru.zip"
Fri 13 Jul 2007 525,374 A..H. — "C:\Documents and Settings\J-Fisch\Desktop\J-Feezle\HWOE\New Folder (2)\Character - Fuuka.zip"

Finished!
Let's try this for that looksmart program.

Open !killbox
click on :
File >>> Open !KillBox Backups:

Right click on

tbupdate.cab and choose copy.

Now navigate to and open the following folder for me.

C:\Program Files\LookSmart Toolbar\tbu90

Right click in a blank/empty are in there and choose paste.
This should replace the file that we removed for now.
Please try the add /remove programs button now for removing looksmart.
If it works and uninstalls were fine.
If it still does not work do the following:

______________________________
Make a new folder on your desktop. Call it reg finder

Download Reg Finder
Extract the files to that folder on the desktop you just created..
Go into that folder and double click RegFinder.vbs.
If any of your software gives you a warning about running this just allow it. It's safe.
Type in Looksmart into the text field that appears and hit enter.
Again… Some protection software may probably flag the script…
just let it run.
It will let you know when its done and a log should pop up ..If it doesn't there will be a file in the folder called results.txt

Post that for me.

______________________________


The rest of the logs seem to be coming back clean.
So after we remove Looksmart unless you still think something is amiss we will finish up.
yes it wouldn't let me emove it again here is the log \/ Windows Registry Editor Version 5.00 ; Regscan.vbs Version: 1.2 by rand1038 ; 7/25/2008 11:56:39 AM ; Search Term(s) Used: "looksmart" ; 22 matches were found. ; The search took 52 seconds. "ProgramItem0085"="[LookSmart Toolbar] (0x00000000)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XBTB01232.XBTB01232] @="LookSmart Toolbar" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XBTB01232.XBTB01232.1] @="LookSmart Toolbar" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XBTB01232.XBTB01232Toolbar] "DisplayName"="LookSmart Toolbar" [HKEY_USERS\S-1-5-21-823518204-688789844-725345543-1003\Software\XBTB01232\SiteAllow] "www.looksmart.com"="" "listings.looksmart.com"="" "search.looksmart.com"="" [HKEY_USERS\S-1-5-21-823518204-688789844-725345543-1003\Software\XBTB01232\Toolbar] "uninstallMsg"="This will remove the LookSmart Toolbar from your computer! Are you sure?" "updateMsg"="This will try to update the LookSmart Toolbar from the server. Continue?" "autoUpdateMsg"="New version of LookSmart Toolbar is available. Would you like to download and install new version?" "lastVersionMsg"="You have the latest version of the LookSmart Toolbar." "contextMenuItemName"="LookSmart Toolbar search" "closeAllWindowsForUpdate"="All running IE Windows will be closed before updating the LookSmart Toolbar. Continue?" "PopStop"="LookSmart Toolbar has blocked a Pop-up window" "firstURL"="http://www.looksmart.com/?pi=lstb3&tv=1" "serverpath"="http://search.looksmart.com/s/partner/lstb2/toolbar/" "urlAfterUpdate"="http://www.looksmart.com/" "urlAfterUninstall"="http://www.looksmart.com/?pi=lstb3&tv=uninstall" "contextSearch"="http://search.looksmart.com/p/search?pi=lstb3&tb=web&tv=1&qt=%selection" "AutoSearch"="http://search.looksmart.com/p/search?pi=lstb3&qt=%s&tb=web&tv=1" "toolbar_version"="" [HKEY_USERS\S-1-5-21-823518204-688789844-725345543-1003\Software\XBTB01232\Toolbar\tb_items] "tbs_engine_menu_looksmart"=dword:00000001
Backup Your Registry with ERUNT
  • Please use the following link and download ERUNT.
    http://www.snapfiles.com/download/dlerunt.html

    Click the exe file to install it.
    During installation click no to backing up the registry every time windows starts.
    This is a bit of overkill.
Click start/all programs/ERUNT to start the program and backup your registry to a folder you use often to store things.




+++++++++++++++++++++++++++++++++
Open notepad up and copy everything exactly in the box below into it.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XBTB01232.XBTB01232]
@="-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XBTB01232.XBTB01232.1]
@="-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XBTB01232.XBTB01232Toolbar]
"DisplayName"=-

[HKEY_USERS\S-1-5-21-823518204-688789844-725345543-1003\Software\XBTB01232\SiteAllow]
"www.looksmart.com"=-
"listings.looksmart.com"=-
"search.looksmart.com"=-

[HKEY_USERS\S-1-5-21-823518204-688789844-725345543-1003\Software\XBTB01232\Toolbar]
"uninstallMsg"=-
"updateMsg"=-
"autoUpdateMsg"=-
"lastVersionMsg"=-
"contextMenuItemName"=-
"closeAllWindowsForUpdate"=-
"PopStop"=-
"firstURL"=-
"serverpath"=-
"urlAfterUpdate"=-
"urlAfterUninstall"=-
"contextSearch"=-
"AutoSearch"=-
"toolbar_version"=-

[-HKEY_USERS\S-1-5-21-823518204-688789844-725345543-1003\Software\XBTB01232\Toolbar\tb_items]

make sure to have no lines before
REGEDIT4

and

One (1) space before the end.
Now click on save and save TO YOUR DESKTOP

as "File Name" fix.reg

Save as File type "all files" NOT TXT DOCUMENT

Once saved double click the file you just made and when asked to merge with the registry click yes.

Now delete that file.

____________________________

Navigate to and delete the following folder .

c:/windows.program Files/Looksmart toolbar

This should be the end of that program.


___________________________

Reboot the machine and post last HJT log for me.
Let me know if you receive any new errors .
Logfile of HijackThis v1.99.1
Scan saved at 5:32:41 PM, on 7/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ati2sgag.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\VentSrv\ventrilo_svc.exe
C:\Program Files\VentSrv\ventrilo_srv.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\SOUNDMAN.EXE
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] "C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SDTray] C:\Program Files\Spyware Doctor\SDTrayApp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon…/cx_tgctlcm.jsp
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200401…meInstaller.exe
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://fastconnectkitsetup.cox.net/wizlet/…flowActiveX.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InstallTest - Unknown owner - C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\InstallTest.exe" /test (file missing)
O23 - Service: Metric Conversion Calculator Installer - Unknown owner - C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\MCCINST.EXE" /update (file missing)
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)


no errors, I got some time to sit down and play, it's running a lot better.
Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.
Please do these in the order I suggest!

___________________________________

Delete the !killbox.exe file on your desktop


________________________________
Go to start > run and copy and paste this in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the
system/hidden files and resets System Restore again.









A few things to help with possible threats

These are optional . But will help protect you further.
___________________________________

SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.


Here's a site with great advise on how to AVOID malware. Much easier to do than removing it.





Safe and Happy Surfing. :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI