This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Explorer pages freezing after 5mins...please help

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok Tomk…….will do and thanks for staying with it this eve……that very kind an helpful speak later tomorrow (Sorry…cant seem to work my smilies)….least of my probs though! A
Hello Tomk Things seem to be looking up re recent problems. Not as sluggis as its been recently, so good news there….. ready to continue when you are, I would also like to clear any programs other software that is unusedon my pc. Can you tell what I do or dont need from my hijack?…if so please advise regards Andy
andreas,

Good to hear things are better. :thumbup:

Here are some things we can "fix" that are unnecessary. They aren't bad, but they don't need to run at startup.

We must disable certain protection programs that may interfere with our fix:
AVAST
Right click on the avast! icon in system tray (looks like this: [external image: Posted Image]) and choose (Stop On-Access Protection)

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

With that done, Log looks good :D

Please restart your Avast.

You need to create a new Clean restore point.
Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.


Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates. This is very important for you. You need to at least get updated to SP2. SP3 is out and I know of no reason why you shouldn't update straight to SP3. That can be done by going here.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

Using IE-SPYAD to help block unwanted sites and activities

Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Please respond that you understand the above and/or if you have any questions. Being none, I'll close this thread resolved. :thumbup:
Hi Tomk Sorry its taken so long….. I had problems with the disc cleaning….after nearly two hours i realised something was jammed so started again but same problem so its all done except that. I have managed to download the programms you have advised. You will see from my hijack log that i already have Avast antivirus and commodo firewall, also have superantispyware. I trust the programms I have downloaded wont clash in any way with the ones I already have? If you require a final hijack log just say and ill post you one. also, my outlook express is performing poorly since this morning, getting messages back saying 'message sending failed'. Is there something that needs regulating since the recent changes? ok tomk…..I'll look out for your reply on a regular basis. In the maeantime I will start running some of these new downloads. Many thanks.. andreas
andreas,

Nothing in the recommendations that I gave you should conflict.

I don't know much about Outlook Express. I don't believe that anything we did should have effected it but I can't be sure. :blush:
I would suggest that you start a new topic here and ask the Tech Experts for advise. If you do this, please provide them a link to this topic in your post so that they can see what was done.

seem to have 3 anti spyware programms now…..but will run them seperately.

They are similar but do different things. These "new" programs will run on their own in the background. You just need to check for updates from time to time.

I'm glad we could help.

Good Luck and be well. :thumbup:
Tomk Im having poblems with a couple of your suggestions:- Your instruction was…. 'At top, click on More Options tab. Click Clean Up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.)……………… ………….There is only an 'OK 'or 'cancel' option here, there is no 'more options' or 'system restore' box. When I click ok to 'run', i t shows a box with a timer bar, but the bar doesnt show progress….sarted it last night and was the same this morning. Also Im having problems with the 'ie spyad' I downloaded. I had to download a programm called zoneout, but I think these have to be worked together somehow….cant get them to work…..could you shed some light on this please? thankyou andreas
andreas,

cleanmgr should take only a few seconds for the progress bar to finish and then the window with the tabs will come up. Try it again. If it "hangs" and doesn't move on after 5 minutes, hit cancel. Reboot (shut-off and restart) your computer and then try again a couple of times if necessary. Please let me know if you are still unsuccessful.

As far as IE-SPYAD goes, have a look at this link for instructions.
Sorry Tomk
after clicking r'un' the progress bar jams with a little progress showing.

Have given up on the iespyad and zoneout as there are no clear instructions or startups that start anything. Have therefore uninstalled all the bits that were downloaded. Im usually ok with downloads and startups, but this one takes the biscuit for complicated!

Could you take a look at the below hijack as my comp is now delaying on every command I make….the hour glass timer just stays on for around 30 seconds or so…even having to restart every so often as it just freezes….AAhh

ThANKYOU
A

Logfile of HijackThis v1.99.1
Scan saved at 16:55:09, on 24/07/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Silvercrest OM1007 driver\StartAutorun.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Silvercrest OM1007 driver\KMConfig.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Silvercrest OM1007 driver\KMProcess.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Silvercrest OM1007 driver\KMWDSrv.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Andreas\Desktop\Hijack This\HijackThis2.exe

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Silvercrest OM1007 driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BE07A3C-C870-4952-98E2-77ED80999B76}: NameServer = 83.146.21.6 212.158.249.5
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Silvercrest OM1007 driver\KMWDSrv.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
andreas,

I'm not seeing the problem but lets dig a little deeper.


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

AVAST
Right click on the avast! icon in system tray (looks like this: [external image: Posted Image]) and choose (Stop On-Access Protection)


C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Tomk
Here is the combofix from the run menu, ….also my avast icon has disappeared from bottom right, so cant turn it back on!
Hijack at the bottom
A

ComboFix 08-07-23.5 - Andreas 2008-07-24 19:22:14.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.234 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-06-24 to 2008-07-24 )))))))))))))))))))))))))))))))
.

2008-07-23 00:16 . 2008-07-23 00:16 d——– C:\Program Files\BillP Studios
2008-07-23 00:16 . 2008-07-23 00:16 d——– C:\Documents and Settings\Andreas\Application Data\WinPatrol
2008-07-22 23:56 . 2008-07-22 23:56 d——– C:\ie-spyad_zo
2008-07-22 23:37 . 2008-07-24 00:15 d——– C:\Program Files\Spyware Terminator
2008-07-22 23:37 . 2008-07-23 00:36 d——– C:\Documents and Settings\Andreas\Application Data\Spyware Terminator
2008-07-22 23:37 . 2008-07-23 04:22 d——– C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-07-22 23:37 . 2008-07-22 23:37 141,312 –a—— C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-07-21 20:53 . 2008-07-21 20:53 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-07-21 20:53 . 2008-07-21 20:53 d——– C:\Documents and Settings\Andreas\Application Data\Malwarebytes
2008-07-21 20:53 . 2008-07-21 20:53 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-21 20:53 . 2008-07-20 20:21 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-21 20:53 . 2008-07-20 20:21 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-21 19:16 . 2001-07-09 12:50 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2008-07-21 18:00 . 2008-07-21 18:00 0 –a—-t- C:\WINDOWS\000001_.tmp
2008-07-21 16:46 . 2008-07-21 16:46 d——– C:\WINDOWS\ServicePackFiles
2008-07-21 16:46 . 2008-07-21 16:46 d——– C:\WINDOWS\ehome
2008-07-21 16:45 . 2002-08-29 09:09 5,504 ——— C:\WINDOWS\system32\drivers\smbali.sys
2008-07-21 16:41 . 2002-08-29 11:40 377,984 ——— C:\WINDOWS\system32\ati2dvaa.dll
2008-07-21 16:41 . 2002-04-16 05:11 67,866 ——— C:\WINDOWS\system32\drivers\netwlan5.img
2008-07-21 16:35 . 2002-08-29 09:32 17,792 ——— C:\WINDOWS\system32\drivers\irbus.sys
2008-07-21 16:20 . 2008-07-21 16:20 d——– C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-07-17 17:41 . 2008-07-17 17:41 d——– C:\Program Files\GNU
2008-07-17 17:30 . 2008-07-17 17:48 d——– C:\Program Files\GRETECH
2008-07-16 21:33 . 2008-07-16 21:33 d——– C:\Program Files\Common Files\Vbox
2008-07-16 15:45 . 2008-07-24 17:08 d——– C:\Documents and Settings\Andreas\Application Data\dvdcss
2008-07-16 15:44 . 2008-07-16 15:44 d——– C:\Documents and Settings\Andreas\Application Data\vlc

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-24 18:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-07-21 19:24 ——— d—–w C:\Program Files\SUPERAntiSpyware
2008-07-21 19:24 ——— d—–w C:\Program Files\QuickTime
2008-07-21 19:24 ——— d—–w C:\Program Files\Lexmark X1100 Series
2008-07-21 15:21 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-17 17:35 ——— d—–w C:\Program Files\Yahoo!
2008-05-29 17:29 ——— d—–w C:\Program Files\Common Files\xing shared
2008-05-29 17:29 ——— d—–w C:\Program Files\Common Files\Real
2008-03-28 12:00 21,960 —-a-w C:\Documents and Settings\Andreas\Application Data\GDIPFONTCACHEV1.DAT
2007-09-22 12:26 16,309,944 —-a-w C:\Program Files\AVAST setupeng.exe
2007-09-05 00:09 1,281,060 —-a-w C:\Documents and Settings\Andreas\az.exe
.

((((((((((((((((((((((((((((( snapshot@2008-07-24_18.50.56.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-24 18:25:51 16,384 —-atw C:\WINDOWS\temp\Perflib_Perfdata_490.dat
+ 2008-07-24 18:26:29 16,384 —-atw C:\WINDOWS\temp\Perflib_Perfdata_e8.dat
+ 2008-07-24 18:26:35 40,960 —-a-w C:\WINDOWS\temp\rtdrvmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 04:41 13312]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-29 11:41 1511453]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-05 10:29 1506544]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-07 10:32 68856]
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 12:23 1032640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-03-28 14:18 57344]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 12:22 7700480]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-10-22 12:22 86016]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-09-22 13:33 1115728]
"KMCONFIG"="C:\Program Files\Silvercrest OM1007 driver\StartAutorun.exe" [2007-03-06 15:51 212992]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 12:23 1032640]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-07-04 17:58 333120]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 04:41 13312]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-20 23:09:58 110592]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-27 23:40 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2007-05-25 15:22 63040 C:\WINDOWS\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=NVDESK32.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SmcService"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

R1 aswSP;avast! Self Protection;C:\WINDOWS\System32\drivers\aswSP.sys [2008-07-19 15:35]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\System32\drivers\sp_rsdrv2.sys [2008-07-22 23:37]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service;C:\Program Files\Silvercrest OM1007 driver\KMWDSrv.exe [2007-06-16 10:30]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\System32\drivers\LMIRfsDriver.sys [2007-04-05 11:55]
S2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-07-19 13:05:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.co.uk/
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie
R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-24 19:26:45
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Silvercrest OM1007 driver\KMCONFIG.exe
C:\Program Files\Silvercrest OM1007 driver\KMProcess.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
.
**************************************************************************
.
Completion time: 2008-07-24 19:31:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-24 18:31:04
ComboFix2.txt 2008-07-24 17:59:21
ComboFix3.txt 2008-07-24 17:51:38

Pre-Run: 61,352,419,328 bytes free
Post-Run: 61,342,076,928 bytes free

157


Logfile of HijackThis v1.99.1
Scan saved at 19:41, on 2008-07-24
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Silvercrest OM1007 driver\KMWDSrv.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Silvercrest OM1007 driver\StartAutorun.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Silvercrest OM1007 driver\KMConfig.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Silvercrest OM1007 driver\KMProcess.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Andreas\Desktop\Hijack This\HijackThis2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Silvercrest OM1007 driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BE07A3C-C870-4952-98E2-77ED80999B76}: NameServer = 83.146.21.6 212.158.249.5
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Silvercrest OM1007 driver\KMWDSrv.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
andreas,

Sorry. I'm not seeing anything to cause your problems. :wacko:

I suggest you do this:
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Then

Uninstall Avast and then reinstall it. Please download the install file before uninstalling. It can be found here

Next

Go to windows update and get SP3 installed. That can be done by going here.

If after that you are still having problems. Please start a new thread in the windows forum and ask the Tech Experts for help. If you do that, please provide a link to this topic in your post so they will have as much information as possible.
andreas,

If you are having troubles with your windows update, please try this:

Download the diagnostic tool MGADiag and save it to your desktop.

  • Double-click on MGADiag.exe.
  • Click Run and Run again.
  • Click Continue, then Copy.
  • Paste the report in your next reply.
andreas,

Based upon the following Diagnostics report that you PM'd to me:

Diagnostic Report (1.7.0095.0):
—————————————–
WGA Data–>
Validation Status: Invalid Product Key
Validation Code: 8
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-GVGFH-XCY66-WDYQ3
Windows Product Key Hash: zj3bBnd5RPJbiRX/4xk7+LKkUDU=
Windows Product ID: 55274-642-4311057-23971
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.1.0.pro
CSVLK Server: N/A
CSVLK PID: N/A
ID: {E77A548B-5B74-41BA-B2CD-A5DEAD056093}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1
Resolution Status: N/A

WgaER Data–>
ThreatID(s): N/A
Version: N/A

WGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data–>
Office Status: 114 Blocked VLK 2
Microsoft Office XP Professional with FrontPage - 114 Blocked VLK 2
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-171-1

Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data–>

Other data–>
Office Details: {E77A548B-5B74-41BA-B2CD-A5DEAD056093}1.7.0095.05.1.2600.2.00010100.1.0.prox32*****-*****-*****-*****-WDYQ355274-642-4311057-239711S-1-5-21-484763869-796845957-725345543Dell Computer CorporationDimension 4300 Dell Computer CorporationA0420011207******.******+***7CF23A8F0184C05E08090409GMT Standard Time(GMT+00:00)03 114

Not only is the product key for your windows a well known pirated version, but your Microsoft Office is also running on a pirated key.
Please read forum policy here.

Without a valid copy of windows and Microsoft Office, you will be unable to get updates which leaves you extremely vulnerable to malware. It also severely reduces the likelihood of receiving help on forums such as this one.

This topic will now be closed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI