Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

SpySheriff?


  • This topic is locked This topic is locked

#16
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Use this scanner:

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

When you started the topic, you reported issues with SpySheriff and it was about half way through when you mentioned the issues with IE. Was that the time when it started 'acting up' or has it been doing that for a while?
  • 0

Advertisements


#17
HaveAHeartRunaway

HaveAHeartRunaway

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
"Marc" - 07-01-26 2:02:21 Service Pack 2
ComboFix 07-01-25 - Running from: "C:\Documents and Settings\Marc\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-12-26 to 2007-01-26 ))))))))))))))))))))))))))))))))))


2007-01-25 20:20 <DIR> d-------- C:\WINDOWS\WBEM
2007-01-25 20:20 <DIR> d-------- C:\WINDOWS\SYSTEM32\en-US
2007-01-25 20:17 <DIR> d--h-c--- C:\WINDOWS\ie7
2007-01-25 20:14 121,856 --------- C:\WINDOWS\SYSTEM32\xmllite.dll
2007-01-25 20:13 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-01-25 20:09 15,505,200 --a------ C:\Program Files\IE7-WindowsXP-x86-enu.exe
2007-01-25 20:09 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Windows Genuine Advantage
2007-01-25 19:52 <DIR> d-------- C:\Program Files\System Security Suite 1.04
2007-01-25 18:07 57,344 --a------ C:\WINDOWS\SYSTEM32\COMMTB32.DLL
2007-01-25 18:07 169,984 --a------ C:\WINDOWS\SYSTEM32\P2D.DLL
2007-01-25 18:07 161,552 --a------ C:\WINDOWS\SYSTEM32\ASYCPICT.DLL
2007-01-25 11:16 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgArCln.sys
2007-01-25 01:32 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-01-25 01:32 <DIR> d-------- C:\DOCUME~1\Marc\Application Data\SUPERAntiSpyware.com
2007-01-25 01:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\SUPERAntiSpyware.com
2007-01-25 01:31 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-01-25 01:07 2,904 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-01-24 22:30 <DIR> d-------- C:\Program Files\HijackThis
2007-01-24 20:02 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgclean.sys
2007-01-24 20:02 18,240 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys
2007-01-24 14:42 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-01-22 20:54 <DIR> d-------- C:\WINDOWS\SYSTEM32\bak
2007-01-18 06:00 5,632 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgarkt.sys
2007-01-11 12:49 <DIR> d-------- C:\New Folder
2007-01-08 15:20 13,864 --a------ C:\Program Files\googletoolbardownloader_en_signed.exe
2006-12-31 13:25 5,632 --a------ C:\WINDOWS\SYSTEM32\ptpusb.dll
2006-12-31 13:25 159,232 --a------ C:\WINDOWS\SYSTEM32\ptpusd.dll
2006-12-31 13:25 15,104 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbscan.sys
2006-12-30 18:09 <DIR> d-------- C:\Program Files\Common Files\Canon
2006-12-30 18:09 <DIR> d-------- C:\Program Files\Canon


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-25 19:05 -------- d-------- C:\Program Files\messenger
2007-01-25 19:04 -------- d-------- C:\Program Files\google
2007-01-25 11:16 -------- d-------- C:\Program Files\grisoft
2007-01-24 20:02 816672 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avg7core.sys
2007-01-24 20:02 4224 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avg7rsw.sys
2007-01-24 20:02 28416 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avg7rsxp.sys
2007-01-24 19:59 -------- d-------- C:\Program Files\snood
2007-01-24 19:57 -------- d-------- C:\DOCUME~1\Marc\Application Data\lavasoft
2007-01-24 19:54 44288 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\cdr4_xp.sys
2007-01-22 21:26 -------- d-------- C:\Program Files\quicktime
2007-01-22 21:26 -------- d-------- C:\Program Files\itunes
2007-01-22 21:26 -------- d-------- C:\Program Files\dell support
2007-01-22 21:26 -------- d-------- C:\Program Files\aim
2007-01-22 21:24 24588 --a------ C:\WINDOWS\SYSTEM32\nerocheck.exe
2007-01-22 21:24 24588 --a------ C:\WINDOWS\SYSTEM32\lxsupmon.exe
2007-01-22 21:24 24588 --a------ C:\WINDOWS\SYSTEM32\dsentry.exe
2007-01-08 15:22 -------- d-------- C:\DOCUME~1\Marc\Application Data\google
2006-12-28 15:19 -------- d-------- C:\Program Files\movies
2006-12-25 23:58 -------- d-------- C:\Program Files\musicmatch
2006-12-07 00:40 2362184 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-12-04 22:27 -------- d-------- C:\DOCUME~1\Marc\Application Data\leadertech
2006-12-04 22:27 -------- d-------- C:\DOCUME~1\Marc\Application Data\adobe
2006-11-29 20:06 -------- d---s---- C:\DOCUME~1\Marc\Application Data\microsoft
2006-11-18 18:48 225280 --a------ C:\PlayerHost.dll
2006-11-07 23:06 679424 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\SYSTEM32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\SYSTEM32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\SYSTEM32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\SYSTEM32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\SYSTEM32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\SYSTEM32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\SYSTEM32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\SYSTEM32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\SYSTEM32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\SYSTEM32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\SYSTEM32\msxml4.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"BCMSMMSG"="BCMSMMSG.exe"
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"LXSUPMON"="C:\\WINDOWS\\system32\\LXSUPMON.EXE RUN"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DirectCD"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAZAA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KazaaLite"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Kazaa Lite K++\\kpp.exe\" \"C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp\" /SYSTRAY"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mm_tray"
"hkey"="HKLM"
"command"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"_NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0


Completion time: 07-01-26 2:04:44
  • 0

#18
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP

When you started the topic, you reported issues with SpySheriff and it was about half way through when you mentioned the issues with IE. Was that the time when it started 'acting up' or has it been doing that for a while?


  • 0

#19
HaveAHeartRunaway

HaveAHeartRunaway

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Out of bad habit, I don't reboot my computer often. Every now and again it will start to slow down. Afte rebooting, it will typically speed up again.
However,
The other morning SpySheriff showed up, things slowed down, and remained slow and unable to open programs. I did reboot and ran some scans, all of which showed nothing.
Since then my life has been miserable.

So it was the morning when SpySheriff showed up that all of my issues truly began.
  • 0

#20
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
I can't see anything that could be causing this. Try one more scan - please do an online scan with Kaspersky WebScanner.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

  • 0

#21
HaveAHeartRunaway

HaveAHeartRunaway

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
I'm having trouble running this scan.

"
Failed to load Kaspersky Online Scanner ActiveX control!

You must have administrative rights on this computer;
you also must have the IE security settings to the Medium level. "

My settings are down to minimum.
I cannot completely verify that I have administrator rights.
-I went into Control Panel and Computer Management, then to System Tools-- but there is no folder for 'Local Users and Groups' to be found...That leads me to assume I must be, but then why the former issue..

Quick fix?
  • 0

#22
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Have you set IE security to Medium?
  • 0

#23
HaveAHeartRunaway

HaveAHeartRunaway

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Yes.
  • 0

#24
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Apologies for the delay getting back to you - I have the flu. I'll respond again when I'm back on my feet.
  • 0

#25
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
OK, I'm back - do you still require assistance?
  • 0

Advertisements


#26
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP