We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Slow computer fix - Spamfighter
Comments
-
This is the bit above the spamfighter list...
ComboFix 09-06-16.05 - (name) 17/06/2009 15:52.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.382.121 [GMT 1:00]
Running from: c:\documents and settings\(name)\Desktop\qwerty.exe
Command switches used :: c:\my downloads\Notepad\CFScript.txt
AV: Norton 360 *On-access scanning disabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
FW: Norton 360 *disabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
Here's the rest...
((((((((((((((((((((((((( Files Created from 2009-05-17 to 2009-06-17 )))))))))))))))))))))))))))))))
.
2009-06-16 20:42 . 2009-06-16 21:05
d-s---w- C:\ComboFix
2009-06-15 14:33 . 2009-06-17 11:33 117760 ----a-w- c:\documents and settings\(name)\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-15 14:31 . 2009-06-15 14:31
d
w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-15 14:31 . 2009-06-15 14:31 65024 ----a-r- c:\documents and settings\(name)\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
2009-06-15 14:31 . 2009-06-15 14:31 18944 ----a-r- c:\documents and settings\(name)\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
2009-06-15 14:30 . 2009-06-15 14:30
d
w- c:\program files\SUPERAntiSpyware
2009-06-15 14:30 . 2009-06-15 14:30
d
w- c:\documents and settings\(name)\Application Data\SUPERAntiSpyware.com
2009-06-15 14:28 . 2009-06-15 14:28
d
w- c:\program files\Common Files\Wise Installation Wizard
2009-06-15 13:41 . 2009-06-15 13:42
d
w- c:\program files\Crawler
2009-06-15 13:41 . 2009-06-15 13:41 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2009-06-15 13:41 . 2009-06-15 13:41 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2009-06-15 13:41 . 2009-06-15 13:41 141312 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2009-06-15 13:41 . 2009-06-15 13:46
d
w- c:\documents and settings\(name)\Application Data\Spyware Terminator
2009-06-15 13:41 . 2009-06-15 13:41
d
w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-06-15 13:41 . 2009-06-15 13:45
d
w- c:\program files\Spyware Terminator
2009-06-15 12:11 . 2009-06-15 12:13
d
w- C:\32788R22FWJFW.0.tmp
2009-06-14 13:46 . 2009-06-14 13:46
d
w- c:\documents and settings\(name)\Application Data\Malwarebytes
2009-06-14 13:45 . 2009-05-26 12:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 13:45 . 2009-06-14 13:45
d
w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-14 13:45 . 2009-05-26 12:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-14 13:45 . 2009-06-14 13:46
d
w- c:\program files\Malwarebytes' Anti-Malware
2009-06-13 20:01 . 2009-06-13 20:01
d
w- c:\documents and settings\All Users\Application Data\Fighters
2009-06-12 22:01 . 2009-06-12 22:01
d
w- c:\windows\ie8updates
2009-06-12 18:44 . 2009-04-30 21:22 12800
w- c:\windows\system32\dllcache\xpshims.dll
2009-06-12 18:44 . 2009-04-30 21:22 246272
w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-12 17:44 . 2009-06-12 17:44 390664 ----a-w- c:\documents and settings\(name)\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-17 15:01 . 2008-06-01 12:17
d
w- c:\documents and settings\All Users\Application Data\Kontiki
2009-06-17 14:47 . 2006-04-24 06:25
d
w- c:\program files\Common Files\Symantec Shared
2009-06-16 14:28 . 2006-06-02 16:38 3624 ----a-w- c:\documents and settings\(name)\Application Data\wklnhst.dat
2009-06-01 12:59 . 2006-04-24 06:30
d
w- c:\program files\Google
2009-05-15 17:26 . 2009-05-15 17:26
d
w- c:\program files\Common Files\Application
2009-05-13 05:15 . 2004-08-04 08:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-04 08:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 19:44 . 2009-05-01 19:44
d
w- c:\program files\Common Files\xing shared
2009-05-01 19:44 . 2006-06-12 18:01
d
w- c:\program files\Common Files\Real
2009-05-01 19:43 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-04-17 12:26 . 2004-08-04 08:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 08:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 20:41 . 2009-04-09 20:41 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-03-31 21:46 . 2008-02-24 02:07 9584 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\NCO20.dll
2009-03-19 15:32 . 2009-03-19 15:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 15:32 . 2008-01-29 11:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-31 21:47 . 2008-07-28 08:12 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-09-14 15:04 . 2008-09-14 15:05 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-09-20 14:09 . 2008-04-17 13:40 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-09-20 14:09 . 2008-04-17 13:40 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-09-20 14:09 . 2008-04-17 13:40 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-09-20 14:09 . 2008-04-17 13:40 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-09-20 14:09 . 2008-04-17 13:40 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2006-07-30 12:55 . 2006-07-30 12:55 22 --sha-w- c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( [EMAIL="SnapShot@2009-06-15_13.01.25"]SnapShot@2009-06-15_13.01.25[/EMAIL] )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-17 11:32 . 2009-06-17 11:32 16384 c:\windows\Temp\Perflib_Perfdata_710.dat
+ 2009-06-17 11:21 . 2009-06-17 11:21 16384 c:\windows\Temp\Perflib_Perfdata_1b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-02-27 1032376]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-10 344064]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-22 405504]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"TIxDSL"="c:\progra~1\FREESE~1\BIN\WIN2K\tidslmon.exe" [2002-10-21 421888]
"D-Link AirPlus G"="c:\program files\D-Link\AirPlus G\AirGCFG.exe" [2005-11-23 1544192]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-10-19 49152]
"Share-to-Web Namespace Daemon"="c:\program files\HP\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 69632]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-14 29744]
"SmartDefrag"="c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2007-10-19 2736384]
"btbb_wcm_McciTrayApp"="c:\program files\btbb_wcm\McciTrayApp.exe" [2006-12-07 935936]
"btbb_McciTrayApp"="c:\program files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe" [2007-05-23 936960]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-01 198160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-08-17 439872]
c:\documents and settings\(name)\Start Menu\Programs\Startup\
WkCalRem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-6-23 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
BT Broadband Desktop Help.lnk - c:\program files\BT Broadband Desktop Help\bin\matcli.exe [2008-7-8 217088]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
hp psc 2000 Series.lnk - c:\program files\HP\Digital Imaging\bin\hpobnz08.exe [2002-6-27 323646]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
officejet 6100.lnk - c:\program files\HP\Digital Imaging\bin\hposol08.exe [2002-6-27 147456]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [26/05/2009 10:05 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [26/05/2009 10:05 72944]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [18/02/2008 20:37 149352]
R3 AtmElan;ATM Emulated LAN;c:\windows\system32\drivers\atmlane.sys [04/08/2004 09:00 55808]
R3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [13/01/2008 03:32 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [14/04/2009 18:38 101936]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [22/08/2005 10:06 231424]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [26/05/2009 10:05 7408]
R3 TIAU5CO;Copperjet ADSL modem connecting with Freeserve Broadband;c:\windows\system32\drivers\tiau5co.sys [01/06/2006 18:22 57093]
S2 gupdate1c9abe3fa07a260;Google Update Service (gupdate1c9abe3fa07a260);c:\program files\Google\Update\GoogleUpdate.exe [23/03/2009 19:19 133104]
S2 SPAMfighter Update Service;SPAMfighter Update Service;"c:\program files\SPAMfighter\sfus.exe" --> c:\program files\SPAMfighter\sfus.exe [?]
S3 AtmLane;ATM LAN Emulation;c:\windows\system32\drivers\atmlane.sys [04/08/2004 09:00 55808]
S3 Freeserve;TIDSLInstaller Device Driver;c:\windows\system32\drivers\instl.sys [01/06/2006 18:18 11878]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [11/02/2007 13:03 29744]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [14/06/2009 14:45 40160]
S3 TIAu5Bt;Copperjet ADSL modem Boot Device;c:\windows\system32\drivers\tiau5bt.sys [01/06/2006 18:22 11775]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:34]
2009-06-17 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-23 18:19]
2009-04-26 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\schedule.exe [2007-11-21 22:05]
2009-06-17 c:\windows\Tasks\User_Feed_Synchronization-{ACE5ED9C-5C7A-4F2F-BF45-27846BBDA8DC}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SPAMfighter Agent - c:\program files\SPAMfighter\SFAgent.exe
.
Supplementary Scan
.
uStart Page = hxxp://news.bbc.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Search
IE: Crawler Search - tbr:iemenu
TCP: {501E3199-A0C5-45A9-BE06-C748BCDB77E1} = 195.92.195.90 195.92.195.91
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
DPF: Microsoft XML Parser for Java - [URL]file:///C:/WINDOWS/Java/classes/xmldso.cab[/URL]
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-17 16:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????????n??|?????? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
DLLs Loaded Under Running Processes
- - - - - - - > 'winlogon.exe'(1348)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-06-17 16:06
ComboFix-quarantined-files.txt 2009-06-17 15:06
ComboFix2.txt 2009-06-16 21:04
ComboFix3.txt 2009-06-15 13:07
Pre-Run: 34,116,067,328 bytes free
Post-Run: 34,110,595,072 bytes free
597 --- E O F --- 2009-06-16 21:38I haven't bogged off yet, and I ain't no babe
0 -
bringing up task manger and selecting 'explorer.exe' should bring everything up as normal:idea:0
-
wheres 'spyware terminator' come from??:idea:0
-
-
Babe. Please tell me what youve done aside from the advice on here I already know of:idea:0
-
bringing up task manger and selecting 'explorer.exe' should bring everything up as normal
I am going to cry in a minute. I've got task manager up and found ieexplorer.exe in the applications tab, but clicking on it makes nothing happen. So I chose New Task and typed in www.explorer.exe but it brough up an error message, likewise when I tried it with www.ieexplorer.exe.
Please could you explain in simple terms what I am meant to do? To be honest I'm getting to the point of going to PC World and buying a new computer!I haven't bogged off yet, and I ain't no babe
0 -
-
goto new task and type (in RED only)
explorer.exe:idea:0 -
Uninstall (If you can) ~
spyware terminator
crawler (This one is a worry)
Download CCLEANER (Make sure you click 'DOWNLOAD LATEST VERSION' ~ make sure YAHOO TOOLBAR is unticked on installation)
http://www.filehippo.com/download_ccleaner/
Run the CLEANER scan
Then run the REGISTRY scan (Backup the registry when it asks)
Open malwarebytes, update and run a FULL scan:idea:0 -
goto new task and type (in RED only)
explorer.exe
I love you :T.
Now on to the tricky bits...
(Btw I realise you have a life to lead, and feel really guilty for all the time you are spending on helping me. Please just say if it all gets too much! I'm off to my other residence on Friday for 12 days, where I have a brilliant Asus mini-computer, so won't be bothering you after tomorrow!)I haven't bogged off yet, and I ain't no babe
0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 352K Banking & Borrowing
- 253.5K Reduce Debt & Boost Income
- 454.2K Spending & Discounts
- 245K Work, Benefits & Business
- 600.6K Mortgages, Homes & Bills
- 177.4K Life & Family
- 258.8K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.2K Discuss & Feedback
- 37.6K Read-Only Boards