Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


So many viruses and at the end of my tether

  • This topic is locked This topic is locked
4 replies to this topic

#1 bittybotty


  • Members
  • 11 posts
  • Local time:01:07 PM

Posted 10 April 2010 - 06:15 AM


Further information here: http://www.bleepingcomputer.com/forums/t/308354/so-many-viruses-and-problems-urgently-need-help/ ~ OB

I have had the ave.exe virus. Sdra64.exe virus, inst.exe virus. Been through removal and things are getting worse.

The computer locks up all the time. I get an error when I try and run HJT. I cannot execute programs properly.
I can't get into safe mode as I get a message saying "Press enter to continue loading SPTD.sys"

I have it running in diagnostic mode at the moment however, for some reason some services i.e windows messenger are loading on their own.

I managed to do a log a while ago but I have managed to go through it, however, seen as its the only one I still have. Here it is


This log file is located at C:rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Ryan on 09/04/2010 at 17:07:10.

Processes terminated by Rkill or while it was running:

C:Program FilesGoogleUpdateGoogleUpdate.exe

Rkill completed on 09/04/2010 at 17:07:17.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:37:44, on 09/04/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
C:Documents and SettingsRyanApplication Datasdra64.exe
C:Program FilesGoogleUpdateGoogleUpdate.exe
C:Program FilesJavajre6binjusched.exe
C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe
C:Program FilesSpyware DoctorpctsTray.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
C:Program FilesAdobeReader 9.0ReaderReader_sl.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesWindows LiveMessengermsnmsgr.exe
C:Program FilesDAEMON Tools LiteDTLite.exe
C:Program FilesSlySoftAnyDVDAnyDVDtray.exe
C:Program FilesGoogleUpdateGoogleUpdate.exe
C:Program FilesJavajre6binjqs.exe
C:Program FilesGoogleUpdateGoogleUpdate.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesTrend MicroHijackThisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.homecall.co.uk/
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe,C:Documents and SettingsRyanApplication Datasdra64.exe,C:WINDOWSsystem32sdra64.exe,
O1 - Hosts: ECHO is on.
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6binjp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O4 - HKLM..Run: [notepad] rundll32.exe C:WINDOWSsystem32notepad.dll,_IWMPEvents@0
O4 - HKLM..Run: [UserFaultCheck] %systemroot%system32dumprep 0 -u
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre6binjusched.exe"
O4 - HKLM..Run: [snpstd3] C:WINDOWSvsnpstd3.exe
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [ISUSScheduler] "C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe" -start
O4 - HKLM..Run: [ISTray] "C:Program FilesSpyware DoctorpctsTray.exe"
O4 - HKLM..Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM..Run: [avgnt] "C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" /min
O4 - HKLM..Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 9.0ReaderReader_sl.exe"
O4 - HKCU..Run: [notepad] rundll32.exe C:DOCUME~1NETWOR~1ntload.dll,_IWMPEvents@0
O4 - HKCU..Run: [msnmsgr] "C:Program FilesWindows LiveMessengermsnmsgr.exe" /background
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [RegistryMechanic] C:Program FilesRegistry MechanicRegMech.exe /H
O4 - HKCU..Run: [DAEMON Tools Lite] "C:Program FilesDAEMON Tools LiteDTLite.exe" -autorun
O4 - HKCU..Run: [AnyDVD] C:Program FilesSlySoftAnyDVDAnyDVDtray.exe
O4 - HKCU..PoliciesExplorerRun: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKUSS-1-5-21-583907252-1993962763-725345543-1005..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'postgres')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra button: Ladbrokes Casino - 85635E0E-231E-4DBB-94D5-83A18E90FBEA - C:MicrogamingCasinoLadbrokesCasinogame.exe (HKCU)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:Program FilesJavajre6binjqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:Program FilesPostgreSQL8.3binpg_ctl.exe
O23 - Service: wampapache - Apache Software Foundation - c:wampbinapacheapache2.2.11binhttpd.exe
O23 - Service: wampmysqld - Unknown owner - c:wampbinmysqlmysql5.1.36binmysqld.exe

End of file - 7984 bytes

Managed to get DDS to work. Here are the logs. Attach is attached

DDS (Ver_10-03-17.01) - NTFSx86
Run by Ryan at 13:28:11.32 on 10/04/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13

============== Running Processes ===============

============== Pseudo HJT Report ===============

uStart Page = www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
uInternet Connection Wizard,ShellNext = hxxp://www.homecall.co.uk/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:program filescommon filesmicrosoft sharedwindows liveWindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:program filesjavajre6binjp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll
uRun: [notepad] rundll32.exe c:docume~1networ~1ntload.dll,_IWMPEvents@0
uRun: [MSMSGS] "c:program filesmessengermsmsgs.exe" /background
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
mRun: [notepad] rundll32.exe c:windowssystem32notepad.dll,_IWMPEvents@0
mRun: [UserFaultCheck] %systemroot%system32dumprep 0 -u
mRun: [TkBellExe] "c:program filescommon filesrealupdate_obrealsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:program filesjavajre6binjusched.exe"
mRun: [snpstd3] c:windowsvsnpstd3.exe
mRun: [QuickTime Task] "c:program filesquicktimeqttask.exe" -atboottime
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:windowssystem32NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:windowssystem32NvCpl.dll,NvStartup
mRun: [ISUSScheduler] "c:program filescommon filesinstallshieldupdateserviceissch.exe" -start
mRun: [ISUSPM Startup] c:progra~1common~1instal~1update~1ISUSPM.exe -startup
mRun: [ISTray] "c:program filesspyware doctorpctsTray.exe"
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [avgnt] "c:program filesaviraantivir personaledition classicavgnt.exe" /min
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe Reader Speed Launcher] "c:program filesadobereader 9.0readerReader_sl.exe"
dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE
uExplorerRun: [MSMSGS] "c:program filesmessengermsmsgs.exe" /background
uPolicies-explorer: DisallowRun = 1 (0x1)
uPolicies-disallowrun: 1 = firefox.exe
uPolicies-disallowrun: 2 = opera.exe
uPolicies-disallowrun: 3 = chrome.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~2office11REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll
IFEO: RapportMgmtService.exe - ZASRAKOMONDOHUI31338.EXE
IFEO: RapportService.exe - ZASRAKOMONDOHUI31338.EXE

================= FIREFOX ===================

FF - ProfilePath - c:docume~1ryanapplic~1mozillafirefoxprofilesqoni6mab.default
FF - prefs.js: browser.startup.homepage - hxxp://forums.moneysavingexpert.com/
FF - plugin: c:documents and settingsryanapplication datamozillafirefoxprofilesqoni6mab.defaultextensions{4d144bc3-23fb-47de-90c5-63ccb0139ccf}pluginsnpww.dll
FF - plugin: c:program filesgooglegoogle earthpluginnpgeplugin.dll
FF - plugin: c:program filesgoogleupdate1.2.183.23npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsmicrosoft.netframeworkv3.5windows presentation foundationdotnetassistantextension
FF - HiddenExtension: Java Console: No Registry Reference - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

=============== Created Last 30 ================

2010-04-10 12:00:47 0 d-----w- C:VundoFix Backups
2010-04-10 11:46:38 0 d-----w- c:program filescommon filesWise Installation Wizard
2010-04-09 11:16:35 0 ----a-w- c:documents and settingsryanCD
2010-04-09 11:08:32 87784 ----a-w- c:windowssystem32driversPCTAppEvent.sys
2010-04-09 11:08:32 7412 ----a-w- c:windowssystem32driversPCTAppEvent.cat
2010-04-09 11:08:32 7383 ----a-w- c:windowssystem32driverspctcore.cat
2010-04-09 11:08:32 207280 ----a-w- c:windowssystem32driversPCTCore.sys
2010-04-09 11:08:28 7383 ----a-w- c:windowssystem32driverspctplsg.cat
2010-04-09 11:08:28 70408 ----a-w- c:windowssystem32driverspctplsg.sys
2010-04-09 11:08:19 0 d-----w- c:program filesSpyware Doctor
2010-04-09 11:08:19 0 d-----w- c:program filescommon filesPC Tools
2010-04-09 11:08:19 0 d-----w- c:docume~1ryanapplic~1PC Tools
2010-04-09 11:08:19 0 d-----w- c:docume~1alluse~1applic~1PC Tools
2010-04-08 21:31:05 823808 ----a-w- c:windowssystem32driverslkkmfj.sys
2010-04-08 21:29:29 0 d-----w- C:spoolerlogs
2010-04-05 15:39:16 0 d-----w- c:program filesBetTraderEvolution
2010-04-05 15:39:16 0 d-----w- c:docume~1ryanapplic~1BetTraderEvolution
2010-04-05 15:37:37 0 d-----w- c:program filesEvoTray
2010-04-05 15:37:36 0 d-----w- c:docume~1ryanapplic~1EvoTray
2010-03-25 16:36:22 0 d-----w- c:program filesEnigma Software Group
2010-03-11 20:22:24 0 d-----w- C:wamp

==================== Find3M ====================

2010-03-29 14:24:46 20824 ----a-w- c:windowssystem32driversmbam.sys
2009-03-21 14:06:58 34304 --sha-w- c:windowssystem32notepad.dll

============= FINISH: 13:29:19.17 ===============

Merged posts. ~ OB

Attached Files

Edited by Orange Blossom, 11 April 2010 - 03:25 PM.

BC AdBot (Login to Remove)


#2 extremeboy


  • Malware Response Team
  • 12,975 posts
  • Gender:Male
  • Local time:08:07 AM

Posted 12 April 2010 - 09:06 PM


My name is Extremeboy (or EB for short), and I will be helping you with your log. I apologize for the delay.

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a GMER log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or GMER log please refer to this page and in step #6 and Step #7 and Step #8 for further instructions on downloading and running DDS & GMER. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.

For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-GMER log
-Description of any remaining problems you may still have.

With Regards,
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 bittybotty

  • Topic Starter

  • Members
  • 11 posts
  • Local time:01:07 PM

Posted 13 April 2010 - 08:53 AM

I had no choice but to format the drive. It wouldn't even boot anymore.

At time of writing I am trying to format and re-install windows. I managed to hook it up to a laptop as a slave to backup vital files.

However I have had a couple of problems when trying to do so.

#4 extremeboy


  • Malware Response Team
  • 12,975 posts
  • Gender:Male
  • Local time:08:07 AM

Posted 13 April 2010 - 03:59 PM

Sorry, that we couldn't help you any more. Although, I'm glad you were able to fix it and salvage your important files.

Is there anything else since you mentioned you had some problems? If not, let me know and I'll close off this topic.


Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#5 extremeboy


  • Malware Response Team
  • 12,975 posts
  • Gender:Male
  • Local time:08:07 AM

Posted 08 May 2010 - 11:48 AM


Due to Lack of feedback, this topic is now Closed

If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic.

With Regards,
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users