This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Rundll, Spyware Guard And Trojan Horse Issues. Please Help!

46 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've tried running the scan in safe mode, but it still comes up Not Responding when it begins scanning the Run Keys. Incidentally, what options should be selected on the lefthand side? Maybe it has something to do with that. I've noticed you can still minimise and expand WinPFind3U as if its still running. How long should I be leaving the program to scan exactly?
Hi

Try this:
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
    • In the Files Created Within group click 30 days
    • In the Files Modified Within group select 30 days
    • In the File String Search group select Non-Microsoft
  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in.
I hate to say this, but all those options have been set to default as soon as I open WinpFind3u, so I've been running scans with those selected already. Maybe they need to be modified coz clearly it refuses to keep going when it gets to Run Keys. I dont know if this is relevant, but in the task manager, it seems to come up as 2 WinpFind3u tasks that are Not Responding and it will be keep going up to 99 CPU and stuck on 5628Kb memory usage. I'm sorry this is taking longer than it should've to get a scan happening, it's frustrating for me as well :P
Nah, it still comes up as not responding despite ending the tasks manually and restarting the program several times. It must'nt be compatible with my system or something. I think trying another scanner is the go
Hi

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post. in your reply
Deckard's System Scan ran with no problems, yay :). Here are the 2 logs:

Main Log

Deckard's System Scanner v20070328.36
Run by [removed] on 2007-04-06 at 10:03:56
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
11: 2007-04-06 00:04:05 UTC - RP466 - Deckard's System Scanner Restore Point
10: 2007-04-05 00:24:10 UTC - RP465 - Software Distribution Service 2.0
9: 2007-04-04 06:28:07 UTC - RP464 - System Checkpoint
8: 2007-04-02 11:32:43 UTC - RP463 - Removed J2SE Runtime Environment 5.0 Update 9
7: 2007-04-02 11:30:56 UTC - RP462 - Removed J2SE Runtime Environment 5.0 Update 8


– First Restore Point –
1: 2007-03-31 07:29:10 UTC - RP456 - System Checkpoint


Performed disk cleanup.


– HijackThis (run as michael.exe) ———————————————

Logfile of HijackThis v1.99.1
Scan saved at 10:04:22 AM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Programs\Avast!\aswUpdSv.exe
D:\Programs\Avast!\ashserv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\svchost.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
D:\programs\Quicktime\qttask.exe
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
D:\Programs\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\michael\Desktop\dss.exe
D:\Programs\HIJACK~1\michael.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: (no name) - {5A061C36-916E-417C-9434-4EAA3A09C01C} - C:\WINDOWS\system32\mllkh.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7D064D71-DD76-4596-90C0-921766AD560A} - C:\WINDOWS\system32\pmnkijg.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9A5942DD-EE9C-406B-96C1-919FA763BE25} - C:\WINDOWS\system32\ddccd.dll
O2 - BHO: (no name) - {B508CBF1-6B54-4603-8C23-C305C486B8A8} - C:\WINDOWS\system32\gebab.dll (file missing)
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\dqjyaggm.dll",setvm
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ddccd - C:\WINDOWS\system32\ddccd.dll
O20 - Winlogon Notify: pmnkijg - C:\WINDOWS\SYSTEM32\pmnkijg.dll
O20 - Winlogon Notify: pmnmmkh - C:\WINDOWS\SYSTEM32\pmnmmkh.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


– HijackThis Fixed Entries (D:\Programs\HIJACK~1\backups\) ——————–

backup-20051207-132932-119 O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - http://akamai.downloadv3.com/binaries/IA/dtc32_EN_XP.cab
backup-20051207-132932-133 O1 - Hosts: 64.233.167.104 liveupdate.symantecliveupdate.com
backup-20051207-132932-138 O1 - Hosts: 64.233.167.104 customer.symantec.com
backup-20051207-132932-155 O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} - http://akamai.downloadv3.com/binaries/IA/netia32_EN_XP.cab
backup-20051207-132932-198 O1 - Hosts: 64.233.167.104 www.kaspersky.com
backup-20051207-132932-211 O1 - Hosts: 64.233.167.104 sandbox.norman.no
backup-20051207-132932-227 O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe
backup-20051207-132932-230 O1 - Hosts: 64.233.167.104 nai.com
backup-20051207-132932-302 O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
backup-20051207-132932-303 O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
backup-20051207-132932-327 O1 - Hosts: 64.233.167.104 ca.com
backup-20051207-132932-342 O1 - Hosts: 64.233.167.104 dispatch.mcafee.com
backup-20051207-132932-362 O1 - Hosts: 64.233.167.104 mcafee.com
backup-20051207-132932-391 O1 - Hosts: 64.233.167.104 us.mcafee.com
backup-20051207-132932-408 R3 - Default URLSearchHook is missing
backup-20051207-132932-420 O1 - Hosts: 64.233.167.104 www.my-etrust.com
backup-20051207-132932-434 O1 - Hosts: 64.233.167.104 avp.com
backup-20051207-132932-437 O4 - HKLM\..\Run: [RVP] "C:\Program Files\RVP\bpc.exe"
backup-20051207-132932-441 O1 - Hosts: 64.233.167.104 mast.mcafee.com
backup-20051207-132932-444 O1 - Hosts: 64.233.167.104 www.avp.com
backup-20051207-132932-451 O1 - Hosts: 64.233.167.104 www.f-secure.com
backup-20051207-132932-459 O1 - Hosts: 64.233.167.104 www.ca.com
backup-20051207-132932-462 O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
backup-20051207-132932-477 O4 - HKLM\..\Run: [WinFixer 2005] D:\Programs\WinFixer 2005\wfx5.exe
backup-20051207-132932-498 O1 - Hosts: 64.233.167.104 f-secure.com
backup-20051207-132932-523 O1 - Hosts: 64.233.167.104 updates.symantec.com
backup-20051207-132932-580 O1 - Hosts: 64.233.167.104 www.grisoft.com
backup-20051207-132932-602 O1 - Hosts: 64.233.167.104 grisoft.com
backup-20051207-132932-615 O1 - Hosts: 64.233.167.104 viruslist.com
backup-20051207-132932-623 O1 - Hosts: 64.233.167.104 update.symantec.com
backup-20051207-132932-629 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
backup-20051207-132932-644 O4 - HKLM\..\Run: [Wast] C:\WINDOWS\Wast
backup-20051207-132932-650 O1 - Hosts: 64.233.167.104 www.pandasoftware.com
backup-20051207-132932-661 O1 - Hosts: 64.233.167.104 www.nai.com
backup-20051207-132932-706 O1 - Hosts: 64.233.167.104 www.sophos.com
backup-20051207-132932-725 O1 - Hosts: 64.233.167.104 uk.trendmicro-europe.com
backup-20051207-132932-751 O1 - Hosts: 64.233.167.104 liveupdate.symantec.com
backup-20051207-132932-755 O1 - Hosts: 64.233.167.104 secure.nai.com
backup-20051207-132932-772 O1 - Hosts: 64.233.167.104 my-etrust.com
backup-20051207-132932-782 O1 - Hosts: 64.233.167.104 www.viruslist.com
backup-20051207-132932-785 O1 - Hosts: 64.233.167.104 securityresponse.symantec.com
backup-20051207-132932-793 O1 - Hosts: 64.233.167.104 kaspersky-labs.com
backup-20051207-132932-805 O1 - Hosts: 64.233.167.104 trendmicro.com
backup-20051207-132932-836 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
backup-20051207-132932-843 O4 - HKLM\..\Run: [WhenUSearchWHSE] "C:\Program Files\WhenUSearch\whse.exe"
backup-20051207-132932-850 O1 - Hosts: 64.233.167.104 kaspersky.com
backup-20051207-132932-855 O1 - Hosts: 64.233.167.104 networkassociates.com
backup-20051207-132932-864 O1 - Hosts: 64.233.167.104 symantec.com
backup-20051207-132932-884 O1 - Hosts: 64.233.167.104 www.symantec.com
backup-20051207-132932-915 O1 - Hosts: 64.233.167.104 rads.mcafee.com
backup-20051207-132932-935 O1 - Hosts: 64.233.167.104 www.networkassociates.com
backup-20051207-132932-936 O1 - Hosts: 64.233.167.104 www.trendmicro.com
backup-20051207-132932-973 O1 - Hosts: 64.233.167.104 www.mcafee.com
backup-20051207-132932-997 O1 - Hosts: 64.233.167.104 download.mcafee.com
backup-20051207-132933-385 O16 - DPF: {EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1} - http://akamai.downloadv3.com/binaries/IA/netpe32_EN_XP.cab
backup-20051207-132933-601 O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
backup-20051215-133249-230 O4 - HKLM\..\Run: [acesigneachcool] C:\Documents and Settings\All Users\Application Data\does multi ace sign\OpenPoll.exe
backup-20051215-133249-241 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
backup-20051215-133249-320 O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
backup-20051215-133249-416 R3 - URLSearchHook: (no name) - - (no file)
backup-20051215-133249-589 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
backup-20051215-133858-358 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
backup-20051219-160158-472 O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
backup-20051219-160158-580 O4 - HKCU\..\Run: [SeekUser] C:\DOCUME~1\michael\APPLIC~1\THATSK~1\DELETE LOGO BLUE.exe
backup-20051219-160158-899 O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
backup-20051219-224748-475 O4 - HKCU\..\Run: [SeekUser] C:\DOCUME~1\michael\APPLIC~1\THATSK~1\DELETE LOGO BLUE.exe
backup-20051221-001710-653 O4 - HKCU\..\Run: [SeekUser] C:\DOCUME~1\michael\APPLIC~1\THATSK~1\DELETE LOGO BLUE.exe
backup-20060815-105856-238 O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)

– File Associations ———————————————————–

.scr - AutoCADScriptFile - shell\open\command - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys
R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys
R0 SiSide - c:\windows\system32\drivers\siside.sys
R0 sisidex - c:\windows\system32\drivers\sisidex.sys
R0 sisperf (Add Performance Filter Driver) - c:\windows\system32\drivers\sisperf.sys
R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys
R2 CdaD10BA - c:\windows\system32\drivers\cdad10ba.sys
R2 ElbyCDIO (ElbyCDIO Driver) - c:\windows\system32\drivers\elbycdio.sys
R2 ScFBPNT2 (CanoScan FBP2 Port Driver) - c:\windows\system32\drivers\scfbpnt2.sys
R3 cmuda (C-Media WDM Audio Interface) - c:\windows\system32\drivers\cmuda.sys
R3 ElbyCDFL - c:\windows\system32\drivers\elbycdfl.sys
R3 ENETHUSB (Speedstream Ethernet USB Adapter) - c:\windows\system32\drivers\enethusb.sys
R3 PID_0928 (Logitech QuickCam Express(PID_0928)) - c:\windows\system32\drivers\lv561av.sys
R3 StillCam (Still Serial Digital Camera Driver) - c:\windows\system32\drivers\serscan.sys

S3 ltmodem5 (LT Modem Driver) - c:\windows\system32\drivers\ltmdmnt.sys
S3 U81xbus (LGE U8XXX driver (WDM)) - c:\windows\system32\drivers\u81xbus.sys
S3 U81xmdfl (LGE U8XXX USB WMC Modem Filter) - c:\windows\system32\drivers\u81xmdfl.sys
S3 U81xmdm (LGE U8XXX USB WMC Modem Driver) - c:\windows\system32\drivers\u81xmdm.sys
S3 U81xmgmt (LGE U8XXX USB WMC Device Management Drivers (WDM)) - c:\windows\system32\drivers\u81xmgmt.sys
S3 U81xobex (LGE U8XXX USB WMC OBEX Interface) - c:\windows\system32\drivers\u81xobex.sys


– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ——————–

S2 STOPzilla Local Service - d:\programs\stopzilla\szntsvc.exe /service "stopzilla local service" (file missing)
S3 Autodesk Licensing Service - "c:\program files\common files\autodesk shared\service\adskscsrv.exe"


– Scheduled Tasks ————————————————————-

2007-04-06 02:00:00 272 –ah—– C:\WINDOWS\Tasks\AC6A430691FDF76E.job
2007-04-01 22:30:01 284 –a—— C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


– Files created between 2007-03-06 and 2007-04-06 —————————–

2007-04-06 09:57:59 462330 –a—— C:\dss.exe
2007-04-05 22:53:19 26694 –a—— C:\WINDOWS\system32\awturpq.dll
2007-04-05 17:09:50 26694 –a—— C:\WINDOWS\system32\yaywuuv.dll
2007-04-05 12:34:51 26694 –a—— C:\WINDOWS\system32\ssqqqno.dll
2007-04-05 09:01:22 26694 –a—— C:\WINDOWS\system32\urqonol.dll
2007-04-05 08:51:27 26694 –a—— C:\WINDOWS\system32\tuvstsr.dll
2007-04-04 22:32:08 26694 –a—— C:\WINDOWS\system32\urqqonm.dll
2007-04-04 22:31:55 193024 –a—— C:\Documents and Settings\michael\uuu.exe
2007-04-04 20:31:55 26694 –a—— C:\WINDOWS\system32\vtuttut.dll
2007-04-04 18:21:56 26694 –a—— C:\WINDOWS\system32\awtrppq.dll
2007-04-04 17:21:58 26694 –a—— C:\WINDOWS\system32\pmnmmkh.dll
2007-04-04 15:15:26 26694 –a—— C:\WINDOWS\system32\ljjghih.dll
2007-04-04 12:00:25 26694 –a—— C:\WINDOWS\system32\ljjkhif.dll
2007-04-04 10:40:44 26694 –a—— C:\WINDOWS\system32\mljklmm.dll
2007-04-04 10:40:26 188928 –a—— C:\Documents and Settings\michael\iii.exe
2007-04-03 23:14:29 26694 –a—— C:\WINDOWS\system32\khfcaxv.dll
2007-04-03 22:46:22 516209 —hs—- C:\WINDOWS\system32\dccdd.bak2
2007-04-03 21:39:28 26694 –a—— C:\WINDOWS\system32\yaywtsr.dll
2007-04-03 20:09:28 26694 –a—— C:\WINDOWS\system32\ddcbyaa.dll
2007-04-03 18:24:34 0 d——– C:\Getservice
2007-04-03 18:19:27 26694 –a—— C:\WINDOWS\system32\khfcdaa.dll
2007-04-03 16:29:24 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-04-03 15:49:27 26694 –a—— C:\WINDOWS\system32\mljgdbb.dll
2007-04-03 12:49:28 26694 –a—— C:\WINDOWS\system32\jkkjjig.dll
2007-04-03 09:12:32 26694 –a—— C:\WINDOWS\system32\qommjgf.dll
2007-04-02 23:41:04 26694 –a—— C:\WINDOWS\system32\opnlljk.dll
2007-04-02 23:40:29 26694 –a—— C:\WINDOWS\system32\ddccbca.dll
2007-04-02 23:39:31 26694 –a—— C:\WINDOWS\system32\mljhefd.dll
2007-04-02 23:39:05 26694 –a—— C:\WINDOWS\system32\ssqopoo.dll
2007-04-02 22:51:04 26694 –a—— C:\WINDOWS\system32\yayaawx.dll
2007-04-02 22:50:29 26694 –a—— C:\WINDOWS\system32\yayyaww.dll
2007-04-02 22:50:27 602112 –a—— C:\WINDOWS\system32\x.exe
2007-04-02 22:49:03 26694 –a—— C:\WINDOWS\system32\iifecdb.dll
2007-04-02 22:46:05 507857 —hs—- C:\WINDOWS\system32\dccdd.bak1
2007-04-02 22:45:20 280676 —hs—- C:\WINDOWS\system32\ddccd.dll
2007-04-02 22:40:06 26694 –a—— C:\WINDOWS\system32\pmnkijg.dll
2007-04-02 22:36:09 44963 –a—— C:\WINDOWS\system32\tuvss.dll
2007-04-02 21:57:49 26694 –a—— C:\WINDOWS\system32\ddcdaxv.dll
2007-04-02 10:26:43 192000 –a—— C:\Documents and Settings\michael\x.exe
2007-04-02 10:26:31 0 d——– C:\VundoFix Backups
2007-03-29 21:59:20 0 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-03-23 15:49:19 0 d——– C:\Documents and Settings\michael\Application Data\Google
2007-03-11 23:23:37 0 d——– C:\Documents and Settings\michael\Application Data\Yahoo! Messenger


– Find3M Report —————————————————————

2007-04-06 10:01:03 0 d——– C:\Program Files\SP2 Connection Patcher
2007-04-02 21:32:59 0 d——– C:\Program Files\Java
2007-04-01 21:01:30 4212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-03-29 21:59:32 0 d——– C:\Program Files\MSN Messenger
2007-03-23 15:48:12 0 d–h—– C:\Program Files\InstallShield Installation Information
2007-03-23 15:48:12 0 d——– C:\Program Files\Google
2007-03-09 01:36:28 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-09 01:36:28 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-09 01:36:28 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-09 00:02:00 75512 –a—— C:\WINDOWS\zllsputility.exe
2007-03-09 00:01:42 1087216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-03-08 23:47:48 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-03 21:00:24 532480 –a—— C:\WINDOWS\system32\Sci Fi Screensaver.scr
2007-03-03 09:55:02 0 d——– C:\Program Files\Common Files\Ahead
2007-01-27 15:53:42 139264 –a—— C:\WINDOWS\mirar_distro_876260.exe
2007-01-27 15:53:34 374 –a—— C:\Documents and Settings\michael\Application Data\internaldb6334.dat
2007-01-27 15:53:33 538 –a—— C:\Documents and Settings\michael\Application Data\internaldb8467.dat
2007-01-27 15:53:33 18432 –a—— C:\Documents and Settings\michael\Application Data\internaldb41.dat
2007-01-19 11:53:04 51056 –a—— C:\WINDOWS\system32\sirenacm.dll
2007-01-16 03:32:07 689280 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-01-16 03:23:20 90112 –a—— C:\WINDOWS\system32\AVASTSS.scr


– Registry Dump —————————————————————


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"SP2 Connection Patcher"="\"C:\\Program Files\\SP2 Connection Patcher\\SP2ConnPatcher.exe\" -n=200"
"Creative Detector"="D:\\Programs\\Creative MediaSource\\Detector\\CTDetect.exe /R"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Yahoo! Pager"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"avast!"="D:\\Programs\\Avast!\\ashDisp.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"WinPatrol"="D:\\Programs\\WinPatrol 9.8\\winpatrol.exe"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"D:\\programs\\Quicktime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"D:\\Programs\\iTunes\\iTunesHelper.exe\""
"SoundService"="rundll32.exe \"C:\\WINDOWS\\system32\\dqjyaggm.dll\",setvm"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{81559C35-8464-49F7-BB0E-07A383BEF910}"="SpywareGuard"
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"serpe"="C:\\WINDOWS\\system32\\serbw.exe"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ http://i.myspace.com/img/groups/crs/goblet…r/group_800.jpg

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccd
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnkijg
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmmkh

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



– End of Deckard's System Scanner: finished at 2007-04-06 at 10:05:06 ———

Extra Log

Deckard's System Scanner v20070328.36
Extra logfile - please post this as an attachment with your post.
——————————————————————————–

– System Information ———————————————————-

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® 4 CPU 1.70GHz
Percentage of Memory in Use: 57%
Physical Memory (total/avail): 511.48 MiB / 218.49 MiB
Pagefile Memory (total/avail): 1250.16 MiB / 972.5 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1997.54 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 9.77 GiB total, 1.8 GiB free.
D: is Fixed (NTFS) - 27.5 GiB total, 16.51 GiB free.
E: is CDROM (No Media)
F: is CDROM (No Media)


– Security Center ————————————————————-

AUOptions is set to notify before install.
Windows Internal Firewall is disabled.

AntivirusOverride is set.
FirewallOverride is set.

FW: ZoneAlarm Firewall v7.0.337.000 (Check Point, LTD.)
AV: avast! antivirus 4.7.942 [VPS 000730-4] v4.7.942 (ALWIL Software)


– Environment Variables ——————————————————-

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\michael\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_11\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=PAPERLIN-3LBIRH
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\michael
LOGONSERVER=\\PAPERLIN-3LBIRH
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;"C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier";D:\programs\Quicktime\QTSystem\;;C:\PROGRA~1\COMMON~1\AUTODE~1
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 1 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0103
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_11\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\michael\LOCALS~1\Temp
TMP=C:\DOCUME~1\michael\LOCALS~1\Temp
tvdumpflags=8
USERDOMAIN=PAPERLIN-3LBIRH
USERNAME=michael
USERPROFILE=C:\Documents and Settings\michael
windir=C:\WINDOWS


– User Profiles —————————————————————

michael (admin)
Administrator (admin)


– Add/Remove Programs ———————————————————

–> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2616B36E-38CE-4357-8AB5-8B3EE9B1C117}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2616B36E-38CE-4357-8AB5-8B3EE9B1C117}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{836612F0-1571-4C65-A4B7-58A39AA578EE}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{836612F0-1571-4C65-A4B7-58A39AA578EE}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B7A778E-AF38-4341-9EA0-1FC981106ADA}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B7A778E-AF38-4341-9EA0-1FC981106ADA}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D524239C-FD5C-4183-A49C-7930915A9C0A}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D524239C-FD5C-4183-A49C-7930915A9C0A}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D9A812DA-143D-4780-BEDC-FD6D41386317}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D9A812DA-143D-4780-BEDC-FD6D41386317}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DAAC5938-8026-4D0C-A476-D1954917B7F5}\SETUP.EXE" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DAAC5938-8026-4D0C-A476-D1954917B7F5}\SETUP.EXE" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DAB2EE2E-EF1F-4410-BA50-C3BFBE651F92}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DAB2EE2E-EF1F-4410-BA50-C3BFBE651F92}\setup.exe" -l0x9 /remove
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD2D9012-E5A1-4717-8EE9-8DB3F36E2F8C}\setup.exe" -l0x9
–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD2D9012-E5A1-4717-8EE9-8DB3F36E2F8C}\setup.exe" -l0x9 /remove
–> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent –> "C:\Program Files\uTorrent\uninstall.exe"
AC3Filter (remove only) –> D:\Programs\ac3filter\uninstall.exe
Acoustica MP3 CD Burner 2.07 –> D:\Programs\ACOUST~1\UNWISE.EXE D:\Programs\ACOUST~1\INSTALL.LOG
Ad-Aware SE Personal –> D:\Programs\AD-AWA~1\UNWISE.EXE D:\Programs\AD-AWA~1\INSTALL.LOG
Adobe Acrobat 5.0 –> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Apple Software Update –> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
AutoCAD 2007 - English –> MsiExec.exe /I{5783F2D7-5001-0409-0012-0060B0CE6BBA}
Autodesk DWF Viewer –> C:\PROGRA~1\Autodesk\AUTODE~1\Setup.exe /remove /q0
avast! Antivirus –> rundll32 D:\Programs\Avast!\Setup\setiface.dll,RunSetup
BigPond Broadband ADSL FAQ –> MsiExec.exe /I{86EAA5D0-3445-4945-993A-98F128C9299E}
BJC-255SP –> C:\WINDOWS\System32\CNMCP1L.EXE -@C:\WINDOWS\IsUninst.exe -f"C:\BJPrinter\CNMWINDOWS\Canon BJC-255SP Installer\Inst\DeIsL2.isu" -pCanon BJC-255SP-c"C:\BJPrinter\CNMWINDOWS\Canon BJC-255SP Installer\Inst\bjinst.dll
Boggle –> C:\WINDOWS\uninst.exe -fC:\WINDOWS\DeIsL1.isu
C-Media Audio –> C:\WINDOWS\CMIUnInstall.exe
Canon CanoCraft CS-P 3.7 –> C:\WINDOWS\IsUninst.exe -fd:\programs\CanoCraft\Uninst.isu -c"d:\programs\CanoCraft\scuninst.dll"
CCleaner (remove only) –> "D:\Programs\CCleaner\uninst.exe"
CloneCD –> C:\WINDOWS\IsUninst.exe -f"d:\programs\clone cd\Uninst.isu" -c"d:\programs\clone cd\InstallHelp.dll"
Creative MediaSource –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}\SETUP.EXE" -l0x9 /remove
Creative System Information –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove
Creative Zen Nano Plus –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BA63612E-0458-416A-ADCD-B2349194F20F}\SETUP.EXE" -l0x9 /remove
designIT –> MsiExec.exe /I{2FDF653E-95E3-4F59-B36C-606A5E7969A2}
Diablo II –> C:\WINDOWS\DIIUnin.exe C:\WINDOWS\DIIUnin.dat
DivX Codec –> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader –> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter –> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
DivX Player –> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player –> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
e-tax 2005 –> D:\Programs\etax2005\e-tax 2005_uninstall.exe
e-tax 2006 –> D:\Programs\etax2006\e-tax 2006_uninstall.exe
FirstRate 4.0 Demo –> "d:\programs\First Rate\IsStub32.exe" -f"d:\programs\First Rate\DeIsL1.isu" -c"d:\programs\First Rate\_ISREG32.DLL"
Freelancer –> "D:\Games\Freelancer\UNINSTAL.EXE" /runtemp /addremove
Google Earth –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
Harry Potter II –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7BF68B83-5057-4D4B-0093-28285EEB9EE3}\setup.exe" -l0x9 Uninstall
Harry Potter Lumos Screen Saver –> C:\WINDOWS\Harry Potter Lumos.scr /u
HarryPotter Screen Saver –> C:\WINDOWS\system32\HarryPotter.scr /u
Hazard Perception Test Demo –> C:\WINDOWS\st6unst.exe -n "d:\Programs\Hazard Perception Test\ST6UNST.LOG"
HijackThis 1.99.1 –> D:\Programs\HiJackThis\HijackThis.exe /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) –> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Indeo® XP Software –> C:\WINDOWS\IsUninst.exe -f"d:\programs\Indeo XP\UninstXP.isu"
InterActual Player –> C:\Program Files\InterActual\InterActual Player\inuninst.exe
iPod for Windows 2006-03-23 –> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB} /l1033
iTunes –> MsiExec.exe /I{AB90749C-7422-4580-8A7A-66CC5E9E5F98}
J2SE Runtime Environment 5.0 Update 10 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 11 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
Java 2 Runtime Environment Standard Edition v1.3.1_04 –> C:\WINDOWS\IsUninst.exe -f"c:\program files\Java Runtime\Uninst.isu"
Kill Bill Vol 01 –> C:\PROGRA~1\FILESU~1\KILLBI~1\UNWISE.EXE C:\PROGRA~1\FILESU~1\KILLBI~1\INSTALL.LOG
LG PC Sync –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{0E3469E7-E33A-4A79-99B7-24883BE62EC9} /l1033
LG Phone Manager –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{D130E8E3-C39F-4572-A622-8636BBB09865} /l1033
Linkin Park Theme –> C:\PROGRA~1\FILESU~1\LINKIN~1\UNWISE.EXE C:\PROGRA~1\FILESU~1\LINKIN~1\INSTALL.LOG
Logitech Desktop Messenger –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x9 UNINSTALL
Logitech Print Service –> C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
Logitech QuickCam Software –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x9
Logitech® Camera Driver –> "C:\Program Files\Common Files\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
LucasArts' X-Wing vs. TIE Fighter Demo –> C:\WINDOWS\uninst.exe -f"d:\games\X-Wing vs. TIE Fighter\DeIsL1.isu"
Macromedia Flash Player 8 –> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5
Macromedia Shockwave Player –> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Microsoft Age of Empires –> C:\Program Files\Microsoft Games\Age of Empires\Uninstal.exe /uninstall
Microsoft Compression Client Pack 1.0 for Windows XP –> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Data Access Components KB870669 –> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Encarta 99 Encyclopedia –> RunDll32 D:\Programs\ENCART~1\UNENC99.DLL,Uninstall D:\Programs\ENCART~1\SETUP99Z\INST99Z.LOG
Microsoft Golf 1999 Edition –> "D:\Games\Microsoft Golf 1999\Setup" /runtemp
Microsoft Halo –> "D:\Games\Halo\UNINSTAL.EXE" /runtemp /addremove
Microsoft Office 2000 Professional –> MsiExec.exe /I{00010409-78E1-11D2-B60F-006097C998E7}
Microsoft User-Mode Driver Framework Feature Pack 1.0 –> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Monopoly –> C:\WINDOWS\IsUninst.exe -fd:\games\Monopoly\Uninst.isu
Mozilla Firefox (2.0.0.3) –> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MyVirtualHome –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C66FE99D-7C15-40A0-AE4A-A1A3900D9EE3}\setup.exe" -l0x9 -removeonly
Nero 6 Ultra Edition –> D:\Programs\Nero 6\nero\uninstall\UNNERO.exe /UNINSTALL
OLYMPUS CAMEDIA Master 4.2 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{30BB4D60-81DB-11D5-BB77-00400536ABAC}\setup.exe" CAMEDIA Master 4.2
PotterHH –> C:\PROGRA~1\AAASCR~1\PotterHH\UNWISE.EXE C:\PROGRA~1\AAASCR~1\PotterHH\INSTALL.LOG
PowerDVD –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
Project64 1.6 –> MsiExec.exe /X{9559F7CA-5E34-4237-A2D9-D856464AD727}
QuickTime –> MsiExec.exe /I{5E863175-E85D-44A6-8968-82507D34AE7F}
RealDownload –> D:\Programs\RealDownload\Realdownload.exe -u
RealPlayer –> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Sci Fi Screensaver –> C:\WINDOWS\system32\Sci Fi Screensaver.scr /u
Search Assistant - My Search –> mshta res://C:\PROGRA~1\MyWay\SrchAstt\1.bin\mysrchas.dll/101
Secure Game Player –> C:\Program Files\SkillJam Technologies\Secure Player\Uninstall.exe
Shizmoo Web Games (Uproar) –> C:\Program Files\shizmoo\uproar_webgames\uninstall.exe
South Park Rally –> C:\WINDOWS\IsUninst.exe -f"d:\games\South Park Rally\sprally.isu"
SP2 Connection Patcher –> C:\Program Files\SP2 Connection Patcher\uninstall.exe
Spybot - Search & Destroy 1.4 –> "D:\Programs\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster v3.5.1 –> "D:\Programs\SpywareBlaster\unins000.exe"
SpywareGuard v2.2 –> D:\Programs\SpywareGuard\unins000.exe
Starcraft –> C:\WINDOWS\SCunin.exe C:\WINDOWS\SCunin.dat
The Cat in the Hat™ Demo –> C:\Program Files\Common Files\Vivendi Universal Games\Uninstall\CatHatDemoUn.exe
thegobletoffire.zip –> C:\PROGRA~1\FILESU~1\THEGOB~1.ZIP\UNWISE.EXE C:\PROGRA~1\FILESU~1\THEGOB~1.ZIP\INSTALL.LOG
Tomb Raider Chronicles –> C:\WINDOWS\IsUninst.exe -f"d:\games\Tomb Raider Chronicles Demo\Uninst.isu"
Tomb Raider II –> C:\WINDOWS\IsUninst.exe -f"d:\games\Tomb Raider 2\Uninst.isu"
Total Annihilation –> D:\CAVEDOG\TOTALA\setup.exe -u
Total Annihilation - Battle Tactics –> D:\CAVEDOG\TOTALA\tabtunst.exe D:\CAVEDOG\TOTALA
Total Annihilation - Core Contingency –> D:\CAVEDOG\TOTALA\CC\CCQUERY.EXE
UpTown Engine –> C:\WINDOWS\system32\UpMedia\uninstallSE.exe
URGE –> MsiExec.exe /I{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}
Westwood Online –> d:\games\command & conquer\UNINSTWC.EXE C:\WINDOWS\UNINST.EXE -fd:\games\COMMAN~1\DeIsL2.isu
Windows Live Messenger –> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Media Format 11 runtime –> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinPatrol 9.8 –> MsiExec.exe /I{F46E4DFF-FC47-4862-AC56-B1BE95BA7D7E}
WinZip –> "D:\Programs\Winzip\WINZIP32.EXE" /uninstall
Worms World Party –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A200E68-D5F4-4E70-910F-2871753A0E2B}\setup.exe"
Yahoo! Companion –> rundll32.exe C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\YCOMP5~1.DLL,DllCommand ui
Yahoo! Messenger –> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
ZoneAlarm –> C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe


– End of Deckard's System Scanner: finished at 2007-04-06 at 10:05:06 ———
Hi

Let's try this next:

First we'll need to backup registry:

Start -> Run -> regedit -> ok. Then File -> Export. Give it a name and press Save.

Save text below as fix.reg on Notepad (save it as all files (*.*)) on Desktop

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundService"=-

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"serpe"=-

It should look like this -> [external image: Posted Image]

Doubleclick fix.reg, press Yes and ok.

(In case you are unsure how to create a reg file, take a look here with screenshots.)

1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to delete:
C:\WINDOWS\system32\awturpq.dll
C:\WINDOWS\system32\yaywuuv.dll
C:\WINDOWS\system32\ssqqqno.dll
C:\WINDOWS\system32\urqonol.dll
C:\WINDOWS\system32\tuvstsr.dll
C:\WINDOWS\system32\urqqonm.dll
C:\Documents and Settings\michael\uuu.exe
C:\WINDOWS\system32\vtuttut.dll
C:\WINDOWS\system32\awtrppq.dll
C:\WINDOWS\system32\pmnmmkh.dll
C:\WINDOWS\system32\ljjghih.dll
C:\WINDOWS\system32\ljjkhif.dll
C:\WINDOWS\system32\mljklmm.dll
C:\Documents and Settings\michael\iii.exe
C:\WINDOWS\system32\khfcaxv.dll
C:\WINDOWS\system32\dccdd.bak2
C:\WINDOWS\system32\yaywtsr.dll
C:\WINDOWS\system32\ddcbyaa.dll
C:\WINDOWS\system32\yaywtsr.dll
C:\WINDOWS\system32\ddcbyaa.dll
C:\WINDOWS\system32\khfcdaa.dll
C:\WINDOWS\system32\mljgdbb.dll
C:\WINDOWS\system32\jkkjjig.dll
C:\WINDOWS\system32\qommjgf.dll
C:\WINDOWS\system32\opnlljk.dll
C:\WINDOWS\system32\ddccbca.dll
C:\WINDOWS\system32\mljhefd.dll
C:\WINDOWS\system32\ssqopoo.dll
C:\WINDOWS\system32\yayaawx.dll
C:\WINDOWS\system32\yayyaww.dll
C:\WINDOWS\system32\x.exe
C:\WINDOWS\system32\iifecdb.dll
C:\WINDOWS\system32\dccdd.bak1
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\system32\pmnkijg.dll
C:\WINDOWS\system32\tuvss.dll
C:\WINDOWS\system32\ddcdaxv.dll
C:\Documents and Settings\michael\x.exe


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply

Re-run vundofix

Re-run dss

Post:

- dss log
- vundofix report
I followed your instructions related to the backup registry and The Avenger, but it came back with this error in the report. I'll try running it again a few more times. Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\nkjsxcxg ******************* Script file located at: jjhqvqvo Could not open script file! Error Could not open script file! Status: 0xc000003b Abort!
I just worked it out, I forgot to put the .reg file into the Avenger folder, its all good now. Heres the report:

Avenger.txt

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\xxyxiehd

*******************

Script file located at: \??\C:\WINDOWS\urqwgtmb.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\awturpq.dll deleted successfully.
File C:\WINDOWS\system32\yaywuuv.dll deleted successfully.
File C:\WINDOWS\system32\ssqqqno.dll deleted successfully.
File C:\WINDOWS\system32\urqonol.dll deleted successfully.
File C:\WINDOWS\system32\tuvstsr.dll deleted successfully.
File C:\WINDOWS\system32\urqqonm.dll deleted successfully.
File C:\Documents and Settings\michael\uuu.exe deleted successfully.
File C:\WINDOWS\system32\vtuttut.dll deleted successfully.
File C:\WINDOWS\system32\awtrppq.dll deleted successfully.
File C:\WINDOWS\system32\pmnmmkh.dll deleted successfully.
File C:\WINDOWS\system32\ljjghih.dll deleted successfully.
File C:\WINDOWS\system32\ljjkhif.dll deleted successfully.
File C:\WINDOWS\system32\mljklmm.dll deleted successfully.
File C:\Documents and Settings\michael\iii.exe deleted successfully.
File C:\WINDOWS\system32\khfcaxv.dll deleted successfully.
File C:\WINDOWS\system32\dccdd.bak2 deleted successfully.
File C:\WINDOWS\system32\yaywtsr.dll deleted successfully.
File C:\WINDOWS\system32\ddcbyaa.dll deleted successfully.


File C:\WINDOWS\system32\yaywtsr.dll not found!
Deletion of file C:\WINDOWS\system32\yaywtsr.dll failed!

Could not process line:
C:\WINDOWS\system32\yaywtsr.dll
Status: 0xc0000034



File C:\WINDOWS\system32\ddcbyaa.dll not found!
Deletion of file C:\WINDOWS\system32\ddcbyaa.dll failed!

Could not process line:
C:\WINDOWS\system32\ddcbyaa.dll
Status: 0xc0000034

File C:\WINDOWS\system32\khfcdaa.dll deleted successfully.
File C:\WINDOWS\system32\mljgdbb.dll deleted successfully.
File C:\WINDOWS\system32\jkkjjig.dll deleted successfully.
File C:\WINDOWS\system32\qommjgf.dll deleted successfully.
File C:\WINDOWS\system32\opnlljk.dll deleted successfully.
File C:\WINDOWS\system32\ddccbca.dll deleted successfully.
File C:\WINDOWS\system32\mljhefd.dll deleted successfully.
File C:\WINDOWS\system32\ssqopoo.dll deleted successfully.
File C:\WINDOWS\system32\yayaawx.dll deleted successfully.
File C:\WINDOWS\system32\yayyaww.dll deleted successfully.
File C:\WINDOWS\system32\x.exe deleted successfully.
File C:\WINDOWS\system32\iifecdb.dll deleted successfully.
File C:\WINDOWS\system32\dccdd.bak1 deleted successfully.
File C:\WINDOWS\system32\ddccd.dll deleted successfully.
File C:\WINDOWS\system32\pmnkijg.dll deleted successfully.
File C:\WINDOWS\system32\tuvss.dll deleted successfully.
File C:\WINDOWS\system32\ddcdaxv.dll deleted successfully.
File C:\Documents and Settings\michael\x.exe deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

HiJackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 8:13:13 PM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Programs\Avast!\aswUpdSv.exe
D:\Programs\Avast!\ashserv.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
D:\programs\Quicktime\qttask.exe
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\netdde.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
D:\Programs\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
D:\Programs\HiJackThis\foamy.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: (no name) - {5A061C36-916E-417C-9434-4EAA3A09C01C} - C:\WINDOWS\system32\mllkh.dll (file missing)
O2 - BHO: (no name) - {5C2C6A63-5AD3-4E71-BD49-E8499FF2F8B9} - C:\WINDOWS\system32\gebxu.dll
O2 - BHO: (no name) - {608F64DE-BEAE-454B-A872-105D5BB1060F} - C:\WINDOWS\system32\ddccd.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7D064D71-DD76-4596-90C0-921766AD560A} - C:\WINDOWS\system32\pmnkijg.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {B508CBF1-6B54-4603-8C23-C305C486B8A8} - C:\WINDOWS\system32\gebab.dll (file missing)
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\ortgeufj.dll",setvm
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ddccd - C:\WINDOWS\system32\ddccd.dll (file missing)
O20 - Winlogon Notify: gebxu - C:\WINDOWS\system32\gebxu.dll
O20 - Winlogon Notify: pmnkijg - pmnkijg.dll (file missing)
O20 - Winlogon Notify: pmnmmkh - pmnmmkh.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O20 - Winlogon Notify: yayyvvu - C:\WINDOWS\SYSTEM32\yayyvvu.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Sorry they're coming, I knew you'd ask for those, I'm just splitting them up thats all ;)

Vundofix log

VundoFix V6.3.18

Checking Java version…

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 8:15:15 PM 4/6/2007

Listing files found while scanning….

C:\WINDOWS\system32\dccdd.ini
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\system32\gebccby.dll
C:\WINDOWS\system32\gebxu.dll
C:\WINDOWS\system32\iifcyaa.dll
C:\WINDOWS\system32\jfuegtro.ini
C:\WINDOWS\system32\jkkljhh.dll
C:\WINDOWS\system32\ortgeufj.dll
C:\WINDOWS\system32\vturssq.dll
C:\WINDOWS\system32\wvuuutq.dll
C:\WINDOWS\system32\xxyywxw.dll
C:\WINDOWS\system32\yayyvvu.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\dccdd.ini
C:\WINDOWS\system32\dccdd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebccby.dll
C:\WINDOWS\system32\gebccby.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebxu.dll
C:\WINDOWS\system32\gebxu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iifcyaa.dll
C:\WINDOWS\system32\iifcyaa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jfuegtro.ini
C:\WINDOWS\system32\jfuegtro.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkkljhh.dll
C:\WINDOWS\system32\jkkljhh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ortgeufj.dll
C:\WINDOWS\system32\ortgeufj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vturssq.dll
C:\WINDOWS\system32\vturssq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvuuutq.dll
C:\WINDOWS\system32\wvuuutq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxyywxw.dll
C:\WINDOWS\system32\xxyywxw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yayyvvu.dll
C:\WINDOWS\system32\yayyvvu.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\yayyvvu.dll
C:\WINDOWS\system32\yayyvvu.dll Has been deleted!

Performing Repairs to the registry.
Done!


Deckard's System Scanner

Deckard's System Scanner v20070328.36
Run by [removed] on 2007-04-06 at 20:43:26
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as michael.exe) ———————————————

Logfile of HijackThis v1.99.1
Scan saved at 8:43:39 PM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Programs\Avast!\aswUpdSv.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashserv.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
D:\programs\Quicktime\qttask.exe
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
D:\Programs\SpywareGuard\sgbhp.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\michael\Desktop\dss.exe
D:\Programs\HIJACK~1\michael.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: (no name) - {5A061C36-916E-417C-9434-4EAA3A09C01C} - C:\WINDOWS\system32\mllkh.dll (file missing)
O2 - BHO: (no name) - {5C2C6A63-5AD3-4E71-BD49-E8499FF2F8B9} - C:\WINDOWS\system32\gebxu.dll (file missing)
O2 - BHO: (no name) - {608F64DE-BEAE-454B-A872-105D5BB1060F} - C:\WINDOWS\system32\ddccd.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7D064D71-DD76-4596-90C0-921766AD560A} - C:\WINDOWS\system32\pmnkijg.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {B508CBF1-6B54-4603-8C23-C305C486B8A8} - C:\WINDOWS\system32\gebab.dll (file missing)
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\ortgeufj.dll",setvm
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ddccd - C:\WINDOWS\system32\ddccd.dll (file missing)
O20 - Winlogon Notify: jkkjjjj - C:\WINDOWS\SYSTEM32\jkkjjjj.dll
O20 - Winlogon Notify: pmnkijg - pmnkijg.dll (file missing)
O20 - Winlogon Notify: pmnmmkh - pmnmmkh.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


– Files created between 2007-03-06 and 2007-04-06 —————————–

2007-04-06 20:39:40 26694 –a—— C:\WINDOWS\system32\jkkjjjj.dll
2007-04-06 20:11:44 517935 —hs—- C:\WINDOWS\system32\uxbeg.bak1
2007-04-06 20:05:01 0 d——– C:\avenger
2007-04-06 15:28:03 0 d——– C:\WAR2
2007-04-06 10:06:07 192000 –a—— C:\Documents and Settings\michael\pp.exe
2007-04-06 09:57:59 462330 –a—— C:\dss.exe
2007-04-03 18:24:34 0 d——– C:\Getservice
2007-04-03 16:29:24 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-04-02 10:26:31 0 d——– C:\VundoFix Backups
2007-03-29 21:59:20 0 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-03-23 15:49:19 0 d——– C:\Documents and Settings\michael\Application Data\Google
2007-03-11 23:23:37 0 d——– C:\Documents and Settings\michael\Application Data\Yahoo! Messenger


– Find3M Report —————————————————————

2007-04-06 20:39:01 0 d——– C:\Program Files\SP2 Connection Patcher
2007-04-06 19:50:56 2576 –a—— C:\Program Files\vwjotcbc.txt
2007-04-02 21:32:59 0 d——– C:\Program Files\Java
2007-04-01 21:01:30 4212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-03-29 21:59:32 0 d——– C:\Program Files\MSN Messenger
2007-03-23 15:48:12 0 d–h—– C:\Program Files\InstallShield Installation Information
2007-03-23 15:48:12 0 d——– C:\Program Files\Google
2007-03-09 01:36:28 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-09 01:36:28 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-09 01:36:28 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-09 00:02:00 75512 –a—— C:\WINDOWS\zllsputility.exe
2007-03-09 00:01:42 1087216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-03-08 23:47:48 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-03 21:00:24 532480 –a—— C:\WINDOWS\system32\Sci Fi Screensaver.scr
2007-03-03 09:55:02 0 d——– C:\Program Files\Common Files\Ahead
2007-01-27 15:53:42 139264 –a—— C:\WINDOWS\mirar_distro_876260.exe
2007-01-27 15:53:34 374 –a—— C:\Documents and Settings\michael\Application Data\internaldb6334.dat
2007-01-27 15:53:33 538 –a—— C:\Documents and Settings\michael\Application Data\internaldb8467.dat
2007-01-27 15:53:33 18432 –a—— C:\Documents and Settings\michael\Application Data\internaldb41.dat
2007-01-19 11:53:04 51056 –a—— C:\WINDOWS\system32\sirenacm.dll
2007-01-16 03:32:07 689280 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-01-16 03:23:20 90112 –a—— C:\WINDOWS\system32\AVASTSS.scr


– Registry Dump —————————————————————


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"SP2 Connection Patcher"="\"C:\\Program Files\\SP2 Connection Patcher\\SP2ConnPatcher.exe\" -n=200"
"Creative Detector"="D:\\Programs\\Creative MediaSource\\Detector\\CTDetect.exe /R"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Yahoo! Pager"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"avast!"="D:\\Programs\\Avast!\\ashDisp.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"WinPatrol"="D:\\Programs\\WinPatrol 9.8\\winpatrol.exe"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"D:\\programs\\Quicktime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"D:\\Programs\\iTunes\\iTunesHelper.exe\""
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"SoundService"="rundll32.exe \"C:\\WINDOWS\\system32\\ortgeufj.dll\",setvm"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{81559C35-8464-49F7-BB0E-07A383BEF910}"="SpywareGuard"
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""
"{D15EFFBE-61EE-480B-9507-25264732DE0F}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ http://i.myspace.com/img/groups/crs/goblet…r/group_800.jpg

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccd
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjjjj
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnkijg
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmmkh

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



– End of Deckard's System Scanner: finished at 2007-04-06 at 20:44:21 ———
Hi

Right click the running icon of Spywareguard in the system tray to open the program. Then go to Menu, File, and choose Exit. It will automatically restart at next boot.

Right-click the running icon of Winpatrol in the system tray and choose exit. It will automatically restart at next boot.

Open HijackThis, click do a system scan only and checkmark these:

O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: (no name) - {5A061C36-916E-417C-9434-4EAA3A09C01C} - C:\WINDOWS\system32\mllkh.dll (file missing)
O2 - BHO: (no name) - {5C2C6A63-5AD3-4E71-BD49-E8499FF2F8B9} - C:\WINDOWS\system32\gebxu.dll (file missing)
O2 - BHO: (no name) - {608F64DE-BEAE-454B-A872-105D5BB1060F} - C:\WINDOWS\system32\ddccd.dll (file missing)
O2 - BHO: (no name) - {7D064D71-DD76-4596-90C0-921766AD560A} - C:\WINDOWS\system32\pmnkijg.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {B508CBF1-6B54-4603-8C23-C305C486B8A8} - C:\WINDOWS\system32\gebab.dll (file missing)
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\ortgeufj.dll",setvm
O20 - Winlogon Notify: ddccd - C:\WINDOWS\system32\ddccd.dll (file missing)
O20 - Winlogon Notify: pmnkijg - pmnkijg.dll (file missing)
O20 - Winlogon Notify: pmnmmkh - pmnmmkh.dll (file missing)


Go to start -> run

Type this into box and click ok:

regsvr32 C:\WINDOWS\system32\ortgeufj.dll /u

Close all windows including browser and press fix checked.

Please download Process Explorer by Systernals from here

Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of jkkjjjj.dll once and then click the kill button.

After you have killed all of the jkkjjjj.dll under winlogon click OK

Also look for any .ini or bak files or reverse named dll's with either the same name or the file name in reverse & kill them as well. See above for examples

Click on the Threads tab at the top.

Once you have done that click OK again.

Also look for any .ini or bak files or other dll's with either the same name or the file name in reverse & kill them as well

Examples:

jkkjjjj.dll
jkkjjjj.ini
jkkjjjj.reg

or

jjjjkkj.bak
jjjjkkj.ini etc.

Next double click on explorer.exe and again click once on each instance of jkkjjjj.dll then click the kill button.

Also look for any .ini or bak files or reverse named dll's with either the same name or the file name in reverse & kill them as well. See above for examples

Click on the Threads tab at the top.

Once you have done that click OK again.

Please download the Killbox.
Unzip it to the desktop.

Please run Killbox.

Select "Standard file kill" and "All files"

Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\system32\ortgeufj.dll
C:\WINDOWS\SYSTEM32\jkkjjjj.dll
C:\WINDOWS\system32\uxbeg.bak1

Go to the File menu, and choose "Paste from Clipboard".

Click the red-and-white "Delete File" button. Click "No" at the Pending Operations prompt.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again..

Re-run vundofix

Post:

- a fresh HijackThis log
- vundofix report
All the scans ran perfectly well, though I get the feeling some of these .dll files just keep coming back. I'm still getting a RUNDLL error coming up, this time for C:\WINDOWS\system32\mcryilyr.dll, as well as trojan horse and watchdog alerts. Just thought I'd mension that. Here's the logs:

Vundofix Report

VundoFix V6.3.18

Checking Java version…

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 10:09:03 PM 4/6/2007

Listing files found while scanning….

C:\WINDOWS\system32\ddcdeef.dll
C:\WINDOWS\system32\gebccdb.dll
C:\WINDOWS\system32\mcryilyr.dll
C:\WINDOWS\system32\ryliyrcm.ini
C:\WINDOWS\system32\utpakuwb.dll
C:\WINDOWS\system32\xxyyx.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddcdeef.dll
C:\WINDOWS\system32\ddcdeef.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebccdb.dll
C:\WINDOWS\system32\gebccdb.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\mcryilyr.dll
C:\WINDOWS\system32\mcryilyr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ryliyrcm.ini
C:\WINDOWS\system32\ryliyrcm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\utpakuwb.dll
C:\WINDOWS\system32\utpakuwb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxyyx.dll
C:\WINDOWS\system32\xxyyx.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\gebccdb.dll
C:\WINDOWS\system32\gebccdb.dll Has been deleted!

Performing Repairs to the registry.
Done!


HiJackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 10:38:08 PM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Programs\Avast!\aswUpdSv.exe
D:\Programs\Avast!\ashserv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\svchost.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
D:\programs\Quicktime\qttask.exe
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Programs\SpywareGuard\sgbhp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Programs\HiJackThis\foamy.exe
C:\Documents and Settings\michael\pp.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {075DCF1A-760A-42F8-A38A-CA3B7E317F51} - C:\WINDOWS\system32\xxyyx.dll (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\mcryilyr.dll",setvm
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: jkkjjjj - jkkjjjj.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O20 - Winlogon Notify: wvuvutt - C:\WINDOWS\SYSTEM32\wvuvutt.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI