This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Random Pop-ups

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just tonight I started getting random pop-ups, whether or not I even have a web browser open. I've run ad-aware, spybot, and AVG but they're still happening.

Here's the HijackThis log, and thank you in advance for any help you can give.



Logfile of HijackThis v1.99.1
Scan saved at 12:12:05 AM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Atievxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {b3815164-3f97-4e48-9341-d51745ee1017} - C:\WINDOWS\system32\LFCave.dll
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE /P17 "EPSON PictureMate" /O6 "USB001" /M "PictureMate"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKCU\..\Run: [Update Service] "C:\Program Files\Common Files\Teknum Systems\update.exe" /startup
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
O4 - Startup: NAL.EXE.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/16.19/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1098735452069
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: LFCave - C:\WINDOWS\SYSTEM32\LFCave.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Hello Fry and Welcome to TomCoyote,

Let's start with the following please:

STEP 1.
======
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
STEP 2.
======
Deckard’s System Scanner

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post.in your reply
Please post (reply) with the contents of C:\vundofix.txt and logs from Deckard’s System Scanner.
VundoFix didn't find anything, but here are the results of DSS.

Main -

Deckard's System Scanner v20070328.36
Run by [removed] on 2007-04-06 at 19:32:51
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
57: 2007-04-07 01:33:30 UTC - RP342 - Deckard's System Scanner Restore Point
56: 2007-04-04 05:13:57 UTC - RP341 - System Checkpoint
55: 2007-04-03 03:45:42 UTC - RP340 - System Checkpoint
54: 2007-04-01 17:59:31 UTC - RP339 - System Checkpoint
53: 2007-03-31 17:56:38 UTC - RP338 - System Checkpoint


– First Restore Point –
1: 2007-01-05 07:57:01 UTC - RP286 - System Checkpoint


Backed up registry hives.

Performed disk cleanup.


– HijackThis (run as CSampson.exe) ——————————————–

Logfile of HijackThis v1.99.1
Scan saved at 7:37:00 PM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Atievxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\Documents and Settings\CSampson\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\CSampson.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {b3815164-3f97-4e48-9341-d51745ee1017} - C:\WINDOWS\system32\LFCave.dll
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE /P17 "EPSON PictureMate" /O6 "USB001" /M "PictureMate"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\jkkllk.dll",realset
O4 - HKCU\..\Run: [Update Service] "C:\Program Files\Common Files\Teknum Systems\update.exe" /startup
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
O4 - Startup: NAL.EXE.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/16.19/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1098735452069
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: LFCave - C:\WINDOWS\SYSTEM32\LFCave.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe


– File Associations ———————————————————–

.js - JSFile - shell\open\command - %SystemRoot%\System32\CScript.exe "%1" %*
.vbs - VBSFile - shell\open\command - %SystemRoot%\System32\CScript.exe "%1" %*


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 Avg7RsNT (AVG7 Resident Driver NT) - c:\windows\system32\drivers\avg7rsnt.sys
R1 Cdr4_2K - c:\windows\system32\drivers\cdr4_2k.sys
R1 Cdr4_xp - c:\windows\system32\drivers\cdr4_xp.sys
R1 Cdralw2k - c:\windows\system32\drivers\cdralw2k.sys
R1 cdudf_xp - c:\windows\system32\drivers\cdudf_xp.sys
R1 NICM (%ProductNICMDisplayName%) - c:\windows\system32\drivers\nicm.sys
R1 pwd_2k - c:\windows\system32\drivers\pwd_2k.sys
R1 UdfReadr_xp - c:\windows\system32\drivers\udfreadr_xp.sys
R2 NetwareWorkstation (Novell Client for Windows) - c:\windows\system32\netware\nwfs.sys
R2 NWDHCP (Novell DHCP Inform Client) - c:\windows\system32\netware\nwdhcp.sys
R2 NwlnkIpx (NWLink IPX/SPX/NetBIOS Compatible Transport Protocol) - c:\windows\system32\drivers\nwlnkipx.sys
R2 NwlnkNb (NWLink NetBIOS) - c:\windows\system32\drivers\nwlnknb.sys
R2 NwlnkSpx (NWLink SPX/SPXII Protocol) - c:\windows\system32\drivers\nwlnkspx.sys
R2 NWSIPX32 (Novell NetWare IPX/SPX Transport Interface) - c:\windows\system32\netware\nwsipx32.sys
R2 RESMGR (Novell NetWare Resource Manager) - c:\windows\system32\netware\resmgr.sys
R2 SRVLOC (Novell Service Location) - c:\windows\system32\netware\srvloc.sys
R3 atimtai - c:\windows\system32\drivers\atimtai.sys
R3 AWINDIS5 (AWINDIS5 Protocol Driver) - c:\windows\system32\awindis5.sys
R3 l8042pr2 (Logitech PS/2 Mouse Filter Driver) - c:\windows\system32\drivers\l8042pr2.sys
R3 ltmodem5 (LT Modem Driver) - c:\windows\system32\drivers\ltmdmnt.sys
R3 maestro (ESS Maestro 3 Audio Driver (WDM)) - c:\windows\system32\drivers\es198x.sys
R3 mmc_2K - c:\windows\system32\drivers\mmc_2k.sys
R3 MODEMCSA (Unimodem Streaming Filter Device) - c:\windows\system32\drivers\modemcsa.sys
R3 NWDNS (Novell DNS Name Space Service Provider) - c:\windows\system32\netware\nwdns.sys
R3 NWHOST (Novell Host File Name Space Service Provider) - c:\windows\system32\netware\nwhost.sys
R3 NWSAP (Novell SAP Name Space Provider) - c:\windows\system32\netware\nwsap.sys
R3 NWSLP (Novell SLP Name Space Service Provider) - c:\windows\system32\netware\nwslp.sys
R3 NWSNS (Novell Simple Naming Services) - c:\windows\system32\netware\nwsns.sys
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys
R3 PRISM_ICB (NETGEAR WG511 Wireless LAN Driver) - c:\windows\system32\drivers\wg511icb.sys

S2 DzlDvc2p (Dazzle DVC II PCI Device) - c:\windows\system32\drivers\dzldvc2p.sys
S2 FilterService (Filter Service) - c:\windows\system32\drivers\nusbd.sys
S2 NECEHCD (NEC PCI to USB Enhanced Host Controller) - c:\windows\system32\drivers\nehcd.sys
S3 ALABULKO (OLYMPUS USB Media Adapter device driver) - c:\windows\system32\drivers\alablk2o.sys
S3 dvd_2K - c:\windows\system32\drivers\dvd_2k.sys
S3 DVXUSBKS (DVXCEL Streaming Class Driver) - c:\windows\system32\drivers\dvxusbks.sys
S3 DVXUSBLD - c:\windows\system32\drivers\dvxusbld.sys
S3 DzlUsb (Dazzle DVC USB Device) - c:\windows\system32\drivers\dzlusb.sys
S3 MR97310_USB_DUAL_CAMERA (MR97310 CIF Dual Mode Camera) - c:\windows\system32\drivers\mr97310c.sys
S3 nusb2hub (Generic USB Hub on USB 2.0 Bus) - c:\windows\system32\drivers\nusb2hub.sys


– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ——————–

R2 Diskeeper - c:\program files\executive software\diskeeperworkstation\dkservice.exe


– Files created between 2007-03-06 and 2007-04-06 —————————–

2007-04-06 19:32:50 0 d——– \Deckard
2007-04-06 19:24:35 106767 –a—— C:\WINDOWS\jkkllk.dll
2007-04-06 01:28:40 0 d——– \VundoFix Backups
2007-04-03 22:59:11 0 d——– C:\WINDOWS\system32\bak
2007-04-03 20:40:07 0 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-04-02 20:47:52 19275 –a—— C:\WINDOWS\system32\LFCave.dll
2007-03-22 13:48:23 0 d—s—- C:\Documents and Settings\LocalService\UserData


– Find3M Report —————————————————————

2007-04-06 02:52:30 467664896 –ahs—- \pagefile.sys
2007-04-03 22:59:11 0 d——– C:\Program Files\QuickTime
2007-04-03 22:59:11 0 d——– C:\Program Files\iTunes
2007-04-03 22:52:16 267939840 –ahs—- \hiberfil.sys
2007-04-02 20:43:37 0 d—s—- C:\Program Files\Common Files\Teknum Systems
2007-03-27 11:20:21 0 d——– C:\Documents and Settings\CSampson\Application Data\Microsoft
2007-03-22 16:27:38 0 d——– C:\Program Files\Qimage


– Registry Dump —————————————————————


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Update Service"="\"C:\\Program Files\\Common Files\\Teknum Systems\\update.exe\" /startup"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NWTRAY"="NWTRAY.EXE"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"WG511WLU"="C:\\Program Files\\NETGEAR\\WG511\\Utility\\WG511WLU.exe"
"EPSON PictureMate"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2P1.EXE /P17 \"EPSON PictureMate\" /O6 \"USB001\" /M \"PictureMate\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Lexmark_X79-55"="C:\\WINDOWS\\system32\\lsasss.exe"
"BootService"="rundll32.exe \"C:\\WINDOWS\\jkkllk.dll\",realset"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS\VCMnet11.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VCMnet11"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\VCMnet11.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Logi_MwX"
"hkey"="HKLM"
"command"="Logi_MwX.Exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RxMon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Roxio\\Easy CD Creator 6\\AudioCentral\\RxMon.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DrgToDsc"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Roxio\\Easy CD Creator 6\\DragToDisc\\DrgToDsc.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="EngUtil"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Roxio Shared\\System\\EngUtil.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_02\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"prutsct"="C:\\WINDOWS\\System32\\prutsct.exe"
"tcujxtrdxf.exe"="C:\\WINDOWS\\system\\tcujxtrdxf.exe"
"csrdko"="C:\\WINDOWS\\System32\\csrdko.exe"
"bjpiprf.exe"="C:\\WINDOWS\\system\\bjpiprf.exe"
"{882626DB-0381-1033-0702-020201160001}"="\"C:\\Program Files\\Common Files\\{882626DB-0381-1033-0702-020201160001}\\Update.exe\" mc-110-12-0000103"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LFCave

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0



– End of Deckard's System Scanner: finished at 2007-04-06 at 19:37:58 ———






Extra -


Deckard's System Scanner v20070328.36
Extra logfile - please post this as an attachment with your post.
——————————————————————————–

– System Information ———————————————————-

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel Pentium III processor
Percentage of Memory in Use: 81%
Physical Memory (total/avail): 255.46 MiB / 47.95 MiB
Pagefile Memory (total/avail): 679.36 MiB / 311.16 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1999.78 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 27.95 GiB total, 4.14 GiB free.
D: is CDROM (No Media)
F: is Fixed (NTFS) - 186.31 GiB total, 5.92 GiB free.


– Security Center ————————————————————-

AUOptions is set to notify before install.
Windows Internal Firewall is enabled.

AV: AVG 7.5.446 v7.5.446 (GRISOFT) Outdated


– Environment Variables ——————————————————-

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\CSampson\Application Data
CLASSPATH=C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=SA-I8000-CS
ComSpec=C:\WINDOWS\system32\cmd.exe
DiskeeperIcon=C:\Program Files\Executive Software\DiskeeperWorkstation\
FP_NO_HOST_CHECK=NO
LOGONSERVER=\\SA-I8000-CS
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\system32\nls;C:\WINDOWS\system32\nls\ENGLISH;C:\Program Files\Executive Software\DiskeeperWorkstation\;C:\Program Files\Sonic\MyDVD;;C:\Program Files\Sonic\MyDVD;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\QuickTime\QTSystem\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\system32\nls;C:\WINDOWS\system32\nls\ENGLISH;C:\Program Files\Executive Software\DiskeeperWorkstation\;C:\Program Files\Sonic\MyDVD;;C:\Program Files\Sonic\MyDVD;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\QuickTime\QTSystem\;C:\PROGRA~1\MOVIES~1\BIN
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 8 Stepping 6, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0806
ProgramFiles=C:\Program Files
PROMPT=$P$G
PS5ROOT=C:\Program Files\Roxio\Easy CD Creator 6\PhotoSuite\
QTJAVA=C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\CSampson\LOCALS~1\Temp
TMP=C:\DOCUME~1\CSampson\LOCALS~1\Temp
USERDOMAIN=SA-I8000-CS
USERNAME=CSampson
USERPROFILE=C:\Documents and Settings\CSampson
windir=C:\WINDOWS


– User Profiles —————————————————————

CSampson (admin)


– Add/Remove Programs ———————————————————

–> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8D5D99B8-DFA2-4018-ADE9-A6B83E655C65}\setup.exe" -l0x9 anything
–> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware SE Personal –> C:\PROGRA~1\Lavasoft\AD-AWA~2\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~2\INSTALL.LOG
Adobe Acrobat 5.0 –> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Adobe Flash Player 9 ActiveX –> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Photoshop 6.0 –> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 6.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 6.0\Uninst.dll"
Ahead Nero Burning ROM –> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
ArcSoft Camera Suite –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AD708DF0-9F04-4CB3-821A-85804A833B4D}\setup.exe" -l0x9 -uninst
ArcSoft PhotoImpression 4 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{68D5CEF9-0DA8-47FE-B0EB-4CBFB5AAF662}\setup.exe" -l0x9
ArcSoft PhotoStudio 5 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{03F1CC67-5BD8-4C36-8394-76311B2AE69A}\setup.exe" -l0x9 -uninst
AVG 7.5 –> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
AviSynth 2.5 –> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Best Buy Rhapsody –> "C:\Program Files\Best Buy Rhapsody\Unwise32.exe" C:\PROGRA~1\BESTBU~1\Install.log
BitComet 0.59 –> C:\Program Files\BitComet\uninst.exe
BitTorrent 3.4.2 –> "C:\Program Files\BitTorrent\uninstall.exe"
Caché in C:\CacheSys –> C:\WINDOWS\IsUninst.exe -fC:\CacheSys\Uninst.isu -cC:\CacheSys\_UNODBC.DLL
Camera Driver –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D1B3874F-3057-11D6-B2EA-0050BA18806B}\Setup.exe"
Canon Camera Window for ZoomBrowser EX –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{093625E3-7B87-49D3-AA53-AD0FCFABAF49}
Canon PhotoRecord –> C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\Canon\PhotoRecord\Uninst.isu -c"C:\PROGRA~1\Canon\PhotoRecord\Program\uninstdll.dll"
Canon Utilities File Viewer Utility 1.2 –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{EF0DD8B7-471C-463B-A298-6066C2FABAF5}
Canon Utilities PhotoStitch 3.1 –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{03CDDD00-BD57-4326-9480-4C74449AF597}
Canon Utilities RemoteCapture 2.7 –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{BEB03A1A-1EB6-48EB-9985-8B97315EE5C0}
Canon Utilities ZoomBrowser EX –> MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
CCleaner (remove only) –> "C:\Program Files\CCleaner\uninst.exe"
Cool Edit 2000 –> C:\Program Files\Cool2000\ce2Kunin.exe
Corel WordPerfect Suite 8 –> C:\Corel\Suite8\AppMan\Setup\REMOVELAUNCHER.EXE
Dazzle MovieStar 5 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F8766B65-4B9C-11D6-830E-0050DABBB449}\Setup.exe"
Dazzle Photo Editor –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39C5A3E0-31AF-11D6-830E-0050DABBB449}\Setup.exe"
Digital Video Creator 150 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E4AF027-7027-4A51-A812-99F507582B0B}\setup.exe" /UnInstall -L0x9
DiskeeperWorkstation –> MsiExec.exe /I{66C6F7B6-12D9-4042-976A-BF74D0AAFC84}
DivX –> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Player –> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
Driver Update –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{681AE860-D843-11D5-8311-0050DABBB21D}\setup.exe"
DVD Complete –> MsiExec.exe /X{44A0C48D-D548-4F36-9FFF-600CEC4688EB}
Easy CD & DVD Creator 6 –> MsiExec.exe /I{644F9DBE-CEDB-45AF-ACB8-E26692B74F62}
EPSON CardMonitor –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{109D28C7-FB38-483A-9C91-001CB59E2699}\Setup.exe" -l0x9 uninst
EPSON PhotoStarter3.0 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5983C895-DDA4-45D9-A8D1-877D5DE7693E}\Setup.exe" uninst
EPSON PictureMate User's Guide –> C:\Program Files\epson\guide\picturemate_e\uninstall.exe
EPSON Printer Software –> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
ewido anti-spyware 4.0 –> C:\Program Files\ewido anti-spyware 4.0\Uninstall.exe
HandyBits File Shredder –> "C:\Program Files\Common Files\Teknum Systems\tsUninst.exe" "C:\Program Files\HandyBits\File Shredder\HandyBits File Shredder.del"
Hijackthis 1.99.1 –> "C:\Program Files\Hijackthis\unins000.exe"
HijackThis 1.99.1 –> C:\DOCUME~1\CSampson\LOCALS~1\Temp\~AceTemp\hijackthis[1]\HijackThis.exe /uninstall
HP Deskjet 3740 –> msiexec /x{F901CA6D-A074-42D3-A11D-33AAE6FFD0C1}
HP Software Update –> MsiExec.exe /X{B81023A5-71ED-46EB-BE3B-9F974D1155F1}
HTML Help Workshop –> C:\Program Files\HTML Help Workshop\setup.exe Uninstall
Icons –> C:\WINDOWS\system32\uninstIcn.exe
iMesh –> C:\PROGRA~1\iMesh\Client\UNWISE.EXE C:\PROGRA~1\iMesh\Client\INSTALL.LOG
InterVideo WinDVD –> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\InterVideo\WinDVD\Uninst.isu"
iPod for Windows 2005-02-22 –> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{B6ACFF51-248A-4290-B50B-E50C81F25B97} /l1033
iTunes –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{59C4F14F-7590-45FC-BE9F-A67AB3590709} /l1033
J2SE Runtime Environment 5.0 Update 2 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
Java 2 Runtime Environment Standard Edition v1.3.1_03 –> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\JavaSoft\JRE\1.3.1_03\Uninst.isu"
Java 2 Runtime Environment, SE v1.4.0_01 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7CF31609-270B-11D6-9445-000102308676}\Setup.exe" Anytext
Java Web Start –> "C:\Program Files\Java Web Start\uninst-javaws.exe"
LimeShop –> wjview /cp:p "C:\Program Files\LimeShop\System\Code" Main lp: "C:\Program Files\LimeShop" ls: deletefeature ld: feature=limeshop.xml
LimeWire 4.12.6 –> "C:\Program Files\LimeWire\LimeWire 4.2.5\uninstall.exe"
Logitech MouseWare 9.76 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5809E7CF-4DCF-11D4-9875-00105ACE7734}\setup.exe" -l0x9 -l0009 UNINSTALL
Macromedia Shockwave Player –> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
MciRecorder 1.70 –> "C:\Program Files\MciRecorder\unins000.exe"
Microsoft DirectX Transform optional components –> RUNDLL32.EXE ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\DXTXTRA.INF,UNINSTALL.NT,12
Microsoft Office 2000 Small Business –> MsiExec.exe /I{00030409-78E1-11D2-B60F-006097C998E7}
Microsoft PowerPoint Viewer 97 –> C:\Program Files\PowerPoint Viewer\setup\setup.exe
MovieStar –> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MovieStar\MovieStar.isu"
Mp3 To Wave Converter PLUS 2.08 –> C:\PROGRA~1\ACOUST~1\UNWISE.EXE C:\PROGRA~1\ACOUST~1\INSTALL.LOG
MSN Messenger 6.2 –> MsiExec.exe /I{ABEB838C-A1A7-4C5D-B7E1-8B4314600205}
NETGEAR WG511 54 Mbps Wireless PC Card –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B1E5CF8-9170-42A2-A88A-A169FBDD128E}\Setup.exe" -l0x9
OLYMPUS USB Reader/Writer –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{9DFC9A77-86B4-4139-A4CF-A5E774422D28} /l1033
OnDVD –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F330A4C0-802E-11D5-8311-0050DABBB21D}\Setup.exe" -L0x0009
Panda ActiveScan –> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
Picasa 2 –> "C:\Program Files\Picasa2\Uninstall.exe"
Pocket DVD Wizard –> C:\PROGRA~1\POCKET~1\UNWISE.EXE C:\PROGRA~1\POCKET~1\INSTALL.LOG
Pop-Up Stopper –> C:\PROGRA~1\PANICW~1\POP-UP~1\UNWISE.EXE C:\PROGRA~1\PANICW~1\POP-UP~1\INSTALL.LOG
Qimage –> C:\PROGRA~1\Qimage\UNWISE.EXE C:\PROGRA~1\Qimage\INSTALL.LOG
Qimage Lite –> C:\PROGRA~1\QIMAGE~1\UNWISE.EXE C:\PROGRA~1\QIMAGE~1\INSTALL.LOG
QuickTime –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{929408E6-D265-4174-805F-81D1D914E2A4} /l1033
RichEditor –> C:\WINDOWS\system32\adbltzun.exe
ShowBiz –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{07295ABF-1245-415A-BE06-863271753443}\setup.exe" -l0x9
SmartSound For Multimedia –> C:\WINDOWS\uninst.exe -f"C:\Program Files\SmartSound For Multimedia\DeIsL2.isu" -cC:\PROGRA~1\SMARTS~1\_ISREG32.DLL
Spybot - Search & Destroy 1.4 –> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
VideoLAN VLC media player 0.8.5 –> C:\Program Files\VideoLAN\VLC\uninstall.exe
Videora iPod Converter 0.91 –> C:\Program Files\VideoraiPodConverter\uninst.exe
VuePrint –> c:\windows\vuepro32.exe /Remove
Webcast –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{200E0DC2-2223-11D6-830E-0050DABBB449}\Setup.exe"
WinAce Archiver –> C:\Program Files\WinAce\SXUNINST.EXE C:\Program Files\WinAce\SXUNINST.INI
WinMX –> C:\Program Files\WinMX\uninstall.exe
WinVNC 3.3.3 –> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ORL\VNC\Uninst.isu"
WinZip –> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
WorkStation Lock 3.3 –> C:\PROGRA~1\Posum\WORKST~1\uninstall.exe


– End of Deckard's System Scanner: finished at 2007-04-06 at 19:37:58 ———
Please show all files for your system.
You will need to reverse this process when all steps are done.


Submit File to Jotti
Please click on Jotti
Use the "Browse" button and locate the following file on your computer:
C:\WINDOWS\system32\LFCave.dll
Click the "Submit" button.
Please copy and post (reply) with the results

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.
========================

Scan with HijackThis. Place a check against each of the following:
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\WINDOWS\system32\lsasss.exe<=file PLEASE BE CAREFUL AND SPELL THIS RIGHT (there is similar good file lsass.exe)
Exit Explorer, and reboot as normal afterwards.

=====================
This scan works with Internet Explorer.
======
Panda Active Scan
Please go to Panda ActiveScan.
Once you are on the Panda site click the Scan your PC button
A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on Local Disks to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, by using Add Reply.
Sorry it took so long to reply. It was hard to get these scans because my computer keeps restarting now.

Jotti:

Found TR/Dldr.ConHook.Gen ArcaVir
Found nothing Avast
Found nothing AVG Antivirus
Found nothing BitDefender
Found Trojan.Duncan.A ClamAV
Found nothing Dr.Web
Found nothing F-Prot Antivirus
Found nothing F-Secure Anti-Virus
Found nothing Fortinet
Found nothing Kaspersky Anti-Virus
Found Trojan-Downloader.Win32.ConHook.an NOD32
Found nothing Norman Virus Control
Found nothing Panda Antivirus
Found nothing Rising Antivirus
Found nothing VirusBuster
Found Packed/Upack VBA32
Found nothing

Panda:



Incident Status Location

Adware:Adware/IPInsight Not disinfected C:\!KillBox\alchem.inf
Adware:Adware/eZula Not disinfected C:\!KillBox\ezPopStub.exe
Spyware:Spyware/SafeSurf Not disinfected C:\!KillBox\InstallerV3.exe
Adware:Adware/ShoppingCommunity Not disinfected C:\!KillBox\moconfig.exe
Spyware:Spyware/BetterInet Not disinfected C:\!KillBox\QBUninstaller.exe
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@112.2o7[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@2o7[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@adrevolver[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][1].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@adtech[2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@adultfriendfinder[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@advertising[1].txt
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@apmebf[2].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@atwola[2].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@azjmp[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@belnk[1].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@bravenet[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed]-sys[2].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@burstnet[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@casalemedia[1].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@clickbank[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@com[1].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@doubleclick[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@drivecleaner[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@fastclick[1].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@findwhat[1].txt
Spyware:Cookie/Comclick Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][1].txt
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@fortunecity[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@gostats[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@go[2].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@hitbox[2].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@kinghost[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@mediaplex[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@overture[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@questionmarket[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@realmedia[1].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@revenue[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@serving-sys[1].txt
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@statcounter[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][1].txt
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@targetnet[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@trafficmp[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@tribalfusion[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@winantivirus[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\CSampson\Cookies\[removed][2].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@yadro[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\CSampson\Cookies\csampson@zedo[1].txt
Potentially unwanted tool:application/bravesentry Not disinfected C:\Documents and Settings\CSampson\Desktop\BraveSentry.lnk
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\CSampson\Desktop\Protection\nailfix\Process.exe
Adware:Adware/Adsmart Not disinfected C:\Documents and Settings\CSampson\Local Settings\Temp\1.dllb
Adware:Adware/Adsmart Not disinfected C:\Documents and Settings\CSampson\Local Settings\Temp\v5x2.g3ame
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Documents and Settings\CSampson\Local Settings\Temporary Internet Files\Content.IE5\OTU7GDMV\WinAntiVirusPro2007FreeInstall[1].cab[UWA7P_0001_N91M0809NetInstaller.exe]
Virus:Trj/KillAV.FG Disinfected C:\Documents and Settings\CSampson\Local Settings\Temporary Internet Files\Content.IE5\WDSBUT6F\c83deecd0481935c409114e8da8b307a[1]
Virus:Trj/KillAV.FG Disinfected C:\Program Files\BraveSentry\BraveSentry.exe
Adware:Adware/BraveSentry Not disinfected C:\Program Files\BraveSentry\Uninstall.exe
Virus:Trj/KillAV.FG Disinfected C:\Program Files\Grisoft\AVG7\avgcc.exe
Virus:Trj/KillAV.FG Disinfected C:\Program Files\Grisoft\AVG7\avgw.exe
Virus:Trj/KillAV.FG Disinfected C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
Virus:Trj/KillAV.FG Disinfected C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
Adware:Adware/Maxifiles Not disinfected C:\Program Files\InetGet2\Installeur.exe
Virus:Trj/KillAV.FG Disinfected C:\Program Files\iTunes\iTunesHelper.exe
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\a.class
Adware:Adware/MoeMoney Not disinfected C:\Program Files\LimeShop\System\Code\bf.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\bq.class
Adware:Adware/MoeMoney Not disinfected C:\Program Files\LimeShop\System\Code\bs.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\dc.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\dm.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\du.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\dx.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\i.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\j.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\p.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\q.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\s.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\t.class
Adware:Adware/TopMoxie Not disinfected C:\Program Files\LimeShop\System\Code\u.class
Virus:Trj/KillAV.FG Disinfected C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
Virus:Trj/KillAV.FG Disinfected C:\Program Files\QuickTime\qttask.exe
Adware:adware/popuper Not disinfected C:\syst.exe
Adware:adware/clickalchemy Not disinfected C:\WINDOWS\alchem.ini
Adware:Adware/Maxifiles Not disinfected C:\WINDOWS\b122.exe
Adware:adware/bravesentry Not disinfected C:\WINDOWS\desktop.html
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\media_motor_bundle.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\adllsmmp.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\clcl3.exe
Spyware:Cookie/Findwhat Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\system@findwhat[1].txt
Spyware:Cookie/Overture Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\system@overture[1].txt
Spyware:Cookie/Overture Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\[removed][1].txt
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\dschkmos.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\system32\icon_mediamotor.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\iedledcs.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\iocndtl.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\kernels32.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\lsasss.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\mseacx.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2P1.EXE
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\spoolsvv.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\svehost.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\system32\ts_mediamotor.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\updater.exe
Adware:adware/ezula Not disinfected C:\WINDOWS\woinstall.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\xpupdate.exe





HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 7:22:19 PM, on 4/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Atievxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\caplzukp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\iedledcs.exe
C:\WINDOWS\system32\iocndtl.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\mseacx.exe
C:\WINDOWS\system32\adllsmmp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DfrgNTFS.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\tmp226.tmp.dll
O2 - BHO: (no name) - {b3815164-3f97-4e48-9341-d51745ee1017} - C:\WINDOWS\system32\LFCave.dll
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [alibdmp] caplzukp.exe
O4 - HKLM\..\Run: [flxplamis] C:\WINDOWS\system32\iedledcs.exe
O4 - HKLM\..\Run: [inlodcxs] C:\WINDOWS\system32\iocndtl.exe
O4 - HKLM\..\Run: [selcnlm] C:\WINDOWS\system32\mseacx.exe
O4 - HKLM\..\Run: [mesjmvce] C:\WINDOWS\system32\adllsmmp.exe
O4 - HKCU\..\Run: [Update Service] "C:\Program Files\Common Files\Teknum Systems\update.exe" /startup
O4 - Startup: NAL.EXE.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/16.19/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1098735452069
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll
O20 - Winlogon Notify: LFCave - C:\WINDOWS\SYSTEM32\LFCave.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Please go to the Control Panel=>Add/Remove Programs and uninstall Limeshop

Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
===========
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\Documents and Settings\CSampson\Local Settings\Temp\1.dllb
C:\Documents and Settings\CSampson\Local Settings\Temp\v5x2.g3ame
C:\Program Files\BraveSentry\Uninstall.exe
C:\Program Files\InetGet2\Installeur.exe
C:\syst.exe
C:\Program Files\LimeShop\System\Code\a.class
C:\Program Files\LimeShop\System\Code\bf.class
C:\Program Files\LimeShop\System\Code\bq.class
C:\Program Files\LimeShop\System\Code\bs.class
C:\Program Files\LimeShop\System\Code\dc.class
C:\Program Files\LimeShop\System\Code\dm.class
C:\Program Files\LimeShop\System\Code\du.class
C:\Program Files\LimeShop\System\Code\dx.class
C:\Program Files\LimeShop\System\Code\i.class
C:\Program Files\LimeShop\System\Code\j.class
C:\Program Files\LimeShop\System\Code\p.class
C:\Program Files\LimeShop\System\Code\q.class
C:\Program Files\LimeShop\System\Code\s.class
C:\Program Files\LimeShop\System\Code\t.class
C:\Program Files\LimeShop\System\Code\u.class
C:\WINDOWS\alchem.ini
C:\WINDOWS\b122.exe
C:\WINDOWS\desktop.html
C:\WINDOWS\system32\icon_mediamotor.exe
C:\WINDOWS\woinstall.exe
C:\WINDOWS\system32\caplzukp.exe
C:\WINDOWS\system32\iedledcs.exe
C:\WINDOWS\system32\iocndtl.exe
C:\WINDOWS\system32\mseacx.exe
C:\WINDOWS\system32\adllsmmp.exe
C:\WINDOWS\system32\rpcc.exe
caplzukp.exe


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X …and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.
===================

Scan with HijackThis. Place a check against each of the following:
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\tmp226.tmp.dll
O2 - BHO: (no name) - {b3815164-3f97-4e48-9341-d51745ee1017} - C:\WINDOWS\system32\LFCave.dll
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [alibdmp] caplzukp.exe
O4 - HKLM\..\Run: [flxplamis] C:\WINDOWS\system32\iedledcs.exe
O4 - HKLM\..\Run: [inlodcxs] C:\WINDOWS\system32\iocndtl.exe
O4 - HKLM\..\Run: [selcnlm] C:\WINDOWS\system32\mseacx.exe
O4 - HKLM\..\Run: [mesjmvce] C:\WINDOWS\system32\adllsmmp.exe
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll
O20 - Winlogon Notify: LFCave - C:\WINDOWS\SYSTEM32\LFCave.dll

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.


Please run Panda again and (reply) with the Panda log and a fresh HijackThis log
I did everything, but try as I might I was unable to uninstall Limeshop. Nothing happend when I clicked "remove." I was also unable to run the lastest Panda scan. I get this error message.

An error has occurred downloading Panda ActiveScan. Please repeat the process. If the error occurs again, restart your system and try againPossible causes of this error are:

Not allowing the application's ActiveX control to be downloaded.

Problems with the Internet connection.

The error could be due to a download error or an installation error due to lack of hard disk space, privileges etc.,…


I tried restarting but it didn't matter. There was no popup or anything in regards to downloading the ActiveX control (which is weird because I downloaded the ActiveX when I did the first scan.

Here's the latest HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:22:25 PM, on 4/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Atievxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\xmlqbfgv.exe
C:\WINDOWS\system32\dschkmos.exe
C:\WINDOWS\system32\mseacx.exe
C:\WINDOWS\system32\adllsmmp.exe
C:\WINDOWS\system32\iedledcs.exe
C:\WINDOWS\win320905-20107656.exe
C:\WINDOWS\ms040765605-201.exe
C:\WINDOWS\system32\micro1\b9.exe
C:\WINDOWS\system32\rundll32.exe
C:\windows\system32\nqdsregk.exe
C:\WINDOWS\system32\owinrodv.exe
C:\WINDOWS\system32\kernels32.exe
C:\WINDOWS\system32\spoolsvv.exe
C:\WINDOWS\updater.exe
C:\WINDOWS\system32\iocndtl.exe
C:\Program Files\Web Buying\v1.6.8\webbuying.exe
C:\Windows\xpupdate.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\cfg32a.exe
C:\WINDOWS\system32\vexga1me4t1.exe
C:\WINDOWS\system32\vexg4am1et2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\inst.exe.exe
C:\WINDOWS\system32\pdp.exe.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\CSampson\LOCALS~1\Temp\spoolsvv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\cfg32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll
O2 - BHO: DeskalertsBHO - {5298B64F-C3F6-4e81-8A30-627CA3671C7C} - C:\Program Files\DeskAlerts\deskbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {645AADB1-8990-4EB8-B2D0-22571178E7C8} - C:\Program Files\Messenger\holemu.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\tmpF.tmp.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: 0 - {8E2C2BD9-EEFF-4E08-2CB1-25F164E755B9} - C:\Program Files\MSN Gaming Zone\lawugeqi.dll
O2 - BHO: (no name) - {b3815164-3f97-4e48-9341-d51745ee1017} - C:\WINDOWS\system32\LFCave.dll
O2 - BHO: Plugin - {C318CD44-E327-4377-A28E-6EC16A921AE8} - C:\Program Files\Web Buying\v1.6.8\webbuying.dll
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [sccnssl] xmlqbfgv.exe
O4 - HKLM\..\Run: [gdmvidll] C:\WINDOWS\system32\dschkmos.exe
O4 - HKLM\..\Run: [selcnlm] C:\WINDOWS\system32\mseacx.exe
O4 - HKLM\..\Run: [mesjmvce] C:\WINDOWS\system32\adllsmmp.exe
O4 - HKLM\..\Run: [flxplamis] C:\WINDOWS\system32\iedledcs.exe
O4 - HKLM\..\Run: [win320905-20107656] C:\WINDOWS\win320905-20107656.exe
O4 - HKLM\..\Run: [ms040765605-201] C:\WINDOWS\ms040765605-201.exe
O4 - HKLM\..\Run: [bantool] C:\WINDOWS\system32\micro1\b9.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [{62-26-6D-DB-ZN}] C:\windows\system32\nqdsregk.exe SKY003
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\owinrodv.exe SKY003
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels32.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe
O4 - HKCU\..\Run: [Update Service] "C:\Program Files\Common Files\Teknum Systems\update.exe" /startup
O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.6.8\webbuying.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\RunOnce: [OSSProxy] c:\windows\system32\rlvknlg.exe -bootinstall
O4 - Startup: NAL.EXE.lnk = ?
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\owinrodv.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'rsvp32_2.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/16.19/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1098735452069
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll
O20 - Winlogon Notify: LFCave - C:\WINDOWS\SYSTEM32\LFCave.dll
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Hell Fry, let's not worry about the Panda problem now but concentrate on your log.

STEP 1.
======
Combofix
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Please post the ComboFix log and a new hijackthis log.
Because no reply was made. This topic is now closed. If you wish it reopened, please send us an email
(Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.


Also follow the recommendations in Tony Klein's article
So how did I get infected in the first place?
Your post has been Moved, Closed or Edited for one of the following reasons:

1.) You posted multiple topics and only one is required

2.) You are spamming links to other places without approval

3.) You have posted your hijackthis log to the wrong forum:
( http://forums.tomcoyote.org/index.php?showforum=27 ) <— correct forum for HijackThis Logs

4.) Abusive language or other problems in your text

5.) Your log is too old (20 days or more) and no replies from you after a volunteer tried to help you

If you came here for help, and you have not posted a Hijackthis log to the proper forum, then you may do so now, if you came here to spam or abuse, you will be dealt with harsher on your next offense

This is a family oriented forum to help those that need help.

==============================


Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI