I get sporadic IE pop-ups when I'm using Mozilla, ranging from every couple minutes to every few seconds. Some of the URLs that pop up include:
http://getmusicfree.aavalue.com/?referrerID=2154264&affid=0
http://www.leadsandfeeds.com/
I have used many antivirus and antispyware programs to attempt to remove the problem, including:
AdAware 2007
AVG 7.5
Spybot Search and Destroy
Spyware Doctor
Malwarebytes' Anti-Malware
SUPERAntiSpyware
Spyware Blaster
I have also followed all five steps before posting, and I still get popups.
I have attached the requested files, and here's my DSS main log:
Deckard's System Scanner v20071014.68
Run by n8sun1 on 2008-04-20 17:50:36
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
70: 2008-04-20 21:50:39 UTC - RP122 - Deckard's System Scanner Restore Point
69: 2008-04-20 07:46:30 UTC - RP121 - System Checkpoint
68: 2008-04-19 04:08:46 UTC - RP120 - System Checkpoint
67: 2008-04-18 03:48:35 UTC - RP119 - System Checkpoint
66: 2008-04-12 23:43:36 UTC - RP118 - Installed SUPERAntiSpyware Free Edition
-- First Restore Point --
1: 2008-01-31 04:31:06 UTC - RP53 - Installed Windows Media Player 10
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-04-20 17:51:54
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
F:\WINDOWS\system32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
F:\WINDOWS\explorer.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\RTHDCPL.exe
F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\Program Files\Grisoft\AVG7\avgamsvr.exe
F:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
F:\Program Files\Grisoft\AVG7\avgupsvc.exe
F:\Program Files\Grisoft\AVG7\avgemc.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Webshots\Webshots.scr
F:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
F:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
F:\WINDOWS\system32\wscntfy.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Documents and Settings\n8sun1\Desktop\dss.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {A0A18F09-06DE-4CAC-7EA4-F369B2339767} - (no file)
O2 - BHO: (no name) - {A1A67F60-AA71-41FD-8EA5-667F4FF15A88} - (no file)
O2 - BHO: (no name) - {C10D9154-2374-426E-A59C-DC0758D35A13} - (no file)
O2 - BHO: (no name) - {D063771C-94D6-4748-A4A1-3686A9D686AD} - (no file)
O2 - BHO: (no name) - {F3026853-4B52-478E-9E76-04A9F235276D} - (no file)
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe " /install
O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"
O4 - HKLM\..\Run: [IMJPMIG8.1] "F:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] "F:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe " /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC"
O4 - HKLM\..\Run: [PHIME2002A] "F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName"
O4 - HKLM\..\Run: [NeroFilterCheck] "F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [LXCJCATS] "rundll32 F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll,[email protected]"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] "F:\PROGRA~1\Grisoft\AVG7\avgcc.exe " /STARTUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Webshots.lnk = F:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://onecare.live.com (HKCU)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - F:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - F:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\Program Files\Common Files\Skype\Skype4COM.dll
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - F:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: awsuapml - F:\WINDOWS\system32\
O20 - Winlogon Notify: xxyaxwt - F:\WINDOWS\system32\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - F:\Program Files\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Unknown owner - f:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: lxcj_device - Unknown owner - F:\WINDOWS\system32\lxcjcoms.exe
O23 - Service: NBService - Unknown owner - F:\Program Files\Nero\Nero 7\Nero
O23 - Service: NMIndexingService - Nero AG - F:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - F:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - F:\Program Files\Spyware Doctor\pctsSvc.exe
--
End of file - 7681 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 ndiswann - f:\windows\system32\drivers\ndiswann.sys
R3 SASENUM - f:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 catchme - f:\docume~1\n8sun1\locals~1\temp\catchme.sys (file missing)
S3 LVcKap (Logitech AEC Driver) - f:\windows\system32\drivers\lvckap.sys (file missing)
S3 LVMVDrv (Logitech Machine Vision Engine Loader) - f:\windows\system32\drivers\lvmvdrv.sys (file missing)
S3 LVPr2Mon (Logitech LVPr2Mon Driver) - f:\windows\system32\drivers\lvpr2mon.sys (file missing)
S3 LVUSBSta (Logitech USB Monitor Filter) - f:\windows\system32\drivers\lvusbsta.sys (file missing)
S3 PID_0928 (Logitech QuickCam Express(PID_0928)) - f:\windows\system32\drivers\lv561av.sys (file missing)
S3 WINFLASH - i:\winflash.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "f:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "f:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
S2 LVPrcSrv (Logitech Process Monitor) - f:\program files\common files\logitech\lvmvfm\lvprcsrv.exe (file missing)
S3 NBService - f:\program files\nero\nero 7\nero backitup\nbservice.exe
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-03-20 and 2008-04-20 -----------------------------
2008-04-20 10:18:20 0 d-------- F:\Program Files\SpywareBlaster
2008-04-19 15:24:06 0 d-------- F:\WINDOWS\LastGood
2008-04-19 15:23:55 0 d-------- F:\Program Files\Panda Security
2008-04-12 19:43:41 0 d-------- F:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-12 19:43:37 0 d-------- F:\Program Files\SUPERAntiSpyware
2008-04-12 19:43:37 0 d-------- F:\Documents and Settings\n8sun1\Application Data\SUPERAntiSpyware.com
2008-04-11 00:19:04 0 d---s---- F:\Documents and Settings\n8sun1\UserData
2008-04-11 00:00:14 68096 --a------ F:\WINDOWS\system32\zip.exe
2008-04-11 00:00:14 98816 --a------ F:\WINDOWS\system32\sed.exe
2008-04-11 00:00:14 80412 --a------ F:\WINDOWS\system32\grep.exe
2008-04-11 00:00:14 73728 --a------ F:\WINDOWS\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-03-29 14:48:36 0 d-------- F:\Documents and Settings\n8sun1\.housecall6.6
2008-03-27 00:18:24 0 d-------- F:\Program Files\Common Files\xing shared
2008-03-27 00:18:12 0 d-------- F:\Program Files\Common Files\Real
2008-03-27 00:18:09 0 d-------- F:\Documents and Settings\n8sun1\Application Data\Real
-- Find3M Report ---------------------------------------------------------------
2008-04-20 17:50:43 0 d-------- F:\Documents and Settings\n8sun1\Application Data\uTorrent
2008-04-19 15:23:56 2554 --a------ F:\WINDOWS\mozver.dat
2008-04-18 21:32:17 0 d-------- F:\Program Files\uTorrent
2008-04-17 22:05:27 0 d-------- F:\Documents and Settings\n8sun1\Application Data\AVG7
2008-04-12 19:43:27 0 d-------- F:\Program Files\Common Files\Wise Installation Wizard
2008-03-30 23:40:30 0 d-------- F:\Program Files\Common Files
2008-03-30 00:44:11 0 d-------- F:\Documents and Settings\n8sun1\Application Data\LimeWire
2008-01-28 00:39:47 10 --a------ F:\Program Files\.autoreg
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0A18F09-06DE-4CAC-7EA4-F369B2339767}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A1A67F60-AA71-41FD-8EA5-667F4FF15A88}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C10D9154-2374-426E-A59C-DC0758D35A13}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D063771C-94D6-4748-A4A1-3686A9D686AD}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3026853-4B52-478E-9E76-04A9F235276D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [02/03/2008 03:26 PM]
"NvCplDaemon"="F:\WINDOWS\system32\NvCpl.dll" [10/04/2007 06:14 PM]
"nwiz"="nwiz.exe" [10/04/2007 06:14 PM F:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [12/20/2007 05:47 PM F:\WINDOWS\RTHDCPL.exe]
"IMJPMIG8.1"="F:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [02/28/2006 08:00 AM]
"MSPY2002"="F:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [02/28/2006 08:00 AM]
"PHIME2002ASync"="F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [02/28/2006 08:00 AM]
"PHIME2002A"="F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [02/28/2006 08:00 AM]
"NeroFilterCheck"="F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/01/2007 04:57 PM]
"LXCJCATS"="F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [02/24/2006 06:07 PM]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 04:42 AM]
"AVG7_CC"="F:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [02/04/2008 02:17 AM]
"Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/27/2008 12:18 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [02/28/2006 08:00 AM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="F:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [06/01/2007 11:21 AM]
"SpybotSD TeaTimer"="F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 12:43 PM]
"SUPERAntiSpyware"="F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/29/2008 04:03 PM]
F:\Documents and Settings\n8sun1\Start Menu\Programs\Startup\
Webshots.lnk - F:\Program Files\Webshots\Launcher.exe [12/27/2007 1:03:28 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= F:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
F:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 F:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awsuapml]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyaxwt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6783bf8d-e165-11dc-a0e4-001aa059ccae}]
AutoRun\command- "L:\Install FreeAgent Tools.exe" /run
*Newly Created Service* - RKPAVPROC
*Newly Created Service* - SASDIFSV
-- End of Deckard's System Scanner: finished at 2008-04-20 17:52:14 ------------
Thanks so much!
http://getmusicfree.aavalue.com/?referrerID=2154264&affid=0
http://www.leadsandfeeds.com/
I have used many antivirus and antispyware programs to attempt to remove the problem, including:
AdAware 2007
AVG 7.5
Spybot Search and Destroy
Spyware Doctor
Malwarebytes' Anti-Malware
SUPERAntiSpyware
Spyware Blaster
I have also followed all five steps before posting, and I still get popups.
I have attached the requested files, and here's my DSS main log:
Deckard's System Scanner v20071014.68
Run by n8sun1 on 2008-04-20 17:50:36
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
70: 2008-04-20 21:50:39 UTC - RP122 - Deckard's System Scanner Restore Point
69: 2008-04-20 07:46:30 UTC - RP121 - System Checkpoint
68: 2008-04-19 04:08:46 UTC - RP120 - System Checkpoint
67: 2008-04-18 03:48:35 UTC - RP119 - System Checkpoint
66: 2008-04-12 23:43:36 UTC - RP118 - Installed SUPERAntiSpyware Free Edition
-- First Restore Point --
1: 2008-01-31 04:31:06 UTC - RP53 - Installed Windows Media Player 10
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-04-20 17:51:54
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
F:\WINDOWS\system32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
F:\WINDOWS\explorer.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\RTHDCPL.exe
F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\Program Files\Grisoft\AVG7\avgamsvr.exe
F:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
F:\Program Files\Grisoft\AVG7\avgupsvc.exe
F:\Program Files\Grisoft\AVG7\avgemc.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Webshots\Webshots.scr
F:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
F:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
F:\WINDOWS\system32\wscntfy.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Documents and Settings\n8sun1\Desktop\dss.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {A0A18F09-06DE-4CAC-7EA4-F369B2339767} - (no file)
O2 - BHO: (no name) - {A1A67F60-AA71-41FD-8EA5-667F4FF15A88} - (no file)
O2 - BHO: (no name) - {C10D9154-2374-426E-A59C-DC0758D35A13} - (no file)
O2 - BHO: (no name) - {D063771C-94D6-4748-A4A1-3686A9D686AD} - (no file)
O2 - BHO: (no name) - {F3026853-4B52-478E-9E76-04A9F235276D} - (no file)
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe " /install
O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"
O4 - HKLM\..\Run: [IMJPMIG8.1] "F:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] "F:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe " /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC"
O4 - HKLM\..\Run: [PHIME2002A] "F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName"
O4 - HKLM\..\Run: [NeroFilterCheck] "F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [LXCJCATS] "rundll32 F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll,[email protected]"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] "F:\PROGRA~1\Grisoft\AVG7\avgcc.exe " /STARTUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Webshots.lnk = F:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://onecare.live.com (HKCU)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - F:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - F:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\Program Files\Common Files\Skype\Skype4COM.dll
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - F:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: awsuapml - F:\WINDOWS\system32\
O20 - Winlogon Notify: xxyaxwt - F:\WINDOWS\system32\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - F:\Program Files\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Unknown owner - f:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: lxcj_device - Unknown owner - F:\WINDOWS\system32\lxcjcoms.exe
O23 - Service: NBService - Unknown owner - F:\Program Files\Nero\Nero 7\Nero
O23 - Service: NMIndexingService - Nero AG - F:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - F:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - F:\Program Files\Spyware Doctor\pctsSvc.exe
--
End of file - 7681 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 ndiswann - f:\windows\system32\drivers\ndiswann.sys
R3 SASENUM - f:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 catchme - f:\docume~1\n8sun1\locals~1\temp\catchme.sys (file missing)
S3 LVcKap (Logitech AEC Driver) - f:\windows\system32\drivers\lvckap.sys (file missing)
S3 LVMVDrv (Logitech Machine Vision Engine Loader) - f:\windows\system32\drivers\lvmvdrv.sys (file missing)
S3 LVPr2Mon (Logitech LVPr2Mon Driver) - f:\windows\system32\drivers\lvpr2mon.sys (file missing)
S3 LVUSBSta (Logitech USB Monitor Filter) - f:\windows\system32\drivers\lvusbsta.sys (file missing)
S3 PID_0928 (Logitech QuickCam Express(PID_0928)) - f:\windows\system32\drivers\lv561av.sys (file missing)
S3 WINFLASH - i:\winflash.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "f:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "f:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
S2 LVPrcSrv (Logitech Process Monitor) - f:\program files\common files\logitech\lvmvfm\lvprcsrv.exe (file missing)
S3 NBService - f:\program files\nero\nero 7\nero backitup\nbservice.exe
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-03-20 and 2008-04-20 -----------------------------
2008-04-20 10:18:20 0 d-------- F:\Program Files\SpywareBlaster
2008-04-19 15:24:06 0 d-------- F:\WINDOWS\LastGood
2008-04-19 15:23:55 0 d-------- F:\Program Files\Panda Security
2008-04-12 19:43:41 0 d-------- F:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-12 19:43:37 0 d-------- F:\Program Files\SUPERAntiSpyware
2008-04-12 19:43:37 0 d-------- F:\Documents and Settings\n8sun1\Application Data\SUPERAntiSpyware.com
2008-04-11 00:19:04 0 d---s---- F:\Documents and Settings\n8sun1\UserData
2008-04-11 00:00:14 68096 --a------ F:\WINDOWS\system32\zip.exe
2008-04-11 00:00:14 98816 --a------ F:\WINDOWS\system32\sed.exe
2008-04-11 00:00:14 80412 --a------ F:\WINDOWS\system32\grep.exe
2008-04-11 00:00:14 73728 --a------ F:\WINDOWS\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-03-29 14:48:36 0 d-------- F:\Documents and Settings\n8sun1\.housecall6.6
2008-03-27 00:18:24 0 d-------- F:\Program Files\Common Files\xing shared
2008-03-27 00:18:12 0 d-------- F:\Program Files\Common Files\Real
2008-03-27 00:18:09 0 d-------- F:\Documents and Settings\n8sun1\Application Data\Real
-- Find3M Report ---------------------------------------------------------------
2008-04-20 17:50:43 0 d-------- F:\Documents and Settings\n8sun1\Application Data\uTorrent
2008-04-19 15:23:56 2554 --a------ F:\WINDOWS\mozver.dat
2008-04-18 21:32:17 0 d-------- F:\Program Files\uTorrent
2008-04-17 22:05:27 0 d-------- F:\Documents and Settings\n8sun1\Application Data\AVG7
2008-04-12 19:43:27 0 d-------- F:\Program Files\Common Files\Wise Installation Wizard
2008-03-30 23:40:30 0 d-------- F:\Program Files\Common Files
2008-03-30 00:44:11 0 d-------- F:\Documents and Settings\n8sun1\Application Data\LimeWire
2008-01-28 00:39:47 10 --a------ F:\Program Files\.autoreg
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0A18F09-06DE-4CAC-7EA4-F369B2339767}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A1A67F60-AA71-41FD-8EA5-667F4FF15A88}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C10D9154-2374-426E-A59C-DC0758D35A13}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D063771C-94D6-4748-A4A1-3686A9D686AD}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3026853-4B52-478E-9E76-04A9F235276D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [02/03/2008 03:26 PM]
"NvCplDaemon"="F:\WINDOWS\system32\NvCpl.dll" [10/04/2007 06:14 PM]
"nwiz"="nwiz.exe" [10/04/2007 06:14 PM F:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [12/20/2007 05:47 PM F:\WINDOWS\RTHDCPL.exe]
"IMJPMIG8.1"="F:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [02/28/2006 08:00 AM]
"MSPY2002"="F:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [02/28/2006 08:00 AM]
"PHIME2002ASync"="F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [02/28/2006 08:00 AM]
"PHIME2002A"="F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [02/28/2006 08:00 AM]
"NeroFilterCheck"="F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/01/2007 04:57 PM]
"LXCJCATS"="F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [02/24/2006 06:07 PM]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 04:42 AM]
"AVG7_CC"="F:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [02/04/2008 02:17 AM]
"Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/27/2008 12:18 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [02/28/2006 08:00 AM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="F:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [06/01/2007 11:21 AM]
"SpybotSD TeaTimer"="F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 12:43 PM]
"SUPERAntiSpyware"="F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/29/2008 04:03 PM]
F:\Documents and Settings\n8sun1\Start Menu\Programs\Startup\
Webshots.lnk - F:\Program Files\Webshots\Launcher.exe [12/27/2007 1:03:28 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= F:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
F:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 F:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awsuapml]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyaxwt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6783bf8d-e165-11dc-a0e4-001aa059ccae}]
AutoRun\command- "L:\Install FreeAgent Tools.exe" /run
*Newly Created Service* - RKPAVPROC
*Newly Created Service* - SASDIFSV
-- End of Deckard's System Scanner: finished at 2008-04-20 17:52:14 ------------
Thanks so much!
Attachments
-
12.2 KB Views: 51
-
19 KB Views: 52