Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Starting today, when logging into my XP account, it has taken very long to load and go to my desktop. Also, when I go to Internet Explorer for the first time after logging in, several pop-ups come up, but don't after that. Since both problems started today, I think they might be linked, but I don't know what caused them or how to fix them.

Val!! there is an excellent link on safe surfing just a few posts below that can help you. More factors in online security
Here is some more info to follow.....
Have you Scanned with SPYBOT,or AD-AWARE?Do you have SPYGUARD,or SPYBLASTER AS spyware preventors?You will also need a firewall,if you dont have one allready installed,and an antivirus to protect your system.#1 Firewall- www.zonelabs.com
#2 Antivirus-http://www.grisoft.com/us/us_index.php
#3 Anti spyware- http://www.majorgeeks.com/download886.html
#4 If you have #1,and 2 allready,you can skip those and download SPYBOT,and AD-AWARE to scan your system for spyware infections.After your system is completely clean,you can download SPYBLASTER,and SPYGUARD to prevent further infections.
#5 If SPYBOT,nor AD-Aware was able to clean your system of spyware,you can then ask for someone to inspect your hijackthis log.
#6 Make sure you update all software before you scan your system,and scan offline.HOPE this helps? PEACE!!!!!!!!!!

I have most of what's on that list, and I am running AdAware as we speak. I will post the HiJackThis log if it does not work.

Still there....
Logfile of HijackThis v1.97.7
Scan saved at 9:18:39 PM, on 3/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\SOUNDMAN.exe
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\aim\aim.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\DOCUME~1\VALERIE\LOCALS~1\Temp\pch3.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\Program Files\SysAI\SysAI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\RYAN\My Documents\PSP\psp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqdstcp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe
C:\Documents and Settings\VALERIE\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchexe.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchexe.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchexe.com/searchbar.html
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-786FA05C83AB} - C:\Program Files\SysAI\AproposPlugin.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {BCC39C29-A4B1-0B0A-9B9F-2CA9F62ED7DD} - C:\PROGRA~1\SECTSI~1\LESSINTER.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: Dogpile Toolbar - {5E92F538-B50B-46c5-9C5F-C6EECED3F6C6} - C:\Program Files\DogpileToolbar\ultrabar.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [winactive] C:\Program Files\Window Active\winactive.exe
O4 - HKLM\..\Run: [THUNK VGA] C:\PROGRA~1\SPAMHT~1\pure ford kind.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - Global Startup: America Online 9.0 Tray Icon.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O8 - Extra context menu item: Dogpile Cursor Search - C:\Documents and Settings\All Users\Application Data\Infospace\DogpileToolbar\contextsearch.htm
O8 - Extra context menu item: Save F&lash with FlashCapture - res://C:\Program Files\FlashCapture\FCIEXT.dll/FCIEXT.htm
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: FlashCapture (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {034CC2DC-3245-4B26-B5C7-7B8777739CB7} - http://64.156.31.70/058726ca.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/ym/yiebio5_0_2_7.cab
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} (EPlugin Control) - http://66.230.146.33/EPlugin.cab
O16 - DPF: {FEC3E5A3-50F7-4B0C-97D8-01CF69DFBFC7} (Measurement Service Client) - http://ccon.madonion.com/global/msc.cab

Hi Val,
First, move Hijack This to a permanent directory like c:\program files\hijack this\hijackthis.exe. This way we can make backups if something goes wrong.
Important to do this while internet connection is working.
1. Download Lsp fix2. Run the LspFix you downloaded. Tell it to remove inetadpt.dll.
In order to be able to select inetadpt.dll, you need to click the "I know what I'm doing" checkbox.
Then check all instances of inetadpt.dll (and nothing else) , and move them to the "Remove" pane.
Then click Finish.Reboot.
Delete c: inetadpt.dll
Run hijackthis again,
put a check next to these, click "fix checked" and reboot.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchexe.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchexe.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchexe.com/searchbar.html
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-786FA05C83AB} - C:\Program Files\SysAI\AproposPlugin.dll
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [winactive] C:\Program Files\Window Active\winactive.exeO16 - DPF: {034CC2DC-3245-4B26-B5C7-7B8777739CB7} - http://64.156.31.70/058726ca.exe
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} (EPlugin Control) - http://66.230.146.33/EPlugin.cab
Find and delete:
C:\PROGRAM FILES\WINDOW ACTIVE folderc:\Program Files\AutoUpdate folder
Good luck,
and FYI SpywareBlaster blocks the 016 entries.
http://www.javacoolsoftware.com/spywareblaster.html

I followed those directions, almost everything is gone now, thank you. The only thing is that unless I set my homepage to about:blank, the next time I open Internet Explorer, searchexe.com will be back. I ran SpyBot and AdAware and both found nothing.

Hi val, looks like others are having that
problem, post another log.
I hope we can find it.
Storms are heading my way, can't stay
online too long.I will research till then.

There is a trail of goofy files with your problem.
Your file to remove;
O4 - HKLM\..\Run: [THUNK VGA] C:\PROGRA~1\SPAMHT~1\pure ford kind.exe
Delete the SPAMHT folder.
Good luck

Some other files that come with searchexe,
everyone has a different name.O4 - HKLM\..\Run: [new window] C:\PROGRA~1\CAKENO~1\Hide Shim.exe
O4 - HKLM\..\Run: [Pollwipe] C:\PROGRA~1\01 grid bash\Five Bib Seek.exe
O4 - HKLM\..\Run: [Once Find] C:\PROGRA~1\DOWNLO~2\Nurb each live.exe
O4 - HKLM\..\Run: [Safe Htm] C:\PROGRA~1\dumb stop jump\managerthirdpart.exe
O4 - HKLM\..\Run: [third user] C:\PROGRA~1\FIRSTS~1\barbholesoftware.exe
O4 - HKLM\..\Run: [EggsSect] C:\PROGRA~1\denthecksave\Settings Phone.exe
O4 - HKLM\..\Run: [nurbglobal] C:\PROGRA~1\LICENS~1\rect tray.exe
O4 - HKLM\..\Run: [KnobBalm] C:\PROGRA~1\Htmelse\Date Cool.exe
O4 - HKLM\..\Run: [StyleCamp] C:\PROGRA~1\DVDROA~1\online license.exe
O4 - HKLM\..\Run: [Third Memo] C:\PROGRA~1\phonejoy\PollTray.exe
O4 - HKLM\..\Run: [DogBike] C:\PROGRA~1\ANTISI~1\lite jump data.exe
O4 - HKLM\..\Run: [greatjoy] C:\PROGRA~1\LOGBOO~1\SafeStop.exe
O4 - HKLM\..\Run: [PopSoftware] C:\PROGRA~1\PLATFO~1\Pile Remote Slow.exe
O4 - HKLM\..\Run: [Find third] C:\PROGRA~1\HEARTL~1\HELPWAYCREATIVE.exe
O4 - HKLM\..\Run: [remotecake] C:\PROGRA~1\LOGBAS~1\film tool grey.exe
O4 - HKLM\..\Run: [dartfree] C:\PROGRA~1\FORDDU~1\FunkFirstSect.exe
O4 - HKLM\..\Run: [AntiBoob] C:\PROGRA~1\PARTER~1\pilephonecdrom.exe
O4 - HKLM\..\Run: [logocake] C:\PROGRA~1\PLAYPL~1\ToolBlah.exe
O4 - HKLM\..\Run: [less part] C:\PROGRA~1\ANTICI~1\Help64test.exe
O4 - HKLM\..\Run: [datesend] C:\PROGRA~1\JOYMOV~1\Manager open ford.exe
O4 - HKLM\..\Run: [manager sect] C:\PROGRA~1\SITEBA~1\barbidolmove.exe
O4 - HKLM\..\Run: [CakeJoy] C:\PROGRA~1\itchtrust\cdromextrashim.exe
O4 - HKLM\..\Run: [TrayIdol] C:\PROGRA~1\Atom rdr view\4 Proc Lies.exe

Thank you everyone! Everything appears to be back to normal, should I post an updated log to make sure everything's fixed?

Here it is, everything look good?
Logfile of HijackThis v1.97.7
Scan saved at 8:02:35 PM, on 3/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\SOUNDMAN.exe
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\aim\aim.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\VALERIE\Desktop\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.homestarrunner.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - Global Startup: America Online 9.0 Tray Icon.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O8 - Extra context menu item: Dogpile Cursor Search - C:\Documents and Settings\All Users\Application Data\Infospace\DogpileToolbar\contextsearch.htm
O8 - Extra context menu item: Save F&lash with FlashCapture - res://C:\Program Files\FlashCapture\FCIEXT.dll/FCIEXT.htm
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: FlashCapture (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/ym/yiebio5_0_2_7.cab
O16 - DPF: {FEC3E5A3-50F7-4B0C-97D8-01CF69DFBFC7} (Measurement Service Client) - http://ccon.madonion.com/global/msc.cab

Hi val, good job looks clean.
Glad we could help.There is a new version of Spywareblaster,
to keep you safe.
Take care.

Good day. Long time user, first time poster. At current I am having the same problems as the above user however I am unable to download the lspfix from the link provided. Even if I go to the website it gives me "The page cannot be found". Is there another spot to download this file from? Any help would be much appreciated :).
-§ir

When looking for help with a dll file that will not be deleted even under safe mode, I ran across this; http://www.spywareeliminator.com/forum/index.php?s=34212fa73d09ee2554e5c15b9a66d64b&showtopic=1133&st=0entry3318. The file in question is avctres.dll. I too am having the same problem as the user describes. I cannot currently exercise the actions that he can because I am in the military and the IT folks do not like us diddling around with our workstations (even though some of us know what we are doing lol). To me, it has the beginings of a virus because despite what we do, it cannot be removed. It has seemingly attached itself as a vital system file so that attempted deletion in safe mode does nothing to erradicate it. I have done tons of registry deletions to no avail because it returns like a bad cold. Oh btw, I went to the HijackThis website (http://www.spywareinfo.com/~merijn/index.html) and downloaded this program called startuplist.exe and this is what I found:
*edit* Text removed due to a pop up warning.Does anyone know what UserInit = C:\WINNT\SYSTEM32\Userinit.exe, is and could it be the culprit?
-§ir

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |