This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] System32/CMD & Command blank screens@ startup

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

System32/CMD & Command startup screens
I just ran Spybot, which identified 1 trojan and numerous registry issues. I removed the trojan and indicated I wanted to decline the registry changes (probably about 15-20). When I restart my PC, I now get at least 15 or so blank screens which pop up momentarily toward the end of the startup, that contain Wndows/System32/CMD or Command.exe or com. This occurs after Windows has loaded and the startup applications are being loaded. The screens only appear for a second or so, not enough time to do anything with them, and then disappear. Most of them are black with nothing else; but a few have a single line of text that disappears before I can read it. The screens are about 5x6 inches in size and by the time all my startup applications have loaded, they are all gone. Everything else seems to run normally.

I certainly appreciate any help in determining the cause and fixing it.

I have a Gateway PC with a Pentium 4 chip (1.3Mhz), 1.5 Gb memory, and I'm running Windows XP SP3.

I ran HiJack This and saved the following (but the O4 lnes for Spybot deletes look strange):

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:13 AM, on 4/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\SK9910DM.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mirra\Mirra.Client.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\mirra\mirra.service.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\SYSTEM32\NOTEPAD.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Clipmarks.Toolbar - {1205D44C-FFD2-44E5-AA1D-929DCA37EB7A} - C:\Program Files\Clipmarks\clipmarks.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search 2\Toolbar\ToolbarContainer101000048.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingD1132] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\MySignatureInsertBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2899] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\MySignaturePreviewBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD887] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\MySignaturePreviewBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7810] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7918] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9472] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3924] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5433] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2447] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB735] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5742] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7043] command.com /c del "C:\Program Files\MyWebSearch\bar\History\search2"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4303] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\History\search2"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1502] command.com /c del "C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2805] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9703] command.com /c del "C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4038] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5023] command.com /c del "C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5381] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7116] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5267] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
O4 - HKCU\..\RunOnce: [SpybotDeletingB655] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1503] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9190] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\settings.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6499] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\settings.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2184] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4719] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5103] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm.bak"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7191] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm.bak"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3086] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3865] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5544] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8790] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7223] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8922] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3080] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4257] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL"
O4 - HKUS\S-1-5-18\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\system32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\system32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Mirra.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZNfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\EARTHLINKIM\AIM.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par…an_unicode.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (GTDownloaderCtrl Class) - http://inst.c-wss.com/82/html/gtdownlr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a224.g.akamai.net/7/224/52/20…eInstaller.exe
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa…bs/tgctlsr.cab
O16 - DPF: {611CF77F-F7F5-4EA1-B979-667671326B4C} (MarketTrader - ETrade v243a) - http://etrade.bridge.com/etgmt_prd/j…b_etrade_i.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu…?1120590696420
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof…?1157582760127
O16 - DPF: {6F8AC4DE-286F-4A2B-98FB-2A73A46595BD} (ActiveNva Control) - http://www.sharp-usa.com/SharpMotion…tiveNva100.cab
O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} (CInstallLPCtrl Object) - http://u3.sandisk.com/download/apps/LPInstaller.CAB
O16 - DPF: {E93A06EF-ABD8-4FA5-96BF-968614B08531} (MarketTrader - Reuters v243b) - http://etrade.bridge.com/etgmt_prd/j…b_bridge_i.cab
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MirraSync Service (Mirra.Service) - Seagate Technology - c:\program files\mirra\mirra.service.exe

–
End of file - 14823 bytes
The windows that you saw appear to be Spybot related and are perfectly normal - it was deleting some files. Reboot your PC and let me know if they appear again - they shouldn't, but i'd like to be sure.
Given that it has picked up a number of files, I think a look-see wouldn't go amiss.

1) Download Malwarebytes' Anti-Malware from here and save it to your Desktop - unless you already have it, in which case skip to the "updating" bit below.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Ensure a checkmark is placed next to both Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware and then click Finish.
  • If an update is found, it will download and install the latest version - you'll need to clear it with your firewall.
  • Once the program has loaded, select Perform full scan and then Scan.
  • When the scan has finished, click OK and then Show Results to view the results - no surprise there!
  • If MBAM finds anything, check the box(es) and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Let me have the MBAM log, a fresh HJT log (run in Normal Mode) AND a description of how your PC is behaving.

2) Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
3) Finally, download Sec-Info.zip from here and save it to your Desktop. You will need to extract the file.

Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see a folder with a .vbs file in it. Double click Sec-info.vbs to run it and a text file called Sec-Info.txt should be created in the same folder - either that or you'll get an error message.
Please copy and paste the contents of the text file into your next reply and then you can delete both of the folders and their contents.
Hi Noviciate,

First, thanks for helping me with this problem; I certainly appreciate your efforts. Second, I have restarted my PC at least 4-5 times and the (mostly) blank screens appear each time. It was not a one time occurrence. My PC seems to be functioning normally, other than the startup screen problem.

Question: Do all the O4 Spybot entries belong in the HiJack This log?

I followed your instructions and have the following data for you to review:


Mbam Log

Malwarebytes' Anti-Malware 1.36
Database version: 2039
Windows 5.1.2600 Service Pack 3

4/25/2009 10:51:05 AM
mbam-log-2009-04-25 (10-51-05).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 226025
Time elapsed: 2 hour(s), 17 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 16
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 15

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096021.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096031.DLL (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096032.EXE (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096037.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096038.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096040.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096041.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096042.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096043.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096044.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096045.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096046.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{6EEFF5EC-76EB-407C-80F0-9684DE197DD2}\RP1371\A0096048.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\WINDOWS\HOSTS (Trojan.Agent) -> Quarantined and deleted successfully.


HiJacThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:38:07 AM, on 4/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\SK9910DM.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Mirra\Mirra.Client.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\mirra\mirra.service.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Clipmarks.Toolbar - {1205D44C-FFD2-44E5-AA1D-929DCA37EB7A} - C:\Program Files\Clipmarks\clipmarks.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search 2\Toolbar\ToolbarContainer101000048.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingD1132] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\MySignatureInsertBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2899] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\MySignaturePreviewBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD887] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\MySignaturePreviewBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7810] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7918] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9472] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3924] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5433] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2447] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB735] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5742] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7043] command.com /c del "C:\Program Files\MyWebSearch\bar\History\search2"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4303] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\History\search2"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1502] command.com /c del "C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2805] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9703] command.com /c del "C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4038] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5023] command.com /c del "C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5381] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7116] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5267] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
O4 - HKCU\..\RunOnce: [SpybotDeletingB655] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1503] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9190] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\settings.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6499] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\settings.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2184] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4719] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5103] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm.bak"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7191] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm.bak"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3086] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3865] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5544] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8790] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7223] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8922] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3080] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4257] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL"
O4 - HKUS\S-1-5-18\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\system32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\system32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Mirra.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZNfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\EARTHLINKIM\AIM.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (GTDownloaderCtrl Class) - http://inst.c-wss.com/82/html/gtdownlr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a224.g.akamai.net/7/224/52/20010620…meInstaller.exe
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab
O16 - DPF: {611CF77F-F7F5-4EA1-B979-667671326B4C} (MarketTrader - ETrade v243a) - http://etrade.bridge.com/etgmt_prd/java/gmtb_etrade_i.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120590696420
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157582760127
O16 - DPF: {6F8AC4DE-286F-4A2B-98FB-2A73A46595BD} (ActiveNva Control) - http://www.sharp-usa.com/SharpMotionART/ac…ctiveNva100.cab
O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} (CInstallLPCtrl Object) - http://u3.sandisk.com/download/apps/LPInstaller.CAB
O16 - DPF: {E93A06EF-ABD8-4FA5-96BF-968614B08531} (MarketTrader - Reuters v243b) - http://etrade.bridge.com/etgmt_prd/java/gmtb_bridge_i.cab
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MirraSync Service (Mirra.Service) - Seagate Technology - c:\program files\mirra\mirra.service.exe

–
End of file - 14823 bytes


HiJack This Uninstall List

56K PCI VOICE MODEM SF-1156IV R9A (Uninstall)
Adaptec DirectCD
Adaptec Easy CD Creator 4
Ad-aware 6 Personal
Adobe Acrobat - Reader 6.0.2 Update
Adobe Acrobat and Reader 6.0.3 Update
Adobe Download Manager 1.2 (Remove Only)
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Reader 6.0.1
AnalogX NetStat Live
APC PowerChute Personal Edition
Apple Mobile Device Support
Apple Software Update
Arcade! Classic Arcade Pack
avast! Antivirus
AVIedit 3.3
Belarc Advisor 7.2
Bonjour
Brother MFL-Pro Suite
Canon Camera WIA Driver 6.0
Canon i850
Canon i850
Canon i960
Canon i960
Canon PhotoRecord
Canon Utilities Easy-PhotoPrint
Canon Utilities PhotoStitch 3.1
Canon Utilities ZoomBrowser EX
Check Identical Files version 2.12
ClearType Tuning Control Panel Applet
Clipmarks
Copernic Desktop Search - Home
Creative Launcher
Creative PlayCenter
Creative Recorder
DATA BECKER - Perfect Photo Printer
DataPilot
DataPilot USB Driver Pack
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Earthlink Instant Messenger
EasyCleaner
FLV Player 2.0, build 24
GanttProject
Gateway Ink Monitor
Gateway Multi-function Keyboard
Google Talk (remove only)
Google Toolbar for Firefox
Google Toolbar for Internet Explorer
Handy Backup 4.0
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB952287)
Intel A/V Codecs V2.0
Intel® Create & Share™ Software
InterTrust InterRights Point
Intertrust Music Pack Manager
IomegaWare
iPod for Windows 2006-03-23
iTunes
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment Standard Edition v1.3.1_11
Java 2 Runtime Environment, SE v1.4.1_01
Java 2 Runtime Environment, SE v1.4.2
Java Web Start
Java™ 6 Update 13
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 4
Java™ 6 Update 5
Java™ 6 Update 7
Java™ SE Runtime Environment 6 Update 1
Kaspersky Online Scanner
Kodak EasyShare software
Logitech MouseWare 9.28
Malwarebytes' Anti-Malware
MGI PhotoSuite 4 (Remove Only)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Picture It! Publishing 2001
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works 2001 Setup Launcher
Microsoft Works 6.0
Mirra PC Software 2.2.151
MOV Converter 3
Movie Converter
Mozilla Firefox (3.0.9)
MPS-Sudoku
MSN Music Assistant
Network Recording Player
OpenOffice.org 2.4
PaperPort
Pawn
Pdf995
PdfEdit995
PhoneTools
PowerPlugs: PhotoActive FX
PS/2 Millennium Keyboard
QuickTime
RealPlayer
Remove Hidden Data Tool
Rival Chess - Unregistered Version
R-Studio 3.0
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Shockwave
Signature995
SnagIt 7
SnagIt 8
Sound Blaster Live! Value
Spybot - Search & Destroy
Spybot - Search & Destroy 1.2
Tweak UI
U3Launcher
Unix Utilities for Yahoo! Widgets
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
USB Universal Driver
WebEx
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows XP Service Pack 3
Windows XP Uninstall
WinZip
Yahoo! Install Manager
Yahoo! Widgets


Thanks – Rich………….
You didn't post the Sec-Info.txt contents - was there a problem?

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Question: Do all the O4 Spybot entries belong in the HiJack This log?

If you look at these entries, they all start O4 - HKCU\..\RunOnce:. In theory they should run once and then the lines should be deleted. For some reason they aren't and this is why there are Command Windows appearing at each boot. Fortunately you appear to be using an old version of Spybot, so we'll kill two birds with one stone.

Uninstall Spybot S&D via Add/Remove Programs and reboot your PC. Then run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKCU\..\RunOnce: [SpybotDeletingD1132] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\MySignatureInsertBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2899] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\MySignaturePreviewBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD887] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\MySignaturePreviewBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7810] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7918] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9472] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3924] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5433] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2447] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB735] command.com /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5742] cmd.exe /c del "C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn-new.html"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7043] command.com /c del "C:\Program Files\MyWebSearch\bar\History\search2"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4303] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\History\search2"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1502] command.com /c del "C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2805] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9703] command.com /c del "C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4038] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5023] command.com /c del "C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5381] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7116] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5267] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
O4 - HKCU\..\RunOnce: [SpybotDeletingB655] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1503] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9190] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\settings.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6499] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\settings.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2184] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4719] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5103] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm.bak"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7191] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm.bak"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3086] command.com /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3865] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\Settings\setting2.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5544] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8790] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7223] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8922] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3080] command.com /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4257] cmd.exe /c del "C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL"


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

You can then install the latest version of Spybot, available here.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download JavaRa from here and save it to your Desktop.
You will need to extract the file(s):
Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


***Please close any instances of Internet Explorer before continuing!***
  • Double-click JavaRa.exe to begin.
  • Pick your prefered language from the drop-down menu and click Select.
  • Click on Remove Older Versions to remove older version of Java - obvious really, isn't it!
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location, just in case you have any problems with Java afterwards.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Your version of Adobe Reader is also out-of-date. You can get the latest version here.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Once you've done all that, let me have the obligatory HJT log and tell me if the PC is behaving itself now - throw in a reboot and tell me the Command Windows have stopped too.
OK, I think we have made significant progress. Here's where things stand:

First, I simply forgot the Sec-Info text, but I'm pasting it in this update (below).

Second, I deleted SpyBot and downloaded the newer version from the website you provided. I should point out that I had downloaded what I thought was the latest version two days ago, and that's when this problem started. Maybe there was a version problem, with both installed.

Third, After deleting SpyBot and running HiJackThis, the RunOnce Spybot stuff was gone. So I deleted the other two lines (R3 & O3).

Then I downloaded and ran JavaRa. It seemed like it deleted a lot of stuff, but then terminated with an error message saying it encountered a problem and had to shut down. I simply ran it again and it deleted less, but finished with the prompt about the logfile, which I saved. Don't think there is a problem, but maybe you can tell me.

I then downloaded Adobe which took forever to install (an hour), but it completed successfully.

Next, I rebooted and everything seemed to load fine, with NO blank screens!!! In addition, PC seems to be running fine. My guess is it will run better now without all the garbage old versions we deleted.

The only thing I noticed is that there are still two "Run Once" lines in the HJT file. Should I also delete these?

Here are the files"

Sec-Info ext

Company Name: ALWIL Software
AV Name: avast! antivirus 4.8.1201 [VPS 090425-0]
Version Number: 4.8.1201
On-Access Scanning Enabled: Yes
Product up-to-date: Yes


HiJack This

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:26:36 PM, on 4/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\SK9910DM.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Mirra\Mirra.Client.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\mirra\mirra.service.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Clipmarks.Toolbar - {1205D44C-FFD2-44E5-AA1D-929DCA37EB7A} - C:\Program Files\Clipmarks\clipmarks.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search 2\Toolbar\ToolbarContainer101000048.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKUS\S-1-5-18\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\system32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\system32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Mirra.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZNfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\EARTHLINKIM\AIM.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (GTDownloaderCtrl Class) - http://inst.c-wss.com/82/html/gtdownlr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a224.g.akamai.net/7/224/52/20010620…meInstaller.exe
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab
O16 - DPF: {611CF77F-F7F5-4EA1-B979-667671326B4C} (MarketTrader - ETrade v243a) - http://etrade.bridge.com/etgmt_prd/java/gmtb_etrade_i.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120590696420
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157582760127
O16 - DPF: {6F8AC4DE-286F-4A2B-98FB-2A73A46595BD} (ActiveNva Control) - http://www.sharp-usa.com/SharpMotionART/ac…ctiveNva100.cab
O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} (CInstallLPCtrl Object) - http://u3.sandisk.com/download/apps/LPInstaller.CAB
O16 - DPF: {E93A06EF-ABD8-4FA5-96BF-968614B08531} (MarketTrader - Reuters v243b) - http://etrade.bridge.com/etgmt_prd/java/gmtb_bridge_i.cab
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MirraSync Service (Mirra.Service) - Seagate Technology - c:\program files\mirra\mirra.service.exe

–
End of file - 9786 bytes

Then I downloaded and ran JavaRa. It seemed like it deleted a lot of stuff, but then terminated with an error message saying it encountered a problem and had to shut down. I simply ran it again and it deleted less, but finished with the prompt about the logfile, which I saved. Don't think there is a problem, but maybe you can tell me.

If there doesn't seem to be a problem when you surf, then Java is running OK. If you are having issues with some site animations then it's poorly-sick and you would need to uninstall the remaining version via Add/Remove programs and reinstall.
If this is the case, go here and click on the Windows XP/Vista/2000/2003 Offline link in the Windows section near the top and save it to your Desktop.
Once you've installed it, save the file somewhere and if you have further issues with Java you can reinstall form the same file and save your bandwidth.

I then downloaded Adobe which took forever to install (an hour), but it completed successfully.

Seems an excessive amount of time, but you could just have a wimpy processor.

The only thing I noticed is that there are still two "Run Once" lines in the HJT file. Should I also delete these?

They should disappear after a reboot, unless Spybot is being a pain again. If it is, come back and we'll play further.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

One final program that needs updating is Open Office. You can get the latest version here.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Your log doesn't appear to show a third-party software firewall installed - if you have one, and i've missed it, please ignore this.
If you are relying the firewall that comes with Service Pack 2, then you need to install one. While the SP2 firewall is better than nothing, it doesn't monitor outgoing traffic, so anything malicious on your computer can 'phone home' at will.
If you are using a wireless router that comes with a NAT hardware firewall, this also doesn't monitor outgoing connections.

There are a few free firewalls available.
Comodo Firewall Pro, available here. This download has both a firewall and anti-virus in the same package, so be sure that you uncheck the AV option if you choose to install this one.
PC Tools Firewall Plus, available here.
Online Armor Free, available here.

It is important to note that you should only have one firewall installed at a time, but you can download them all to your Desktop and install each in turn to see which one you prefer.

Understanding and Using Firewalls: http://www.bleepingcomputer.com/tutorials/tutorial60.html

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I want you to run your PC as normal for a few days and when you are happy that everything is fine, do the following:

Disable System Restore,
Reboot your PC,
Re-enable System Restore,
Create a Restore Point - this will give a clean one should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.
No problem with the JAVA, so I'll just hang onto the link you provided in case. I ran the same program on my laptop to get rid of the old versions and the exact same thing happened, with the same results.

Those two Run Once lines are still there after rebooting 3-4 times. Is it OK to get rid of them like the other lines we 'fixed'?

O4 - HKUS\S-1-5-18\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\system32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\system32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'Default user')

I also wanted to ask about these two lines, because I deleted both of these applications over a year ago. Can I, should I, delete?

O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent ((I don't have Bluetooth installed???))
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab ((I deleted Symantec??))

I will update Open Office.

As for the firewall, I run my internet access through a Linksys router, for all my PCs. Actually, I also have another Linksys wireless router tied into the first router, so I can use my laptop around the house. All the DHCP is handled by the first router. I thought that was providing me with NAT hardware firewall protection. That is why I have the MS firewall turned off. Do you still recommend one of the other software firewalls? Will it work in conjunction with the NAT hardware firewall? Which one do you prefer?


I will create the restore point, as you suggested.

Thanks for the bedtime reading…………….

I want to thank you again for the help!

Rich

I ran the same program on my laptop to get rid of the old versions and the exact same thing happened, with the same results.

Could be a bug in the program.

Those two Run Once lines are still there after rebooting 3-4 times. Is it OK to get rid of them like the other lines we 'fixed'?

I guess that Spybot has issues with these lines for some reason.

You will need to disable Spybot's Tea Timer function, if it is running, as it may interfere with this fix - this is a two step process.
Step one:
  • Right-click the Spybot Icon in the System Tray - It looks like a blue/white calendar with a padlock symbol.
    Click on Exit Spybot-S&D Resident
Step two:
  • Open Spybot S&D.
  • Click Mode at the top, select Advanced Mode and confirm it.
  • Go to the bottom of the left hand pane, and select the + symbol to the left of Tools.
  • Also in left panel, click Resident to the right of the red and white shield.
  • In the Resident protection status frame, Uncheck the box labelled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File > Exit to terminate Spybot.
  • Reboot your machine for the changes to take effect.
You should now be able to fix the HJT lines and then reverse the Spybot instructions to re-enable TeaTimer.

I also wanted to ask about these two lines, because I deleted both of these applications over a year ago. Can I, should I, delete?

O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent ((I don't have Bluetooth installed???))
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab ((I deleted Symantec??))

The second one can go certainly. The first should be OK, but if you find that the PC decides to get upset, not that I expect it will:

Run HJT and click on Open the Misc Tools section.
Select Backups, under Configuration at the top.
Check the box to the left of the entry and then click Restore.

Simples.

I thought that was providing me with NAT hardware firewall protection. That is why I have the MS firewall turned off. Do you still recommend one of the other software firewalls? Will it work in conjunction with the NAT hardware firewall? Which one do you prefer?

NAT is OK, but it not a two-way system as far as i'm aware - you still have outbound connection dangers. I run a router as well and a software firewall woks quite happily alongside it without issues.
There's a neat little movie here: http://www.draytek.co.uk/natmovie.html I have found the streaming to be really bad, so i'd be inclined to download it all and watch it that way. Be aware that it's a 32 Mb file: http://www.draytek.streamlinenettrial.co.u…TekNatMovie.mpg
On the two "Run Once" lines, when I reinstalled Spybot the other day, I never activated Tea Timer. When I installed the new version of SB last week (when this whole problem started) I activated Tea Timer and started getting all these messages about the registry being changed and asking me to approve or reject, which were not clear. So I did not activate it when I reinstalled SB. That means I can go directly to HJT to delete (Fix) lines. I had asked in the last email if you had a preference or would recommend one of the three software firewalls, but you didn't answer. Is there one that is more user friendly or functional? You had suggested trying each one, but can they be easily and totally removed? PC is still running great….. Thanks
Occasionally TeaTimer causes deleted lines to be replaced, presumably thinking that the PC is under attack, so you have to fight against it. If you haven't enabled it, then fix away and that should be that.

Is there one that is more user friendly or functional?

It tends to be a personal preference as to friendliness. If you can't be bothered with a firewall pestering you that much, go for the PC Tools one. I run it on a laptop behind a router and it does it's thing without asking too much.
If you like to be a little more hands-on and perhaps have a little more protection, give the Comodo one a whirl. This is the one that I have on my Desktop.

can they be easily and totally removed?

Add/Remove Programs and a reboot should do that OK. Download the next before you remove one, that way you don't go online without the proper protection.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI