This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Mysearch Toolbar

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a lot of trouble trying to clear an infection which has hijacked my IE explorer homepage and which adds a search bar. I have tried every software I can to fix it this is my last hope.

I have currently installed the full version of Adaware SE plus and Adwatch. plus Spybot and spyware blaster. Others have been tried but unsuccessful.
Adaware fixes the problem briefly. It was picking up a lop infection. However the file is still on my system and reinfects every 0.06 secs. I can watch it's progress on Adwatch event file.

Attached is the last hijack this file and the adwatch file.

Can you help? I would really appreciate it.

Logfile of HijackThis v1.97.7
Scan saved at 5:39:42 PM, on 9/6/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Vet\isafe.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Ash's Folder\Go Away\Plain junk\MsgPlus.exe
C:\Vet\VetTray.exe
C:\PROGRA~1\LAVASOFT\AD-AWA~2\Ad-Watch.exe
C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe
C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe
C:\Program Files\Creative\ShareDLL\MediaDet.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Paul\Local Settings\Temp\Temporary Directory 5 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rkiohwknrlsx.net/zHxw6GdrGTAHiW3DCE…oXOSkrCz1k.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optusnet.com.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGx…54Ljn1fDZU.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.acer.com.au/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {95C7FADF-CEF1-B472-3C2A-718FDD905E93} - C:\PROGRA~1\ADMINH~1\Dart Wave.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Ash's Folder\Go Away\Plain junk\MsgPlus.exe"
O4 - HKLM\..\Run: [PlanDefault] C:\PROGRA~1\TRANSR~1\uploadtick.exe
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [Aluria's Pop-Up Stopper] C:\Program Files\Aluria Software\EPS\eps.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\LAVASOFT\AD-AWA~2\Ad-Watch.exe"
O4 - HKLM\..\Run: [That peak each start] C:\Documents and Settings\All Users\Application Data\ToolMp3ThatPeak\Store comp.exe
O4 - HKCU\..\Run: [TaskTray] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe"
O4 - HKCU\..\Run: [TaskBar] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe"
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.optusnet.com.au
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.optusnet.com.au
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/090922314375c21c8500/…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093676097781
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/…8064.1216203704
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab


Adwatch
Ad-Watch Logfile, exported on 8/31/2004
Total number of events:7
===============================================
8/31/2004 6:25:14 PM - Definitions file SE1R6 30.08.2004 loaded successfully.
Build:SE1R6 30.08.2004
Total Signatures :28058
Target Families :539
Target Categories :6
CSI data Size :5984

File Size :1054736

===============================================
8/31/2004 6:25:14 PM - User preferences file loaded.
Ad-Watch preference file loaded.
Applying user settings
C:\Documents and Settings\Paul\Application Data\Lavasoft\Ad-Aware\awsettings.awc
Initialization complete.




===============================================
8/31/2004 6:25:15 PM - Sites file loaded.
Sites file loaded successfully.
C:\Program Files\Lavasoft\Ad-Aware SE Plus\sites.txt
Total entries : 3229





===============================================
8/31/2004 6:25:17 PM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:SearchAssistant
Data:http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGxUaBJi/myWWm9mZaOj577YoSpTO9M6iZlZ2_WF054Ljn1fDZU.html
New Data:http://rimejuvukiklnbaibdyroovue.com/zHxw6GdrGTC2rpGxUaBJi/myWWm9mZaOj577YoSpTO_2TJFtB33xF054Ljn1fDZU.php



===============================================
8/31/2004 6:25:57 PM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:SearchAssistant
Data:http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGxUaBJi/myWWm9mZaOj577YoSpTO9M6iZlZ2_WF054Ljn1fDZU.html
New Data:http://www.nnumxnxxnstxalwxp.net/zHxw6GdrGTC2rpGxUaBJi/myWWm9mZaOj577YoSpTO_2lQKkmxM2FU54Ljn1fDZU.html



===============================================
8/31/2004 6:26:42 PM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:SearchAssistant
Data:http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGxUaBJi/myWWm9mZaOj577YoSpTO9M6iZlZ2_WF054Ljn1fDZU.html
New Data:http://www.jjcbsahssjcrqgkq.com/zHxw6GdrGTC2rpGxUaBJi/myWWm9mZaOj577YoSpTO/_UGYqHajyXk54Ljn1fDZU.html



===============================================
8/31/2004 6:27:27 PM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:SearchAssistant
Data:http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGxUaBJi/myWWm9mZaOj577YoSpTO9M6iZlZ2_WF054Ljn1fDZU.html
New Data:http://www.vivmnwievkbayggnubw.com/zHxw6GdrGTC2rpGxUaBJi/myWWm9mZaOj577YoSpTO8xco85TbHZJE54Ljn1fDZU.html



===============================================
suer – Thanks for sending your HijackThis log.

Please download the latest version of HijackThis(v1.98.2) and unzip it to a permanent folder such as "C:\hjt", to ensure that backup files are reliably saved.

Do not continue to run HijackThis from "C:\Documents and Settings\Paul\Local Settings\Temp\Temporary Directory 5 for hijackthis.zip\HijackThis.exe" (or from inside unzip utility). We're going to clean out the tempfile folders as part of the fix.

Go ahead and print these instructions, or save them to your desktop, to help keep track of the steps.

To start, allow yourself to view "Hidden files". Open Windows Explorer and go to "Tools" => "Folder Options" => "View" then click on the "Show Hidden Files and Folders" option, and un-check "Hide extensions for known file types" and "Hide protected operating system files" options. Then click the "Apply To All Folders" button.

1 – Reboot into Safe Mode (How do I boot into "Safe" mode?).

2 – Next, use Control Panel > Add/Remove Programs to remove any of the following malware that it finds:

MessengerPlus

3 – Run HijackThis, and press Scan, and put a check against the following entries, if they still show up. Make sure all browsers and program windows are closed except for HijackThis.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rkiohwknrlsx.net/zHxw6GdrGTAHiW3DCE…oXOSkrCz1k.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGx…54Ljn1fDZU.html

O2 - BHO: (no name) - {95C7FADF-CEF1-B472-3C2A-718FDD905E93} - C:\PROGRA~1\ADMINH~1\Dart Wave.exe

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Ash's Folder\Go Away\Plain junk\MsgPlus.exe"
O4 - HKLM\..\Run: [PlanDefault] C:\PROGRA~1\TRANSR~1\uploadtick.exe
O4 - HKLM\..\Run: [That peak each start] C:\Documents and Settings\All Users\Application Data\ToolMp3ThatPeak
\Store comp.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/090922314375c21c8500/…ip/RdxIE601.cab

The following items are optional fixes you may choose to make:

Application Scheduler is installed along with RealOne Player and is running in startup, and is not needed. Once installed, it runs independently of RealOne Player and consumes resources. You can fix this with HJT, but you will also need to set it not to load in RealPlayer itself to keep it from resetting itself: (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK This is the item to fix in HJT:
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

Office Startup Asistant is an optional item that if checked, will eliminate a known resource hog. You will still be able to start Office components from the Start menu. This is the item to fix in HJT:
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE


Once you have selected all the items for HJT to fix, make sure all browsers and program windows are closed except for HijackThis, and click fix checked.

4 – While still in safe mode, use Windows Explorer to delete the following lists of program files and folders, if they still exist.

C:\Program Files\Microsoft Office\Office\FINDFAST.EXE <– this file

C:\Program Files\ADMINH~1\ <– this folder (use "Start > Search" to find a folder starting witht he letters "ADMINH")
C:\Program Files\TRANSR~1\ <– this folder (use "Start > Search" to find a folder starting witht he letters "TRANSR")

C:\Ash's Folder\Go Away\Plain junk\ <– this folder

C:\Documents and Settings\All Users\Application Data\ToolMp3ThatPeak\ <– this folder

Please let me know about any problems with the file/folder deletes.

5 – Next, use "Start > Run" and type in "%temp%" (without the quotes). Delete the entire contents of that "temp" folder (use "Edit > Select All", press "Delete", click "Yes").

Then, Empty your Temporary Internet Cache completely. Close all instances of Outlook and and Internet Explorer, then use "Control Panel > Internet Options > General tab" and click the "Delete File" button. When prompted place a check in: "Delete all offline content", then click OK.

Then, use Windows Explorer to clean out ALL the other temp folders on your system (navigate to the folder, use "Edit > Select All", press "Delete", click "Yes"):

* C:\Documents and Settings\\Local Settings\Temp\
* C:\Documents and Settings\\Local Settings\Temporary Internet Files\
* C:\Documents and Settings\\Local Settings\Temp\
* Empty your "Recycle Bin".

Please let me know about any problems with the temp file deletes.


Now, reboot normally, and we'll take another look at your system.

Please run HijackThis to create a new logfile. Repost it here, and if you had any problems with the steps outlined above, please let us know what they were. Your response and the new logfile will determine the next steps for this fix.

Thanks
daveai
Thanks so much for your help. I am at work at the moment so I will take these steps later today. My fingers are crossed. May I say that this is the fastest reply I have ever received. Took 7 days for adaware people to tell me to try spybot….
Hello Again
After a couple of wrong turns so to speak I have followed your instructions.
I had some files that would not delte in the temp files.. eg bias.res and cmdlne.ext

I did not know what to do after it said it could not delete them.

I removed the messenger plus 3 through add remove hardware but forgot to start in safe mode… so it said that there was some problem removing the attached files. Also after this there appeared some files on the desk top which when I try to delete it says they are system files….album art?? Has some pictures on them of Nora Jones. (who knows what goes on this computer!!)

In Ash's temp file there was a program called Else.res which would not delete.

Anyway the search bar has dissappeared at last thank you. But I have another problem you might be able to help with . I cannot access some sites like citibank and Ht.com.au. And most of my favorites like google are now in the restricted zone so I can't access them.

Any ideas I can't find them on the restricted site area to set it right.

Here is the hijack this file.

Thanks
Logfile of HijackThis v1.98.2
Scan saved at 6:16:53 PM, on 9/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Vet\isafe.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Vet\VetMsg.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\QuickTime\qttask.exe
C:\Vet\VetTray.exe
C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe
C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe
C:\Program Files\Creative\ShareDLL\MediaDet.exe
C:\hijackthis\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Vet\autodown.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://optusnet.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optusnet.com.au
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.acer.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [Aluria's Pop-Up Stopper] C:\Program Files\Aluria Software\EPS\eps.exe
O4 - HKCU\..\Run: [TaskTray] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe"
O4 - HKCU\..\Run: [TaskBar] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.optusnet.com.au
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.optusnet.com.au
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093676097781
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
Just as I thought it was fixed the home page hijacker is back.

This is a list of the temp files I could not delete
bias.res: cmdlineext.oz.dll: curb.res: grid.res: manager.res: poll.res:
up.res. In ash's temp file - else.res.

New hijack this file attached

Logfile of HijackThis v1.98.2
Scan saved at 7:54:19 PM, on 9/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rkiohwknrlsx.net/zHxw6GdrGTAHiW3DCE…oXOSkrCz1k.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optusnet.com.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGx…54Ljn1fDZU.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.acer.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [Aluria's Pop-Up Stopper] C:\Program Files\Aluria Software\EPS\eps.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Ash's Folder\Go Away\Plain junk\MsgPlus.exe"
O4 - HKLM\..\Run: [PlanDefault] C:\PROGRA~1\TRANSR~1\uploadtick.exe
O4 - HKLM\..\Run: [That peak each start] C:\Documents and Settings\All Users\Application Data\ToolMp3ThatPeak\Store comp.exe
O4 - HKCU\..\Run: [TaskTray] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe"
O4 - HKCU\..\Run: [TaskBar] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.optusnet.com.au
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.optusnet.com.au
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093676097781
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
Suer – Thanks for the response.

Part of the original problems came back, probably because of the failed file deletes.

It was important to boot into safe mode, since that's what makes the file/folder deletes more successful.

Let's try again. Please follow the steps in order, and report back to me on how they go. If you run into a problem with a given step, then proceed, but be sure to tell me what happened.

Please do the steps in the order indicated.


1 – Reboot into Safe Mode (How do I boot into "Safe" mode?).

Do not proceed unless you are in safe mode and logged on as user with Administrator privledges

2 – Next, use Control Panel > Add/Remove Programs to remove any of the following malware that it finds:

MessengerPlus

3 – Run HijackThis, and press Scan, and put a check against the following entries, if they still show up. Make sure all browsers and program windows are closed except for HijackThis.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rkiohwknrlsx.net/zHxw6GdrGTAHiW3DCE…oXOSkrCz1k.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGx…54Ljn1fDZU.html

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Ash's Folder\Go Away\Plain junk\MsgPlus.exe"
O4 - HKLM\..\Run: [PlanDefault] C:\PROGRA~1\TRANSR~1\uploadtick.exe
O4 - HKLM\..\Run: [That peak each start] C:\Documents and Settings\All Users\Application Data\ToolMp3ThatPeak
\Store comp.exe

Once you have selected all the items for HJT to fix, make sure all browsers and program windows are closed except for HijackThis, and click fix checked.

4 – While still in safe mode, use Windows Explorer to delete the following lists of program files and folders, if they still exist.

C:\Program Files\ADMINH~1\ <– this folder (use "Start > Search" to find a folder starting with the letters "ADMINH")
C:\Program Files\TRANSR~1\ <– this folder (use "Start > Search" to find a folder starting witht he letters "TRANSR")

C:\Ash's Folder\Go Away\Plain junk\ <– this folder

C:\Documents and Settings\All Users\Application Data\ToolMp3ThatPeak\ <– this folder

Please let me know about any problems with the file/folder deletes.

5 – While still in safe mode, use "Start > Run" and type in "%temp%" (without the quotes). Delete the entire contents of that "temp" folder (use "Edit > Select All", press "Delete", click "Yes").

Then, Empty your Temporary Internet Cache completely. Close all instances of Outlook and and Internet Explorer, then use "Control Panel > Internet Options > General tab" and click the "Delete File" button. When prompted place a check in: "Delete all offline content", then click OK.

Then, use Windows Explorer to clean out ALL the other temp folders on your system (navigate to the folder, use "Edit > Select All", press "Delete", click "Yes"):

* C:\Documents and Settings\\Local Settings\Temp\
* C:\Documents and Settings\\Local Settings\Temporary Internet Files\
* C:\Documents and Settings\\Local Settings\Temp\
* Empty your "Recycle Bin".

Please let me know about any problems with the temp file deletes.

6 – Then reboot normally, and let's run a battery of general scans to give your system a "good scrubbing". Please let me know if anything can not be cleaned by these utilities.

Now, reboot normally, and we'll take another look at your system.

Please run HijackThis to create a new logfile. Repost it here, and if you had any problems with the steps outlined above, please let us know what they were. Your response and the new logfile will determine the next steps for this fix.

Thanks
daveai
Can you tell me if it safe to empty everything in the temp files? What is the story about the ones that would not delete like the cmdlineext.oz.dll: curb.res: grid.res: manager.res: poll.res: up.res. (In ash's temp file - else.res.) I can override the res files but the cmdlineext.oz.dll will not delete. I will try again this afternoon after work Thanks again Oh – also I forgot to mention that a file search did not show up the two files adminh and transr. And I did not delete my daughters folder Ash junk… just supsicious entries in it… I will delete the whole thing now.
Thanks for the reply. Please let me know how the systm is running now.

It is safe to empty the temp folders. Override the ones you can, and use the following technique for the ones like that DLL (that is probably running along with some system process it is infecting. Any executable running from TEMP on a repetitive basis is extremely supicious).

The .res files google to "RES Compiled resource file (Borland C++)" which suggests these are compiled programs. Are you a developer or otherwise programming on your system? If not…who is? And why in the TEMP space?

If you can´t delete a file:
Start Hijackthis and when it opens, click on Config then click on Misc Tools. At the new screen click on the "Delete a file on reboot" button. You will be presented with a dialog asking you to pick a file. Copy and paste the location of the file into the file name field and press the open button.

Hijackthis will prompt you to reboot, please do so. After restarting, confirm that the file no longer exists.



These two are not files, but folders:

C:\Program Files\ADMINH~1\ <– this folder (use "Start > Search" to find a folder starting with the letters "ADMINH")
C:\Program Files\TRANSR~1\ <– this folder (use "Start > Search" to find a folder starting witht he letters "TRANSR")

If there are ANY folders under "C:\Program Files" that start with those letters (and even with spaces…like "admin helper" or "trans report" ) they should be deleted.

I'm sorry that Ash must lose her folder. But your system will be happier if she starts a new, clean one :)

Also, please allow me to suggest some prevention steps to keep your computer clean and secure going forward. You may have already taken a few of the steps, but it never hurts to take a quick look :)

1 – Use an AntiVirus Software, and be sure you update it at least once a week. There are several very good free programs available. Grinler offers an outstanding overview at Virus, Spyware, and Malware Protection and Removal Resources

2 – To reduce re-infection potential for malware in the future, I strongly recommend installing three free programs: SpywareBlaster, SpywareGuard, and IE/Spyad.

3 – Use AdAware SE and Spybot S&D; to regularly to scan your system.

4 – It is very important to make sure that both Internet Explorer and XP are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

5 – Consider using a Firewall. Just by using a Firewall in its default configuration can lower your risk greatly. Check out what Lawrence Abrams has to say at Understanding and Using Firewalls

An excellent overview is: So how did I get infected in the first place?. Be sure to visit the browser test link at the end of the article to really see how secure your system is!!

Thanks
daveai
Hello again I have just gone throught the steps again - did not get your last post till now. But the infection has started again. After I ran adaware and spybot!! These are the things that did not go to plan: Messenger plus was not in add remove programs. The search assistant codes change on every hijack this log so I deleted whatever was there. search assistant eywoyujwdixstg…… Could not find any files/folder with adminh or transr but I will search again. Did come up with a number of files that had matches but they were in Hijack this logs and a register backup by spybot… I did not delete these. C/docs& settings/all users/app data/toolmp3that peak - was not in the folder. Unable to delete cmdlineext02.. access denied… but I will now follow your instructions in hijack this to try to remove it. The computer has all the updates for windows.. I am very careful about that.. I do have a firewall installed and VET antivirus. Prior to this I had Nortons Int Security but the infection came with this running. That's why I switched to VET. I will go through the steps one more time.. I'll Be in touch.
Well I have gone through it all again….. still no luck. It keeps returning What can I do now? I did notice that if Adwatch was running the hijack this program would not fix any checked items. Once disabled it cleared them off… I then clear all temp files etc. re-boot and hey presto back it comes.. I give up….I have spent literally hours on this. You know I could get used to having no homepage but the thing that realy annoys me is not being able to access sites because they are somehow restricted. eg citibank and google, it makes this machine virtually useless. This only occurred after uninstalling Alura Spyware eliminator. Do you think it would be worthwhile doing a repair on Windows IE from the microsoft website? Can you do this without having to re-install windows?
Thanks. I'm confident we can lick this wihtout having to rebuild your system. Send me a new HJT logfile,so I can see the infection. You are right about AdWatch…it prevents registry modifications, which is what HJT does. I'll take a look at the new logfile and send another fix. Hang in there! I understand your frustration, but we have enough expertise at TC to work you through this. daveai
Thanks for the encouragement, here is the log file. P.S. I have gone through every temp file on the system and deleted everything except the desktop.ini files.
and the following :
spool -URTtemp
Temporary ASP.NET files
Install Temp 321342
Temp LFS

I ran a search for files called temp and looked in every one of them.

The infection just keeps coming back. Even though I have deleted Ahs' file and messengerplus.


Logfile of HijackThis v1.98.2
Scan saved at 7:27:48 PM, on 9/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rkiohwknrlsx.net/zHxw6GdrGTAHiW3DCE…oXOSkrCz1k.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGx…54Ljn1fDZU.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.acer.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [Aluria's Pop-Up Stopper] C:\Program Files\Aluria Software\EPS\eps.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\LAVASOFT\AD-AWA~2\Ad-Watch.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Ash's Folder\Go Away\Plain junk\MsgPlus.exe"
O4 - HKLM\..\Run: [PlanDefault] C:\PROGRA~1\TRANSR~1\uploadtick.exe
O4 - HKLM\..\Run: [That peak each start] C:\Documents and Settings\All Users\Application Data\ToolMp3ThatPeak\Store comp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [TaskTray] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe"
O4 - HKCU\..\Run: [TaskBar] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.optusnet.com.au
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.optusnet.com.au
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093676097781
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
Thanks for the latest log, suer.

Go ahead and reset Ad-Watch to NOT run automatically at startup, then terminate the program.Ad-Watch.

Please do this:

1 – Download this LOP uninstaller http://lop.com/new_uninstall.exe

Close Internet Explorer and run the uninstaller; click OK > it will then ask you to type in a number that it supplies, do so and click 'uninstall'>yes>OK>OK.

2 – Run HijackThis, and press Scan, and put a check against the following entries, if they still show up. Make sure all browsers and program windows are closed except for HijackThis.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rkiohwknrlsx.net/zHxw6GdrGTAHiW3DCE…oXOSkrCz1k.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGx…54Ljn1fDZU.html

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Ash's Folder\Go Away\Plain junk\MsgPlus.exe"
O4 - HKLM\..\Run: [PlanDefault] C:\PROGRA~1\TRANSR~1\uploadtick.exe
O4 - HKLM\..\Run: [That peak each start] C:\Documents and Settings\All Users\Application Data\ToolMp3ThatPeak
\Store comp.exe

Once you have selected all the items for HJT to fix, make sure all browsers and program windows are closed except for HijackThis, and click fix checked.

3 – Next, clean out all the temporary files and cookies on your system by using Start > Run and enter: cleanmgr. Let it scan your system for files to remove. Check these three boxes and then press ok to remove: Temporary Files, Temporary Internet Files, Recycle Bin.

Now, reboot normally, and we'll take another look at your system.

Then, reset Ad-Watch to load at startup.

Thanks
daveai
This is some sneaky infection…. tried it as you suggested but it didnt' work. Evan ran a new ADAWARE scan. it does not pick up anything.

Same HJT scan as before. The infection returns even in safe mode..(can watch it's progress through ad watch in safe mode) must be embedded somewhere other than temp files.


Logfile of HijackThis v1.98.2
Scan saved at 3:53:22 PM, on 9/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Vet\isafe.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Vet\VetMsg.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\QuickTime\qttask.exe
C:\Vet\VetTray.exe
C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe
C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe
C:\Program Files\Creative\ShareDLL\MediaDet.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rkiohwknrlsx.net/zHxw6GdrGTAHiW3DCE…oXOSkrCz1k.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optusnet.com.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.sxiaiuwmem.com/zHxw6GdrGTC2rpGx…54Ljn1fDZU.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.acer.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [Aluria's Pop-Up Stopper] C:\Program Files\Aluria Software\EPS\eps.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Ash's Folder\Go Away\Plain junk\MsgPlus.exe"
O4 - HKLM\..\Run: [PlanDefault] C:\PROGRA~1\TRANSR~1\uploadtick.exe
O4 - HKLM\..\Run: [That peak each start] C:\Documents and Settings\All Users\Application Data\ToolMp3ThatPeak\Store comp.exe
O4 - HKCU\..\Run: [TaskTray] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe"
O4 - HKCU\..\Run: [TaskBar] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.optusnet.com.au
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.optusnet.com.au
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093676097781
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI