This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Dealhelper & 2020search

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been using NAV2004, Ad-Aware and SpyBot - none of them have been able to remove, or prevent the infection of my computer with the two adware programs:
2020search and DealHelper.

I've tried going to many websites and following tips on deleting files related to these adware programs, editing the registry, but no matter what I do, the program SPY-BOT continually detects this adware programs.

Any help is much appreciated. Here is my hijack log.

Thanks:

Logfile of HijackThis v1.99.0
Scan saved at 3:58:21 AM, on 12/25/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [476X3mX] newfos.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe"
O4 - HKCU\..\Run: [Zilla Popup Killer] C:\Program Files\Zilla Popup Killer\ZillaPop.exe
O4 - HKCU\..\Run: [Lwp7RgbsV] cnbpact.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - http://mpsnet.com/JavaVM3186.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InCD Helper - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

O4 - HKLM\..\Run: [476X3mX] newfos.exe
O4 - HKCU\..\Run: [Lwp7RgbsV] cnbpact.exe


Reboot when done, rescan with HJT and post a new log here.
I did as you said, and I also disabled my Roadrunner connection before I started just to make sure.

Here's my new Log…and thanks for replying/helping me:

Logfile of HijackThis v1.99.0
Scan saved at 12:30:31 PM, on 12/25/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe"
O4 - HKCU\..\Run: [Zilla Popup Killer] C:\Program Files\Zilla Popup Killer\ZillaPop.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - http://mpsnet.com/JavaVM3186.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InCD Helper - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Well, 2020 is still on there. DealHelper is not. But I was noticing, maybe it was just a coincidence, that this DealHelper didn't appear till I put Ad-Aware/Ad-Watch on my computer. Is it possible that this has spyware in it? The 2020search has not disappeared though. Also, I've seen the DealHelper disappear and then come back again. I've also logged on under my girlfriend's setting, and found dealhelper there, and did the same thing you told me. And then just out of curiousity, I tried turning of the Monitoring for Ad-aware/Ad-Watch. Used Spybot to delete dealHelper and then, ran it again. No Parasites found on her settings. So I reactived Ad-Aware/Ad-Watch, and did the Spybot scan again, and found DealHelper right there again! WTF? Is there anything I should be looking for in the startup list that would help? Just when I thought it was gone I reboot and either 2020 or dealhelper comes right back again,sometimes one, or the other or both! Maybe Spybot is detecting a false positive?
There is no spyware in AdAware. Try this. Click here to download mwavscan. Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.
OK, I'm running the program now. It's been going for 40 minutes already, and it has found 11 viruses and 12 "errors". It's still scanning the files. I will post the findings when it is done. Thanks a lot for helping me, especially over the holiday like this! Jeremy
Well, here it is. I can't understand how useless NAV, Ad-Aware, and Spybot are. They detected none of this. I think I wasted my money on that stuff, I should have researched for a better anti-virus program. This is ridiculous how many adware programs are on this computer… So here is what the scan found: File C:\WINDOWS\system32\ipxorsvc.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{27F92E0D-F198-4E00-883C-20C1242FF1D9}.und infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{7A9FB570-66B1-4F2B-A766-267F6A138BFC}\{0215D76E-ED6B-4AFE-AE93-34FF1F599E2F}.cab infected by "not-a-virus:AdWare.BiSpy.s" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{7A9FB570-66B1-4F2B-A766-267F6A138BFC}\{21F90AA0-1AEE-4C19-B00D-3D20CF4CBC47}.tmp infected by "not-a-virus:AdWare.SurfSide.a" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{FBBC2051-EC2A-4C10-A55D-8CD0E61E884A}\{32A883E8-9B57-4903-9D46-B586B4FCEC98}.dll infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{FBBC2051-EC2A-4C10-A55D-8CD0E61E884A}\{3E774CA4-4FDD-46D7-9C43-DC32BF9ED3E1}.dll infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{FBBC2051-EC2A-4C10-A55D-8CD0E61E884A}\{551CEA12-1927-45F8-B15B-D9E1E57BB684}.dll infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{FBBC2051-EC2A-4C10-A55D-8CD0E61E884A}\{7ED5FF3A-B50A-4716-AA78-8D81A3D3A402}.exe infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{FBBC2051-EC2A-4C10-A55D-8CD0E61E884A}\{879E89B1-0F86-4965-96D2-495F161075B9}.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{FBBC2051-EC2A-4C10-A55D-8CD0E61E884A}\{D17C40B9-26C7-4B88-B261-03A2E8AD430F}.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic 5\Undo\Manual\{FBBC2051-EC2A-4C10-A55D-8CD0E61E884A}\{E3AC0116-E699-40B2-822F-5C76CE629A74}.dll infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\Program Files\MySearch\bar\1.bin\NPMYSRCH.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.j" Virus. Action Taken: No Action Taken. File C:\Program Files\MySearch\bar\1.bin\S42NS.EXE infected by "not-a-virus:AdWare.ToolBar.MyWay.j" Virus. Action Taken: No Action Taken. File C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.j" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\18161DFC infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\181A47F8 infected by "Trojan-Downloader.Win32.Apropo.o" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\260D6DEC infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP102\A0015777.exe infected by "not-a-virus:AdWare.HelpExpress" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016530.exe infected by "not-a-virus:AdWare.ToolBar.MyWay.j" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016566.exe infected by "Trojan.Win32.SecondThought.bf" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016579.exe infected by "Trojan.Win32.SecondThought.ba" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016580.exe infected by "not-a-virus:AdWare.VirtualBouncer.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016582.exe infected by "Trojan.Win32.SecondThought.ba" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016583.exe infected by "Trojan.Win32.SecondThought.bf" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016588.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016622.exe infected by "TrojanDownloader.Win32.Agent.ae" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016623.dll infected by "not-a-virus:AdWare.BiSpy.s" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP110\A0016624.exe infected by "not-a-virus:AdWare.BiSpy.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP111\A0016666.dll infected by "not-a-virus:AdWare.Adstart.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP111\A0016682.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP111\A0016687.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP115\A0017238.exe infected by "not-a-virus:AdWare.WebRebates.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP121\A0021164.exe infected by "Trojan-Downloader.Win32.Apropo.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP121\A0021165.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP126\A0021542.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP126\A0021546.dll infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP126\A0021547.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP126\A0021550.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP126\A0021554.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP140\A0023450.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\bundles\HelperInstaller.exe infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: No Action Taken. File C:\WINDOWS\bundles\saie1101.exe infected by "TrojanDropper.Win32.Small.mr" Virus. Action Taken: No Action Taken. File C:\WINDOWS\bundles\shopinst.exe infected by "TrojanDownloader.Win32.Small.wj" Virus. Action Taken: No Action Taken. File C:\WINDOWS\bundles\SSK_B5.EXE infected by "Trojan-Dropper.Win32.SurfSide.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\ipxorsvc.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\bundles\HelperInstaller.exe infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: No Action Taken. File C:\WINDOWS\bundles\saie1101.exe infected by "TrojanDropper.Win32.Small.mr" Virus. Action Taken: No Action Taken. File C:\WINDOWS\bundles\shopinst.exe infected by "TrojanDownloader.Win32.Small.wj" Virus. Action Taken: No Action Taken. File C:\WINDOWS\bundles\SSK_B5.EXE infected by "Trojan-Dropper.Win32.SurfSide.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\ipxorsvc.exe infected by "Trojan-Downloader.Win32.Envolo.a" Virus. Action Taken: No Action Taken.
It's not as bad as it looks. Do this so you can see hidden files and folders - click here to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double click the xphidden.reg and when asked to merge say yes.

Find and delete the following:

C:\Program Files\MySearch\ <– folder
C:\WINDOWS\bundles\HelperInstaller.exe
C:\WINDOWS\bundles\saie1101.exe
C:\WINDOWS\bundles\shopinst.exe
C:\WINDOWS\bundles\SSK_B5.EXE
C:\WINDOWS\system32\ipxorsvc.exe

Next follow this sequence:

1. Right-click My Computer>Click Properties>Click the System Restore tab>Check the box next to 'Turn off System Restore on all drives'>Click Apply>Click OK.

2. Reboot.

3. Repeat the process but this time remove the check from the box.

Let me know how it is now.
It seems that the 2020search is still being detected by Spybot. I followed your directions and it appears that DealHelper is no longer there, which is good. Thanks for the help on that.

NAV and Ad-Aware still don't pick up the 2020, and I did a Quick scan with the eScan program that you told me to download today, and everything is clear. I'm going to run the full system scan again with the eScan program. Here is my current startup list that I got using hijackthis. I don't know if it helps at all…

StartupList report, 12/25/2004, 7:31:09 PM
StartupList version: 1.52.2
Started from : C:\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HijackThis\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

(Default) =
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
CHotkey = zHotkey.exe
NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
InCD = C:\Program Files\Ahead\InCD\InCD.exe
SunKistEM = C:\Program Files\eMachines Bay Reader\shwiconem.exe
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
Microsoft Works Update Detection = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
RemoteControl = "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
mmtask = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
tgcmd = "C:\Program Files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf
NVMixerTray = "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
nwiz = nwiz.exe /install
AWMON = "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
mqrrmdrwamnk = C:\WINDOWS\system32\zqjfke.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
System Mechanic Popup Stopper = "C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe"
Zilla Popup Killer = C:\Program Files\Zilla Popup Killer\ZillaPop.exe

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}

————————————————–

Enumerating Task Scheduler jobs:

Norton AntiVirus - Scan my computer.job
Symantec NetDetect.job

————————————————–

Enumerating Download Program Files:

[Microsoft VM]
CODEBASE = http://mpsnet.com/JavaVM3186.exe

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock…director/sw.cab

[MSSecurityAdvisor Class]
InProcServer32 = C:\WINDOWS\System32\mssecadv.dll
CODEBASE = http://protect.microsoft.com/security/prot…b?1096343835109

[Office Update Installation Engine]
InProcServer32 = C:\WINDOWS\opuc.dll
CODEBASE = http://office.microsoft.com/officeupdate/content/opuc.cab

[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/…8172.3994444444

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\macromed\flash\Flash.ocx
CODEBASE = http://active.macromedia.com/flash2/cabs/swflash.cab

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
End of report, 6,864 bytes
Report generated in 0.031 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
OK, I ran the full system scan and was clean on the viruses.

However, I ran the Spybot program and 2020search is still there, AND DealHelper is back again. I know this sounds crazy, but that's what happened.

Even though eScan didn't find any viruses, it did find these errors:

Sat Dec 25 19:51:19 2004 => ERROR!!! Invalid Entry Zilla Popup Killer = C:\Program Files\Zilla Popup Killer\ZillaPop.exe. Removing it.

Sat Dec 25 19:51:23 2004 => ERROR!!! Invalid Entry \??\C:\DOCUME~1\JEREMY~1\LOCALS~1\Temp\cdrmkaun.sys in SYSTEM\CurrentControlSet\Services\cdrmkaun…

Sat Dec 25 19:51:37 2004 => ERROR!!! Invalid Entry \??\C:\WINDOWS\System32\Drivers\sunkfiltp.sys in SYSTEM\CurrentControlSet\Services\Sunkfiltp…

Sat Dec 25 19:51:39 2004 => ERROR!!! Invalid Entry System32\DRIVERS\wanatw4.sys in SYSTEM\CurrentControlSet\Services\wanatw…


Do these mean anything? Or have anything to do with these adware programs?


Here's my latest Hijack log:

Logfile of HijackThis v1.99.0
Scan saved at 8:53:38 PM, on 12/25/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\cidaemon.exe
C:\DOCUME~1\JEREMY~1\LOCALS~1\Temp\mwavscan.com
C:\DOCUME~1\JEREMY~1\LOCALS~1\Temp\kavss.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe"
O4 - HKCU\..\Run: [Zilla Popup Killer] C:\Program Files\Zilla Popup Killer\ZillaPop.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - http://mpsnet.com/JavaVM3186.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InCD Helper - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


I'm about ready to delete everything off this computer, just to spite these adware a**holes.

Is there anything else to do?
Click here to download Pocket Killbox by Option^Explicit. Extract it from the zip file then double-click on Killbox.exe to run it. In the 'Full Path of File to Delete' box, copy and paste the following, clicking the red 'Delete File' button after pasting:

C:\WINDOWS\system32\zqjfke.exe

Click 'Exit' when done.

Click Start>Run> type regedit >OK. Navigate to this key in the left hand pane:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

and click it to highlight it. You will see a list of programs in the right hand pane. Right click this one:

mqrrmdrwamnk and select delete.

Don't delete anything else. Exit regedit.

Could you tell me exactly what Spybot detects when you run it - file, registry entry etc.


If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again.
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI