This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot Get Rid Of M?iexec.exe

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings,

I have 3 mUiexec.exe proceses running in Task Manager. How can I get rid of these?

Searching my hard drive (for m?iexec.exe) revealed that I have 4 msiexec.exe files on my system.

msiexec.exe D:\WIN2K\ServicePackFiles\i386 63 KB 6/19/2003
msiexec.exe D:\WIN2K\system32 63 KB 6/19/2003
msiexec.exe D:\WIN2K\system32 380 KB 12/8/2004
msiexec.exe D:\WIN2K\system32\dllcache 63 KB 6/19/2003

I am assuming that I need to delete the msiexec.exe file that has the size of 380 KB.

Please advise on what needs to be done.

Thanks!

Below is my HT log.



Logfile of HijackThis v1.99.0
Scan saved at 12:48:40 PM, on 1/8/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WIN2K\System32\smss.exe
D:\WIN2K\system32\winlogon.exe
D:\WIN2K\system32\services.exe
D:\WIN2K\system32\lsass.exe
D:\WIN2K\system32\svchost.exe
D:\WIN2K\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\Program Files\Executive Software\DiskeeperServer\DKService.exe
D:\WIN2K\System32\svchost.exe
D:\WIN2K\System32\GEARSec.exe
D:\WIN2K\system32\nvsvc32.exe
D:\WIN2K\system32\regsvc.exe
D:\WIN2K\system32\MSTask.exe
D:\WIN2K\system32\ZONELABS\vsmon.exe
D:\WIN2K\Explorer.EXE
D:\WIN2K\System32\WBEM\WinMgmt.exe
D:\Program Files\RealVNC\WinVNC\WinVNC.exe
D:\WIN2K\system32\mspmspsv.exe
D:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
D:\WIN2K\system32\svchost.exe
D:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
D:\WIN2K\Mixer.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\QuickTime\qttask.exe
D:\WIN2K\system32\P2P Networking\P2P Networking.exe
D:\PROGRA~1\AWS\WEATHE~1\Weather.exe
D:\Program Files\AIM95\aim.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\CheckIt\86\CheckIt86.exe
D:\Program Files\Greetings Workshop\GWREMIND.EXE
D:\Software\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {84D1EAF7-5A6E-5ECC-4A52-5CF07CCD6990} - D:\WIN2K\system32\skcdtx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WIN2K\system32\msdxm.ocx
O3 - Toolbar: Searchfst Class - {000277A3-7D84-406a-9799-D12A81594693} - D:\WIN2K\srchfst.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinVNC] "D:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WIN2K\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [P2P Networking] D:\WIN2K\system32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WIN2K\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Weather] D:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Greetings Workshop Reminders.lnk = D:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: CheckIt 86.lnk = D:\Program Files\CheckIt\86\CheckIt86.exe
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Add To CheckIt &86 Trust List - D:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - D:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - D:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM95\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - D:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.napster.com/client/setup.exe
O16 - DPF: {5B59DA81-5B9E-4F3D-AF5B-A0C644037165} (AIM PicDownloader Control) - http://pictures06.aim.com/ygp/aol/plugin/d…AIM.9.5.1.5.cab
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/clo/install/CLOActiveXInstallerProj1.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures02.aim.com/ygp/aol/plugin/u…AIM.9.5.1.7.cab
O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - http://pictures06.aim.com/ygp/aol/plugin/s…IM.9.1.6.27.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - D:\Program Files\Executive Software\DiskeeperServer\DKService.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - D:\WIN2K\System32\dmadmin.exe
O23 - Service: GEARSecurity - GEAR Software - D:\WIN2K\System32\GEARSec.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - D:\WIN2K\system32\nvsvc32.exe
O23 - Service: V2i Protector - PowerQuest Corporation - D:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - D:\WIN2K\system32\ZONELABS\vsmon.exe
O23 - Service: VNC Server - RealVNC Ltd. - D:\Program Files\RealVNC\WinVNC\WinVNC.exe
O23 - Service: WMP54Gv4SVC - Unknown - D:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe" "WMP54Gv4.exe (file missing)
Welcome to the forum.

First of all, open Spybot S&D, click Mode>Advanced>Tools>Resident and remove the check from the Tea Timer box. You can reinstate it later but we don't want it interfering with what we need to do. Reboot when done.


msiexec.exe should be a good file, find each of them, right click on it, choose properties, make sure it's from Microsoft.
http://whatsmyip.auditmypc.com/process/msiexec.asp

Please uninstall P2P Networking from your control panels add/remove programs.

With only HJT running fix these:


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {84D1EAF7-5A6E-5ECC-4A52-5CF07CCD6990} - D:\WIN2K\system32\skcdtx.dll

O3 - Toolbar: Searchfst Class - {000277A3-7D84-406a-9799-D12A81594693} - D:\WIN2K\srchfst.dll

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

O23 - Service: WMP54Gv4SVC - Unknown - D:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe" "WMP54Gv4.exe (file missing)




Delete these files:

D:\WIN2K\system32\skcdtx.dll
D:\WIN2K\srchfst.dll

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

Download this small app, double click on it and allow it to merge into the registry. This will restore all the default search features for Internet Explorer.

http://www.spywareinfo.com/downloads/tools/IEFIX.reg


Reboot and post a fresh HJT log and lets see how we did, MrC
Mr C,

Thanks for the procedure.

msiexec.exe should be a good file, find each of them, right click on it, choose properties, make sure it's from Microsoft.


The following msiexec.exe file is not from Microsoft
msiexec.exe D:\WIN2K\system32 380 KB 12/8/2004
It appears to be from FMC or MFC (the icon has three blocks with those letters on each block).


After uninstalling P2P Networking, the following line in was not in the HJT window to remove:

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
(I assume that removing P2P Networking got rid of it)

Delete these files:

D:\WIN2K\system32\skcdtx.dll
D:\WIN2K\srchfst.dll


Also I could not find the file D:\WIN2K\system32\skcdtx.dll to delete. (I assume HJT took care of that also). I found and deleted D:\WIN2K\srchfst.dll

Below is my HJT log:

I have D:\Documents and Settings\Administrator\Application Data\aaar.exe running on my system. any idea on how to get rid of it?

Thanks for all your help!


Logfile of HijackThis v1.99.0
Scan saved at 6:22:16 PM, on 1/9/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WIN2K\System32\smss.exe
D:\WIN2K\system32\winlogon.exe
D:\WIN2K\system32\services.exe
D:\WIN2K\system32\lsass.exe
D:\WIN2K\system32\svchost.exe
D:\WIN2K\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\Program Files\Executive Software\DiskeeperServer\DKService.exe
D:\WIN2K\System32\svchost.exe
D:\WIN2K\System32\GEARSec.exe
D:\WIN2K\system32\nvsvc32.exe
D:\WIN2K\system32\regsvc.exe
D:\WIN2K\system32\MSTask.exe
D:\WIN2K\system32\ZONELABS\vsmon.exe
D:\WIN2K\Explorer.EXE
D:\WIN2K\System32\WBEM\WinMgmt.exe
D:\Program Files\RealVNC\WinVNC\WinVNC.exe
D:\WIN2K\system32\mspmspsv.exe
D:\WIN2K\system32\svchost.exe
D:\WIN2K\Mixer.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\QuickTime\qttask.exe
D:\PROGRA~1\AWS\WEATHE~1\Weather.exe
D:\Program Files\AIM95\aim.exe
D:\Documents and Settings\Administrator\Application Data\aaar.exe
D:\Program Files\CheckIt\86\CheckIt86.exe
D:\Program Files\Greetings Workshop\GWREMIND.EXE
D:\Software\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WIN2K\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinVNC] "D:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WIN2K\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WIN2K\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Weather] D:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Rlms] D:\Documents and Settings\Administrator\Application Data\aaar.exe
O4 - Startup: Greetings Workshop Reminders.lnk = D:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: CheckIt 86.lnk = D:\Program Files\CheckIt\86\CheckIt86.exe
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Add To CheckIt &86 Trust List - D:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - D:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - D:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM95\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - D:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.napster.com/client/setup.exe
O16 - DPF: {5B59DA81-5B9E-4F3D-AF5B-A0C644037165} (AIM PicDownloader Control) - http://pictures06.aim.com/ygp/aol/plugin/d…AIM.9.5.1.5.cab
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/clo/install/CLOActiveXInstallerProj1.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures02.aim.com/ygp/aol/plugin/u…AIM.9.5.1.7.cab
O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - http://pictures06.aim.com/ygp/aol/plugin/s…IM.9.1.6.27.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - D:\Program Files\Executive Software\DiskeeperServer\DKService.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - D:\WIN2K\System32\dmadmin.exe
O23 - Service: GEARSecurity - GEAR Software - D:\WIN2K\System32\GEARSec.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - D:\WIN2K\system32\nvsvc32.exe
O23 - Service: V2i Protector - PowerQuest Corporation - D:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - D:\WIN2K\system32\ZONELABS\vsmon.exe
O23 - Service: VNC Server - RealVNC Ltd. - D:\Program Files\RealVNC\WinVNC\WinVNC.exe
msiexec.exe

This is what it's supposed to be:

The process known as msiexec.exe is the executable for Microsofts Installer. It is started when you install new software on your computer. It has been known to stay running after installation is complete. If you are installing a new piece of software you should leave this process running. If you have finished installing new software and the process is still running, you should stop the process to free up system resources.

If your sure it's not from MS, try to delete it but don't empty your recycle bin.
You can also just rename it msiexec.old just incase they're good files.
I don't come up with them being malware but you never know.

EDIT: I just looked at those files on my system and they have Microsoft written all over them.


Press Control-Alt-Del to enter the Task Manager.
Click on the Processes tab and end the following processes:

aaar.exe

Exit the Task Manager when finished

Close all programs down, leaving only HijackThis running.
Place a check against the following items:

O4 - HKCU\..\Run: [Rlms] D:\Documents and Settings\Administrator\Application Data\aaar.exe

Click on Fix Checked and exit HijackThis.

HowToShowHiddenFiles - enable this

Now delete this file:
D:\Documents and Settings\Administrator\Application Data\aaar.exe

If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.

Post back a fresh HijackThis log and we'll take another look. MrC
Mr C,

That got rid of the aaar.exe executable that was running.

If your sure it's not from MS, try to delete it but don't empty your recycle bin.
You can also just rename it msiexec.old just incase they're good files.
I don't come up with them being malware but you never know.

EDIT: I just looked at those files on my system and they have Microsoft written all over them.


All of the msiexec.exe files, except for one of them were from Microsoft.

Searching my hard drive (for m?iexec.exe) revealed that I have 4 msiexec.exe files on my system.

msiexec.exe D:\WIN2K\ServicePackFiles\i386 63 KB 6/19/2003
msiexec.exe D:\WIN2K\system32 63 KB 6/19/2003
msiexec.exe D:\WIN2K\system32 380 KB 12/8/2004

msiexec.exe D:\WIN2K\system32\dllcache 63 KB 6/19/2003


I renamed the file that wasn't from Microsoft (the file that has the size of 380 KB) to msiexec_FMC.exe. It was really strange how two files with the same name could reside in the same directory, at least the names "appeared" to be the same.

Thanks again for all your help.

Below is the latest HJT log. Does everything "look good"?

Logfile of HijackThis v1.99.0
Scan saved at 7:52:11 PM, on 1/9/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WIN2K\System32\smss.exe
D:\WIN2K\system32\winlogon.exe
D:\WIN2K\system32\services.exe
D:\WIN2K\system32\lsass.exe
D:\WIN2K\system32\svchost.exe
D:\WIN2K\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\Program Files\Executive Software\DiskeeperServer\DKService.exe
D:\WIN2K\System32\svchost.exe
D:\WIN2K\System32\GEARSec.exe
D:\WIN2K\system32\nvsvc32.exe
D:\WIN2K\system32\regsvc.exe
D:\WIN2K\system32\MSTask.exe
D:\WIN2K\system32\ZONELABS\vsmon.exe
D:\WIN2K\Explorer.EXE
D:\WIN2K\System32\WBEM\WinMgmt.exe
D:\Program Files\RealVNC\WinVNC\WinVNC.exe
D:\WIN2K\system32\mspmspsv.exe
D:\WIN2K\system32\svchost.exe
D:\WIN2K\Mixer.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\QuickTime\qttask.exe
D:\PROGRA~1\AWS\WEATHE~1\Weather.exe
D:\Program Files\AIM95\aim.exe
D:\Program Files\CheckIt\86\CheckIt86.exe
D:\Program Files\Greetings Workshop\GWREMIND.EXE
D:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
D:\Software\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WIN2K\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinVNC] "D:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WIN2K\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WIN2K\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Weather] D:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Startup: Greetings Workshop Reminders.lnk = D:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: CheckIt 86.lnk = D:\Program Files\CheckIt\86\CheckIt86.exe
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Add To CheckIt &86 Trust List - D:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - D:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - D:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM95\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - D:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.napster.com/client/setup.exe
O16 - DPF: {5B59DA81-5B9E-4F3D-AF5B-A0C644037165} (AIM PicDownloader Control) - http://pictures06.aim.com/ygp/aol/plugin/d…AIM.9.5.1.5.cab
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/clo/install/CLOActiveXInstallerProj1.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures02.aim.com/ygp/aol/plugin/u…AIM.9.5.1.7.cab
O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - http://pictures06.aim.com/ygp/aol/plugin/s…IM.9.1.6.27.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - D:\Program Files\Executive Software\DiskeeperServer\DKService.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - D:\WIN2K\System32\dmadmin.exe
O23 - Service: GEARSecurity - GEAR Software - D:\WIN2K\System32\GEARSec.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - D:\WIN2K\system32\nvsvc32.exe
O23 - Service: V2i Protector - PowerQuest Corporation - D:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - D:\WIN2K\system32\ZONELABS\vsmon.exe
O23 - Service: VNC Server - RealVNC Ltd. - D:\Program Files\RealVNC\WinVNC\WinVNC.exe
Looks OK - I'll leave the post open for a while incase you have any problems or questions.

I'll leave you with……….

Some preventive maintenance:

Now that you're clean: Important Step
Delete your system restore files and create a new restore point:

XP system restore

ME system restore


Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked. Check for updates weekly.

SpywareBlaster

SpywareGuard


IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
IE-SPYAD



Need a free anti virus?
AVG*free
(check for updates - daily)

How about a firewall? The front door to your computer.
ZoneAlarm*free

Free spyware removal programs:
SpyBot
AD-Aware

Free Online Trojan Scan

TrojanHunter - free trial

Please consider using Firefox Firefox

Replace Java with SunJava

Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Don't open e-mail attachments without first scanning them with an up-to-date
anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be
"Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Thanks, MrC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI