This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijacked Ie Browser - Begin2search

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been infected/hijacked by a program "begin2search.com" which shows up as a toolbar on my IE browser. It lists various sites as well as establishes links on specific keywords on every page with 'sponsered link'.

I run McAfee antivirus and antispyware, which have not been able to detect much less remove it.

I have tried Lavasoft's adaware, spy sweeper (bought for 29.95), avast and spy ferret, which detect it but do nothing to actually remove it.

Upon the advice of a friend, I downloaded hijack this and this is the log. Any help would be most appreciated as I am at the point of reinstalling XP.

Update: after reading through the forum, I think I have successfully cleaned begin2search by removing it from the hijack log. But I am still getting popups (or something like that since I have SP2 and popups are blocked) - this is the new hijack log after begin2search was removed and I rebooted:

Logfile of HijackThis v1.99.1
Scan saved at 9:21:21 PM, on 2/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\XP\System32\smss.exe
C:\WINDOWS\XP\system32\winlogon.exe
C:\WINDOWS\XP\system32\services.exe
C:\WINDOWS\XP\system32\lsass.exe
C:\WINDOWS\XP\system32\svchost.exe
C:\WINDOWS\XP\System32\svchost.exe
C:\WINDOWS\XP\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\XP\system32\cisvc.exe
c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\XP\system32\nvsvc32.exe
C:\WINDOWS\XP\system32\tcpsvcs.exe
C:\WINDOWS\XP\System32\snmp.exe
C:\WINDOWS\XP\System32\svchost.exe
C:\WINDOWS\XP\System32\Tablet.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\XP\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\XP\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\XP\system32\wuauclt.exe
C:\WINDOWS\XP\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\soft602\pdfSaver.exe
C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
C:\windows\xp\system32\xwxnwhcw.exe
C:\Program Files\PDF\pdfSaver\pdfSaver3.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\WINDOWS\XP\system32\WTablet\TabUserW.exe
C:\windows\xp\system32\packager.exe
C:\Documents and Settings\Denise\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\XP\dlmax.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PnIEBrowserHelperObj Class - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\XP\isrvs\sysupd.dll (file missing)
O2 - BHO: ohb - {988CAFC4-DC0D-4D8C-A35E-5028ABE9E641} - C:\WINDOWS\XP\system32\ic2_win.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [exil] C:\WINDOWS\exil.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo 900] C:\WINDOWS\XP\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.EXE /P22 "EPSON Stylus Photo 900" /O5 "LPT1:" /M "Stylus Photo 900"
O4 - HKLM\..\Run: [EPSON Stylus Photo 900 (Copy 2)] C:\WINDOWS\XP\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.EXE /P31 "EPSON Stylus Photo 900 (Copy 2)" /O5 "LPT1:" /M "Stylus Photo 900"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\XP\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\XP\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [602PC SUITE PDF Saver] "C:\Program Files\Common Files\soft602\pdfSaver.exe"
O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\XP\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [xwxnwhcw] c:\windows\xp\system32\xwxnwhcw.exe
O4 - HKCU\..\Run: [pdfSaver3] "c:\Program Files\PDF\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\XP\system32\WTablet\TabUserW.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…81/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/092150cf23a79f…ip/RdxIE601.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,19/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\XP\system32\nvsvc32.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\XP\System32\Tablet.exe

Note: I run windows XP with a bellsouth DSL line. The only unusual attachment to my computer is a Wacom tablet.

Thanks for any help you can offer.
Hello Cloverbee, and welcome to the TomCoyote Forums. I will be helping you get your system cleaned up and protected. I am currently reviewing your HiJackThis log and will post back shortly. In the meantime, your copy of HijackThis should be moved into a permanent folder, and not on the desktop. HJT creates backups in case anything goes wrong and it is easier to retrieve them from a permanent folder if needed. 1. Please go to your 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'. NOTE: You can place HJT in a directory of your choice. As long as it has it's own folder and is NOT on the desktop or in a temp directory. 2. Copy and paste HijackThis.exe to the new folder. Thank you for your patience. Regards, Dave
Hello Cloverbee,

Please follow these instructions exactly as described and I recommend that
you print them out to use as a reference during the fix. I find it easy to keep
track of what you're doing by crossing out each item as you go. Just a reminder
also about putting HJT into it's own folder as I advised in my last post…make
sure you do that before carrying out these instructions.

You need to disable Teatimer or it will block the fix make by HJT.
Open Spybot and click on Mode and check Advanced Mode.
Click Yes on the next window.
Click on Tools in bottom left hand corner.
Click on System Startup icon.
Uncheck Teatimer box and SpywareGuard (if installed). Also any other anti-malware protective startup programs like WinPatrol, etc… Your antivirus program can be left intact.
Click Allow Change box.
After cleaning your system reverse these steps and re-enable the protection applets for TeaTimer.

First I would recommend that you remove Spy Killer. Spy Killer uses false positives work as goad to purchase and uses inadequate scanning/detection scheme. Ad-Aware and Spybot S&D work better and both are free.

Go to Add/Remove Programs and uninstall Spy Killer.
Click Start > Control Panel > Double Click Add/Remove Programs: Remove Spy Killer

We need to stop a process from running so HJT can fix it.
Please open Task Manager with Ctrl-Alt-Del and END TASK on the following file:

C:\windows\xp\system32\xwxnwhcw.exe

Now you can run HiJackThis. Check the boxes next to these items:

O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\XP\dlmax.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\XP\isrvs\sysupd.dll (file missing)
O2 - BHO: ohb - {988CAFC4-DC0D-4D8C-A35E-5028ABE9E641} - C:\WINDOWS\XP\system32\ic2_win.dll
O4 - HKLM\..\Run: [exil] C:\WINDOWS\exil.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\XP\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [xwxnwhcw] c:\windows\xp\system32\xwxnwhcw.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/092150cf23a79f…ip/RdxIE601.cab

Now close all browser and explorer windows, and tell HijackThis to "Fix checked".

We need to make sure all hidden files are showing so please:
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

Now boot the computer into safe mode:
*Restart the computer.
*As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*Press Enter.

Using Windows Explorer delete the following files and folder if found:

C:\WINDOWS\exil.exe > file
c:\windows\xp\system32\xwxnwhcw.exe > file
C:\WINDOWS\XP\isrvs > folder

Reboot and post a new HJT log for review.

Regards,

Dave
Hi Dave. Thanks for taking the time to help. I followed your instructions and this is the latest HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 6:18:12 AM, on 2/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\XP\System32\smss.exe
C:\WINDOWS\XP\system32\csrss.exe
C:\WINDOWS\XP\system32\winlogon.exe
C:\WINDOWS\XP\system32\services.exe
C:\WINDOWS\XP\system32\lsass.exe
C:\WINDOWS\XP\system32\svchost.exe
C:\WINDOWS\XP\system32\svchost.exe
C:\WINDOWS\XP\System32\svchost.exe
C:\WINDOWS\XP\System32\svchost.exe
C:\WINDOWS\XP\System32\svchost.exe
C:\WINDOWS\XP\system32\spoolsv.exe
C:\WINDOWS\XP\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
C:\WINDOWS\XP\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\XP\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\XP\system32\WTablet\TabUserW.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\XP\system32\cisvc.exe
c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\XP\system32\nvsvc32.exe
C:\WINDOWS\XP\system32\tcpsvcs.exe
C:\WINDOWS\XP\System32\snmp.exe
C:\WINDOWS\XP\System32\svchost.exe
C:\WINDOWS\XP\System32\Tablet.exe
C:\Documents and Settings\Denise\My Documents\hijack\hijackthis\HijackThis.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\WINDOWS\XP\System32\wbem\wmiprvse.exe
C:\WINDOWS\XP\System32\alg.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo 900] C:\WINDOWS\XP\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.EXE /P22 "EPSON Stylus Photo 900" /O5 "LPT1:" /M "Stylus Photo 900"
O4 - HKLM\..\Run: [EPSON Stylus Photo 900 (Copy 2)] C:\WINDOWS\XP\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.EXE /P31 "EPSON Stylus Photo 900 (Copy 2)" /O5 "LPT1:" /M "Stylus Photo 900"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\XP\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\XP\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\XP\system32\WTablet\TabUserW.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…81/mcinsctl.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,19/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\XP\system32\nvsvc32.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\XP\System32\Tablet.exe

The popups and tool bar have disappeared! The only unusual thing that has happened is that I have lost all of the files in the "my documents" folder. Only that particular folder, but they are nowhere to be found. I checked the documents and settings/user/my documents and ran a search for some of the files and they have disappeared. I don't know if I did something by mistake or if it was the results of malware. Anyway, it will teach me to back up.

Once again, thanks for your help.

Denise
Hi Denise, Glad to hear things are running better. I will check through your log and make sure there is nothing else that needs fixing. Sorry to hear about all your files. Did you check the Recycle Bin to see if they're in there? If you accidentally deleted them and didn't empty the bin they might be there. I'll post back with some recommendations for preventing future infection. Regards, Dave
Hello Denise,

Congratulations, your system is clean. Here are a few tips to prevent malware from
infesting your computer in the future.

In addtion to updating and running your current Spyware and Anti-Virus tools I recommend the following:
  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware
  • Install SpywareGuard - SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method. You can download SpywareGuard here:
    http://www.javacoolsoftware.com/sgdownload.html
    A tutorial on installing & using this product can be found here:
    http://www.bleepingcomputer.com/forums/tutorial50.html
  • This point cannot be stressed enough! - Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates
    you WILL NOT be protected when new malicious programs are released.
Here is a link to an article written by Tony Klein, that
also gives some great advice on preventing further infection.

This is a great tutorial on Hardening IE.

I recommend cleaning out your temporary internet files. CCleaner is a
freeware system optimisation tool for PCs. It removes unnecessary junk
from your computer allowing it to run more efficiently and securely.
Please download CCleaner from one of the two websites below:
http://www.majorgeeks.com/download4191.html
http://www.ccleaner.com/

Install CCleaner. Now open and click on the Windows tab.
Check the following items:
Under Internet Explorer:
Temporary Internet Files
History
Recently Typed URLs
Delete Index.dat files
Under System:
Empty Recycle Bin
Temporary Files
Memory Dumps
Chkdsk File Fragments
Old Prefetch Data

Next: click the Options button and then click the Settings tab
Uncheck: Only delete files older than 48 hrs. and click OK

Prior to running click on the Check for updates now… link
Then click the Run Cleaner button. It should only take a few seconds
to complete and exit when it is done.

Follow this list and your potential for being infected again will reduce dramatically.

I also noticed that you appear to be running 3 antivirus programs, AVG, McAfee
and Avast. It is recommended that you only actively run one at any time to avoid conflicts. If you like you can keep all of them installed but only have one active, and the others as a backup if needed. Multiple antivirus programs running in the background can drastically slow down your PC, and cause conflicts.

Safe Surfing!

Dave
Dave, once again - thank you for all your help. I did end up recovering the majority of my files via a program called restoration.exe. I lost only about 2% of them, which is wonderful news. And a reminder that I need to ensure my backups are intact and physically separate from the computer. I was trying every spywre program that I could to get rid of the issues, which is why I had so many running. I have kept McAfee since I have paid for it (although I question its ability to help since it didn't catch this particular one. I have the other deactivated, but will run them periodically (one at a time!) to make sure they have a chance to catch stuff that McAfee misses. I have cleaned the temp files per your instructions. Thanks again for taking the time to help me. :) Denise :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI