This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Msn Search Must Be Airborne Virus!

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Well, happy to have solved the hijacking of my laptop by MSN search this evening, thanks to Ken545's diligent help. Now I'm trying to fix the identical problem on my desktop. Perhaps this entered through BearShare, hard to say, but I'm removing that off this machine, too, then awaiting word on what to do next. I'll go ahead and run the housecall and pandasoftware online virus scans that y'all suggested I run on my laptop in the meantime as I await your response. Thanks.


Logfile of HijackThis v1.99.1
Scan saved at 9:48:07 PM, on 4/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\aimsgr.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\Program Files\CheckIt\86\CheckIt86.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\explorer32\WinsysMngr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\explorer32\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.iquicksearch.net/search.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wdbj7.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.roanoke.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\Program Files\550AccessToolbar\proxy.pac
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6DDC370D-B141-0C94-8450-15550DF07918} - C:\WINDOWS\System32\uptun.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 550Access Toolbar - {26CB33C5-1F3C-4C52-8B26-29D6E0635770} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [wfwjkp] C:\WINDOWS\wfwjkp.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Mswincfg] c:\windows\system32\mswincfg32.exe
O4 - HKLM\..\Run: [MsSpool32] C:\windows\msspool32.exe
O4 - HKLM\..\Run: [tsrqbxayfbhvh] C:\WINDOWS\System32\vowufvbw.exe
O4 - HKLM\..\Run: [netresi] C:\WINDOWS\System32\netresi.exe
O4 - HKLM\..\Run: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\Run: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKLM\..\Run: [AccessMedia P2P Loader] "C:\Program Files\p2pnetworks\amp2pl.exe" /H
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MyAccessMedia] "C:\DOCUME~1\RITANE~1\LOCALS~1\Temp\tmp6A.exe" -Remove
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe
O4 - HKLM\..\Run: [WinLoad] C:\WINDOWS\system32\Winload.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunServices: [Mswincfg] c:\windows\system32\mswincfg32.exe
O4 - HKLM\..\RunServices: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\RunServices: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKCU\..\Run: [mf3216] C:\WINDOWS\System32\mf3216.exe
O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe
O4 - HKCU\..\Run: [Zo48RVf7Q] ipmtprio.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [Xbuwb] C:\WINDOWS\System32\??rvices.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CheckIt 86.lnk = C:\Program Files\CheckIt\86\CheckIt86.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 550Access Toolbar Search - C:\Program Files\550AccessToolbar\550accessmenusearch.htm
O8 - Extra context menu item: Add To CheckIt &86 Trust List - C:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hello Again whatgrayhair?, Rita, the infections on this computer are a little more complicated than your previous machine, I am going to analyze your log and be back a little later this evening. Be sure to reply to this thread only, we are about to close the other one out. Ken
Hello Again whatgrayhair?,

Your infection is a little more serious than the one on your other computer :angry: , but we will be able to get you back to normal. :D

First have windows enable all hidden files
SHOW HIDDEN FILES AND FOLDERS

* Click on MY COMPUTER
* Then on your C: Drive
* Then to TOOLS/ FOLDER OPTIONS/ VIEW
* Choose the radio button to SHOW HIDDEN FILES AND FOLDERS
* Take the checkmark out of HIDE EXTENSIONS FOR KNOWN FILE TYPES
* Then APPLY/ OK

* Don't forget to reverse this once your computer is clean

I would like you to download and install the LSPFix program, download it to your desktop and follow these instructions.

Do the following:
Download and run LSPfix.exe …Note the file extension –> .exe
http://www.cexx.org/lspfix.htm

* Check 'I know what I'm doing'.
* Select all instances of cdlsp.dll
* Click the right-pointing arrow to move those files to the right window pane.
* Click 'Finished'.
* Restart your computer.

Delete the following file:
* C:\Windows\System32\cdlsp.dll <– This file only

You may have to reboot into Safemode to see this file

To Enter SAFEMODE

* Go to START/ SHUT OF YOUR COMPUTER/ RESTART
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
* Then press the ENTER KEY ON YOUR KEYBOARD


Now reboot normally and run HJT (SCAN ONLY) and put a checkmark in the following entries, close all open windows and browsers and click on FIX CHECKED.

* R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
* R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
* O4 - HKLM\..\Run: [wfwjkp] C:\WINDOWS\wfwjkp.exe
* O4 - HKLM\..\Run: [Mswincfg] c:\windows\system32\mswincfg32.exe
* O4 - HKLM\..\Run: [MsSpool32] C:\windows\msspool32.exe
* O4 - HKLM\..\Run: [tsrqbxayfbhvh] C:\WINDOWS\System32\vowufvbw.exe
* O4 - HKLM\..\Run: [netresi] C:\WINDOWS\System32\netresi.exe
* O4 - HKLM\..\Run: [WinLoad] C:\WINDOWS\system32\Winload.exe
* O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe
* O4 - HKCU\..\Run: [Zo48RVf7Q] ipmtprio.exe
* O4 - HKCU\..\Run: [Xbuwb] C:\WINDOWS\System32\??rvices.exe


Now reboot back into Safemode and delete the following files if still present….

C:\WINDOWS\wfwjkp.exe <– This File in Bold
C:\windows\ msspool32.exe <– This File in Bold

c:\windows\system32\ mswincfg32.exe<– This File in Bold
C:\WINDOWS\System32\ vowufvbw.exe <– This File in Bold
C:\WINDOWS\System32\ netresi.exe <– This File in Bold
C:\WINDOWS\system32\ Winload.exe <– This File in Bold

C:\WINDOWS\System32\ ??rvices.exe <– This File in Bold This one may say IEservices.

This one may be in C:\DOCUMENTS AND SETTING\ALL USERS\START MENU\\IEService.exe <– This File

Search for this file…. ipmtprio.exe , it could be in either of these directories and delete it if found.
C:\windows
C:\windows\system
C:\windows\system32




Now reboot normally and post a new HJT log please.
:wavey: Hi Ken, sorry for the delay…I had an unusually busy few days at work along with helping with the prom! I followed all the directions given, and here is my newest log. Thank you, Ken.

Logfile of HijackThis v1.99.1
Scan saved at 3:56:01 PM, on 5/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\Program Files\CheckIt\86\CheckIt86.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.iquicksearch.net/search.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wdbj7.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.roanoke.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\Program Files\550AccessToolbar\proxy.pac
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6DDC370D-B141-0C94-8450-15550DF07918} - C:\WINDOWS\System32\uptun.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 550Access Toolbar - {26CB33C5-1F3C-4C52-8B26-29D6E0635770} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\Run: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKLM\..\Run: [AccessMedia P2P Loader] "C:\Program Files\p2pnetworks\amp2pl.exe" /H
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MyAccessMedia] "C:\DOCUME~1\RITANE~1\LOCALS~1\Temp\tmp6A.exe" -Remove
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [Mswincfg] c:\windows\system32\mswincfg32.exe
O4 - HKLM\..\RunServices: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\RunServices: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKCU\..\Run: [mf3216] C:\WINDOWS\System32\mf3216.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CheckIt 86.lnk = C:\Program Files\CheckIt\86\CheckIt86.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 550Access Toolbar Search - C:\Program Files\550AccessToolbar\550accessmenusearch.htm
O8 - Extra context menu item: Add To CheckIt &86 Trust List - C:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hi Rita,

How are you doing??

We still have a few issues to clean up. I would like you to download and run Trojan Hunter. This is the 30 day evaluation copy, run a full system scan on all your drives. It will fix most things that need fixing, it will also give you the option of saving a log, save that log and post it in your next reply along with a new HJT log.

http://www.trojanhunter.com/

Also that Weather Bug program kind of falls in the grey area as far as malware, your option to uninstall it via the Add-Remove programs in the control panel. If you need a weather program, you can download one from the weather channel that will sit in your system tray with the local temp and such.

http://www.weather.com/services/desktop.ht…=homewxanywhere
Hi Ken,
I ran the trojan hunter after I finally tracked down weather bug and deleted it. It was removed a few days ago, before we started looking at this computer's log but the program was still running, even after numerous reboots. I went to the weather bug site and they walked me through a tedious removal process with "regedit", etc., Anyway, it's gone. Thanks for offering a substitute, also. Trojan Hunter ran, also, but for the life of me I couldn't find any offer to display a log, so I do not have that…sorry. I am posting my latest HJT log below. Thank you, Ken.

Logfile of HijackThis v1.99.1
Scan saved at 10:09:12 PM, on 5/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\CheckIt\86\CheckIt86.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.iquicksearch.net/search.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wdbj7.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.roanoke.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\Program Files\550AccessToolbar\proxy.pac
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6DDC370D-B141-0C94-8450-15550DF07918} - C:\WINDOWS\System32\uptun.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 550Access Toolbar - {26CB33C5-1F3C-4C52-8B26-29D6E0635770} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\Run: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKLM\..\Run: [AccessMedia P2P Loader] "C:\Program Files\p2pnetworks\amp2pl.exe" /H
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MyAccessMedia] "C:\DOCUME~1\RITANE~1\LOCALS~1\Temp\tmp6A.exe" -Remove
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunServices: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\RunServices: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKCU\..\Run: [mf3216] C:\WINDOWS\System32\mf3216.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CheckIt 86.lnk = C:\Program Files\CheckIt\86\CheckIt86.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 550Access Toolbar Search - C:\Program Files\550AccessToolbar\550accessmenusearch.htm
O8 - Extra context menu item: Add To CheckIt &86 Trust List - C:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Rita,

Did Trojan Hunter find much wrong?


Run HJT (SCAN ONLY) and put a tick in the following entries, close all open windows except HJT and click on FIX CHECKED.

* O4 - HKLM\..\Run: [AccessMedia P2P Loader] "C:\Program Files\p2pnetworks\amp2pl.exe" /H

* O4 - HKLM\..\Run: [MyAccessMedia] "C:\DOCUME~1\RITANE~1\LOCALS~1\Temp\tmp6A.exe" -Remove

* O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU


Now enable Hidden files and boot into Safemode ( Rita, you must be a pro at this by now :D )

Delete the following files or folders….

* C:\Program Files\ p2pnetworks<–This entire folder
* C:\PROGRAM FILES\ AWS<– This entire folder


Go to START> SEARCH and do a search for this file and delete it if found

* tmp6A.exe



Rita, where almost home, post a new HJT log when done and let me know if your having any more issues.
Hi Ken, Trojan Hunter did find, I think it was five trojans and a suspected trojan. I ran it again today and it found one more suspected trojan. After getting to the step where I went back into safe mode, I did not find any files for p2p or aws, I also searched for them but nothing came up. I searched for the tmp6A file, and what came up was tmp6A.exe-2ECC6ED8 a .pf tile, under c:\windows\prefetch modified 5/1/05 9:15 pm. I did not do anything with the file. I humbly await your advice, Ken. I have not seen any MSN Search hijacking :D :rofl: :weee: but I do have two questions. 1. often, when I shut down to reboot, a window says it is ending a program called "shellcontll Hidden Window" something like that, I know it is shellcon…something, it flashes off too quickly! Is that anything to be concerned about? It has done this for months, even prior to my recent hijack troubles. Also, #2, on other computers in the past, I usually had programs such as AdAware and Avast running as scheduled tasks, i.e. weekly. I did them on this computer but it won't run them. It has an error message that says "Task scheduler–An error has occured while attempting to set task account information. The specific error is 0x80070005, access is denied. You do not have permission to perform the requested operation." I went to Task Sched.'s help section, but…it was not helpful! I tried with and without passwords, etc. It lets me enter the task, and schedule it, but then says it couldn't run it! They run fine "manually". Also, I finally got around to finishing up on the laptop that you helped me immensely with last week, adding the new programs such as ZoneAlarm, and including Firefox. That was pretty painless. I again warned my family members there were some new formats and new programs, so they might need to get me to tell them what to click on, but it's all good. Be sure to let me know what you want me to add on to this desktop. I can easily switch to Firefox and whatever else you suggest. Thank you, Ken :thumbup:
Hi Rita, :D

In regards to your task schedualer, it looks like one of the critical windows updates messed this up. You can go to ADD-REMOVE PROGRAMS in the CONTROL PANEL and remove this update. KB841873

Microsoft also says there is a HotFix patch to download and install to correct that problem, that would be my first choice before removing it, so don't remove it before you call Microsoft for the Hotfix, here is info on that.
http://support.microsoft.com/default.aspx?…kb;en-us;884573

I will need more info on the shutdown problem to see if it is malware related, if it isn't than I can direct you to some excellant windows tech support sites that know the inner workings of windows better than I do.

Rita, I need you to Run HJT and post a fresh log please to make sure that there is nothing left to be concerned about.
:lol: I had this ready on the clipboard and forgot to paste in onto the post! Sorry Ken. Thanks for the advice on the Task Scheduler.


Logfile of HijackThis v1.99.1
Scan saved at 12:49:25 PM, on 5/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\CheckIt\86\CheckIt86.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MOZILL~1\THUNDE~1.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.iquicksearch.net/search.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wdbj7.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.roanoke.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\Program Files\550AccessToolbar\proxy.pac
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6DDC370D-B141-0C94-8450-15550DF07918} - C:\WINDOWS\System32\uptun.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 550Access Toolbar - {26CB33C5-1F3C-4C52-8B26-29D6E0635770} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\Run: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunServices: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\RunServices: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKCU\..\Run: [mf3216] C:\WINDOWS\System32\mf3216.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CheckIt 86.lnk = C:\Program Files\CheckIt\86\CheckIt86.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 550Access Toolbar Search - C:\Program Files\550AccessToolbar\550accessmenusearch.htm
O8 - Extra context menu item: Add To CheckIt &86 Trust List - C:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hello Rita,

You may still have a virus infection called W32.Spybot.Worm. What I need you to do is to run about 3 online virus scanners. Run them all and look for the option to auto clean or Repair, there all worded differtent. Even if you ran one of them before, run them all again. This worm was probalble downloaded with the Kazaa file shareing program, thats why these kind of programs are not safe.

http://www.bitdefender.com/scan/licence.php
http://housecall.trendmicro.com/
http://www.pandasoftware.com/activescan/

Please post a new HJT log when finished.
Hi Ken,

I ran the scanners, in order, the last two, housecall and panda did not find any viruses! Yay! The first one gave me a long list of confusing data, so I'll post it below, followed by by HJT log.


BitDefender scan 5-4-05

C:\Documents and Settings\Adam\Local Settings\Temp\~449152.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Adam\Local Settings\Temp\~449152.tmp: disinfection failed
C:\Documents and Settings\Adam\Local Settings\Temp\~789267.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Adam\Local Settings\Temp\~789267.tmp: disinfection failed
C:\Documents and Settings\Adam\Local Settings\Temp\~839582.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Adam\Local Settings\Temp\~839582.tmp: disinfection failed
C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\2ZGJMB8F\stc[1].htm: infected with Exploit.Html.Codebase.Exec.Gen
C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\2ZGJMB8F\stc[1].htm: disinfection failed
C:\Documents and Settings\Meghan\Local Settings\Temp\m2Pq3uOw.dll: infected with Trojan.Spy.Middadle.A
C:\Documents and Settings\Meghan\Local Settings\Temp\m2Pq3uOw.dll: disinfection failed
C:\Documents and Settings\Meghan\Local Settings\Temp\~60305.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Meghan\Local Settings\Temp\~60305.tmp: disinfection failed
C:\Documents and Settings\Meghan\Local Settings\Temp\~671182.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Meghan\Local Settings\Temp\~671182.tmp: disinfection failed
C:\Documents and Settings\Rita Neel\Local Settings\Temp\ng.dll: infected with Trojan.Spy.Middadle.A
C:\Documents and Settings\Rita Neel\Local Settings\Temp\ng.dll: disinfection failed
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~110893.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~110893.tmp: disinfection failed
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~122715.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~122715.tmp: disinfection failed
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~2161.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~2161.tmp: disinfection failed
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~314561.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~314561.tmp: disinfection failed
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~320609.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~320609.tmp: disinfection failed
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~422628.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~422628.tmp: disinfection failed
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~448154.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~448154.tmp: disinfection failed
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~455930.tmp: infected with Trojan.Downloader.Wintool.D
C:\Documents and Settings\Rita Neel\Local Settings\Temp\~455930.tmp: disinfection failed
C:\PeoplePC\Branding\ppcstub.exe: suspect BehavesLike:Trojan.StartPage
C:\PeoplePC\Branding\ppcstub.exe: disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000004=>(Quarantine-PE): infected with Backdoor.RBot.5CE10393
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000004=>(Quarantine-PE): deleted
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000004: deleted
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000005=>(Quarantine-PE): infected with Trojan.Dropper.Small.GT
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000005=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000007=>(Quarantine-PE): infected with Trojan.Dropper.Small.GT
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000007=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000000D=>(Quarantine-PE): infected with Application.Dropper.Ncase.Salm
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000000D=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000000E=>(Quarantine-PE): infected with Application.Dropper.Ncase.Salm
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000000E=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000000F=>(Quarantine-PE): infected with Application.Dropper.Ncase.Salm
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000000F=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000010=>(Quarantine-PE): infected with Trojan.Spy.Delf.DX
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000010=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000012=>(Quarantine-PE): infected with Trojan.BettInet.A
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000012=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000013=>(Quarantine-PE): infected with Trojan.Spy.DeskAd.A
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000013=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000014=>(Quarantine-PE): infected with Trojan.Spy.DeskAd.A
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000014=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000015=>(Quarantine-PE): infected with Trojan.Spy.Deskad.A
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000015=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000016=>(Quarantine-PE): infected with Application.Dropper.Ncase.Salm
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000016=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000017=>(Quarantine-PE): infected with Backdoor.PADODOR.GEN
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000017=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000019=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000019=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001B=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001B=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001C=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001C=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001D=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.D
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001D=>(Quarantine-PE): deleted
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001D: deleted
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001E=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.D
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001E=>(Quarantine-PE): deleted
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001E: deleted
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001F=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000001F=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000024=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000024=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000027=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.D
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000027=>(Quarantine-PE): deleted
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000027: deleted
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000002D=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000002D=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000002E=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\0000002E=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000032=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000032=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000034=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000034=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000035=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000035=>(Quarantine-PE): disinfection failed
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000036=>(Quarantine-PE): infected with Trojan.Downloader.Qoologic.F
C:\Program Files\Alwil Software\Avast4\DATA\chest\00000036=>(Quarantine-PE): disinfection failed
C:\RECYCLER\S-1-5-21-2925195779-3626921563-3303464695-1005\Dc1587\Quarantine\4D9738BF.exe=>(Quarantine-2): infected with Trojan.Dropper.Small.IJ
C:\RECYCLER\S-1-5-21-2925195779-3626921563-3303464695-1005\Dc1587\Quarantine\4D9738BF.exe=>(Quarantine-2): disinfection failed
C:\staff.html: infected with HTML.MediaTickets.A
C:\staff.html: disinfection failed
C:\temp\qoolaid.exe: infected with Dropped:Trojan.Downloader.Qoologic.F
C:\temp\qoolaid.exe: disinfection failed
C:\WINDOWS\bundles\WebRebates_Auto_InstallSilent.exe: infected with Dropped:Application.ProcKill.Jk
C:\WINDOWS\bundles\WebRebates_Auto_InstallSilent.exe: disinfection failed
C:\WINDOWS\system32\biU.exe: infected with Trojan.PWS.Bispy
C:\WINDOWS\system32\biU.exe: disinfection failed
C:\WINDOWS\system32\RVICES~1.EXE: infected with Trojan.Dropper.PurityScan.I
C:\WINDOWS\system32\RVICES~1.EXE: disinfection failed






Logfile of HijackThis v1.99.1
Scan saved at 8:20:08 PM, on 5/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\CheckIt\86\CheckIt86.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wdbj7.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.roanoke.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\Program Files\550AccessToolbar\proxy.pac
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6DDC370D-B141-0C94-8450-15550DF07918} - C:\WINDOWS\System32\uptun.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 550Access Toolbar - {26CB33C5-1F3C-4C52-8B26-29D6E0635770} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\Run: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunServices: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\RunServices: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKCU\..\Run: [mf3216] C:\WINDOWS\System32\mf3216.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CheckIt 86.lnk = C:\Program Files\CheckIt\86\CheckIt86.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 550Access Toolbar Search - C:\Program Files\550AccessToolbar\550accessmenusearch.htm
O8 - Extra context menu item: Add To CheckIt &86 Trust List - C:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


:blink: Thanks, Ken!

Rita
Hi Rita,

Run HJT and put a tick in the following entries, close all windows and browsers and click on FIX CHECKED, but lets run HJT from Safemode.

* O2 - BHO: (no name) - {6DDC370D-B141-0C94-8450-15550DF07918} -
C:\WINDOWS\System32\uptun.dll (file missing)

* O4 - HKLM\..\Run: [Microsoft Visual Studio VSA] varpc32.exe

* O4 - HKLM\..\RunServices: [Microsoft Visual Studio VSA] varpc32.exe


Now while in Safemode, do a search for this file varpc32.exe , it could be in either of these directories … and delete it if found. If not in there, go to START> SEARCH and let windows try to find it, make sure windows is enabled to show all fles.

C:\WINDOWS
C:\WINDOWS\SYSTEM
C:\WINDOWS\SYSTEM32


While still in Safemode……….

Most of the bitdefender files were items that where in quarintine from your anti virus program. But you may still have some stuff lurking in the temp folders.

Easy to fix, do this

This process will clean out your TEMP FILES and your TEMPORARY INTERNET FILES. Please do both steps:

Step 1 - DELETE TEMP FILES

* This procedure should be run from SAFEMODE for better results.

* click on START/ RUN and type %temp% and press the ok button.

This should open up the temp directory that your machine uses. You should do this for each user on your system. Please delete all
files that are found there. If you get an error when deleting a file, skip that file and delete all the others.

* Do this same process for %windir%\temp.

NOW RE-BOOT NORMALLY

Step 2 - DELETE TEMPORARY INTERNET FILES

* Now I want you to open up INTERNET EXPLORER
* Click on the TOOLS MENU
* Then INTERNET OPTIONS
* At the GENERAL TAB, (which should be the first tab you are currently on),
* click on the DELETE FILES BUTTON and put a checkmark in DELETE ALL OFFLINE CONTENT.
* Then press the OK BUTTON . This may take quite a while, so do not be alarmed with how long it takes.
When it is done, your Temporary Internet Files will now be deleted.


I am going to look over your log with a fine tooth comb and be back to you tommorrow. The sandman just whacked me in the head with his stick :D
Hi Ken! :o Geesh, Ken, you are working at the computer at 2 in the morning??!!! We keep different hours…I've been up for an hour already! Only because I have to, though, I don't relish the idea of getting up at 5. I printed off your most recent directions and will get to that in a bit. I wanted to point out two issues which may resolve through all of this but I mention them anyway. 1. Both yesterday and today, when I return to this desktop, which is generally always on, as we have a cable connection, I cannot get on the internet after waking it from it's standby mode. My laptop works via the wireless router on the desktop, so obviously it's not the cable. When I reboot, it's fine. Today was the same thing. I rebooted last night when I did the HJT scan, returned a bit later to look up something else, then left the computer for the night. This morning, can't get onto the internet until I rebooted. Hmmm. 2. When I do close down now, I get this flash of a small window that says "Ashserve…application error, memory could not be written at OoX" something something…. it goes away too fast to write it all down (is there a way to freeze the screen so I could actually write it down?). Then it shuts down normally and reboots. Well, I'll work on the rest of your directions and we'll go from there. Thank you, Ken warm regards, (sorry, I stole that from you!) Rita

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI