This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Msn Search Must Be Airborne Virus!

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good Morning Rira,

Your time may be off a little because we are on the same time zone, it was around 9:30 PM when I posted to you.

I and alot of people that I deal with are not big fans of STANDBY MODE, or HIBERNATE, you should just set the screen saver to pop on after a choosen period of time, and then set the monitor to turn off also. I have mine set to screensaver after 15 min and the monitor after about 45 min. Right click on your desktop and select properties, then open the screensaver tab, set the time for your screensaver, then click on the Power tab and under STANDBY, and HIBERNATE, select NEVER, then set your monitor to turn off whenever you choose. It is safe to leave your PC on all day if you are using it from time to time, if you install ZoneAlarm, it is set by default to halt internet traffic when your screensaver pops on, but at the end of the day, I would turn it off for the night.

This error "Ashserve…application error, memory could not be written at OoX" is from your Avast anti virus program, you may want to try reinstalling that program.

So after you run the istructions in my previous post, post a new HJT log.

========================================================

New issue,

as I was closing out your other post, I forgot about these 2 lines in HJT, they are not critical but when you have the chance, run HJT on your OTHER computer and take out these.

* R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
* R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


Ken
Hi Ken,
Well, this has been an all day affair! I'll start with the easy stuff first. I did rightclick my desktop and checked what settings I had. I had the screensaver for 5 min (because the kids like to see the photoshow!) and the monitor for 1 hr. I switched them anyway to 10 min and 45 min. I did have "never" for the hibernate and standby. I'll try to get them to turn it off at least some nights, the instant messaging for teens is like an answering service and they often get late messages, so we'll work out a compromise.

I am continuing to have problems with not getting online. If I walk away from the computer for a few hours, like I did this afternoon, from 2:30 to 7:30, I can't get online. Usually, but not always, I can get into Mozilla for my mail.

Everything is also going very slowly. I had Spybot triggered to start when it boots up, but as often as I've been doing that lately, I stopped that function! Then I ran whatever else I had around before I was going to send you an HJT log, Adaware found 15 objects, 1 "critical" and deleted them, Spybot found 9, then later, none. Then I ran Avast and what usually takes about 4 or 5 minutes took, oh I'd say over an hour before I finally just aborted. It didn't find anything after checking nearly 1,000,000 files. Going along with your previous comment, I think that needs to be re-installed. Or do you suggest not putting it back on? The Trojan Hunter is on, Zone Alarm is running, CheckIt 86, which I think came from Cox Cable is running, avast, Spyware Guard…is there too much going on? This is high speed internet, so when I sign on, it takes 2 seconds, but today it takes about 16 seconds to get onto my homepage, and with each option I select, it takes so much longer, it seems. If I click on to check my mail, it takes about 6 or 7 seconds of "the hourglass" before it actually opens the program, then a few more seconds before it loads the whole program in. :(

In regards to the latest instructions, I ticked off thos items in the HJT and fixed them, but did not find the varpc32.exe in either directory or in the search. I cleaned out my temp files…I guess it's been awhile because I had 915 items! You said to do this in safemode, but that limits me to only "administrator" and my name. I rebooted in regular mode and when through the steps in the other three user names and emptied their temporary files, with 48-88 files in each. Then I repeated the same process with the windir\temp files, got a bunch out there. I went ahead and emptied the recycle bins, I hope I was supposed to do that!
I then went to the internet options on the IE tools and deleted those files you instructed, then repeated the same for the other users, but I probably didn't have to, right? Anyway, the things that it said it could not delete because "it is being used by another person or program" (I was guessing it was something to do with all the scanners and protective programs) were JET4F75, JETed5D, JET58CE, JET5DDF.tmp. T30Debuglogfile.txt, ZLT07b21………

My most recent development is a window that popped up after I left to do something…I think while the Avast was doing its thing…

"Windows-Virtual Memory Minimum Too Low" "Your system is low on virtual memory. Windows is increasing the size of your virtual memory paging file. During this process, memory requests for some applications may be denied. For more information, see Help."

OK…..

Dear Ken, for your reading pleasure, here is my latest log:

Logfile of HijackThis v1.99.1
Scan saved at 8:18:30 PM, on 5/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\CheckIt\86\CheckIt86.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\MOZILL~1\THUNDE~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wdbj7.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.roanoke.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\Program Files\550AccessToolbar\proxy.pac
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 550Access Toolbar - {26CB33C5-1F3C-4C52-8B26-29D6E0635770} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunServices: [AOL Instant Messenger] aimsgr.exe
O4 - HKCU\..\Run: [mf3216] C:\WINDOWS\System32\mf3216.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CheckIt 86.lnk = C:\Program Files\CheckIt\86\CheckIt86.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 550Access Toolbar Search - C:\Program Files\550AccessToolbar\550accessmenusearch.htm
O8 - Extra context menu item: Add To CheckIt &86 Trust List - C:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Whew! You were right, this computer is a bit more involved than the last one… I'll go back and do those last steps on that one now.

Thanks, Ken,

Rita
Rita, I will be offline until tomorrow am, I will go over your new log and get back to you soon. I would like you to check how much ram you have and also the size of your paging file. Do this and post what you have, with all you have going on, I want to see how you stand on memory. Right click on MY COMPUTER> Then click on PROPERTIES, under ther general tape it wil tell you how much ram you have and also the speed of your processor. Then under the ADVANCED tab/ PERFORMANCE SETTINGS/ ADVANCED.. It will tell you the amount of your paging file. Back to you in the am
Hello Again Rita,

Let me know about the amount of memory you have and the size of your paging file.

Run HJT and put a tick in this and get rid of it.

* O4 - HKCU\..\Run: [mf3216] C:\WINDOWS\System32\mf3216.exe

Then do the Hidden files and Safemode thing and delete this if still present

* C:\WINDOWS\System32\mf3216.exe <– This file

Now download and run CleanUp
http://cleanup.stevengould.org/

After you delete the above mentioned entry, your log appears to be free of any Viruses or Malware. The not being able to log without rebooting may be an issue with either your cable company, your cable modem or your router. It could also be a windows issue. If you can't get any satisfaction from any of the above, you may post your problem on one of these fine forums.

http://www.windowsbbs.com/index.php?
http://hwg.mazin.net/hardwareguys/hwgboard/ikonboard.cgi

In relation to Avast Anti-Virus, it is your call for what you want to do with it. If it is something you bought and paid for, you can go here and give them a call and explain the problem. They also have a tech support forum that you can post your question to. Be sure to include the error message "Ashserve…application error, memory could not be written at OoX"

http://www.avast.com/
http://forum.avast.com/

If you decide to uninstall it, here is a excellent free Anti-Virus program that I have installed on my second PC.

http://free.grisoft.com/doc/2/lng/us/tpl/v5

Rita, post a new HJT log to make sure we got rid of that entry. I am going to double check your new log, and if your 100% clean, I won't be able to guide you any longer, you will need the help of a tech support forum that specializes in Hardware and Software issues.

So……………..I'm waiting for your log.
Hi Ken, No, Avast is something I downloaded, it was freeware. The schools use it here on the student laptops here, too. I'l check into their help site at a later point and use your other suggestion if it's not worth the trouble to keep it. here is the other info you asked about: Pentium 4 CPU 2.50GHz 2.5GHz, 448 MB of RAM total paging file size for all drives 672 MB I am working on the other part so I can send another log. Thanks, Rita
Hey Ken, I'm giving your brain a rest for a day…today ended up consuming my time in other ways and tomorrow I will be out of state from before sunrise to midnight. I'll get to it on Sunday! Hope you have a great weekend in the "great Northeast", where ever that it is! Warm regards, Rita
Hi Ken, I got rid of the mf3216 file and emptied my recycle bin. I hope that was OK.

I got to the cleanup! website but when I tried to download the latest version, it kept reverting to a screen saying the page wasn't available. I tried to go through a back door, but no matter what, it won't connect. Please advise!

I'm posting my latest log anyway. Thanks, Ken.


Logfile of HijackThis v1.99.1
Scan saved at 9:23:59 PM, on 5/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\CheckIt\86\CheckIt86.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\THUNDE~1.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wdbj7.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.roanoke.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\Program Files\550AccessToolbar\proxy.pac
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 550Access Toolbar - {26CB33C5-1F3C-4C52-8B26-29D6E0635770} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunServices: [AOL Instant Messenger] aimsgr.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CheckIt 86.lnk = C:\Program Files\CheckIt\86\CheckIt86.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 550Access Toolbar Search - C:\Program Files\550AccessToolbar\550accessmenusearch.htm
O8 - Extra context menu item: Add To CheckIt &86 Trust List - C:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: 550Access Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hello Again Rita,

The amount of memeory you have installed is adequite for your system, and the paging file is right in line also. You may just have to many programs open at once, try to limit them, also if you have fancy screensavers and a large graphic picture as your wallpaper, this will eat up memory. Check all the icons you have on your system tray (THis is on your right by the clock ), those programs are sitting in memory waiting to be used, if there are some that you don't use that often, you may be able to access that program and take the checkmark out of letting it start when windows starts and just run the program manually when you need it. . You will have to do your homework on this.

Your log looks very healthy :D , no more signs of spyware or viruses. Your last post for the first computer can be found here. it is closed, you can't post to it anymore but you can access it for information. You can use it to download and install all those good programs that we put on your other computer and save me a lot of typing :rofl: http://forums.tomcoyote.org/index.php?show…11&#entry161211

The site for the cleaner is working, it was very slow loading for me in both IE and Firefox. Wait a day or two and give it another try.

Well Rita, it has been a pleasure working with you, :thumbup: and I am sure that you have learned alot. Just keep your spyware and virus programs up to date, run the scans and hopefully they will keep you out of trouble.

Any spyware or virus related problems in the future, don't hesitate to post back.

I will keep this thread open for a few days in case you have any more questiions


Warm regards <– Stole this from a nice lady I met in this forum :rofl:

Ken
Hello, Ken! I have started training on my new job this week so I have not had much spare time to finish up on the desktop. I have printed up the instructions you provided on the first "project" we worked out and will download and run those programs on the other pc, also. I'll be running Firefox on that one, too. I really do appreciate all the time and thought you put into both of my sad computers, Ken. I still have some work to do to iron out a few more things, and I appreciate the links you provided to work on some of the other aspects I have to adjust. :oops: At least I have the peace of mind knowing that I am virus-free and the problems are not due to that. And compared to having my browser hijacked, these problems are minor! I have definitely learned a lot from you, Ken. I wish you all the best. Thank you so much for participating in these forums. You can go ahead and close this thread. :wavey: Most sincerely, Rita B)
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be
"Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Thanks, MrC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI