This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CoolWebSearch and more

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been having a problem with my machine. I looked into the registry today and found, under HKEY USERS/S-1-5-21-1396011555-1180733485-2266813057-1003/software/software/microsoft/windows/current version/internet settings/domains, about 200 different forms of malware, including coolwebsearch (s). I have used cwshredder, and a program I found in one of the boards, sdfix, following directions, but with no luck. <_<

OS - XP2, fully updated
Anti mal ware - McAfee, Spy Sweeper, AVG (Ewido), Spybot, Ad aware SE w/vx cleaner, cwshredder, and some clean up programs. I had spyguard and spyblaster, but wiped it when I didn't know what the problem was. All updated!
ISP - Verizon DSL


Logfile of HijackThis v1.99.1
Scan saved at 3:57:14 AM, on 1/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [readericon] "C:\Program Files\Digital Media Reader\readericon45G.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] "C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" /startup
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [VirusScan Online] "C:\Program Files\McAfee.com\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1166463282187
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe
O23 - Service: STW - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\STW.exe (file missing)
O23 - Service: SZYRV - Unknown owner - C:\DOCUME~1\ADMINI~1.LEA\LOCALS~1\Temp\SZYRV.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe



I tried wiping this off the registry in safe mode, ran programs in safe mode, and the carp** is still there. I tried fixing a few entries in hijack this (R1 and R0) which seemed strange, but they won't fix. :scratch:
An 016 entry looks kind of strange too.

Question: Why is there two of these entries?: C:\WINDOWS\System32\svchost.exe

What next?

Thanks

Joey0101
Welcome to the forum.

Those entries are OK and supposed to be there.

————————-

These show "file missing", do you know what they're for and do you use them?

O23 - Service: STW - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\STW.exe (file missing)

O23 - Service: SZYRV - Unknown owner - C:\DOCUME~1\ADMINI~1.LEA\LOCALS~1\Temp\SZYRV.exe (file missing)

———————-

I tried wiping this off the registry in safe mode, ran programs in safe mode, and the carp** is still there.

You have Spybot, Spyware Blaster and SpywareGuard installed.

——————–

I tried fixing a few entries in hijack this (R1 and R0) which seemed strange, but they won't fix.

You have to disable Spybot first and maybe some of the other malware programs.

——————–

An 016 entry looks kind of strange too.

They look OK to me.

———————–

Question: Why is there two of these entries?: C:\WINDOWS\System32\svchost.exe

That's OK - see link:
http://windowsxp.mvps.org/svchost.htm

Let me know , MrC

Welcome to the forum.

Those entries are OK and supposed to be there.

————————-

These show "file missing", do you know what they're for and do you use them?

O23 - Service: STW - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\STW.exe (file missing)

O23 - Service: SZYRV - Unknown owner - C:\DOCUME~1\ADMINI~1.LEA\LOCALS~1\Temp\SZYRV.exe (file missing)

———————-

I tried wiping this off the registry in safe mode, ran programs in safe mode, and the carp** is still there.

You have Spybot, Spyware Blaster and SpywareGuard installed.

——————–

I tried fixing a few entries in hijack this (R1 and R0) which seemed strange, but they won't fix.

You have to disable Spybot first and maybe some of the other malware programs.

——————–

An 016 entry looks kind of strange too.

They look OK to me.

———————–

Question: Why is there two of these entries?: C:\WINDOWS\System32\svchost.exe

That's OK - see link:
http://windowsxp.mvps.org/svchost.htm

Let me know , MrC





Hi here MrC

"These show "file missing", do you know what they're for and do you use them?

O23 - Service: STW - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\STW.exe (file missing)

O23 - Service: SZYRV - Unknown owner - C:\DOCUME~1\ADMINI~1.LEA\LOCALS~1\Temp\SZYRV.exe (file missing)"

I have no idea what they are for. I wait for further instructions from you for removal. I will disable spybot and others then try to fix the R0 and R1 items. I'll get back to you with those results. 016 looks good to you, so I will leave it alone.

I think I understand that to fix 023, I need to wipe those items in the registry also. "To Remove from XP, enter: sc delete servicename in run. Delete the service. Delete the service using hijack this." This is what I have in my hijackthis notes from my studies. (I am studying with tech support, and was dying to get this type of "carp**" on my machine, to get experience on removal, lol. I didn't go to them because I am a little embarrassed.

Thanks,
joey0101

Enable hidden files:
Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK" (reverse this procedure when we are done)


Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
STW

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

Do the same for SZYRV

————————

Open HijackThis. Click on 'Open the miscellaneous tools section'
Click on 'Delete an NT Service'
Paste in this:

STW

and click 'OK'

same for SZYRV

Close HijackThis.

—————-

Delete these files if found:

C:\DOCUME~1\Owner\LOCALS~1\Temp\STW.exe

C:\DOCUME~1\ADMINI~1.LEA\LOCALS~1\Temp\SZYRV.exe

———————
Have HJT fix these if still present:

O23 - Service: STW - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\STW.exe (file missing)

O23 - Service: SZYRV - Unknown owner - C:\DOCUME~1\ADMINI~1.LEA\LOCALS~1\Temp\SZYRV.exe (file missing)"

Let me know, MrC
Hi There, "Go to Start->Run and type "Services.msc" (without quotes) then hit Ok Scroll down and find the service called: STW When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps. Do the same for SZYRV" I find the "stop" buttons in the windows, STW and SZYRV, under services to be grayed out. Only the start button is not grayed out. I assumed that this was because the items were already stopped, some how. So I went to highjackthis, "Open HijackThis. Click on 'Open the miscellaneous tools section' Click on 'Delete an NT Service' Paste in this: STW and click 'OK' same for SZYRV", and that wouldn't work because of not being able to "stop" these 2 items. :scratch: I have the hidden items unhidden. What's next? joey0101

Hi There,

"Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
STW

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

Do the same for SZYRV"

I find the "stop" buttons in the windows, STW and SZYRV, under services to be grayed out. Only the start button is not grayed out. I assumed that this was because the items were already stopped, some how. So I went to highjackthis,

"Open HijackThis. Click on 'Open the miscellaneous tools section'
Click on 'Delete an NT Service'
Paste in this:

STW

and click 'OK'

same for SZYRV",

and that wouldn't work because of not being able to "stop" these 2 items. :scratch:

I have the hidden items unhidden.

What's next?

joey0101



One other thing, I couldn't have tea timer with spybot, and I am not sure how to disable it altogether. I can disable spy sweeper, AVG, and mcafee.
Can you just fix them with HJT?

Try this:

Go to Start > Run and paste these commands into the open field hitting OK after each:

sc stop SZYRV
sc delete SZYRV
sc stop STW
sc delete STW

————————-

If that doesn't work……….

Download: Registry Search Tool from this link (it's about 2/3s the way down the page)
http://billsway.com/vbspage/

Unzip and double-click "RegSrch.vbs"
Note: if your Antivirus or another program prompts about running a ".vbs" file, allow the script to run

In the open field copy and paste the below in bold then hit OK

STW

Do the same for SZYRV

Post the results for both back here.

———-

Please disable TeaTimer by opening Spybot SD and on the left menu choose Tools and then Resident. In the right hand pane you will see a check box for TeaTimer and for SDHelper . Please uncheck both boxes and then close Spybot. You can reinstate it later but we don't want it interfering with what we need to do. Reboot when done

————–

Let me know, MrC
Hi There, and Happy New Year :D ,

I did as instructed:

"Try this:

Go to Start > Run and paste these commands into the open field hitting OK after each:

sc stop SZYRV
sc delete SZYRV
sc stop STW
sc delete STW".

I then went to hijackthis and ran the "Delete an NT Service". The commands resulted in "not found in registry".

I have run RegSrch.vbs. and could only get a report on STW. When running for SZYRV, I recieved no report, but did get a conformation window that reads: "Search cocmpleted in 19 seconds. No instances of 'SZYRV' found. ok." (which I did 2 times because of no report)

I checked registry and find that the route to the problem, which seems to have use to lay under 'domains' is gone. :thumbup:

EXCELLENT!

Where are the learning pages in this site?

IE Log:

Logfile of HijackThis v1.99.1
Scan saved at 4:43:15 PM, on 1/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [readericon] "C:\Program Files\Digital Media Reader\readericon45G.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] "C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" /startup
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [VirusScan Online] "C:\Program Files\McAfee.com\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1166463282187
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

RegSrch.vbs © Bill James log:

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "STW" 1/1/2007 4:17:46 PM

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3DAB30ED-8132-40bf-A8BA-7B5057F0CD10}\ProgID]
@="Neptune.JustWorks.AutoDiscovery.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3DAB30ED-8132-40bf-A8BA-7B5057F0CD10}\VersionIndependentProgID]
@="Neptune.JustWorks.AutoDiscovery"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{78F52D5C-EE63-4812-82B4-C1E4A4D80DF9}]
@="MPSTwainCamera Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{78F52D5C-EE63-4812-82B4-C1E4A4D80DF9}\ProgID]
@="GetActivityPanes.MPSTwainCamera.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{78F52D5C-EE63-4812-82B4-C1E4A4D80DF9}\VersionIndependentProgID]
@="GetActivityPanes.MPSTwainCamera"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7EC1D817-D9DC-42FA-9F66-BFF68659E97C}]
@="MPSTWAINDeviceManager Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7EC1D817-D9DC-42FA-9F66-BFF68659E97C}\ProgID]
@="SupportTWAIN.MPSTWAINDeviceManager.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7EC1D817-D9DC-42FA-9F66-BFF68659E97C}\VersionIndependentProgID]
@="SupportTWAIN.MPSTWAINDeviceManager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GetActivityPanes.MPSTwainCamera]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GetActivityPanes.MPSTwainCamera]
@="MPSTwainCamera Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GetActivityPanes.MPSTwainCamera\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GetActivityPanes.MPSTwainCamera\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GetActivityPanes.MPSTwainCamera\CurVer]
@="GetActivityPanes.MPSTwainCamera.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GetActivityPanes.MPSTwainCamera.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GetActivityPanes.MPSTwainCamera.1]
@="MPSTwainCamera Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GetActivityPanes.MPSTwainCamera.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{013A9507-76E2-46A9-9123-B2E7A34081A4}]
@="IMPSTWAINNotification"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{349CBB45-2E5A-4822-8E4A-A75555A186F7}]
@="IITPlaylistWindow"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Neptune.JustWorks.AutoDiscovery]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Neptune.JustWorks.AutoDiscovery\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Neptune.JustWorks.AutoDiscovery\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Neptune.JustWorks.AutoDiscovery\CurVer]
@="Neptune.JustWorks.AutoDiscovery.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Neptune.JustWorks.AutoDiscovery.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Neptune.JustWorks.AutoDiscovery.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SupportTWAIN.MPSTWAINDeviceManager]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SupportTWAIN.MPSTWAINDeviceManager]
@="MPSTWAINDeviceManager Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SupportTWAIN.MPSTWAINDeviceManager\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SupportTWAIN.MPSTWAINDeviceManager\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SupportTWAIN.MPSTWAINDeviceManager\CurVer]
@="SupportTWAIN.MPSTWAINDeviceManager.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SupportTWAIN.MPSTWAINDeviceManager.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SupportTWAIN.MPSTWAINDeviceManager.1]
@="MPSTWAINDeviceManager Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SupportTWAIN.MPSTWAINDeviceManager.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\RegWiz\Installer]
"RegWizLog#047"="Show Post WOW : TRUE. —- Goto : postwel.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\Subscriptions\{EEFFC993-813A-4A0E-A394-2AA3AE485781}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}]
"MethodName"="RequestWriterInfo"

"URTM_STD_ENU_X86_IXP"="aZO,H*K2`Ee8MkbIdFwU!{NsuoCmf=44=j4p3XlX$WJ'HdC-g?is~rZ3+5{5@Md^v2=d,=ML%i]bR7$jQo=5CHk?O@*8FD6r.[HiA@KOh(5fd9]})wGdP-H+L.JhO2v?W@%fvc@9YSrTOSG2FA*kl?=aY-S93Y[&JZ+(rL}iF=N$!OUVcNW'foy91^qt[@7-apU5=1cGrV,.lh87AA)N'5b2S7rU%}}64`+,E?S(sMBY[U~EQnynx9OH(AzYPFybsoeVDIPKPpCN{9N}b7P14U5O1n^&?ri`+A_pnPWY,!WjbF$'`3EVn@7Rqu7Eu$X?!$.-(}AkdA=BL*0)'4mei]}7fPZU)={{?fTrt0PwF&gW4t'Sn?zQ_5wVgW].gO?vU6B_Q?pOeAIi3@7xOA4k6n2wE@L{-se+75F'e8ACh8tW&?WO^`tl-9=xXS.4v6=yV?1t$'xTRA_7W,qzl'')*=onPqgVjtEkb*q'C,3]i@xb$O&,-qlXF~lE2@-oz@%$-((~eMC@(l0$d+IA1@PwkJ6Ac9gzP}$'ZNK5q@.^L^!_b^KTFQ'7On,5}9Cj(MC03k+szK~oio1{t8PhTKlh*[F7c{[uLO[IHAX5=XrAu{b?^S_T-dqji9(OAHJ@f*N'Qanodq{gS@LE?UmjgLNG]g3.T(-N%9NUiHn)uXN1?$kMW)8i59EQt,YDIDWqDYkJbT,)b9A!]Y+^.rrbI'tRr.L0x?3LhZ_=[8PM*MLLuG_,eAoziS%4D^Wo`fUl7{GTe@edzr09_F8x+ZOc2P^fV=h!dBi=)^V47v_([$+qD?^]xkMSfvQT(HUiXuPHl9tG*_hI~FdQ{IUZ!dzG7AHOfD4{&3*37EFmH)29S9G}vsKbK0pTE[LRF*n6p@a[`Hk-785(QB3%S}Rfc=&UMSC!7`Q2I6X-tXB~'?wk'bxAIm(PX!g7]~`&x@9PDD&7{Q.uJe^03Gi)dA^j+KatnX-vUaV!f&dfB?v8?jGmhqoc*Lvfk0pE4@gmc'sH8dTWJkrjs*Kk2?xb@e.^EupyKul'pbF_K9W,KL=$g8_3?Y!GRzx?VALDt}hGeSuyQkl_j^e4[AP%@Mvp}-&(.(S&Q@~9~=M^kgn'+k71JKwHb-.}v8^~NZLfx@3A2@mkJ{44-AUCH6n,l.iQB1Mz%qYwi8rPcC,4J8rj52d?H`(Gp@qM{'U`soUG([Nl_X=SY=gfveog7B^S{dY!XdlNr@BOtP8E*(?CC*]p(zuGP9E3l*E~1J_)5_u&')1`_@xb83BJ~g~cH%z$cL3s[=ldHJfAxS&5JPEY1RojQ?JuO?Q(9)=={y'g2Vqs&9kI*DBfgAQQ]]J+$eqc_=6[xdeFyWGoB=P%Qt+nT=%Uxvq`AW-)-c(t^@nS[=I)n[O=ztkeZ@}w(@VPI?`qL6*SzZ+a~W9WDi^Q{=ID]bO2iv,gG$nriB?xH=u[x(=%oaD0PU*Fi.=C~?kRFlx6(IG'snIC%dvYN=VOH~.yh+{U'um07?S&j=lB{Y4o$w}3`=zZjcvhbAvV8g,jhVxR]FHsUdVih?}.=G7,NY]^JC41TeL&B9fosOhOa_mpQNAr6_rmf?0u6@fpfZ=BFfSQkV^]Y?+JV118Ae!tbIA~2f9FSA?{F1JVkjrt{ALm8N1i5A09&609)952D+ELEg1.MA@TQE83aMsl&1ImY!yL3?Xer}b=MCS=Vh3qm}L1g@,n}BcyA'CX4KBN9L$0G=u7R=Apz!x'hZadS4een?I]F&'qBVQeGT1Pw(tys?V.-6BJe.i`}j.&?PA869(J`N![removed]!a=.'=*q~[g^MfcSM3JIDN?MG94^gbyZs`mK[jxb]}u+ZA43[(@G}KVz[TmumPRJQ=hQHjQA.SW_JTc8F-YnI9-+xs*kKUO3fLxJYe4K[=ti5y0U4E4g813H44`U!9AXpvoV+DMp{3nk&CREs=`kdK&zJWKM08c$C=u+s?4w*tFWfK_dS9OcaIFYv@Qvs`.jM'+HHKL3C5tex@4]MF_.DJGqcm-I4eZ6f=W`-[P1NE`NaZEnq9x)v9z4@H!U2BI(s!Ph=PZ(z85-rN8{q1,`cv(?Zt+iH9^7cqxqIHJX{xGeB-}cz?{iG!Ey_I5.+,4-{!CuVAiFCDGLjhii]c2g_BvQz=v[11hO`0-C^RpU_f{}@9LrN&jYAGMCR,e?K3Fj&=!@U`@vtcB]pC46JlCv?AoW?)HP{Ts]5L{6EyJ-$A0(iGpR!J0jL])PeTrG2AKgNNi4GvcBhh`6EI]vU=eNP]I))&-5}~%PNXp+Z9kUK_n-EK%*FOXO*vD*g(HTy?VXB]2d}_$qtaJ0t@xe)vC?P5yV^$795CtDZ87Tt'.i@YAVR(,^JR..v@X=ojiAFKF=i]0G.'^?g(Z1z?VXB]2d_]-+!jVx9=N2SvY6Rjdzv&%m5si&B9MtlUz=Ch2Vq&ov3Hcf^9AQ2[e2VKx31I`W5MMaq8*g5`,$4c'Qe4^gIuIua8W1)TUQ1PQpcE^cf$5Kt?]+a78qC%[Ft%6kBd('L9lQY7AQ_!_XRnj6T2RTY=%-OV?DBHCf}x,o_-dUT=.euyhbHIUC[s+I!zdUt9?u5ND4Lhs?&!%Aei5%i8GuctV{`c=b&aXoe@&f~=~2(0T`1P,q`%Jysycp$AWg6ERmTW)$ksMnFXbNW9@'AcRo[1)gm%^T+.Xfv@Y[x6H`]R8`$+iYURi4FAx`=S_35pzd4hf4!zPH5=R8J,dHa({Qvcl]*Iq1g(Svy?VXB]2ds!fA%2J3z?iiec!1z)h]aKcj%E?zx?7xbNQ7OO'GwWYWdKnVW?oh?_N+y+'Z*2HZMA5pV@J%YrASJjl`&9IT8!TgR?}9NP8z&tG*0kY@S2'U]8]+j-]IYwxL.?FA3Kd~P?WcNOJa.rORQ+IBD(mA!A6$Iw.484)J4-`)E3wu=91Q=kgS__+ZkV^B7PVM9=moUkB~4zIHBc~HMt@*^8q^P^Y@!GkgTnC,l?Ij9AA2eC6fL($v2},H*sMh&@as0PH.NMpHAOEhsGp8r8zQgGcdnD4bz_w=ovJ.t@3]]3q(,6wM5$*K,le6w=i8ecaf6nRv11v&zWK~Q?nE)Mfx~q-gx~L@yt2nh=1g0nQ($iP$*U)^q74=TAf,F~jL~0z1y,5,Y]c18AK`5m+sc1g9Q4^YB*28r=FRh]GGt{R)6'XBY}tnK?h~Rh*?)y,jZ7`9$3nUu=Z@9?%yw(.L_X=yV7M94@Rs^*a{[.=++H&x5yOc2A9f2rJNZ]!Kj!F,a%mR`?V0oI3dk`o8XK!ZVMKe!?(Fe*LUQ&nVYL..jc}YU9UP2Cf$_8QCPCWxJ^eij9xoQwV}krKe)!OXfKcRaA)gIF-(f$=s-7h!_!dS39[@VhYlrhL)O.BKod8`SA-c,JF0cEPAhZ?6{'n*~8.e@RbY-?@^{K^IYn3?Z@b`Bn(P2O%p.[I.l{l,k9A+()ARN%q&N(t4fz^_+=*qa5Wylv1QL1kEz,4-E@KtOwML$BBZnwr.-N)YNA!%cqbhI{hh_HR+4e^'b8XCj1*vqFW'jA%NOQlxIA1o4IXw@[0Uv42_$[yPr?1,QYE%N))&u}.p)}RkA97O%LLI7=vyX51Ml[}ty?X^gZ'}!$9%Yo`J)EN%l?I!%_f2i5gZ=Lm3bEGH=AvNGB5nU{%e-riPmXJNq@,'f=AHw7ECkwDdNbP%s9fBd4n9nmxKhVSGN3x!297GkFLCQg6F1z=rmy?*y@CiP8qEsRZry^Zt)F_^4=}oyob3V.aATaC$DF.C4?]~jTQRVs.J@_{2qO4+59hcU2[zsSPSVoc^'HCf2@iHoKq@dFWPk^]T6~uLc84J{bQu.O9`i=keai('89SCL+7fa!@z_NGhOvdP2=X.X1&cwBfq9!]c@q-Uv9]jN^0_dcWy&vS_SOn*K9l*f,7v!IxWrx2sikfmZ=^R[8nVn1H%2==SJfa?}=vx)IU1gNl+Shs{]{EVd=G5SnG3}p26}3@NjTPjk8Hj`kM17%wEpByQpA?le8i@WtW[Ab0[O3)iF1TN`=[nt@.3W=Pj'nKY8aJ{{=-dokb*`kbNvru[kaiDI?pCT(RPb&l!Jr3PZP{b=?Fgg^RLB(oZuLHDh&r*q=0,1gA}SujU8E8!'47w(=u+&99=^vNA'5WCz3(_U@uF0qj8+Jgh=[%R+[]1e@Y@ZneH`kfw6$t8.[_8i8IVucW_XKtRQ!b*$jC1^A{8MEP7IlQYbfnI^'Krm@Im($wvV}BwV6693X.12?w@rP]`Okz(M~_2(G2LP@=,OO^dwHsZH]Wmb_y=j=5U(2GNw~)(-KQYh,S54?=[y}&STw]=!}8Ek]+2{=*k=L+O{ezQA*d0`!UGZA}D3$kdR==ObP^X2~)Sw8$OXktzpKRBw&uag$yhR=A4}9XEtPCtEiqyM`UpX=Qcgdte4PVSr`pYQQPb)AD%9A)g2DLs)&Q!olKfD?.l.Zh~pzh`iNOkvsp8H@vERMmqfNJ[0acd0Sh4K=jQ0Foh5VouBX(+Bx%`DA%Pn`cwzS0Av1'Mr2pak=Yyt`i[6D&yCcrN@u^yx8*?-Ej!*hUl6zD$)a]L$?x}$H]mFv38@&MtTZ_bm@ahTf[CM$9hW}nm`Y*!b@][X.uPveyqnetAOF4tJ9~QDAy93'bm'LUzm8RW{=[F7)5Jfptt9WC8nemgF=QZDnSB~Q9?(Ln?99$z-?s3Nr[cl&8DbVh`pM_Y19kqHtLeC{pQ~KaQLdOF]9!x'Tn*mjB8q8lU7ew,g(Lay?VXB]2dwvjXn*6.g(Ojy?VXB]2dtvjXn*6.g(Ojy?VXB]2da$tytNY2g(Svy?VXB]2d_j0,Y]s!So*9MkbIdFwU_j0,Y]s!Soe8MkbIdFwU_j0,Y]s!Sou8MkbIdFwU%9YbWIfIbe?9MkbIdFwUaZO,H*K2`E*9MkbIdFwUs&$6xuz5,@BaM?(.Na)N[JzDwE4j!@h7^P=dyurJl%&(W7aj)9o0Oj9dd0,BAcrnX}{b4?6D.%`6M{8KuW_^YapJ&?0DKhKWKmQo_g^mo7,my@oqZ_yiM!f&*FneAbIH99bv_Y3Tp6&l.%zzF`h_b9+$AMh9yhY`x)rAZTkpo9u!-Gb}$QWP,RBTTu50'@_[U&MV?+)y{I_G.T{G7?gT1[k~EgOEB]MzKk`@9=0O_8U)(7&E`Z?C$rK'6?~~9*[?YG4`xtl5a^]n9?&!Or0lC_A]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WPAEvents]
"LastWPAEventLogged"=hex:d4,07,08,00,04,00,1a,00,0b,00,09,00,1d,00,dd,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Parameters\Ipx]
"FirstWanNet"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Parameters\Ipx]
"LastWanNet"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_STW]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_STW\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_STW\0000]
"Service"="STW"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_STW\0000]
"DeviceDesc"="STW"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RemoteAccess\Parameters\Ipx]
"FirstWanNet"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RemoteAccess\Parameters\Ipx]
"LastWanNet"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\STW]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\STW]
"DisplayName"="STW"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\STW\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ipx]
"FirstWanNet"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ipx]
"LastWanNet"=dword:00000000

[HKEY_USERS\.DEFAULT\Control Panel\International]
"iFirstWeekOfYear"="0"

[HKEY_USERS\S-1-5-19\Control Panel\International]
"iFirstWeekOfYear"="0"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestweblinks.com]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestworldgirls-for-u.net]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestworldgirls-for-u.net\www]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fastwebfinder.com]

[HKEY_USERS\S-1-5-20\Control Panel\International]
"iFirstWeekOfYear"="0"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestweblinks.com]

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestworldgirls-for-u.net]

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestworldgirls-for-u.net\www]

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fastwebfinder.com]

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Control Panel\International]
"iFirstWeekOfYear"="0"

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Software\Microsoft\MediaPlayer\Player\Tasks\NowPlaying]
"PlaylistWidth"=dword:000000ba

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"f"="sc stop STW\\1"

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"g"="sc delete STW\\1"

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestwaycum.com]

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestweblinks.com]

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestwebslinks.com]

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestworldgirls-for-u.net]

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestworldgirls-for-u.net\www]

[HKEY_USERS\S-1-5-21-1396001555-1180733485-2266813057-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fastwebfinder.com]

[HKEY_USERS\S-1-5-18\Control Panel\International]
"iFirstWeekOfYear"="0"

I think I understand what happened when I ran this program. It wiped all that junk from under 'domains'. Cool Tool!


Thanks for he help and lessons. Looking forward to hearing from you again for confirmation and any other advice.

joey0101 B)
Where are the learning pages in this site?
Classroom
——————-
The HJT log looks OK
———————-
I checked registry and find that the route to the problem, which seems to have use to lay under 'domains' is gone.
I think I understand what happened when I ran this program. It wiped all that junk from under 'domains'. Cool Tool!


Those "names under this key are suppose to be there - they are put there by Spybot and SpywareBlaster.
The search tool doesn't delete anything - it just searches.

———————-

Copy the text in blue into notepad and save it as fix.reg
save it as type "all files"
save it to your desktop
now double click on it and allow it to merge into the registry.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\STW]


MrC
Hello again,

I did what you suggested with the copy to note pad and then merged it in registry. I also took a peek into the classroom link that you so generously provided to me.

I am having a problem connecting to bleepingcomputer.com in both browsers. IE 7 takes me to google first, then to the “IE cannot display this web page”. Firefox is "unable to connect". I was wondering if they were having a problem or was my machine still experiencing a problem.

Also, when I try to connect to www.techsupport.com, I am redirected to http://www.arrow.com/, when using firefox. IE takes me to the proper site, no problem.

Google searches are taking a long time too.

Partial hijackthis log:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll

The entries in color are the entries I question, and don’t know how to find information on. (I can’t use the bleepingcomputer site, which is where I was studing.)

This red entry say something about “search bar”, I don’t have a google search bar, unless the little address entry bar is considered so.

The purple entries here are Microsoft search pages, and the only way I can think they got there is perhaps the use of spyblaster and the other like programs.

The green entries look like they go with the red entry, which all end in “www.google.com/ie.”

The violet entry is my firefox, I believe, and I think it is a safe popup blocker for that browser. (sysinfo.org)

After careful examining the rest of the log, I don’t have any other questions as the reason why my browsers seem to be hijacked, except here.
Any thoughts on what may be causing this redirecting?


Thanks

Joey0101
All those "R" entries are OK
The 02 is a pop-up blocker - OK

—————————–

Here's three links to the HJT tutorial:

http://www.castlecops.com/HijackThis.html

http://www.aumha.org/a/hjttutor.php

http://www.pchell.com/support/hijackthistutorial.shtml

—————————-

What ever you don't want have HJT fix - you'll have to disable the malware programs to make any changes.

I already gave you Spybot

The link below has more:
http://wiki.castlecops.com/Malware_Removal…toring_Programs

————–

I don't use IE7 because of all the problems with it.

To put things back to default……

Open up Internet Explorer , Tools, General Tab, reset your home page to what you want, now the Programs Tab, click Reset Web Settings
That will change everything back to the default settings.

MrC

Can I close this post now??

Please let me know, MrC





Hi mrC,

I am still having problems with the browsers. I am reading up on it, and trying things. If I need more help, I will contact you, but in a new thread or this one

Thanks a lot!

joey0101
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI