This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

180 Solutions and 2nd Thought

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have recently installed AdsGone Spyware and Popup Blocker and have run scans with it now about five times. Each time it detects registry threats from 180 Solutions and 2nd Thought. I clean and quarantine them each time and rescan till nothing shows. The next time I run a scan they are there again. Spybot does not detect them and my NOD 32 does not show any detection. I had issues with 180 Solutions in the past and thought I had rid myself of it. I have run HJT and attached is the log. Any help would be appreciated.



Logfile of HijackThis v1.99.1
Scan saved at 1:17:31 PM, on 1/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = https://login.yahoo.com/config/mail?.intl=us
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: PPCScamBHO Class - {7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AdsGone] C:\Program Files\AdsGone\AdsGone.exe -s
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .TIF: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service (CFSvcs) - Unknown owner - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (file missing)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Just to update, I have downloaded and ran Adaware and Spyhunter. Neither have found the 180Solutions or 2nd Thought entries but AdsGone continues to find them. This is driving me crazy. Anyone with any ideas? Thanks
Hello and welcome to the forums

Download DelDomains.inf
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click and select….. Save Target As….Save

To use: Right-click and select……. Install (no need to restart)
**Note** This will remove all entries in the "Trusted Zone"

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download AVG Anti-Spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select " "Quarantine" .".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the
    results of the AVG Anti-Spyware report scan along with a new HijackThis log.
Please use the [external image: Posted Image] Button below to reply.
The AVG Spyware report

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:04:41 PM 1/17/2007

+ Scan result:



C:\WINDOWS\system32\gtdownls_95.ocx -> Adware.Gdown : Cleaned with backup (quarantined).
C:\Documents and Settings\Seatrek\My Documents\My Received Files\NOD32.rar/NOD32\patch.rar/patch1.exe -> Trojan.Agent.vw : Cleaned with backup (quarantined).


::Report end


The new HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 11:17:03 PM, on 1/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
https://login.yahoo.com/config/mail?.intl=us
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper -
{02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
- C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection -
{4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program
Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -
C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} -
(no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe"
/WAITSERVICE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] C:\Program Files\AdsGone\AdsGone.exe -s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG
Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: SpywareGuard.lnk = C:\Program
Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program
Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program
Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} -
C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell -
{0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program
Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} -
C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options -
{1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program
Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} -
(no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .TIF: C:\Program Files\Internet
Explorer\PLUGINS\npqtplugin5.dll
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should
be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should
be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should
be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should
be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should
be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object)
-
http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine
Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content
Update) - http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class)
-
http://photos.msn.com/resources/neutral/co…X2.cab?10,0,910,
0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 -
HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A
}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner -
C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program
Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner -
C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. -
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - Unknown owner - C:\Program
Files\TOSHIBA\ConfigFree\CFSvcs.exe (file missing)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program
Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co.,
Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. -
C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP
Pro 3\Tools\NMSAccess.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program
Files\Eset\nod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown
owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Thanks for the help. I am running Spybot, Spyguard, Spyblaster, NOD 32 Anti-Virus and AdsGone Spyware and Pop-Up blocker and this stuff still got on the computer. Appreciate the review of the HJT Log. All items have been completed as per your instructions.
I suggest you do this:



With AVG Anti-Spyware, if you click on the Infections icon, then it will show you all the items in Quarrantine and you can remove them that way. Just click Select All (if all of the items in quarrantine need removing) then Remove Finally


Please do not delete anything unless instructed to.



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R3 - Default URLSearchHook is missing
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should
be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should
be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should
be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should
be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should
be Internet Zone (HKLM)
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -

Close ALL windows and browsers except HijackThis and click "Fix checked"



Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


Please use the [external image: Posted Image] Button below to reply.
Followed all of your instructions. the following is the HJT log


Logfile of HijackThis v1.99.1
Scan saved at 9:09:26 PM, on 1/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = https://login.yahoo.com/config/mail?.intl=us
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] C:\Program Files\AdsGone\AdsGone.exe -s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .TIF: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ConfigFree Service (CFSvcs) - Unknown owner - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (file missing)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

After completeing all of your instructions I ran HJT to get this report. Also ran AdsGone again and the four infected files show up again. They are
180solutions software\microsoft\ internet explorer\urlsearchhooks
180solutions software vb and vba program settings
2ndThought Software\Microsoft\Windows\Current Version\Internet Settings
2ndThought Software\Microsoft\Windows\Current Version\Internet Settings
I check the boxes and click to remove then run the scan again and nothing shows up. The next time I boot up th computer and run the AdsGone scan they are back again. Other that that the computer seems to run fine. The above is all of the information AdsGone gives me.
we need to fix those 015's

Download: ResetProtocolDefaults.reg
http://www.mvps.org/winhelp2002/ResetProtocolDefaults.reg

Locate "ResetProtocolDefaults.reg"
Right-click and select: Merge (Ok the prompt)

Post a new HJT log.
Will download as you instructed and post back. As further info here is the AdsGone log that might provide you with more info "SOFTWARE\Microsoft\DownloadManager, Found , 1/15/2007 6:08:24 PM" "aspfile\persistenthandler, Found , 1/15/2007 6:08:26 PM" "software\microsoft\mediaplayer\control\playbar, Found , 1/15/2007 6:08:27 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 6:08:29 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 6:08:29 PM" "software\vb and vba program settings, Found , 1/15/2007 6:08:29 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 6:08:30 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 6:08:30 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/15/2007 6:08:31 PM" "software\microsoft\internet explorer\menuext\&download with &dap, Found , 1/15/2007 6:08:32 PM" "software\classes\anigifctrl.anigif\insertable, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002}, Found , 1/15/2007 6:08:32 PM" "software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000}, Found , 1/15/2007 6:08:32 PM" "software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 6:08:32 PM" "software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM" "software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9}, Found , 1/15/2007 6:08:32 PM" "software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 6:08:32 PM" "software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9}, Found , 1/15/2007 6:08:32 PM" "software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM" "software\speedbit, Found , 1/15/2007 6:08:32 PM" "software\speedbit, Found , 1/15/2007 6:08:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/15/2007 6:08:44 PM" "software\microsoft\windows\currentversion\moduleusage\, Found , 1/15/2007 6:08:48 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/15/2007 6:08:48 PM" "SOFTWARE\Microsoft\DownloadManager, Found , 1/15/2007 7:49:56 PM" "aspfile\persistenthandler, Found , 1/15/2007 7:49:59 PM" "software\microsoft\mediaplayer\control\playbar, Found , 1/15/2007 7:50:01 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 7:50:05 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 7:50:05 PM" "software\vb and vba program settings, Found , 1/15/2007 7:50:05 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 7:50:08 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 7:50:08 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/15/2007 7:50:09 PM" "software\microsoft\internet explorer\menuext\&download with &dap, Found , 1/15/2007 7:50:11 PM" "software\classes\anigifctrl.anigif\insertable, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002}, Found , 1/15/2007 7:50:11 PM" "software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000}, Found , 1/15/2007 7:50:11 PM" "software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 7:50:11 PM" "software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM" "software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9}, Found , 1/15/2007 7:50:11 PM" "software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 7:50:11 PM" "software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9}, Found , 1/15/2007 7:50:11 PM" "software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM" "software\speedbit, Found , 1/15/2007 7:50:11 PM" "software\speedbit, Found , 1/15/2007 7:50:11 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/15/2007 7:50:23 PM" "software\microsoft\windows\currentversion\moduleusage\, Found , 1/15/2007 7:50:27 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/15/2007 7:50:27 PM" "SOFTWARE\Microsoft\DownloadManager, Found , 1/15/2007 8:03:02 PM" "aspfile\persistenthandler, Found , 1/15/2007 8:03:05 PM" "software\microsoft\mediaplayer\control\playbar, Found , 1/15/2007 8:03:06 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 8:03:09 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 8:03:09 PM" "software\vb and vba program settings, Found , 1/15/2007 8:03:09 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 8:03:11 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 8:03:11 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/15/2007 8:03:13 PM" "software\microsoft\internet explorer\menuext\&download with &dap, Found , 1/15/2007 8:03:14 PM" "software\classes\anigifctrl.anigif\insertable, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002}, Found , 1/15/2007 8:03:14 PM" "software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000}, Found , 1/15/2007 8:03:14 PM" "software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 8:03:14 PM" "software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM" "software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9}, Found , 1/15/2007 8:03:14 PM" "software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 8:03:14 PM" "software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9}, Found , 1/15/2007 8:03:14 PM" "software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM" "software\speedbit, Found , 1/15/2007 8:03:14 PM" "software\speedbit, Found , 1/15/2007 8:03:14 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/15/2007 8:03:27 PM" "software\microsoft\windows\currentversion\moduleusage\, Found , 1/15/2007 8:03:31 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/15/2007 8:03:31 PM" "SOFTWARE\Microsoft\DownloadManage, Remove, 1/15/2007 8:03:40 PM" "aspfile\persistenthandle, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\mediaplayer\control\playba, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/15/2007 8:03:40 PM" "software\vb and vba program setting, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\internet explorer\menuext\&download with &da, Remove, 1/15/2007 8:03:40 PM" "software\classes\anigifctrl.anigif\insertabl, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002, Remove, 1/15/2007 8:03:40 PM" "software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000, Remove, 1/15/2007 8:03:40 PM" "software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e, Remove, 1/15/2007 8:03:40 PM" "software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM" "software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9, Remove, 1/15/2007 8:03:40 PM" "software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e, Remove, 1/15/2007 8:03:40 PM" "software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9, Remove, 1/15/2007 8:03:40 PM" "software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM" "software\speedbi, Remove, 1/15/2007 8:03:40 PM" "software\speedbi, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\windows\currentversion\moduleusage, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\windows\currentversion\shareddlls, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 8:05:02 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 8:05:02 PM" "software\speedbit, Found , 1/15/2007 8:05:03 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/15/2007 8:05:26 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/15/2007 8:05:26 PM" "software\speedbi, Remove, 1/15/2007 8:05:26 PM" "software\vb and vba program settings, Found , 1/15/2007 8:06:35 PM" "software\vb and vba program setting, Remove, 1/15/2007 8:07:04 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine15-01-2007-20-03-40.asr, Removed from Quarantined, 1/15/2007 8:11:23 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine15-01-2007-20-05-26.asr, Removed from Quarantined, 1/15/2007 8:11:28 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine15-01-2007-20-07-04.asr, Removed from Quarantined, 1/15/2007 8:11:32 PM" "software\vb and vba program settings, Found , 1/16/2007 12:46:51 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 12:46:54 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 12:46:54 PM" "software\vb and vba program setting, Remove, 1/16/2007 12:48:18 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 12:48:18 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 12:48:18 PM" "aspfile\persistenthandler, Found , 1/16/2007 6:31:05 PM" "software\vb and vba program settings, Found , 1/16/2007 6:31:11 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 6:31:14 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 6:31:14 PM" "aspfile\persistenthandle, Remove, 1/16/2007 7:13:57 PM" "software\vb and vba program setting, Remove, 1/16/2007 7:13:58 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 7:13:58 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 7:13:58 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 7:16:03 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/16/2007 7:16:18 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 7:30:09 PM" "software\microsoft\windows\currentversion\shareddlls, Remove, 1/16/2007 7:30:09 PM" "aspfile\persistenthandler, Found , 1/17/2007 7:14:38 PM" "software\vb and vba program settings, Found , 1/17/2007 7:14:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 7:14:41 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 7:14:41 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/17/2007 7:14:55 PM" "aspfile\persistenthandle, Remove, 1/17/2007 7:40:53 PM" "software\vb and vba program setting, Remove, 1/17/2007 7:40:53 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 7:40:53 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 7:40:53 PM" "software\microsoft\windows\currentversion\shareddlls, Remove, 1/17/2007 7:40:53 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine16-01-2007-12-48-18.asr, Removed from Quarantined, 1/17/2007 8:22:42 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine17-01-2007-19-40-53.asr, Removed from Quarantined, 1/17/2007 8:22:49 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine16-01-2007-19-30-09.asr, Removed from Quarantined, 1/17/2007 8:22:53 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine16-01-2007-19-13-58.asr, Removed from Quarantined, 1/17/2007 8:22:57 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 8:24:49 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 8:24:49 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/17/2007 8:24:50 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 8:33:22 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/17/2007 8:33:22 PM" "software\vb and vba program settings, Found , 1/17/2007 8:34:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 8:34:45 PM" "software\vb and vba program setting, Remove, 1/17/2007 8:35:10 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 8:35:10 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/18/2007 8:51:28 PM" "software\vb and vba program settings, Found , 1/18/2007 8:51:28 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 8:51:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 8:51:32 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine17-01-2007-20-35-10.asr, Removed from Quarantined, 1/18/2007 9:05:24 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine17-01-2007-20-33-22.asr, Removed from Quarantined, 1/18/2007 9:05:30 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/18/2007 9:13:32 PM" "software\vb and vba program settings, Found , 1/18/2007 9:13:33 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 9:13:35 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 9:13:35 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/18/2007 9:20:17 PM" "software\vb and vba program setting, Remove, 1/18/2007 9:20:17 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 9:20:17 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 9:20:17 PM" Thanks again for all of your help. Chuck
Here is the new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 9:46:57 PM, on 1/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = https://login.yahoo.com/config/mail?.intl=us
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] C:\Program Files\AdsGone\AdsGone.exe -s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .TIF: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ConfigFree Service (CFSvcs) - Unknown owner - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (file missing)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Lets see if this will cleanup the registry issues.

Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe



I recommend you download RegSeeker. Extract it to it's own folder, open and double click RegSeeker.exe to start the program. Maximize the window and click clean registry. Check all sections and click OK. When the scan is complete, verify the backup box in lower left corner is checked and click the select all button, then select all again. Then right click within the search results and select delete. Run it again and again, deleting everything it finds until it finds nothing. Reboot and make sure your programs are working properly, control panel and add/remove programs windows open, etc (basically just do a quick check of everything). In the event anything was 'broken', you can open RegSeeker, click backups and double click any/all files to put the information back. A reboot may be required for the effects to be seen. Reboot When done.

NOTE: To be extra safe you can choose to only remove the items in RED.
Some items may come back because of the programs you have running.
OK I have run RegSeeker and cleaned out pretty much everything. I get 8 files that keep showing up over and over as obsolete. Should I continue to try and remove these 8. They don't seem to want to go away. In addition I have run AdsGone again and the 180solutions and 2ndThought entries are still there. They do not show up on AVG or Spybot. Is there maybe something I am missing? Here is the most recent HJT log. Thanks once again.

Logfile of HijackThis v1.99.1
Scan saved at 11:01:39 PM, on 1/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] C:\Program Files\AdsGone\AdsGone.exe -s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I get 8 files that keep showing up

Don't worry about those.

Launch Notepad, and copy/paste all the bold REGEDIT below to it
Don't forget the REGEDIT4
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000


Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.

Lets see if that took care of it.
Not sure if I plan to shoot myself or the computer. Ran the file and it ran OK. Rebooted the computer just for grins. Ran the AdsGone scan and guess what. There they were same as always. Here is the log "software\microsoft\internet explorer\urlsearchhooks, Found , 1/19/2007 4:47:35 PM" "software\vb and vba program settings, Found , 1/19/2007 4:47:35 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 4:47:38 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 4:47:38 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/19/2007 4:48:09 PM" "software\vb and vba program setting, Remove, 1/19/2007 4:48:09 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 4:48:10 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 4:48:10 PM" The top two are 180Solutions and the second two are 2ndThought. :rant2:
Here is a new HJT log


Logfile of HijackThis v1.99.1
Scan saved at 5:04:33 PM, on 1/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] C:\Program Files\AdsGone\AdsGone.exe -s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI