May i please ask for your Windows XP Home help

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • Spalding12
    Junior Member
    • Jan 2006
    • 11

    May i please ask for your Windows XP Home help

    I have a windows XP Home edition machine
    service pack

    all was well until last week...
    when i boot my computer
    it opens the

    C:\WINDOWS\system32

    folder automatically
    if i close it... the icons disappear and the computer locks up
    if i leave it open and just minimize it... the computer works most of the time but freezes intermittently for no apparent reason

    when i first boot a message comes up that there is a suspect SHIELD-TYPE virus found and that i should run my anti-virus software
    i have used McAfeee and Symantec NU and neither can find the virus or problem
    i have gone to MICROSOFT'S site and let their online software try to find the menace to NO avail

    i did a
    start
    run
    services.msc
    ..................
    remote procedure call (RPC)
    and found this line in the "path to executable"

    C:\WINDOWS\system32\svchost -k rpcss

    can anyone please help me
    i really appreciate it a great deal

    thanks in advance
    greg savel
  • Kevin P
    Member
    • Aug 2000
    • 10808

    #2
    Here's a couple more on-line antivirus scanners you can try:

    housecall.trendmicro.com
    www.pandasoftware.com

    Have you run any anti-spyware tools?

    I'd download and run:

    CWShredder

    Ad-Aware SE Personal - after installing, run an update and then do a full scan

    Spybot Search and Destroy - after installing, run an update and then do a full scan

    Hijack This - Download this and unzip to a folder, but do not run it yet, keep reading

    After running the scans, let them clean whatever they can.

    Then, run Hijack This, and tell it to scan and generate a log file. Don't fix anything yet. Open the resulting log file in Notepad, and post it here (copy & paste). I'll look through it and tell you what needs to be removed, and any additional steps that need to be taken.

    BTW, your Remote Procedure Call entry in Services looks fine to me.

    Comment

    • Spalding12
      Junior Member
      • Jan 2006
      • 11

      #3
      Kevin
      how nice of you to respond... i was hoping that you would
      i'm going to get on your ideas right now
      i can't tell you how much i appreciate this

      greg savel

      Comment

      • Spalding12
        Junior Member
        • Jan 2006
        • 11

        #4
        hey kevin

        i ran it all
        and then, of course, that virus came back
        please remember that i did a restore from 2 months ago previous to that and the virus was still in hiding
        then....
        after a few restarts it was back and choking the internet explorer program
        the computer is frozen now
        when i hard restart it.... it immediately opens that windows system32 folder again and it can't be closed with locking up the system

        hmmmmmm
        any thoughts?
        greg

        Comment

        • Spalding12
          Junior Member
          • Jan 2006
          • 11

          #5
          here is the logfile

          netscape is working better than IE, if that means anything

          here is the logfile

          Logfile of HijackThis v1.99.1
          Scan saved at 12:20:58 PM, on 2/25/2006
          Platform: Windows XP SP1 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\brsvc01a.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\System32\brss01a.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\eMachines Bay Reader\shwiconem.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
          C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\System32\HDAudPropShortcut.exe
          C:\WINDOWS\zHotkey.exe
          C:\Program Files\Common Files\AOL\1140883202\ee\services\sscAntiSpywarePlu gin\ver1_10_3_1\AOLSP Scheduler.exe
          C:\Program Files\mcafee.com\antivirus\oasclnt.exe
          C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
          C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
          C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
          C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\aolavupd.exe
          C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
          C:\Program Files\mcafee.com\personal firewall\MPFService.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\SSCEvtHdlr.exe
          C:\Program Files\Common Files\AOL\1140883202\ee\aolsoftware.exe
          C:\Program Files\Netscape\Netscape\Netscp.exe
          C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/yco...search/ie.html
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com
          R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
          N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csea rchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\29zvdzey.slt\prefs.j s)
          O1 - Hosts: 202.67.220.230 win.mail.ru
          O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
          O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0. dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
          O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\java\trustlib\dllms.dll
          O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
          O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0. dll
          O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1140883202\ee\AOLSoftware.exe
          O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
          O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
          O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
          O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
          O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
          O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
          O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
          O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1140883202\ee\services\sscAntiSpywarePlu gin\ver1_10_3_1\AOLSP Scheduler.exe
          O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\SSCRun.exe
          O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
          O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
          O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
          O4 - HKLM\..\RunOnce: [Run IPH] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
          O4 - HKCU\..\Run: [WinFixer2006] "C:\Program Files\WinFixer_2006\uwfx6.exe" /scan
          O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
          O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm408YYUS
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
          O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
          O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
          O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
          O14 - IERESET.INF: START_PAGE_URL=http://www.gateway.com
          O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
          O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
          O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/CursorManiaFWBInitialSetup1.0.0.8-2.cab
          O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
          O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
          O20 - Winlogon Notify: dllms - C:\WINDOWS\java\trustlib\dllms.dll
          O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
          O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
          O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
          O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\aolavupd.exe
          O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
          O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe

          Comment

          • Kevin P
            Member
            • Aug 2000
            • 10808

            #6
            You've got Virtumundo adware on your system. I'm researching how to remove it presently. I will post back with specific instructions in a bit.

            By the way, do you get pop-up messages from "WinFixer"?

            For starters, go into Add/Remove Programs, and remove anything that references WinFixer and MyWebSearch.

            UPDATE: Go to this link: http://wiki.castlecops.com/Malware_Removal:_Virtumundo

            and follow the steps under Removal Directions. Post another HJT log afterward.

            Comment

            • Spalding12
              Junior Member
              • Jan 2006
              • 11

              #7
              Originally posted by Kevin P
              You've got Virtumondo adware on your system. I'm researching how to remove it presently. I will post back with specific instructions in a bit.

              By the way, do you get pop-up messages from "WinFixer"?

              For starters, go into Add/Remove Programs, and remove anything that references WinFixer and MyWebSearch. Then post another HJT log. By then I'll have removal instructions for Virtumondo compiled for you.

              i DID delete WinFixer
              ......
              you are a lifesaver
              i can't thank you enough
              i'm so sorry to trouble you with this trivial issue on the HT forum

              thanks again
              greg

              Comment

              • Kevin P
                Member
                • Aug 2000
                • 10808

                #8
                I posted a link in my post above that has instructions on removing Virtumundo. Follow those steps and then post another HJT log.

                Comment

                • Spalding12
                  Junior Member
                  • Jan 2006
                  • 11

                  #9
                  i ran the program

                  it found some files and deleted them
                  i restarted the compter
                  and the windows32 folder came up again
                  but.... i could immediately close it, however and the computer is working fine
                  so.......
                  i am making progress thanks to YOUR expertise

                  again, my appreciation
                  greg savel

                  Comment

                  • Spalding12
                    Junior Member
                    • Jan 2006
                    • 11

                    #10
                    the NEW logfile from HJ

                    Logfile of HijackThis v1.99.1
                    Scan saved at 1:01:48 PM, on 2/25/2006
                    Platform: Windows XP SP1 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\System32\brsvc01a.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\System32\brss01a.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Common Files\AOL\1140883202\ee\aolsoftware.exe
                    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
                    C:\Program Files\eMachines Bay Reader\shwiconem.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\WINDOWS\System32\HDAudPropShortcut.exe
                    C:\WINDOWS\zHotkey.exe
                    C:\Program Files\Common Files\AOL\1140883202\ee\services\sscAntiSpywarePlu gin\ver1_10_3_1\AOLSP Scheduler.exe
                    C:\Program Files\mcafee.com\antivirus\oasclnt.exe
                    C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
                    C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
                    C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\SSCEvtHdlr.exe
                    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                    C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\aolavupd.exe
                    C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
                    C:\Program Files\mcafee.com\personal firewall\MPFService.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    c:\program files\common files\aol\1140883202\ee\aolssc.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/yco...search/ie.html
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com
                    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
                    N3 - Netscape 7: user_pref("browser.startup.homepage", "my.yahoo.com"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\29zvdzey.slt\prefs.j s)
                    N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csea rchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\29zvdzey.slt\prefs.j s)
                    O1 - Hosts: 202.67.220.230 win.mail.ru
                    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
                    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0. dll
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
                    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
                    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0. dll
                    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
                    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1140883202\ee\AOLSoftware.exe
                    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
                    O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
                    O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
                    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
                    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
                    O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
                    O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1140883202\ee\services\sscAntiSpywarePlu gin\ver1_10_3_1\AOLSP Scheduler.exe
                    O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\SSCRun.exe
                    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
                    O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
                    O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
                    O4 - HKCU\..\Run: [WinFixer2006] "C:\Program Files\WinFixer_2006\uwfx6.exe" /scan
                    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm408YYUS
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
                    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
                    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
                    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
                    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                    O14 - IERESET.INF: START_PAGE_URL=http://www.gateway.com
                    O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
                    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
                    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/CursorManiaFWBInitialSetup1.0.0.8-2.cab
                    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
                    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
                    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                    O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\aolavupd.exe
                    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
                    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe

                    Comment

                    • Kevin P
                      Member
                      • Aug 2000
                      • 10808

                      #11
                      Ok Greg, we're almost there!!

                      Run Hijack This once more, check off the following items, and click Fix:

                      R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)

                      O1 - Hosts: 202.67.220.230 win.mail.ru

                      O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL

                      O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
                      O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

                      O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe

                      O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
                      (This should stop your System32 folder from opening on startup)

                      O4 - HKCU\..\Run: [WinFixer2006] "C:\Program Files\WinFixer_2006\uwfx6.exe" /scan

                      O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm408YYUS

                      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/CursorManiaFWBInitialSetup1.0.0.8-2.cab
                      O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
                      O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab

                      These next two can be optionally removed. Removing them will speed up startup but may slow down the initial launch of the associated application (Adobe Reader, and MS Office, respectively)

                      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


                      You can also optionally remove this one (stops Quicktime taskbar icon from loading):

                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

                      After removing these entries, reboot your PC, and then delete the following files or folders:

                      ShowWnd.exe (search for and delete)
                      C:\Program Files\MyWebSearch (delete entire folder)
                      C:\Program Files\WinFixer_2006 (delete entire folder)

                      Hopefully this will take care of your problems...
                      KJP

                      Comment

                      • Spalding12
                        Junior Member
                        • Jan 2006
                        • 11

                        #12
                        kevin
                        i just got back
                        thanks for going through all that trouble
                        i'm going to do it immediately and get back to you
                        thanks so much

                        greg

                        Comment

                        • Spalding12
                          Junior Member
                          • Jan 2006
                          • 11

                          #13
                          well, it's done

                          it IS working better
                          the nuisance boot to that system32 folder still occurs
                          but i can just close it and the computer is 100% fine
                          i won't be using IE on this machine any longer (i'm sure a lot of you have sworn it off years ago)

                          again....
                          you are such a great guy to spend time helping me with this problem
                          i appreciate your efforts
                          oh, and my daughter MACKENZIE also thanks you

                          greg savel

                          Comment

                          • Kevin P
                            Member
                            • Aug 2000
                            • 10808

                            #14
                            Post another HJT log and I'll try and figure out that system32 window problem...

                            Comment

                            • Spalding12
                              Junior Member
                              • Jan 2006
                              • 11

                              #15
                              i owe you 3 dinners now

                              Logfile of HijackThis v1.99.1
                              Scan saved at 4:55:19 PM, on 2/25/2006
                              Platform: Windows XP SP1 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\brsvc01a.exe
                              C:\WINDOWS\System32\brss01a.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Common Files\AOL\1140883202\ee\AOLSoftware.exe
                              C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
                              C:\Program Files\eMachines Bay Reader\shwiconem.exe
                              C:\Program Files\QuickTime\qttask.exe
                              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                              C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\WINDOWS\System32\HDAudPropShortcut.exe
                              C:\WINDOWS\zHotkey.exe
                              C:\Program Files\Common Files\AOL\1140883202\ee\services\sscAntiSpywarePlu gin\ver1_10_3_1\AOLSP Scheduler.exe
                              C:\Program Files\mcafee.com\antivirus\oasclnt.exe
                              C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
                              C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
                              C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\SSCEvtHdlr.exe
                              C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                              C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                              C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\aolavupd.exe
                              C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
                              C:\Program Files\mcafee.com\personal firewall\MPFService.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              c:\program files\common files\aol\1140883202\ee\aolssc.exe
                              C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 6 for hijackthis.zip\HijackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/yco...search/ie.html
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com
                              N3 - Netscape 7: user_pref("browser.startup.homepage", "my.yahoo.com"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\29zvdzey.slt\prefs.j s)
                              N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csea rchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\29zvdzey.slt\prefs.j s)
                              O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0. dll
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                              O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0. dll
                              O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
                              O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1140883202\ee\AOLSoftware.exe
                              O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
                              O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
                              O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                              O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
                              O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
                              O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
                              O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1140883202\ee\services\sscAntiSpywarePlu gin\ver1_10_3_1\AOLSP Scheduler.exe
                              O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\SSCRun.exe
                              O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
                              O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
                              O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
                              O4 - HKCU\..\Run: [WinFixer2006] "C:\Program Files\WinFixer_2006\uwfx6.exe" /scan
                              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                              O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                              O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm408YYUS
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
                              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
                              O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
                              O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
                              O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
                              O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
                              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                              O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                              O14 - IERESET.INF: START_PAGE_URL=http://www.gateway.com
                              O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
                              O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
                              O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/CursorManiaFWBInitialSetup1.0.0.8-2.cab
                              O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
                              O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
                              O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                              O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                              O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                              O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1140883202\ee\services\sscFirewallPlugin \ver1_10_3_1\aolavupd.exe
                              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
                              O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe

                              Comment

                              • Kevin P
                                Member
                                • Aug 2000
                                • 10808

                                #16
                                You still have these entries in your HJT log that need to be removed:

                                O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
                                O4 - HKCU\..\Run: [WinFixer2006] "C:\Program Files\WinFixer_2006\uwfx6.exe" /scan
                                O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearc...p=ZCxdm408YYUS

                                Remove them, then reboot and run HJT again and make sure they're really gone this time. If they aren't, try booting up in Safe Mode and running HJT from there and removing them again.

                                Also make sure you deleted C:\Program Files\WinFixer_2006\ and C:\Program Files\MyWebSearch\.

                                Once you remove those entries, you shouldn't get the System32 window on start-up.

                                Comment

                                • Spalding12
                                  Junior Member
                                  • Jan 2006
                                  • 11

                                  #17
                                  Hey Kevin

                                  weird thing
                                  when i run HJ and delete the 3 things....
                                  even before i reboot....
                                  if i run the HJ again..... they are right back there
                                  whether i deleted them in regular or safe mode
                                  but.....
                                  the computer is healthier because of your tireless efforts to assist me
                                  and i'm am forever thankful for it

                                  get some rest
                                  i applaud your efforts to help me
                                  thanks very much

                                  greg savel

                                  Comment

                                  • Kevin P
                                    Member
                                    • Aug 2000
                                    • 10808

                                    #18
                                    Ok, time to resort to guerilla warefare You still have something running on there that doesn't belong, and darned if I'm gonna let it outsmart little old me.

                                    Go into Task Manager, Processes tab, and kill zHotkey.exe. Then try removing those entries again. If they don't come back, we found the culprit - run HJT again and remove the zHotkey.exe entry, and delete the offending file off your system and reboot.

                                    If that doesn't work, kill everything you can other than svchost.exe, lsass.exe, rpcss.exe, explorer.exe from Task Manager. Some things may tell you "access denied", and if you kill the wrong thing, Windows may give you a "restarting in 60 seconds" dialog - if you get this, immediately go to Start->Run and type "shutdown -a".

                                    Once you prune your running processes down to the bare minimum, try the Hijack This again. If it stays deleted this time around, reboot and then check again to make sure they didn't return. Post back with your results.

                                    Comment

                                    • JOY DIVISION
                                      Senior Member
                                      • Aug 2004
                                      • 152

                                      #19
                                      - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/instal...sinstaller.cab
                                      O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin

                                      O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0. dll

                                      Quit looking at pornos, free games means they invade your PC as well, Active x contents pretend to be safe but those crap are loaded with malware and other craps!

                                      Comment

                                      Working...
                                      Searching...Please wait.
                                      An unexpected error was returned: 'Your submission could not be processed because you have logged in since the previous page was loaded.

                                      Please push the back button and reload the previous window.'
                                      An unexpected error was returned: 'Your submission could not be processed because the token has expired.

                                      Please push the back button and reload the previous window.'
                                      An internal error has occurred and the module cannot be displayed.
                                      There are no results that meet this criteria.
                                      Search Result for "|||"