Home Search Assistant, Search Extender, and Shopping Wizard causing problems with AIM

Reply

Join Date: Jun 2005
Posts: 1
Reputation: nick123 is an unknown quantity at this point 
Solved Threads: 0
nick123 nick123 is offline Offline
Newbie Poster

Home Search Assistant, Search Extender, and Shopping Wizard causing problems with AIM

 
0
  #1
Jul 5th, 2005
Home Search Assistant, Search Extender, and Shopping Wizard are causing my AIM to crash. I'm sure that there is plenty more wrong with my computer, but these are the only three that I know for a fact are messing things up. If you could help me out that'd be great. Here is my log:

Logfile of HijackThis v1.99.1
Scan saved at 1:47:09 PM, on 7/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\d3mv.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\AIM95\aim.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\QuixNet.net\LRBROWSE.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.quixnet.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\iapvv.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\iapvv.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\iapvv.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\iapvv.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.quixnet.net/
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {124FAA2B-986B-4226-EDE4-73956513EB6C} - C:\WINDOWS\system32\appwv32.dll
O2 - BHO: Class - {24EDB288-AF4A-18FA-270B-627C10F2632F} - C:\WINDOWS\system32\appfr.dll
O2 - BHO: Class - {27E4633B-37DB-09B0-10DB-1674088EC3BA} - C:\WINDOWS\system32\ntul32.dll
O2 - BHO: Class - {2A70656C-8CDF-3715-42B5-E643EB99E370} - C:\WINDOWS\system32\javaly.dll
O2 - BHO: Class - {404BD3C3-E850-6D52-BF73-C5C235C5B48D} - C:\WINDOWS\sysaw.dll
O2 - BHO: Class - {4C57E717-CFF7-3593-E15F-0DB069077A96} - C:\WINDOWS\crvg.dll
O2 - BHO: Class - {5201EB82-B2A7-ABAA-7873-CEB8249B292F} - C:\WINDOWS\system32\netvc32.dll
O2 - BHO: Class - {538ECC2F-29D9-9161-D485-51734843D8C5} - C:\WINDOWS\system32\addcx.dll
O2 - BHO: Class - {5461BE13-F536-594F-118B-41BE2C201324} - C:\WINDOWS\addvn.dll
O2 - BHO: Class - {546F602F-64D8-A0FB-286E-6A961DD4CD13} - C:\WINDOWS\system32\sdkow.dll
O2 - BHO: Class - {5649FC80-401D-6577-0C0F-E130C201E57E} - C:\WINDOWS\ipds32.dll
O2 - BHO: Class - {64A6ABE0-9644-5928-19BA-9CBAE0E5D13F} - C:\WINDOWS\sdkvx32.dll
O2 - BHO: Class - {6A6B2A88-0B1D-370A-A538-E681460CB879} - C:\WINDOWS\system32\addie32.dll
O2 - BHO: Class - {7CE28F1A-C75D-E86A-7653-65342618DF9B} - C:\WINDOWS\syslj32.dll
O2 - BHO: Class - {809BEC2F-9B63-B600-853B-83F15DB31424} - C:\WINDOWS\system32\d3uy.dll
O2 - BHO: Class - {866A3A28-5F61-83BA-C3CA-AA1516A9ABFB} - C:\WINDOWS\atlaq32.dll
O2 - BHO: Class - {983BB056-EFD0-7204-73D3-F6E9D7EBA6AB} - C:\WINDOWS\system32\msyh32.dll
O2 - BHO: Class - {AA8263C2-BEC0-1A3A-53EC-210BF773BE14} - C:\WINDOWS\apint32.dll
O2 - BHO: Class - {BB29E22A-397D-B30C-9434-091292AD4089} - C:\WINDOWS\system32\addaf.dll
O2 - BHO: Class - {CB9342B7-A3E8-772F-764C-619AA31BFA17} - C:\WINDOWS\system32\addyx.dll
O2 - BHO: Class - {DC8B0938-5FED-2CB4-7F25-40FB2AA50A25} - C:\WINDOWS\netkm32.dll
O2 - BHO: Class - {E7E40E04-9CBA-8F0C-C943-6791199E07B6} - C:\WINDOWS\windu.dll
O2 - BHO: Class - {FC344FA8-CC15-2847-A8F1-50D9B4E50E70} - C:\WINDOWS\system32\apike32.dll
O2 - BHO: Class - {FEB83F4D-CC42-5BB2-2F5F-FF52E5B474D5} - C:\WINDOWS\crua32.dll
O2 - BHO: Class - {FFCD035F-429E-054F-1D01-F49E14490C2E} - C:\WINDOWS\sdkwz32.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [pnVFRYS] C:\documents and settings\nevole's\local settings\temp\pnVFRYS.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [d3mv.exe] C:\WINDOWS\system32\d3mv.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunOnce: [ntvu.exe] C:\WINDOWS\system32\ntvu.exe
O4 - HKLM\..\RunOnce: [javatr32.exe] C:\WINDOWS\system32\javatr32.exe
O4 - HKLM\..\RunOnce: [sysln.exe] C:\WINDOWS\system32\sysln.exe
O4 - HKLM\..\RunOnce: [apptg.exe] C:\WINDOWS\apptg.exe
O4 - HKLM\..\RunOnce: [iped32.exe] C:\WINDOWS\system32\iped32.exe
O4 - HKLM\..\RunOnce: [apiph32.exe] C:\WINDOWS\system32\apiph32.exe
O4 - HKLM\..\RunOnce: [netfn.exe] C:\WINDOWS\system32\netfn.exe
O4 - HKLM\..\RunOnce: [winrr.exe] C:\WINDOWS\system32\winrr.exe
O4 - HKLM\..\RunOnce: [atljp32.exe] C:\WINDOWS\atljp32.exe
O4 - HKLM\..\RunOnce: [msor32.exe] C:\WINDOWS\msor32.exe
O4 - HKLM\..\RunOnce: [mskq32.exe] C:\WINDOWS\system32\mskq32.exe
O4 - HKLM\..\RunOnce: [ntpk32.exe] C:\WINDOWS\system32\ntpk32.exe
O4 - HKLM\..\RunOnce: [mfcfc.exe] C:\WINDOWS\mfcfc.exe
O4 - HKLM\..\RunOnce: [iekw32.exe] C:\WINDOWS\iekw32.exe
O4 - HKLM\..\RunOnce: [javail.exe] C:\WINDOWS\system32\javail.exe
O4 - HKLM\..\RunOnce: [mssy.exe] C:\WINDOWS\system32\mssy.exe
O4 - HKLM\..\RunOnce: [ipyb32.exe] C:\WINDOWS\ipyb32.exe
O4 - HKLM\..\RunOnce: [netvo32.exe] C:\WINDOWS\system32\netvo32.exe
O4 - HKLM\..\RunOnce: [winii.exe] C:\WINDOWS\system32\winii.exe
O4 - HKLM\..\RunOnce: [d3ab.exe] C:\WINDOWS\system32\d3ab.exe
O4 - HKLM\..\RunOnce: [netql32.exe] C:\WINDOWS\system32\netql32.exe
O4 - HKLM\..\RunOnce: [addef.exe] C:\WINDOWS\system32\addef.exe
O4 - HKLM\..\RunOnce: [netuy.exe] C:\WINDOWS\system32\netuy.exe
O4 - HKLM\..\RunOnce: [addhs32.exe] C:\WINDOWS\system32\addhs32.exe
O4 - HKLM\..\RunOnce: [javakp.exe] C:\WINDOWS\system32\javakp.exe
O4 - HKLM\..\RunOnce: [mfcqk32.exe] C:\WINDOWS\mfcqk32.exe
O4 - HKLM\..\RunOnce: [iegv32.exe] C:\WINDOWS\iegv32.exe
O4 - HKLM\..\RunOnce: [addwd32.exe] C:\WINDOWS\addwd32.exe
O4 - HKLM\..\RunOnce: [sysrh.exe] C:\WINDOWS\sysrh.exe
O4 - HKLM\..\RunOnce: [javaqw32.exe] C:\WINDOWS\javaqw32.exe
O4 - HKLM\..\RunOnce: [netom32.exe] C:\WINDOWS\system32\netom32.exe
O4 - HKLM\..\RunOnce: [ipou.exe] C:\WINDOWS\system32\ipou.exe
O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\apixu.exe
O4 - HKLM\..\RunOnce: [crmr.exe] C:\WINDOWS\system32\crmr.exe
O4 - HKLM\..\RunOnce: [ntcy32.exe] C:\WINDOWS\system32\ntcy32.exe
O4 - HKLM\..\RunOnce: [javavr.exe] C:\WINDOWS\javavr.exe
O4 - HKLM\..\RunOnce: [iern32.exe] C:\WINDOWS\iern32.exe
O4 - HKLM\..\RunOnce: [crbw.exe] C:\WINDOWS\crbw.exe
O4 - HKLM\..\RunOnce: [d3ol32.exe] C:\WINDOWS\d3ol32.exe
O4 - HKLM\..\RunOnce: [crvi32.exe] C:\WINDOWS\system32\crvi32.exe
O4 - HKLM\..\RunOnce: [netam32.exe] C:\WINDOWS\netam32.exe
O4 - HKLM\..\RunOnce: [d3dy32.exe] C:\WINDOWS\system32\d3dy32.exe
O4 - HKLM\..\RunOnce: [syshc.exe] C:\WINDOWS\system32\syshc.exe
O4 - HKLM\..\RunOnce: [ieic32.exe] C:\WINDOWS\system32\ieic32.exe
O4 - HKLM\..\RunOnce: [msxz32.exe] C:\WINDOWS\system32\msxz32.exe
O4 - HKLM\..\RunOnce: [ntcv32.exe] C:\WINDOWS\system32\ntcv32.exe
O4 - HKLM\..\RunOnce: [sdkkb.exe] C:\WINDOWS\system32\sdkkb.exe
O4 - HKLM\..\RunOnce: [sdkev32.exe] C:\WINDOWS\sdkev32.exe
O4 - HKLM\..\RunOnce: [apiuk.exe] C:\WINDOWS\system32\apiuk.exe
O4 - HKLM\..\RunOnce: [systa32.exe] C:\WINDOWS\system32\systa32.exe
O4 - HKLM\..\RunOnce: [crrp32.exe] C:\WINDOWS\crrp32.exe
O4 - HKLM\..\RunOnce: [d3rx.exe] C:\WINDOWS\d3rx.exe
O4 - HKLM\..\RunOnce: [crax.exe] C:\WINDOWS\system32\crax.exe
O4 - HKLM\..\RunOnce: [winpn32.exe] C:\WINDOWS\winpn32.exe
O4 - HKLM\..\RunOnce: [mfcgu32.exe] C:\WINDOWS\mfcgu32.exe
O4 - HKLM\..\RunOnce: [appjg.exe] C:\WINDOWS\appjg.exe
O4 - HKLM\..\RunOnce: [d3iw32.exe] C:\WINDOWS\d3iw32.exe
O4 - HKLM\..\RunOnce: [ntyd32.exe] C:\WINDOWS\system32\ntyd32.exe
O4 - HKLM\..\RunOnce: [sdkgt.exe] C:\WINDOWS\system32\sdkgt.exe
O4 - HKLM\..\RunOnce: [ntht.exe] C:\WINDOWS\ntht.exe
O4 - HKLM\..\RunOnce: [mswi32.exe] C:\WINDOWS\system32\mswi32.exe
O4 - HKLM\..\RunOnce: [adduq32.exe] C:\WINDOWS\system32\adduq32.exe
O4 - HKLM\..\RunOnce: [ipkl32.exe] C:\WINDOWS\ipkl32.exe
O4 - HKLM\..\RunOnce: [ntdw.exe] C:\WINDOWS\system32\ntdw.exe
O4 - HKLM\..\RunOnce: [d3za.exe] C:\WINDOWS\system32\d3za.exe
O4 - HKLM\..\RunOnce: [winsb32.exe] C:\WINDOWS\system32\winsb32.exe
O4 - HKLM\..\RunOnce: [atlii.exe] C:\WINDOWS\system32\atlii.exe
O4 - HKLM\..\RunOnce: [ipmm32.exe] C:\WINDOWS\ipmm32.exe
O4 - HKLM\..\RunOnce: [apiwn.exe] C:\WINDOWS\system32\apiwn.exe
O4 - HKLM\..\RunOnce: [netbj32.exe] C:\WINDOWS\system32\netbj32.exe
O4 - HKLM\..\RunOnce: [mskq.exe] C:\WINDOWS\system32\mskq.exe
O4 - HKLM\..\RunOnce: [appaf32.exe] C:\WINDOWS\appaf32.exe
O4 - HKLM\..\RunOnce: [netqm.exe] C:\WINDOWS\netqm.exe
O4 - HKLM\..\RunOnce: [javauq32.exe] C:\WINDOWS\system32\javauq32.exe
O4 - HKLM\..\RunOnce: [iper.exe] C:\WINDOWS\system32\iper.exe
O4 - HKLM\..\RunOnce: [ntjn32.exe] C:\WINDOWS\system32\ntjn32.exe
O4 - HKLM\..\RunOnce: [ntyk32.exe] C:\WINDOWS\ntyk32.exe
O4 - HKLM\..\RunOnce: [appdh32.exe] C:\WINDOWS\appdh32.exe
O4 - HKLM\..\RunOnce: [ntgs.exe] C:\WINDOWS\ntgs.exe
O4 - HKLM\..\RunOnce: [mseo32.exe] C:\WINDOWS\mseo32.exe
O4 - HKLM\..\RunOnce: [ieew32.exe] C:\WINDOWS\ieew32.exe
O4 - HKLM\..\RunOnce: [atlow32.exe] C:\WINDOWS\atlow32.exe
O4 - HKLM\..\RunOnce: [crow.exe] C:\WINDOWS\system32\crow.exe
O4 - HKLM\..\RunOnce: [ntsi.exe] C:\WINDOWS\system32\ntsi.exe
O4 - HKLM\..\RunOnce: [mshx32.exe] C:\WINDOWS\mshx32.exe
O4 - HKLM\..\RunOnce: [addxf.exe] C:\WINDOWS\addxf.exe
O4 - HKLM\..\RunOnce: [apibj32.exe] C:\WINDOWS\apibj32.exe
O4 - HKLM\..\RunOnce: [applr.exe] C:\WINDOWS\applr.exe
O4 - HKLM\..\RunOnce: [atlqg32.exe] C:\WINDOWS\atlqg32.exe
O4 - HKLM\..\RunOnce: [appfd32.exe] C:\WINDOWS\system32\appfd32.exe
O4 - HKLM\..\RunOnce: [apieq.exe] C:\WINDOWS\apieq.exe
O4 - HKLM\..\RunOnce: [appux.exe] C:\WINDOWS\system32\appux.exe
O4 - HKLM\..\RunOnce: [mseq32.exe] C:\WINDOWS\system32\mseq32.exe
O4 - HKLM\..\RunOnce: [sysyk.exe] C:\WINDOWS\sysyk.exe
O4 - HKLM\..\RunOnce: [atlco.exe] C:\WINDOWS\atlco.exe
O4 - HKLM\..\RunOnce: [netmg32.exe] C:\WINDOWS\netmg32.exe
O4 - HKLM\..\RunOnce: [javaco.exe] C:\WINDOWS\javaco.exe
O4 - HKLM\..\RunOnce: [iegs32.exe] C:\WINDOWS\iegs32.exe
O4 - HKLM\..\RunOnce: [crqs.exe] C:\WINDOWS\crqs.exe
O4 - HKLM\..\RunOnce: [d3wp32.exe] C:\WINDOWS\d3wp32.exe
O4 - HKLM\..\RunOnce: [d3km32.exe] C:\WINDOWS\d3km32.exe
O4 - HKLM\..\RunOnce: [netpi32.exe] C:\WINDOWS\netpi32.exe
O4 - HKLM\..\RunOnce: [d3ku32.exe] C:\WINDOWS\system32\d3ku32.exe
O4 - HKLM\..\RunOnce: [sysxy.exe] C:\WINDOWS\system32\sysxy.exe
O4 - HKLM\..\RunOnce: [iexy32.exe] C:\WINDOWS\system32\iexy32.exe
O4 - HKLM\..\RunOnce: [ntrx.exe] C:\WINDOWS\system32\ntrx.exe
O4 - HKLM\..\RunOnce: [winlj.exe] C:\WINDOWS\winlj.exe
O4 - HKLM\..\RunOnce: [msbq.exe] C:\WINDOWS\msbq.exe
O4 - HKLM\..\RunOnce: [ntlj32.exe] C:\WINDOWS\system32\ntlj32.exe
O4 - HKLM\..\RunOnce: [sdkfc.exe] C:\WINDOWS\system32\sdkfc.exe
O4 - HKLM\..\RunOnce: [iebg.exe] C:\WINDOWS\iebg.exe
O4 - HKLM\..\RunOnce: [addtz32.exe] C:\WINDOWS\system32\addtz32.exe
O4 - HKLM\..\RunOnce: [msey32.exe] C:\WINDOWS\msey32.exe
O4 - HKLM\..\RunOnce: [d3tv32.exe] C:\WINDOWS\system32\d3tv32.exe
O4 - HKLM\..\RunOnce: [iesa.exe] C:\WINDOWS\iesa.exe
O4 - HKLM\..\RunOnce: [d3ip.exe] C:\WINDOWS\d3ip.exe
O4 - HKLM\..\RunOnce: [ipai32.exe] C:\WINDOWS\system32\ipai32.exe
O4 - HKLM\..\RunOnce: [javafk.exe] C:\WINDOWS\javafk.exe
O4 - HKLM\..\RunOnce: [netjo32.exe] C:\WINDOWS\netjo32.exe
O4 - HKLM\..\RunOnce: [msny32.exe] C:\WINDOWS\system32\msny32.exe
O4 - HKLM\..\RunOnce: [ipyz32.exe] C:\WINDOWS\system32\ipyz32.exe
O4 - HKLM\..\RunOnce: [ipgh32.exe] C:\WINDOWS\ipgh32.exe
O4 - HKLM\..\RunOnce: [d3qi32.exe] C:\WINDOWS\system32\d3qi32.exe
O4 - HKLM\..\RunOnce: [apipi.exe] C:\WINDOWS\apipi.exe
O4 - HKLM\..\RunOnce: [atlfd.exe] C:\WINDOWS\atlfd.exe
O4 - HKLM\..\RunOnce: [msek32.exe] C:\WINDOWS\msek32.exe
O4 - HKLM\..\RunOnce: [mfctz32.exe] C:\WINDOWS\mfctz32.exe
O4 - HKLM\..\RunOnce: [d3th32.exe] C:\WINDOWS\system32\d3th32.exe
O4 - HKLM\..\RunOnce: [atlot32.exe] C:\WINDOWS\system32\atlot32.exe
O4 - HKLM\..\RunOnce: [apitx.exe] C:\WINDOWS\apitx.exe
O4 - HKLM\..\RunOnce: [mfcby32.exe] C:\WINDOWS\system32\mfcby32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program Files\FastSeeker\FastSeekerToolbar011203.dll/cmsearch.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/bestfriends/retro64_loader.dll
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minib...ansporter.cab?
O16 - DPF: {3B02AAA2-327C-40ED-A849-4BE819AE5385} (ImgSizer Control) - file://C:\Documents and Settings\Nevole's\Local Settings\Temp\~DlfnTmp0\imgSizer.ocx
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/17817348836fdf5...p/RdxIE601.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://autos.msn.com/components/ocx/survid/MSSurVid.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/...or/Outside.cab
O16 - DPF: {C8BAC37C-A8D2-425E-B7FC-80B9537FB14A} (SBFullS Control) - http://www.spyblast.com/download/SBFS.cab
O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) - http://autos.msn.com/components/ocx/...autopricer.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{15CF83A1-58D4-4B95-9675-BBCF341F1E8D}: NameServer = 205.171.3.65 205.171.2.65
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\ntvu.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 363
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Home Search Assistant, Search Extender, and Shopping Wizard causing problems with

 
0
  #2
Jul 5th, 2005
Hi nick123, welcome to the site.

Also, please go to the front counter to collect your prize- that is the ugliest log I've seen in days. :mrgreen:

Seriously though- you are pretty infested. Please perform the following general detection and removal proceedures to get some of the nasties cleaned up:


1. Run at least two or three of the following online anti-virus/anti-spyware scans and let them fix what they can:

http://www.kaspersky.com/scanforvirus.html
http://housecall.trendmicro.com/
http://us.mcafee.com/root/mfs/default.asp?cid=9914
http://www.pandasoftware.com/active...n_principal.htm
http://www.ravantivirus.com/scan/
http://www.bitdefender.com/scan/licence.php


2. Download, install, and run the following (free) detection and removal tools (use each program's online update function before running them to make sure you have the most current updates installed).

After each utility completes its fixes, reboot before continuing on to the next utility; have the utilities fix all of the problematic/malicious items they find:

ewido Security Suite - http://www.ewido.net/en/download/
Microsoft Anti-Spyware beta - http://www.microsoft.com/downloads/...&displaylang=en
Ad Aware SE Personal - http://www.lavasoftusa.com/
SpyBot Search & Destroy - http://www.safer-networking.org/


3. Reboot into safe mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up)

- Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types".

- For every user account listed under C:\Documents and Settings, delete the entire contents of these folders (but not the folders themselves):

Important: One of the normal steps in eliminating malicious programs is to entirely delete the contents of all Temp folders. Given that, if any data that you care about is living in those Temp folders, you need to move it to a safe location now, or it will be erased along with everything else!

1. Cookies
2. Local Settings\Temp
3. Local Settings\History
4. Local Settings\Temporary Internet Files

- Delete the entire content of your C:\Windows\Temp folder.

- Delete the entire content of your C:\Windows\Prefetch folder.

Note- If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll be automatically regenerated by Windows if needed. Windows will allow you to delete the versions of those files which exist in sub-folders within the main Temp/Temorary folders, but might not let you delete the versions of those files that exist in the main Temp folders themselves; this is normal and OK.

- Empty your Recycle Bin.

- Reboot normally.

- Run HijackThis again and post a new log. Also post the scan report that ewido generated, as well as any reports the online scanners gave you.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC