I, like many others, am plagued by the prosearching and SearchAssistant "viruses." I followed Crunchie's steps from an earlier post as closely as I could and I still have the bugs. How the heck do I get rid of these things? Any help would be GREATLY appreciated! Thanks for the help. My last HJT log looks like this:

Logfile of HijackThis v1.97.7
Scan saved at 1:46:49 PM, on 6/1/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\3Com_DMI\3CDMINIC.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINNT\system32\crypserv.exe
C:\WINNT\System32\mnmsrvc.exe
C:\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\Suss.exe
C:\OfficeScan NT\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\System32\CCM\CcmExec.exe
C:\OfficeScan NT\ofcdog.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\essapm.exe
C:\WINNT\system32\PRPCUI.exe
C:\OfficeScan NT\pccntmon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\WINNT\System32\qttask.exe
C:\OfficeScan NT\RAUAgent.exe
C:\PROGRA~1\LIESWA~1\Extra Show.exe
C:\PROGRA~1\CENTRA~2\bin\centraSystray.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Hijack This\HijackThis.exe
C:\Program Files\Common Files\Real\Update_OB\rndal.exe
C:\Program Files\Common Files\Real\Update_OB\rndal.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {185FDDA7-A61F-89AA-1B04-DD423042EA06} - C:\PROGRA~1\MEETBA~1\debug new.dll
O2 - BHO: (no name) - {B4496A4E-1EE2-11D5-AC63-0010A4D17343} - C:\Program Files\Guru Inc\Shared\BHO.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: Download site inter - {A5BA5867-BC9E-72B7-2A7A-8EF6C18733E6} - C:\PROGRA~1\MEETBA~1\debug new.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [essapm] essapm.exe
O4 - HKLM\..\Run: [NetMeeting] "C:\Program Files\NetMeeting\useredits.exe" /s
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [QuickTime Task] C:\WINNT\System32\qttask.exe
O4 - HKLM\..\Run: [RemoteAgent] C:\OfficeScan NT\RAUAgent.exe
O4 - HKLM\..\Run: [System Service] C:\WINNT\System32\msrexe.exe
O4 - HKLM\..\Run: [UpdateSerialNumber] C:\WINNT\System32\updateserial.exe /s
O4 - HKLM\..\Run: [Memo Htm] C:\PROGRA~1\LIESWA~1\Extra Show.exe
O4 - HKCU\..\Run: [Centra Launcher] C:\PROGRA~1\CENTRA~2\bin\centraSystray.exe /startup
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .asp: C:\PROGRA~1\Plus!\MICROS~1\PLUGINS\npdyn32.dll
O12 - Plugin for .mts: C:\PROGRA~1\METACR~1\METAST~1\npmetastream.dll
O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} (SBITAX7Ctrl Class) -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) -
O16 - DPF: {14325268-79E0-4D2A-89A4-FFFC6E22741E} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_3_EN.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E876D003-BCDE-11D3-9131-000094B61529} (ERPageAddin Class) -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = ,,l3.com,,
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = ,,l3.com,,
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ,,l3.com,,

Dani AI

Generated

Good troubleshooting by and well-documented follow-through by — the combination of patching the system, booting to Safe Mode, removing the offending startup entries and folder, then rescanning is exactly the right pattern for removing persistent browser toolbars that reinstall themselves. Those nuisances normally survive by placing files in startup locations or registering helper objects; removing both the files and the persistence points breaks the cycle.

Recommended verification steps include:

  • Boot to Safe Mode (minimal drivers/services) and run a fresh scan so the helper can’t reload. Back up the registry or create a system image before making removals.
  • Re-scan with an on-demand AV + an updated anti‑malware tool to catch leftovers; update signatures first.
  • Use an autorun/startup viewer to inspect every startup location (HKLM/HKCU Run, RunOnce, services, scheduled tasks, Browser Helper Objects and toolbars, Winlogon notifications) and remove anything unknown.
  • Check browser settings (homepage/search provider/proxy) and the Hosts file for redirects; clear temp files and caches and then reset the browser’s settings if necessary.
  • Remove old System Restore points that predate the cleanup, then create a fresh restore point once the system is verified clean.

If a component keeps returning, consider an offline rescue scan (boot from a clean rescue medium) or review drivers/network-layer hooks (LSPs/DNS/proxies). On corporate machines, escalate to IT before deleting files tied to enterprise software. After cleanup, rotate any passwords used from the infected machine and keep regular backups.

Prevention: run as a limited user for daily work, keep OS/browser/AV signatures current, avoid unknown toolbars/add-ons, and keep a recovery image. Thanks to for the clear Safe Mode + removal workflow; the thread’s resolution is a good reference for future readers.

Recommended Answers

All 6 Replies

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {185FDDA7-A61F-89AA-1B04-DD423042EA06} - C:\PROGRA~1\MEETBA~1\debug new.dll
O2 - BHO: (no name) - {B4496A4E-1EE2-11D5-AC63-0010A4D17343} - C:\Program Files\Guru Inc\Shared\BHO.dll

O3 - Toolbar: Download site inter - {A5BA5867-BC9E-72B7-2A7A-8EF6C18733E6} - C:\PROGRA~1\MEETBA~1\debug new.dll

O4 - HKLM\..\Run: [System Service] C:\WINNT\System32\msrexe.exe
O4 - HKLM\..\Run: [UpdateSerialNumber] C:\WINNT\System32\updateserial.exe /s

Reboot into safe mode following the instructions & navigate to & delete the following if found:

C:\WINNT\System32\msrexe.exe< file
C:\WINNT\System32\updateserial.exe< file

Reboot normally.
There are a few things there I haven't seen B4. Is this a work computer? If so & you know, can you highlight the entries that reference these work programs plz.
Update W2K to SP4 & also you should urgently upgrade to IE6 for security reasons. The one you use now is out of date & therefore very vulnerable to attack.

Thanks for the help, Crunchie. I did as you suggested: I upgraded to W2K SP4 and upgraded to IE6 as well as delete the items you identified. I then ran SpyBot and AdAware again. Below you'll find my most recent HJT log. Your previous suggestion did seem to take care of the blue Search Assistant tool bar at the top of the browser, but the pesky gray prosearching tool bar at the bottom keeps popping up. For what it's worth, the prosearching toolbar keeps setting my homepage link to: http://look-today.com/passthrough/index.html?<then my homepage address> I marked all work entries that I recognize with a * in the log below.

Logfile of HijackThis v1.97.7
Scan saved at 4:29:48 PM, on 6/2/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\3Com_DMI\3CDMINIC.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINNT\system32\crypserv.exe
C:\WINNT\System32\mnmsrvc.exe
C:\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\Suss.exe
C:\OfficeScan NT\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\System32\CCM\CcmExec.exe
C:\OfficeScan NT\ofcdog.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\essapm.exe
C:\WINNT\system32\PRPCUI.exe
C:\OfficeScan NT\pccntmon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\WINNT\System32\qttask.exe
C:\OfficeScan NT\RAUAgent.exe
C:\PROGRA~1\LIESWA~1\Extra Show.exe
* C:\PROGRA~1\CENTRA~2\bin\centraSystray.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\hijackthis\hijackthis.exe
C:\Program Files\Common Files\Real\Update_OB\rndal.exe
C:\Program Files\Common Files\Real\Update_OB\rndal.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://look-today.com/passthrough/index.html? *
O2 - BHO: (no name) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [essapm] essapm.exe
O4 - HKLM\..\Run: [NetMeeting] "C:\Program Files\NetMeeting\useredits.exe" /s
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [QuickTime Task] C:\WINNT\System32\qttask.exe
O4 - HKLM\..\Run: [RemoteAgent] C:\OfficeScan NT\RAUAgent.exe
O4 - HKLM\..\Run: [Memo Htm] C:\PROGRA~1\LIESWA~1\Extra Show.exe
* O4 - HKCU\..\Run: [Centra Launcher] C:\PROGRA~1\CENTRA~2\bin\centraSystray.exe /startup
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .asp: C:\PROGRA~1\Plus!\MICROS~1\PLUGINS\npdyn32.dll
O12 - Plugin for .mts: C:\PROGRA~1\METACR~1\METAST~1\npmetastream.dll
O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} (SBITAX7Ctrl Class) -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) -
O16 - DPF: {14325268-79E0-4D2A-89A4-FFFC6E22741E} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_3_EN.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E876D003-BCDE-11D3-9131-000094B61529} (ERPageAddin Class) -
* O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
*O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
* O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = ,,l3.com,,
* O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
* O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = ,,l3.com,,
* O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ,,l3.com,,

Thanks again for the help. I really appreciate it!

--Fever

Reboot into safe mode following the instructions & Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://look-today.com/passthrough/index.html? *
O4 - HKLM\..\Run: [Memo Htm] C:\PROGRA~1\LIESWA~1\Extra Show.exe

Delete the C:\PROGRA~1\LIESWA~1< folder. I do not know the full title of the folder.

Reboot normally when done. They are the only two there that I can see.

I think that did it! Thanks Crunchie! I will be much more proactive, now about updating my security. I really appreciate your help.

--Johnny Fever

check the !!please read in Crunchies signature

You are welcome. Marking this as solved. Anyone else with the same problem please start your own thread. Thank you.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.