Problem with Internet Explorer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ComputerChallenged, Jun 4, 2004.

  1. ComputerChallenged

    ComputerChallenged Private E-2

    For the last few days, I've been having a problem with my internet explorer. When I am on a web page, a new internet explorer window appears. Sometimes several windows pop up. Mostly it is my home page that pops up. How do I get this to stop? I have run Spybot and Adaware 6. I've also done a virus scan and it says I have no viruses. Can someone help me please?

    Thank you.

    Tina
     
  2. Radiofool

    Radiofool Private First Class

    Hmm. What is your homepage? It might be causing the popups. The other thing to try is the Google bar. It acts as a kinda handy search bar, and also blocks i reckon about 99.5% of popups that you will encounter (you can allow popups on certain websites too).

    I'm not sure if will will solve your specific problem but either way, i use it, its free, isn't spyware and works well for me and can't do you any harm.. :)

    http://toolbar.google.com/

    Uh, yeah.. I'm really not being paid by Google or anything...

    :D
     
  3. ComputerChallenged

    ComputerChallenged Private E-2

    My home page has always been msn. What do you suggest I should change it to? I'll download the google toolbar, too. :)
     
  4. Radiofool

    Radiofool Private First Class

    MSN Should be fine. Some website sorta force you/hijack you into making them your homepage. Often pretending to be search engines or something. These things can spawn popups all over the place, but MSN won't do that. Hopefully Google bar will sort you out. Let me know.

    :)
     
  5. nickson2

    nickson2 Master Sergeant

    Have you got the latest updates on spybot and adaware?
     
  6. ComputerChallenged

    ComputerChallenged Private E-2

    I installed the google toolbar. I rebooted, but when I hit the internet explorer to connect to the internet, 4 msn windows appears and there was no toolbar.

    I did get the latest updates for spybot & adaware. I will try again, though. Thanks.
     
  7. nickson2

    nickson2 Master Sergeant

     
  8. Radiofool

    Radiofool Private First Class

    The Google bar requires Internet Explorer 5.5 to block popups.. So make sure you have that- but to be honest, the more i hear about this issue the less i think it will be solved by Google.. Good luck.
     
  9. nickson2

    nickson2 Master Sergeant

    what version of IE are you using?
     
  10. simonk

    simonk Corporal

  11. ComputerChallenged

    ComputerChallenged Private E-2

    Please don't laugh at me, but how do I find this out. I really don't know. :confused:

    This is what hijack this says:

    Logfile of HijackThis v1.97.7
    Scan saved at 11:31:07 AM, on 6/4/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\LEXBCES.EXE
    C:\WINDOWS\SYSTEM\RPCSS.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\ATICWD32.EXE
    C:\WINDOWS\SYSTEM\ATITASK.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\REAL\PLAYER\REALPLAY.EXE
    C:\PROGRAM FILES\SONY\IMAGESTATION\USB DIRECT CONNECT\SONYC2W.EXE
    C:\PROGRAM FILES\LEXMARKX83\ACMONITOR_X83.EXE
    C:\PROGRAM FILES\LEXMARKX83\ACBTNMGR_X83.EXE
    C:\WINDOWS\SYSTEM\PRINTRAY.EXE
    C:\WINDOWS\WDSKCTL.EXE
    C:\PROGRAM FILES\COMMON FILES\FOTONATION\EVLSTNR.EXE
    C:\WINDOWS\MSCMGR.EXE
    C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
    C:\WINDOWS\RunDLL.exe
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
    C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
    C:\WINDOWS\TEMP\HIJACKTHIS.EXE
    R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\TV MEDIA\TvmBho.dll
    N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.huntel.net"); (C:\Program Files\Internet\Netscape\users\twelveosix\prefs.js)
    O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiKey] Atitask.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\REAL\PLAYER\REALPLAY.EXE SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [SonyC2W] C:\Program Files\Sony\ImageStation\USB Direct Connect\SonyC2W.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~2\ACMonitor_X83.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~2\AcBtnMgr_X83.exe
    O4 - HKLM\..\Run: [LexStart] Lexstart.exe
    O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
    O4 - HKLM\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe
    O4 - HKLM\..\Run: [WinEssential] C:\WINDOWS\SYSTEM\KEYWORD.exe
    O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe
    O4 - HKLM\..\Run: [MSN Manager] C:\WINDOWS\mscmgr.exe
    O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [Installer] C:\WINDOWS\SYSTEM\INSTALLER.EXE
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O4 - HKCU\..\RunServices: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\RunServices: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\RunServices: [TV Media] C:\TV MEDIA\TVM.EXE
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2e529727a6ef04/housecall.antivirus.com/housecall/xscan53.cab
     
  12. nickson2

    nickson2 Master Sergeant

    no prob, go to help at top of browser then about internet explorer but it says on your log that you have IE6
     
  13. nickson2

    nickson2 Master Sergeant

  14. ComputerChallenged

    ComputerChallenged Private E-2

    Thank you. :eek:
     
  15. nickson2

    nickson2 Master Sergeant

    keep posting im sure we can sort this, or someone will :)
     
  16. nickson2

    nickson2 Master Sergeant

  17. ComputerChallenged

    ComputerChallenged Private E-2

    I'm trying to see what I can do to make my log shorter. lol And thank you so much.
     
  18. nickson2

    nickson2 Master Sergeant

    no probs :) theres so many helpfull peeps on here, just waiting to help.... GEEKS ARE GREAT
     
  19. ComputerChallenged

    ComputerChallenged Private E-2

    You guys are wonderful! I'm sure you hate computer morons like me. lol

    I hope this is shorter, but I doubt it:

    Logfile of HijackThis v1.97.7
    Scan saved at 12:38:26 PM, on 6/4/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\LEXBCES.EXE
    C:\WINDOWS\SYSTEM\RPCSS.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\ATICWD32.EXE
    C:\WINDOWS\SYSTEM\ATITASK.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\PROGRAM FILES\LEXMARKX83\ACMONITOR_X83.EXE
    C:\WINDOWS\SYSTEM\PRINTRAY.EXE
    C:\WINDOWS\MSCMGR.EXE
    C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
    C:\WINDOWS\RunDLL.exe
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
    C:\WINDOWS\TEMP\HIJACKTHIS.EXE
    R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\TV MEDIA\TvmBho.dll
    N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.huntel.net"); (C:\Program Files\Internet\Netscape\users\twelveosix\prefs.js)
    O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiKey] Atitask.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\REAL\PLAYER\REALPLAY.EXE SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [SonyC2W] C:\Program Files\Sony\ImageStation\USB Direct Connect\SonyC2W.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~2\ACMonitor_X83.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~2\AcBtnMgr_X83.exe
    O4 - HKLM\..\Run: [LexStart] Lexstart.exe
    O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
    O4 - HKLM\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe
    O4 - HKLM\..\Run: [WinEssential] C:\WINDOWS\SYSTEM\KEYWORD.exe
    O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe
    O4 - HKLM\..\Run: [MSN Manager] C:\WINDOWS\mscmgr.exe
    O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [Installer] C:\WINDOWS\SYSTEM\INSTALLER.EXE
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2e529727a6ef04/housecall.antivirus.com/housecall/xscan53.cab
     
  20. nickson2

    nickson2 Master Sergeant

    looks like you still got a lot of proggies running on startup, have you tried the thread posted earlier
     
  21. alanc

    alanc MajorGeek

    Tina, did you update Adaware and Spybot before you ran them? If not, do that.

    Also, what anti virus did you run and is it updated to the latest definitions? It looks like you've got at least one trojan. After you update/scan with Adaware/Spybot again, scan with these online virus scanners

    http://www.pandasoftware.com/activescan
    http://housecall.trendmicro.com

    and then post a new HijackThis log.
     
  22. nickson2

    nickson2 Master Sergeant

    Knew it wouldnt be long before the pro stepped in.... good one if you can post what she should fix i would be gratefull, as ive printed off her hijack file and im tryin to decipher it with the help of Sysinfo.org and Merijn.org. Then i will know if im learning or not..
     
  23. nickson2

    nickson2 Master Sergeant

    and are them C:\WINDOWS\SYSTEM\********* etc applications that are running, some of which can be cancelled/ended before log is posted?
     
  24. alanc

    alanc MajorGeek

    Well I'm not a pro, I've just learned a few things.

    IMHO, it's always best to use the good anti-spyware and anti-virus tools first to clean a system as much as possible - then look at the HJT log. Those tools will clean up a lot of baddies that show up in the log.

    The lines I don't like are:
    R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\TV MEDIA\TvmBho.dll
    O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file)
    O4 - HKLM\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe <-- I believe this is a trojan
    O4 - HKLM\..\Run: [WinEssential] C:\WINDOWS\SYSTEM\KEYWORD.exe
    O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe
    O4 - HKCU\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE

    There may be more, I didn't do a thorough check.
    Search the forums for that TV Media crap - we've seen it before but I don't remember the exact method for removing it.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Heh Alan, I was working on this too. Here is what I found:
    First you have a couple of Trojans on your PC.
    This line:
    O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe
    is the OneNet Trojan and needs to be fixed.
    See http://it.trendmicro-europe.com/consumer/security_info/ve_detail.php?Vname=TROJ_ONENET.A
    Go here and run the free online scan and clean what it finds:
    http://housecall.trendmicro.com/housecall/start_corp.asp
    Now Reboot.
    Now before running anything else (and make sure all browsers and
    Win Explorer sessions are closed) run Hijaak This again and fix
    the following:

    R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\TV MEDIA\TvmBho.dll
    O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file)
    O4 - HKLM\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O4 - HKCU\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe

    The next line is the WinEssential hijaaker.
    See http://www.kephyr.com/spywarescanner/library/winessential/index.phtml
    Fix the next line:
    O4 - HKLM\..\Run: [WinEssential] C:\WINDOWS\SYSTEM\KEYWORD.exe

    I'm not sure about mscmgr.exe. Right click on it an see if you can
    get properties to see who write it. Leave it if unsure.
    O4 - HKLM\..\Run: [MSN Manager] C:\WINDOWS\mscmgr.exe

    The below line is another Trojan, W32/Ticton-A.
    See http://www.sophos.com/virusinfo/analyses/w32tictona.html.
    Remove it if it stll exists after the previous on line scan.
    O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup

    Not sure what this next line is. I do not think it belongs there:
    O4 - HKLM\..\RunServices: [Installer] C:\WINDOWS\SYSTEM\INSTALLER.EXE
    After Hijaak This cleanup, reboot in safe mode and make sure the
    below files are gone. If not, delete them
    C:\WINDOWS\wdskctl.exe
    C:\WINDOWS\SYSTEM\KEYWORD.exe
    C:\WINDOWS\fash.exe
    C:\WINDOWS\SYSTEM\wucrtupd.exe
     
  26. Maxwell

    Maxwell Folgers

    Chas, I'm not sure where you get your information but this is the Windows Critical Update Notification application from Microsoft and is used to notify you of critical updates. See http://support.microsoft.com/default.aspx?scid=kb;en-us;224420
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your right Maxwell! Bad mistake. :eek: The one I'm referring too would be in c:\windows not c:\windows\system. Thanks for picking up on this.
     
  28. ComputerChallenged

    ComputerChallenged Private E-2

    Just a quick note before I head out. I will do all that you've suggested when I get a chance on Monday. I'll be out all weekend, so I didn't want you to think I was ignoring you nice people. Thank you for all you've done. I'll let you know as soon as I get a chance to do this.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay ComputerChallenged, but make sure you do not fix the one line that I had a mistake on. See the message below from Maxwell. The line was : O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
     
  30. ComputerChallenged

    ComputerChallenged Private E-2

    I did everything you said to. I did have one virus: ADW RULEDOR.C

    Here's my new hijack log:

    Logfile of HijackThis v1.97.7
    Scan saved at 10:08:44 PM, on 6/7/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\LEXBCES.EXE
    C:\WINDOWS\SYSTEM\RPCSS.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\ATICWD32.EXE
    C:\WINDOWS\SYSTEM\ATITASK.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\PROGRAM FILES\LEXMARKX83\ACMONITOR_X83.EXE
    C:\WINDOWS\SYSTEM\PRINTRAY.EXE
    C:\WINDOWS\MSCMGR.EXE
    C:\WINDOWS\RunDLL.exe
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\TEMP\HIJACKTHIS.EXE
    R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\TV MEDIA\TvmBho.dll
    N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.huntel.net"); (C:\Program Files\Internet\Netscape\users\twelveosix\prefs.js)
    O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file)
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiKey] Atitask.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\REAL\PLAYER\REALPLAY.EXE SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [SonyC2W] C:\Program Files\Sony\ImageStation\USB Direct Connect\SonyC2W.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~2\ACMonitor_X83.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~2\AcBtnMgr_X83.exe
    O4 - HKLM\..\Run: [LexStart] Lexstart.exe
    O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
    O4 - HKLM\..\Run: [MSN Manager] C:\WINDOWS\mscmgr.exe
    O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
    O4 - HKLM\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [Installer] C:\WINDOWS\SYSTEM\INSTALLER.EXE
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O4 - HKCU\..\RunServices: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\RunServices: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\RunServices: [TV Media] C:\TV MEDIA\TVM.EXE
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2e529727a6ef04/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.addictivetechnologies.net/DM0/cab/AESS2.cab
    O16 - DPF: {E2F2B9D0-96B9-4B25-B90C-636ECB207D18} - http://www.whenusearch.com/WUInstSECS.cab
    O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50138/QDow_AS2.cab
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay CC, looks better but you did not cleanup the TV Media stuff. Did you skip it on purpose or did it come back. See the below in your log:

    R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\TV MEDIA\TvmBho.dll
    O4 - HKLM\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
    O4 - HKCU\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
     
  32. ComputerChallenged

    ComputerChallenged Private E-2

    I didn't skip it. It came back evidently. Now what? I'm still having the same problems.
     
  33. Kodo

    Kodo SNATCHSQUATCH


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds