1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

IE/Outlook Express Gone Graxy

Discussion in 'Web & Email' started by referee07, Sep 14, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,374
    Something has happened to my IE/Outlook Express and I think it might be a virus, although I have run my antivirus program, AVG, which has found nothing. For no apparent reason, while I am serfing the web, the font size will change or my mouse/keyboard will not respond. Also, for some reason, LYCOS has appeared and although I have attempted to get rid of it several times, it shows up again! I have Zone Alarm and Spy Blocker but still get unwanted ads. Do you think I have a virus? If so, is AVG a good antivirus program? Thanks.

    :confused:
     
  2. e-liam

    e-liam

    Joined:
    Jun 19, 2003
    Messages:
    1,241
    Hi referee07, and welcome to TSG.. :)

    Although there's a chance that it could be a virus, if an updated AVG didn't find it, then it is more likely to be spy/adware, especially as you mention getting popups.

    Could you please download 'Hijack This!' from http://www.spywareinfo.com/files/hijackthis.zip
    Unzip, doubleclick HijackThis.exe, and hit "Scan".
    When the scan is finished, click "Save Log", and copy and paste it in a reply.

    This will give us a rundown of what’s going on in your PC. One of us here will be glad to analyse it for you. Don’t fix anything yourself yet, as a lot of the stuff on that list will be harmless or required. If there is an evasive virus or trojan lurking, it should also show itself.

    Cheers

    Liam

    The edit... :) Yes AVG is about as good as they come, as long as you regularly update the definitions. (y)
     
  3. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,374
    Liam, thanks. I will do that. BTW, which is your favorite soccer team?
     
  4. e-liam

    e-liam

    Joined:
    Jun 19, 2003
    Messages:
    1,241
    No problem referee.. :)

    I don't really watch football much, referee; but if I was tied to the chair in front of the telly and forced to watch, I think I'd prefer it to be Manchester Utd. vs Chelsea. (With Chelsea losing 15-0) :D

    Cheers

    Liam
     
  5. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,374
    Thanks.:p
     
  6. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,374
    Liam, this is the result of my using Hijack This. Thanks for helping.




    Logfile of HijackThis v1.97.1
    Scan saved at 5:50:46 PM, on 9/14/2003
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\GEARSEC.EXE
    C:\WINDOWS\system32\ZONELABS\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\SpyBlocker Software\spyblocker.exe
    C:\WINDOWS\System32\qttask.exe
    C:\Program Files\QUICKENW\QAGENT.EXE
    C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    C:\Program Files\PestPatrol\PPControl.exe
    C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    C:\WINDOWS\System32\RunDll32.exe
    C:\WINDOWS\System32\carpserv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Media\Media\UpdateStats.exe
    C:\WINDOWS\System32\mrtMngr.EXE
    C:\WINDOWS\System32\rundll32.exe
    C:\WINDOWS\MSMGT.exe
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
    C:\Program Files\ClearSearch\Loader.exe
    C:\WINDOWS\System32\OqxOq.exe
    C:\WINDOWS\System32\EsdH.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Documents and Settings\Carl Neighbors\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchassistant.iwon.com/srchlft.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchassistant.iwon.com/srchlft.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll
    O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C:\Program Files\Lycos\Sidesearch\sidesearch1211.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {2CF0B992-5EEB-4143-99C0-5297EF71F443} - C:\WINDOWS\System32\stlbdist.dll
    O2 - BHO: (no name) - {2E214705-BDAF-4830-B444-63CCD77AA524} - C:\WINDOWS\System32\igasads.dll
    O2 - BHO: Clear Search - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\Program Files\ClearSearch\IE_ClrSch.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Search - {2CF0B992-5EEB-4143-99C0-5297EF71F444} - C:\WINDOWS\System32\stlbdist.dll
    O3 - Toolbar: (no name) - {FE6A5095-C616-40CF-B33C-34A9854A0E20} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SpyBlocker] C:\Program Files\SpyBlocker Software\spyblocker.exe
    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
    O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
    O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe
    O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [UpdateStats] C:\Program Files\Media\Media\UpdateStats.exe
    O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-5297EF71F444}] rundll32.exe C:\WINDOWS\System32\stlbdist.dll,DllRunMain
    O4 - HKLM\..\Run: [5BGB87A2Y5ZCER] C:\WINDOWS\System32\MtyJ62F.exe
    O4 - HKLM\..\Run: [MSMGT] C:\WINDOWS\MSMGT.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
    O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe
    O4 - HKLM\..\Run: [msbb] c:\msbb.exe
    O4 - HKLM\..\Run: [RunWindowsUpdate] C:\WINDOWS\uptodate.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O9 - Extra button: Sidesearch (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
     
  7. Miz

    Miz

    Joined:
    Jul 1, 2002
    Messages:
    2,146
    A superficial look-over of your Hijack This log shows that you have some spyware which you should get rid of.

    Try downloading, installing, immediately updating and running Spybot and/or AdAware (I prefer Spybot but I use them both about once a week) Let them clean up any spyware they find.

    It also shows you have some unnecessary processes running. Turning off XP's unnecessary services does wonders. It takes a little time but it's well worth it in terms of better system performance and online security.

    There are numerous guides online for which services to turn off, which to set to manual and which to leave on automatic but I've found the guide on Black Viper's site the easiest to read...and the links to explanations of each service are handy.
     
  8. e-liam

    e-liam

    Joined:
    Jun 19, 2003
    Messages:
    1,241
    Hi referee07,

    Are you sure that that is all of the HJT! log? It seems to run out before the end. There should normally be a few 016 rereferences at the end, and possibly more.

    I can see the stuff that is giving you problems, and can get rid of it for you, but unless I see all the log, the chances are that you will get the same problems next time you boot up, so if you just confirm for me if thaTt is the entire log, I'd be gratefull.

    If that is all there is, then fine, it just doesn't look right. :)

    Cheers

    Liam

    Cheers

    Liam
     
  9. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,374
    I will try cutting and pasting again to see if the same information is obtained. Thanks.

    Logfile of HijackThis v1.97.1
    Scan saved at 3:50:06 PM, on 9/15/2003
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\SpyBlocker Software\spyblocker.exe
    C:\WINDOWS\System32\qttask.exe
    C:\Program Files\QUICKENW\QAGENT.EXE
    C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    C:\Program Files\PestPatrol\PPControl.exe
    C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    C:\WINDOWS\System32\RunDll32.exe
    C:\WINDOWS\System32\carpserv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Media\Media\UpdateStats.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\WINDOWS\System32\mrtMngr.EXE
    C:\WINDOWS\MSMGT.exe
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
    C:\Program Files\ClearSearch\Loader.exe
    C:\WINDOWS\uptodate.exe
    C:\Program Files\Common files\KeenValue\KeenValue.exe
    C:\Program Files\SuperBar\sbhc.exe
    C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
    C:\Program Files\Altnet\Points Manager\Points Manager.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\GEARSEC.EXE
    C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
    C:\WINDOWS\system32\ZONELABS\vsmon.exe
    C:\WINDOWS\System32\EsdH.exe
    C:\WINDOWS\System32\FnwN9.exe
    C:\Program Files\Common files\KeenValue\KWM.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Carl Neighbors\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchassistant.iwon.com/srchlft.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchassistant.iwon.com/srchlft.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll
    O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C:\Program Files\Lycos\Sidesearch\sidesearch1211.dll
    O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {136A9D1D-1F4B-43D4-8359-6F2382449255} - C:\Program Files\SuperBar\SuperBar.Dll
    O2 - BHO: (no name) - {2CF0B992-5EEB-4143-99C0-5297EF71F443} - C:\WINDOWS\System32\stlbdist.dll
    O2 - BHO: (no name) - {2E214705-BDAF-4830-B444-63CCD77AA524} - C:\WINDOWS\System32\igasads.dll
    O2 - BHO: Clear Search - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\Program Files\ClearSearch\IE_ClrSch.DLL
    O2 - BHO: (no name) - {B1F3DF3E-9042-4D2D-8F49-E5CAE5079BB4} - C:\WINDOWS\System32\raesmontr.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Search - {2CF0B992-5EEB-4143-99C0-5297EF71F444} - C:\WINDOWS\System32\stlbdist.dll
    O3 - Toolbar: (no name) - {FE6A5095-C616-40CF-B33C-34A9854A0E20} - (no file)
    O3 - Toolbar: SuperBar - {C876AC3D-A818-47F4-B7DE-88A394A26348} - C:\Program Files\SuperBar\SuperBar.Dll
    O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SpyBlocker] C:\Program Files\SpyBlocker Software\spyblocker.exe
    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
    O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
    O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe
    O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [UpdateStats] C:\Program Files\Media\Media\UpdateStats.exe
    O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-5297EF71F444}] rundll32.exe C:\WINDOWS\System32\stlbdist.dll,DllRunMain
    O4 - HKLM\..\Run: [5BGB87A2Y5ZCER] C:\WINDOWS\System32\LhoK8W3.exe
    O4 - HKLM\..\Run: [MSMGT] C:\WINDOWS\MSMGT.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
    O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe
    O4 - HKLM\..\Run: [RunWindowsUpdate] C:\WINDOWS\uptodate.exe
    O4 - HKLM\..\Run: [KeenValue] C:\Program Files\Common files\KeenValue\KeenValue.exe
    O4 - HKLM\..\Run: [SBHC] C:\Program Files\SuperBar\sbhc.exe
    O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
    O4 - HKLM\..\Run: [AltnetPointsManager] C:\Program Files\Altnet\Points Manager\Points Manager.exe -s
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: KeenValue.lnk = C:\Program Files\Common Files\KeenValue\keenvalue.exe
    O9 - Extra button: Sidesearch (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)

    This is it. I hope this is the information you need.

    BTW, just now it appeared that IE stopped working, i.e., I tried to place the curser and nothing happend for several tries.
     
  10. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,374
    Liam, als
     
  11. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,374
    Liam, also, the caps lock locks at will, the curser disappears and the color changes on the screen and Kazza and P2P are back. (my son has been on the computer and probably downloaded them.) Also, the "plopping" sound has come back. Thanks.
     
  12. e-liam

    e-liam

    Joined:
    Jun 19, 2003
    Messages:
    1,241
    Hi referee,

    Just going out for an hour or so, but I'll get you sorted out on my return. There's a fair bit of junk there that'll cause your problems, but we'll get rid of it. :) (y)

    Catch you in a bit.

    Cheers

    Liam
     
  13. e-liam

    e-liam

    Joined:
    Jun 19, 2003
    Messages:
    1,241
    Hi referee,

    Could you please run a new HJT! log, and "check to fix" the following entries. Next, close all browser windows, and click Fix

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchassistant.iwon.com/srchlft.html

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchassistant.iwon.com/srchlft.html

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll

    O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C:\Program Files\Lycos\Sidesearch\sidesearch1211.dll

    O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL

    O2 - BHO: (no name) - {136A9D1D-1F4B-43D4-8359-6F2382449255} - C:\Program Files\SuperBar\SuperBar.Dll

    O2 - BHO: (no name) - {2CF0B992-5EEB-4143-99C0-5297EF71F443} - C:\WINDOWS\System32\stlbdist.dll

    O2 - BHO: (no name) - {2E214705-BDAF-4830-B444-63CCD77AA524} - C:\WINDOWS\System32\igasads.dll

    O2 - BHO: Clear Search - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\Program Files\ClearSearch\IE_ClrSch.DLL

    O2 - BHO: (no name) - {B1F3DF3E-9042-4D2D-8F49-E5CAE5079BB4} - C:\WINDOWS\System32\raesmontr.dll

    O3 - Toolbar: Search - {2CF0B992-5EEB-4143-99C0-5297EF71F444} - C:\WINDOWS\System32\stlbdist.dll

    O3 - Toolbar: (no name) - {FE6A5095-C616-40CF-B33C-34A9854A0E20} - (no file)

    O3 - Toolbar: SuperBar - {C876AC3D-A818-47F4-B7DE-88A394A26348} - C:\Program Files\SuperBar\SuperBar.Dll

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe

    O4 - HKLM\..\Run: [5BGB87A2Y5ZCER] C:\WINDOWS\System32\LhoK8W3.exe

    O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe

    O4 - HKLM\..\Run: [RunWindowsUpdate] C:\WINDOWS\uptodate.exe

    O4 - HKLM\..\Run: [KeenValue] C:\Program Files\Common files\KeenValue\KeenValue.exe

    O4 - HKLM\..\Run: [SBHC] C:\Program Files\SuperBar\sbhc.exe

    O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe

    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

    O4 - HKLM\..\Run: [AltnetPointsManager] C:\Program Files\Altnet\Points Manager\Points Manager.exe -s

    O4 - Global Startup: KeenValue.lnk = C:\Program Files\Common Files\KeenValue\keenvalue.exe


    Then reboot and delete the following bolded files/folders...

    C:\Program Files\Common files\KeenValue
    C:\Program Files\SuperBar
    C:\Program Files\ClearSearch
    C:\WINDOWS\System32\P2P Networking
    C:\WINDOWS\System32\EsdH.exe
    C:\WINDOWS\System32\FnwN9.exe
    C:\WINDOWS\System32\stlbdist.DLL
    C:\WINDOWS\uptodate.exe

    Next, reboot.... again and download Spybot - Search & Destroy, from www.tomcoyote.org/spybot : if you haven't already got the program.

    Now press Settings, and Settings again.
    Go to the Webupdate section, and check "Display also available beta versions".

    Now press Online, and search for, put a check mark at, and install all updates.

    Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all it finds marked RED.


    Finally. reboot. Rebooting. although tedious, has to be done. :)

    Then if you could post a new HJT! log, just for a final once over.

    Cheers

    Liam
     
  14. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,374
    Quick question. I have Pest Patrol, Zone Alarm and Spy Blocker and delete many of the spyware, adware, etc, that finds its way into my computer only to find that it is back! I thought Pest Patrol and Spy Blocker would be able to stop this stuff. Can you suggest ways I can tune-up my spyware programs to better prevent spyware, adware, etc. from downloading without my permission? Many thanks.
     
  15. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,374
    Sorry... but... I just noticed that a "Power Search" searchbar is now at the top of my IE desktop. Is there a way to stop this stuff once and for all with an exceptional program. Thanks... again.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/164734

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice