IE always seems to come back to "ABOUT:BLANK" no matter what I do to eliminate it. Something is also allowing a great number of popups. Can you please review this HIJACK log file and help me identify what may be causing this? It looks like there is a lot of "Junk" also being executed in the background like "rebates" etc. I've used SPYBOT, CWSHREDDER but to no avail. Thanks.
Logfile of HijackThis v1.97.7
Scan saved at 5:38:01 PM, on 7/18/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCE
S.EXE
C:\WINDOWS\system32\LEXPPS
.EXE
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentr
y.exe
C:\Program Files\MUSICMATCH\MUSICMATC
H Jukebox\mm_tray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Dell\EUSW\Support.ex
e
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\MUSICMATCH\MUSICMATC
H Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\documents and settings\ellie friedman\local settings\temp\PCGnjM2wi.ex
e
C:\WINDOWS\System32\IEHost
.exe
C:\PROGRA~1\WHENUS~1\Searc
h.exe
C:\Program Files\AutoUpdate\AutoUpdat
e.exe
C:\WINDOWS\system32\pcs\pc
svc.exe
C:\Program Files\Common Files\Dpi\dpi.exe
C:\WINDOWS\dhbrwsr.exe
C:\WINDOWS\klgt.exe
C:\PROGRA~1\INTERN~3\inetm
gr.exe
C:\Program Files\Common files\WinTools\WToolsA.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\System32\SahAge
nt.exe
C:\WINDOWS\System32\wzcdss
.exe
C:\Program Files\Dell\Support\Alert\b
in\NotifyA
lert.exe
C:\Program Files\Web_Rebates\WebRebat
es0.exe
C:\WINDOWS\System32\RUNDLL
32.EXE
C:\WINDOWS\System32\xenwsx
.exe
C:\PROGRA~1\PANICW~1\POP-U
P~1\PSFree
.exe
C:\Program Files\America Online 9.0a\aoltray.exe
C:\PROGRA~1\COMMON~1\AOL\A
CS\acsd.ex
e
C:\Program Files\Creative\SBLive\Diag
nostics\di
agent.exe
C:\WINDOWS\System32\ET11FS
.exe
C:\PROGRA~1\INTERN~3\inets
vc.exe
C:\WINDOWS\System32\ECUR32
S.exe
C:\WINDOWS\System32\cisvc.
exe
C:\WINDOWS\System32\ETEVEN
TN.exe
C:\WINDOWS\System32\CTsvcC
DA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\System32\OboZjh
0.exe
C:\WINDOWS\System32\snmp.e
xe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common files\WinTools\WToolsS.exe
C:\WINDOWS\System32\OboZjh
0.exe
C:\WINDOWS\System32\MsPMSP
Sv.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\Program Files\Web_Rebates\WebRebat
es1.exe
C:\WINDOWS\dhsvr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Ellie Friedman\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.
exe
C:\Documents and Settings\Ellie Friedman\My Documents\hijackthis\hijac
kthis\Hija
ckThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.websearch.com/ie.aspx?tb_id=3R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = about:blank
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch = res://C:\PROGRA~1\Toolbar\
toolbar.dl
l/sa
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://www.websearch.com/ie.aspx?tb_id=3R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) = about:blank
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,SearchAssist
ant =
http://www.websearch.com/ie.aspx?tb_id=3R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,CustomizeSea
rch = res://C:\PROGRA~1\Toolbar\
toolbar.dl
l/sa
R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-E
A101271BC2
5} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {00000000-0000-0000-0000-0
0000000022
1} - C:\Program Files\ClearSearch\CSIE.DLL
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4
A4827C2E4C
8} - C:\WINDOWS\nem219.dll
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8
D32436323D
9} - C:\WINDOWS\bxxs5.dll
O2 - BHO: (no name) - {046D6EA4-15E3-4b27-8010-4
5BD78A9219
E} - C:\PROGRA~1\INTERN~3\inetk
w.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {0982868C-47F0-4EFB-A664-C
7B0B101580
8} - C:\WINDOWS\System32\mskhhe
.dll
O2 - BHO: (no name) - {25F7FA20-3FC3-11D7-B487-0
0D05990014
C} - C:\WINDOWS\System32\mseggo
.gif
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6
BB168A7031
0} - C:\PROGRA~1\INCRED~1\BHO\I
NCFIN~1.DL
L
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-0
0E04C60FAF
2} - C:\WINDOWS\2_0_1browserhel
per2.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3
D5FEC94A18
3} - C:\PROGRA~1\COMMON~1\WinTo
ols\WTools
B.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3
DBE0391097
2} - C:\Program Files\Toolbar\toolbar.dll
O2 - BHO: (no name) - {9E992732-295F-4987-8BE3-1
6FAC163919
8} - C:\DOCUME~1\ALLUSE~1\APPLI
C~1\IESERV
~1\IEServi
ce.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
2.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-5
00A16B6CF9
4} - C:\Program Files\SEP\sep.dll
O2 - BHO: (no name) - {CC916B4B-BE44-4026-A19D-8
C74BBD2336
1} - C:\WINDOWS\System32\msfaol
.dll
O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A
57F0CCA1C1
3} - C:\WINDOWS\dealhlpr.dll
O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-7
20FAF53D84
1} - C:\Program Files\Common Files\midaddle\midaddle.dl
l
O2 - BHO: (no name) - {FCADDC14-BD46-408A-9842-C
DBE1C6D37E
B} - C:\WINDOWS\System32\msnkmi
.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: Band Class - {D848A3CA-0BFB-4DE0-BA9E-A
57F0CCA1C1
3} - C:\WINDOWS\dealhlpr.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-5
00A16B6CF9
4} - C:\Program Files\SEP\sep.dll
O3 - Toolbar: zSearch Bar - {5886A6DC-AAF4-45E9-979A-8
E5E6DEE30E
7} - C:\Program Files\zSearch\zSearch.dll (file missing)
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-2
9EA915965E
C} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diag
nostics\di
agent.exe"
startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentr
y.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATC
H Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.ex
e
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATC
H Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [PCGnjM2wi] C:\documents and settings\ellie friedman\local settings\temp\PCGnjM2wi.ex
e
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Cax65.
exe
O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\System32\IEHost
.exe
O4 - HKLM\..\Run: [WhenUSearch] "C:\PROGRA~1\WHENUS~1\Sear
ch.exe"
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdat
e.exe"
O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pc
svc.exe
O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRu
n
O4 - HKLM\..\Run: [DealHelperUpdate] C:\WINDOWS\DHUpdt.exe
O4 - HKLM\..\Run: [DealHelperBrwsr] C:\WINDOWS\dhbrwsr.exe
O4 - HKLM\..\Run: [dpbvi] C:\WINDOWS\klgt.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\w
hSurvey.ex
e"
O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~3\inetm
gr.exe
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [webHancer Agent] "C:\Program Files\webHancer\Programs\w
hAgent.exe
"
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\System32\SahAge
nt.exe
O4 - HKLM\..\Run: [ps6k39g] wzcdss.exe
O4 - HKLM\..\Run: [mswspl] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Bargains] C:\Program Files\Bargain Buddy\bin\bargains.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebat
es0.exe"
O4 - HKLM\..\Run: [ET11FS] C:\WINDOWS\System32\ET11FS
.exe
O4 - HKLM\..\Run: [ECUR32S] C:\WINDOWS\System32\ECUR32
S.exe
O4 - HKLM\..\Run: [ETEVENTN] C:\WINDOWS\System32\ETEVEN
TN.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTR
AY.DLL,NvT
askbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [FreeMem Pro] "C:\PROGRA~1\FREEME~1\Fmem
pro.exe" autostart
O4 - HKCU\..\Run: [ClockSync] "C:\PROGRA~1\CLOCKS~1\Sync
.exe" /q
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msgked
.exe
O4 - HKCU\..\Run: [YBpqRVM5R] xenwsx.exe
O4 - HKCU\..\Run: [zSearch] C:\Program Files\zSearch\Zstb.exe
O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLI
C~1\IESERV
~1\IEServi
ce.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-
UP~1\PSFre
e.exe"
O4 - HKLM\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: America Online Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
2.dll/cmse
arch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar
2.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar
2.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar
2.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
2.dll/cmtr
ans.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\T
p1150\scri
1150a.htm
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.
dll
O16 - DPF: Yahoo! Euchre -
http://download.games.yahoo.com/games/clients/y/et1_x.cabO16 - DPF: {33564D57-0000-0010-8000-0
0AA00389B7
1} -
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CABO16 - DPF: {89D75D39-5531-47BA-9E4F-B
346BA9C362
C} (CWDL_DownLoadControl Class) -
http://www.callwave.com/include/cab/CWDL_DownLoad.CAB