Have you tried malwarebytes anti-malware?
http://www.download.com/Ma
Main Topics
Browse All TopicsI have done every scan known to man & it found nothing? I have run my a/v and nothing? I have went thru my registry and nothing? I did find this: mediaactivextask.com and castolecops says it is malware?
but none of my scans found nothing?
Here is a hjt log from today:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:24:22 AM, on 10/16/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\tasken
C:\Windows\system32\Dwm.ex
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.ex
C:\Users\The Smith's\AppData\Local\Goog
C:\Windows\ehome\ehtray.ex
C:\Windows\system32\wbem\u
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.ex
C:\Windows\System32\mobsyn
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
R0 - HKCU\Software\Microsoft\In
R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7
O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-F
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-3
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-B
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast
O4 - HKCU\..\Run: [P2kAutostart] V49E
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.ex
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4I
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: @C:\Windows\WindowsMobile\
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-1
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-1
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D
O16 - DPF: {0E5F0222-96B9-11D3-8997-0
O16 - DPF: {30528230-99f7-4bb4-88d8-f
O16 - DPF: {406B5949-7190-4245-91A9-3
O16 - DPF: {459E93B6-150E-45D5-8D4B-4
O16 - DPF: {48DD0448-9209-4F81-9F6D-D
O16 - DPF: {49312E18-AA92-4CC2-BB97-5
O16 - DPF: {917623D1-D8E5-11D2-BE8B-0
O16 - DPF: {9600F64D-755F-11D4-A47F-0
O16 - DPF: {D0C0F75C-683A-4390-A791-1
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SAS
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\48
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aa
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSr
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\Pyt
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.ex
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.e
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponde
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-0610
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\48
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
--
End of file - 10234 bytes
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Have you tried malwarebytes anti-malware?
http://www.download.com/Ma
Have you removed this entry with HiJackthis in Safe Mode?
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4I
You might also try Spybot Search and Destroy from here. (Free)
http://www.safer-networkin
Download it, update it and run it in Safe Mode.
I used adaware, spybot s&d, malwarebytes, superantispyware, and then i ran my antivirus too!
they would find minor stuff and remove; i then ran hijack this and sent the log here!!
this thing is hateful; it loads one time then it may let me search google the next time? but its like if i do a search for something and the link i click on; carries e to the ask.com search sites results then?
kinda crazy!
i dont kno how to post scans from any except for hijack this?
thanks!
Maybe I've missed something, but as this is about you're issue, rather than mine!.. I'll ask anyway!
When you've started "Something keeps redirecting my search to ask.com" what do you exactly mean?
1) That when searching in Google.com, that it then redirects to Ask.com?
2) That IE7 Search Bar goes to Ask.com, although Google is listed?
on my ie the top right search bar has search powered by ask.com in it even tho i have removed it many times it keeps coming right back. i set google as default and remove ask but it returns by the next reboot?
and yes when i search google and then click on a link they show; it then redirects me to ask search results????
so really it is doing both!!!!
i am at wits end with this; i have tried everything??
thanks in advance for the advice!
To the right of the IE7 search bar there is the search icon (magnifying glass) then a down arrow icon to choose the search provider. I'm assuming that this is the option that you are using to change and remove?
I'm suspecting that there is a permissions issue with the settings in the registry that list these options. This would prevent the changes from sticking. I'm unsure without checking, but I suspect that these option are user.dat related. i.e. profile user profile defined.
1) Try creating a new admin level user. (I'm assuming that you're on XP).
2) Log-on with the new one, then check/change delete ask.com - if present.
If the issue goes away, then it a profile related issue. Creating a new profile will fix. Also finding the registry keys that hold this info and ensuring that the user can modify/delete should also fix it, which is the preferred option.
Let me know the result.
Zenassist
i unloaded webshots; tried an older version but same problem?
honestly i think it is something to do with internet explorer; and reason it happens in firefox is because i setup internet explorer options in firefox too? it copied alot of my stuff to it from ie?
can i remove ie and reinstall? or will it cause more problems to try this?
Run services.msc then look to see if you have AG windows service. If so then stop it, then disable it.
Then - run Regedit and browse to HKEY_LOCAL_MACHINE\SYSTEM\
IMPORANT - Back up the key AGWinService by exporting it.
Delete the key AGWinService.
Did you by any chance download the Kiwee toolbar?
I am certain its the AG Windows Service.... My Hijack this logs also had AG Windows Service...
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\Pyt
&
R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5
If you just run Hijack This and delete them without stopping the service, it just recreates itself...
Ok I finally got Dell to do a online session & the did several things. The one I think has made the most difference is reverting to IE7..... i had updated and ie8 beta was in it? so far i have not seen ask.com
I will wait a day or two & let you know if its gone! If so I will close this out!!!
I hope it works!
I had this problem after I installed Webshots Desktop.
Followed instructions above - and it got rid of "Ask" -
1. Stopped and Disabled the AG windows service.
2. Removed the AGWinService key from HKEY_LOCAL_MACHINE\SYSTEM\
3. In IE7-Options-Search Default, set Google as default and deleted Ask.
4. Reboot - Fixed
Business Accounts
Answer for Membership
by: Admin3kPosted on 2008-10-16 at 08:40:02ID: 22732393
Some signs of hijack that can be removed using HJT
E.dll/MENU SEARCH.HTM
0\G2AWinLo gon.dll (file missing) 58798DCC11 8} - (no file) A8D5E23E04 5} - (no file)
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4I
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\48
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-B
I am not sure regarding this entry, if this is something you know what it is , then you can safely ignore it, if not , then I would suggest fixing it using HJT.
O4 - HKCU\..\Run: [P2kAutostart] V49E
once done you may want to empty your browser cache & try again, if the problem persists please post another HJT log.