Need help please

I decided to go ahead and delete the SpyWare Doctor and registry cleaner I had downloaded previously from pcworld. com and went with the beclean cleaner as given by one of the links in Spyros’s post. I have run SpyBot, AdAware and CCleaner before going online, and ran the registry cleaner as I was online. I also ran a hijack this log and am posting it here to see if the registry cleaner did its thing and to show that the two items to be removed as mentioned by Spyros have been removed so here it is:

Logfile of HijackThis v1.99.1
Scan saved at 7:57:23 PM, on 3/31/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MSNDELL\MSNCOREFILES\MSN6.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\WUAUCLT.EXE
C:\PROGRAM FILES\HIJACK\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/slv/ycheck/as/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/slv/ycheck/as/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bluesnews.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/slv/ycheck/as/*http://search.yahoo.com/search?p=%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM..\Run: [SystemTray] SysTray.Exe
O4 - HKLM..\Run: [Zone Labs Client] “C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe”
O4 - HKLM..\Run: [LoadQM] loadqm.exe
O4 - HKLM..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 - HKLM..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKLM..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU..\Run: [msnmsgr] “C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE” /background
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.dellnet.com
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = nbc.educorp.edu
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 192.168.1.182,192.168.1.181

It seems like it is much smaller than it has been in previous posts, so maybe things are getting to where they should be? Also, I am thinking I should go ahead and do the script fix as mentioned in a previous post but I notice it said it is for IE 5.5 and I have version 6. Should I go ahead and perform that fix?

I went through all of the server controls also in ZoneAlarm and made sure that no programs had server rights but I could swear that sometimes I check to make sure that the settings haven’t changed and it seems like sometimes it does??? Does anyone have any ideas on how to check to see if someone is still connected/connecting to my computer?

Thanks

Hi dondasch,


THESE ITEMS ARE EITHER HARMFULL OR A SECURITY RISK
WE STRONGLY RECOMMEND TO FIX THEM :

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)


THE FOLLOWING ITEMS ARE NOT NEEDED TO LOAD
AT BOOTTIME FOR THE SYSTEM TO WORK PROPERLY :

O4 - HKLM..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s

Also i would be very suspicious of ‘C:[i]WINDOWS[/i][b]WUAUCLT.EXE[/b]’ as it is suppost to be located in 'c:\windows[i]system32[/i]', so it could well be a virus, i suggest you research it.

–lee

Hi lee,

on Win ME, a \System32\ folder would imho be even more suspicious than a wuauclt.exe
http://www.liutilities.com/products/wintaskspro/processlibrary/wuauclt/
:wink:

Hi whocares,

I went to that exact page, then decided it didn’t give enough info, so i then ventured here: http://www.neuber.com/taskmanager/process/wuauclt.exe.html

I then decided it was bad that it being in the C:\windows folder was bad.

–lee

Well,
sometimes it pays to know german: :wink:
Bei Windows ME befindet sich wuauclt.exe in c:\windows und nicht in c:\windows\system32. Siehe auch die Microsoft-Website. See also: Link


With Windows ME wuauclt.exe is in c:\windows and not in c:\windows\system32. See also the Microsoft Website. Lake thus: Left

http://support.microsoft.com/kb/312477/EN-US/

Ahh, i see, i never understood why ME seemed so different to other OS’s, fair enough, looks genuine enough then.

–lee

Hi all. I deleted the two files that Hijack this brought up and that Lee mentioned and will post another log shortly. I am wondering though, is the file WUAUCLT.EXE’ one that I shouldn’t worry about? It looks as though there was some discussion but that it turned out being ok to have this on the PC. Is that right?

Also, I have a question on the script fix relating to IE that was posted some time back on this thread. Will the fix that applies to IE 5.5 also be ok to use on IE 6? Am wondering about this due to the different version numbers along with IE still locking my PC up whenever I try to open it. A thin green bar will go across the top of my screen and I will see the Avast script blocker come up.

Here is hijack this:

Logfile of HijackThis v1.99.1
Scan saved at 11:19:43 AM, on 4/2/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\WUAUCLT.EXE
C:\PROGRAM FILES\MSNDELL\MSNCOREFILES\MSN6.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\HIJACK\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/slv/ycheck/as/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/slv/ycheck/as/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bluesnews.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/slv/ycheck/as/*http://search.yahoo.com/search?p=%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM..\Run: [SystemTray] SysTray.Exe
O4 - HKLM..\Run: [Zone Labs Client] “C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe”
O4 - HKLM..\Run: [LoadQM] loadqm.exe
O4 - HKLM..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 - HKLM..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKLM..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU..\Run: [msnmsgr] “C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE” /background
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.dellnet.com
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = nbc.educorp.edu
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 192.168.1.182,192.168.1.181

Thanks all.

Forgot to post this in previous post, sorry.

When I click on the IE logo it briefly brings me up to my homepage, then I get the avast script error notification followed by lockup with green bar at the top.

I also get the following errors. When I log onto IE, it will go directly to blue screen and instruct me to CTRL ALT DEL but also says that I can press any key to continue and gives me error messages. The two I have written down are:

Error: 0D: 1004: 00000102
Error: 06: 0000: 00000813

Hi,

seems rather clean so far…

some more tips:

  • scan with ESCAN

  • install & use the newest SUN-JAVA-VM

  • secure your browser: use the Zone model, disable scripting & activeX except for known secure sites …
    or better use a more secure browser: Mozilla, Firefox, Opera, Netscape

  • make sure you have all the windowsupdates

More details on the above can be found in link “VirusRemoval” below

  • check your firewall settings (read FW-help/docu first) if you still experience problems with avast updating

:wink: