Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Mssearchnet.exe and fat.exe
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Mssearchnet.exe and fat.exe  
Forum Quick Jump
 
New Topic Post reply to : Mssearchnet.exe and fat.exe Printable version of : Mssearchnet.exe and fat.exe
[ << Previous Thread | Next Thread >> ]

Shack
New Member


Date Joined Dec 2005
Total Posts : 1
 
   Posted 12-7-2005 1:40 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
i have mssearchnet.exe infecting my computer i deleted it through dos out of windows\prefetch and windows\system32 but it just keeps coming back anybody have some suggestions on how to get this off also i have fat.exe and i deleted from windows\prefetch but im not sure if that was enough to fully get rid of that so if i did that right let me know if not let me know again thank you
Back to Top
 

dcdoode7
New Member


Date Joined Dec 2005
Total Posts : 1
 
   Posted 12-14-2005 3:29 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
hello,
just to make sure, if mssearchnet.exe is the spyware/malware that shows up as a windows upgrade globe in the icontray, and when you click the "upgrade baloon" you are forwarded to www.spyaxe.com, if it is, then there are multiple scans to complete.  www.ewido.com is an excellent 14 day trial.  also, http://www.safer-networking.org/en/download/index.html is spybot S&D 1.4 is an excellent spyware detector/cleaner.  if this is what i think it is, then we will get rid of it ASAP, and these scans will help dramatically.  if possible, can u post a screen shot of where you see mssearchnet.exe?
 
thx hope these help. 
Back to Top
 

Mihai GT
New Member




Date Joined Aug 2004
Total Posts : 32
 
   Posted 12-14-2005 3:35 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
Hello there,
 
 
Please do the following in order for me to provide more accurate advice:
 
1. Download the "hijackthis.exe" file onto your computer. The attachment is an archive, not the actual executable file. Download it from
2. Run the "hijackthis.exe" file and a new window will appear. In that new window please click on the button that says "Do a system scan and save a logfile".
3. After the program finishes searching for abnormal objects, the logfile will be saved automatically in the same folder in which you have placed the contents of the archive.
4. Open the log, and then copy it and paste it on the forum... will need that log
 
Then, you should disabl the following Windows service if you use Windows XP (or any version above):
 
1. click START->RUN
2. type "services.msc"
3. in the Services window locate the Windows service named MESENGER
4. right click it and choose Properties
5. STOP the service and put it to the DISABLED mode - this is the cause for a lot of pop-ups that pop on your screen
Now, will need to see the Hijack This report.


Mihai Gherghelescu | Support Team
mihai@bullguard.com

Back to Top
 

BooGiE_MaN
New Member


Date Joined Dec 2005
Total Posts : 1
 
   Posted 12-21-2005 5:26 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
Hi Mahai

I found this forum by Google. Here is my log file from Hijack This

Logfile of HijackThis v1.99.1
Scan saved at 06:20:44 PM, on 2005/12/21
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINTEMP\System32\smss.exe
C:\WINTEMP\system32\winlogon.exe
C:\WINTEMP\system32\services.exe
C:\WINTEMP\system32\lsass.exe
C:\WINTEMP\system32\svchost.exe
C:\WINTEMP\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINTEMP\Explorer.EXE
C:\WINTEMP\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINTEMP\System32\nvsvc32.exe
C:\WINTEMP\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINTEMP\system32\fxssvc.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\WINTEMP\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINTEMP\SOUNDMAN.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINTEMP\System32\rundll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINTEMP\System32\nvctrl.exe
C:\WINTEMP\System32\WISPTIS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
c:\wamp\wampserver.exe
c:\wamp\apache\Apache.exe
c:\wamp\apache\Apache.exe
c:\wamp\MySQL\bin\mysqld-nt.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\WINTEMP\System32\dwwin.exe
C:\WINTEMP\System32\mssearchnet.exe
C:\Program Files\Common Files\Symantec Shared\NMain.exe
C:\DOCUMENTS AND SETTINGS\USER\DESKTOP\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.za/
R3 - Default URLSearchHook is missing
O2 - BHO: HomepageBHO - {1ca480cd-c0e5-4548-874e-b85b17905b3a} - C:\WINTEMP\System32\hp606F.tmp
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINTEMP\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINTEMP\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINTEMP\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINTEMP\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [MSConfig] C:\WINTEMP\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINTEMP\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpyAxe] C:\Program Files\SpyAxe\spyaxe.exe /h
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4EDE1544-37BC-4C50-AD6A-3DA5F618721D}: NameServer = 168.210.2.2 196.14.239.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA66B9C3-DCC8-4770-B480-A2891646BD5E}: NameServer = 111.112.113.114,211.212.213.214
O17 - HKLM\System\CS1\Services\Tcpip\..\{4EDE1544-37BC-4C50-AD6A-3DA5F618721D}: NameServer = 168.210.2.2 196.14.239.2
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINTEMP\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINTEMP\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: wampapache - Unknown owner - c:\wamp\apache\Apache.exe" --ntservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\MySQL\bin\mysqld-nt.exe


What do I do??? confused
Back to Top
 

Yettie
New Member


Date Joined Dec 2005
Total Posts : 5
 
   Posted 12-22-2005 9:54 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
i am so glad i found this forum, i got the same thing except i only got mssearchnet.exe. the thing is irritating and i went to noton's website and they said to turn off windows restore and run norton's system scan but that didn't pick up anythingconfused  i use spybot 1.4 regulary and its helped me alot so far but all it picks up is smitfraud and it says HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\nvctrl.exe
 
anybody got any ideas?
Back to Top
 

AgentArchangel
New Member


Date Joined Jan 2006
Total Posts : 1
 
   Posted 1-3-2006 4:30 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
According to FProt Antivirus, the three problematic files still left on my computer after numerous scans through Hijack This, Ewido, Ad Aware, and Spybot are as follows:

hpqaf9d.tmp
mssearchnet.exe
nvctrl.exe

I can' t remove them because supposedly a program is already using them even when i'm off the internet. Could someone please tell me how I remove these files and what else is a problem to my computer that I might not be aware about? Here's the latest HijackThis! log i have.

Logfile of HijackThis v1.99.1
Scan saved at 9:22:28 PM, on 1/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\FSI\F-Prot\fpavupdm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Novell\ZENworks\nalntsrv.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Novell\ZENworks\wm.exe
C:\Program Files\Novell\ZENworks\WMRUNDLL.EXE
C:\WINDOWS\System32\Novell\XTAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\system32\nvctrl.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\AOL\1132177429\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\ewido anti-malware\SecuritySuite.exe
C:\Program Files\FSI\F-Prot\F-StopW.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.notrly.com/jackbauer/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpAF9D.tmp
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [KeyAccess] C:\WINDOWS\keyacc32.exe
O4 - HKLM\..\Run: [F-StopW] C:\Program Files\FSI\F-Prot\F-StopW.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1132177429\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Application Explorer.lnk = C:\Program Files\Novell\ZENworks\NalView.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: KeyAccess.lnk = C:\WINDOWS\keyacc32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Novell Messenger - {3C3171BC-1025-43d1-8D1D-61CF4B38A28F} - C:\Novell\MESSEN~1\NMCL32.exe
O9 - Extra 'Tools' menuitem: Novell Messenger - {3C3171BC-1025-43d1-8D1D-61CF4B38A28F} - C:\Novell\MESSEN~1\NMCL32.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program Files\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ad.drew.edu
O17 - HKLM\Software\..\Telephony: DomainName = ad.drew.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ad.drew.edu
O18 - Protocol: nim - {3D206AE2-3039-413B-B748-3ACC562EC22A} - C:\Novell\Messenger\nmcg32.dll
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
O20 - AppInit_DLLs: KATRACK.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NetIdentity Notification - C:\WINDOWS\system32\Novell\XtNotify.dll
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: F-Prot Antivirus Update Monitor - FRISK Software - C:\Program Files\FSI\F-Prot\fpavupdm.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\Program Files\Novell\ZENworks\nalntsrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Novell XTier Agent Services (XTAgent) - Novell, Inc. - C:\WINDOWS\System32\Novell\XTAgent.exe
O23 - Service: Workstation Manager (ZFDWM) - Novell, Inc. - C:\Program Files\Novell\ZENworks\wm.exe
Back to Top
 

lyonpride
New Member


Date Joined Jan 2006
Total Posts : 1
 
   Posted 1-3-2006 9:40 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
I too was infected by mssearchnet (very annoying) and used AVG 7.1 Professional (Free 30 day trial) to get rid of it.  It found a few malware applets that Ad Aware and Spybot missed.  Good luck.
Back to Top
 

manu4ever88
New Member


Date Joined Jan 2006
Total Posts : 1
 
   Posted 1-4-2006 12:26 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
yeah i got rid of it once just by sheer luck becuase it was takign a long time to open when i checked in task manager, so i went ot system32 where it was located in mine and deleted it before it could start.... but then like two days later it came back and i duno how.... !!!! thing. it was with spyaxe but i got rid of spyaxe using another program that found and got rid of the trojan, so now it's just mssearchnet.exe thatn eeds to be removed. avg doesn't find anything, neither does norton, or spybot or adaware
Back to Top
 

Jagmar
New Member


Date Joined Jan 2006
Total Posts : 1
 
   Posted Yesterday 5:26 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
I too had this file infecting my computer giving me pop-ups while working or playing a game. I tried several things to remove this pain, including terminating the program/process then deleting the file, yet that didn't work. Spybot did't find it, Ad-Aware didn't find it, McAfee didn't find it, but when i got AVG it found it while setting up! So hopefully AVG will get rid of it, i'm using version 7.1 and updated it. Will post here again if I can't remove it with AVG!
Back to Top
 

pandemonian
New Member


Date Joined Jan 2006
Total Posts : 1
 
   Posted 1-7-2006 1:45 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
Heres how i got rid of this crap.

*WARNING*
Manual registry editing is required!

You have to restart your compy into a safe mode. That way the only stuff thats running is what the system needs.

Run: Regedit

Go to the address one of the previous posters noted.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\

Now.. there will be a couple keys there that dont do anything but run the offending programs.
Delete them. Next, the other two that look like they should be pointing to windows programs, I.E. Kernel32.dll, and wininet.dll. Modify those two files to point back to the appropriate files.

NEXT

Run your anti-virus stuff and spyware stuff as usuall, but pay attention to the virus filename. IIRC, hpqaf9d.tmp is a trojan downloader. Most programs should pick that one up. Now, run a file search through your HDD for mssearchnet, nvctrl and delete all that show up. Prefetch, the file, all of it. I think mssearchnet.exe is located in your /windows/system32/ dir.

These steps worked for me. Good luck everyone.
Back to Top
 

Venom
New Member


Date Joined Jan 2006
Total Posts : 1
 
   Posted 1-7-2006 3:58 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
hello guys i am dutch so forgive me if my english is not so good i just was hoping that you guys could help me out.
i have the program called mssearchnet.exe i just cant get it of my computer i keep getting pop-ups that advise me to get antispyware like spybot. plz help me to get this JUNK of my pc becouse it drives me crazy when i am playing a game and i keep getting the pop-ups.
forgive my bad english this is a scanninglog of hijacthis..
 
 
 
Logfile of HijackThis v1.99.1
Scan saved at 3:39:51, on 7-1-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\apvxdwin.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvctrl.exe
C:\Program Files\iolo\System Mechanic Professional 6\SystemGuardAlerter.exe
C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
C:\Program Files\iolo\System Mechanic Professional 6\PopupBlocker.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\Program Files\iolo\System Mechanic Professional 6\SysMech6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\Documents and Settings\Koen\Bureaublad\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tbsclan.eu.tt/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: HomepageBHO - {27150f81-0877-42e9-af13-55e5a3439a26} - C:\WINDOWS\system32\hp19CC.tmp
O4 - HKLM\..\Run: [SystemGuardAlerter] "C:\Program Files\iolo\System Mechanic Professional 6\SystemGuardAlerter.exe"
O4 - HKLM\..\Run: [ioloDelayModule] C:\Program Files\iolo\System Mechanic Professional 6\delay.exe
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\System Mechanic\PopupStopper.exe"
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [System Mechanic Popup Blocker] "C:\Program Files\iolo\System Mechanic Professional 6\PopupBlocker.exe"
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {C9B8ABB6-1CC3-4957-9CA3-053036B2EE3A} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .tga: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
 
 
Back to Top
 

bengalf
New Member


Date Joined Jan 2006
Total Posts : 1
 
   Posted 1-13-2006 1:40 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
HI!!
Im new here, and I had teh same problem with mssearchnet.exe, and it really !!!!ed me off, so I know what you have been going through, and i found this site, wich has everything you have to do if you want to get rid of this malware, and another thing, as pandemonian have said you have to go to regedit and change the registers, otherwise u wont be able to close and delete the program msserach.net.
Here is the link they explain everything yeah Bye Bye mssearchnet.exeyeah
anything just email me, marcelohorst@gmail.com
Back to Top
 

dragon2000
New Member


Date Joined Jan 2006
Total Posts : 1
 
   Posted 1-25-2006 5:25 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
Very important !!!
I went to safe mode and removed msseachnet.exe and nvctrl.exe but problem still haven't been solved because my home page in Explorer was abused so after further investigation I noticed that LDC42A.TMP file had to be cleaned. That's acctualy file that creates different name every time one is affected so you need also to search out files with extension .TMP created on the day you have been affected and remove the blody monster (myone was found in system32 folder).
Good luck.
burger 
 
Back to Top
 

Araphon1
New Member


Date Joined Feb 2006
Total Posts : 1
 
   Posted 2-9-2006 8:48 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
This bugger is pretty hard to get rid of. I've got this thing two times, and the first time i had to reinstall windows to get rid of it. This time though i sat down and evaporated that thing.

1 Fist, if you're an XP user, download the Microsoft (GIANT) Anti Spyware, or if you're not, Download AdAware. Now, don't be lazy, google them out if you dont have em.

2 Download the new definitions and update the main program, and then run the scans.

3 Delete everything they find, then download Norton Antivirus Trail (15 Days), run Live Update, run a scan and delete everything it find.

4 Download smitfraud and install it.

5 Go to the start menu, run, and type msconfig.

6 Under the BOOT.INI tab, run in safemode. Restart your computer (there's a popup window that lets you do this automaticly)

7 Run Smitfraud, and it will delete everything it finds automaticly.

8 While still in safemode, repeat step 5, only type regedit instead. Under HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Currentversion/Policies there is a register key value that says kernel32.dll = mssearchnet.exe

9 Delete it. While here, check for things that you are sure not belong there, like values that have nvctrl.exe or fat.exe and delete them as well. WARNING! Do NOT make any changes in the regestry if you are not ENTIRELY sure of what yo are doing! I am not responsible for any dmg you might cause while editing you regestry!

10 Now, search for mssearchnet.exe and delete it. I found mine in the %SYSTEM32% folder, but the location may variate. Also search for fat.exe and/or nvctrl, if you have these viruses too, and delete them as well. In order to find them, just use the builtin search function in windows.

Finally, most of these instructions are written for windows XP users, so if something doesnt work and you dont have XP, dont balme me. In fact, im just doing this to help, and I am not responsible for any damage you may cause on your computer or company compyters or network. Good luck, and happy Virus&Spyware hunting! Give em hell from me!
Back to Top
 

jio
New Member


Date Joined Feb 2006
Total Posts : 1
 
   Posted 2-21-2006 8:00 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
can you please help me with this. I have mssearchnet.exe and i can't fix it.
Logfile of HijackThis v1.99.1
Scan saved at 8:52:56 μμ, on 21/2/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\CA\eTrust Antivirus\InoRpc.exe
E:\Program Files\CA\eTrust Antivirus\InoRT.exe
E:\Program Files\CA\eTrust Antivirus\InoTask.exe
E:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
E:\WINDOWS\SOUNDMAN.EXE
E:\WINDOWS\System32\rundll32.exe
E:\Program Files\Messenger\msmsgs.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\WINDOWS\System32\nvctrl.exe
E:\WINDOWS\System32\mssearchnet.exe
E:\WINDOWS\System32\taskmgr.exe
E:\Documents and Settings\lab1\Επιφάνεια εργασίας\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - E:\WINDOWS\System32\hpAEBE.tmp (file missing)
O3 - Toolbar: &Ραδιόφωνο - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "E:\Program Files\Microcom\Microcom USB Network\CnxTrApp.dll",AppEntry -REG "Conexant\Conexant USB Network"
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Realtime Monitor] E:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: Download ALL with IDA - E:\Program Files\IDA\idaieall.htm
O8 - Extra context menu item: Download with IDA - E:\Program Files\IDA\idaie.htm
O8 - Extra context menu item: Ε&ξαγωγή στο Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - E:\Program Files\IDA\ida.exe (file missing)
O9 - Extra 'Tools' menuitem: &Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - E:\Program Files\IDA\ida.exe (file missing)
O12 - Plugin for .spop: E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: WRNotifier - E:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - E:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - E:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - E:\Program Files\CA\eTrust Antivirus\InoTask.exe
Thank either you can helpme or not
ioannis
Back to Top
 

antispy
Junior Member


Date Joined May 2005
Total Posts : 93
 
   Posted 4-24-2006 10:13 (GMT +1)    Quote: Mssearchnet.exe and fat.exeAlert an admin about: Mssearchnet.exe and fat.exe
this might be useful in mssearchnet removal


 

Back to Top
 
New Topic Post reply to : Mssearchnet.exe and fat.exe Printable version of : Mssearchnet.exe and fat.exe
 
Forum Information
Currently it is Tuesday, January 06, 2009 3:53 PM (GMT +1)
There are a total of 65.870 posts in 16.165 threads.
In the last 3 days there were 22 new threads and 93 reply posts. View Active Threads
Who's Online
This forum has 27758 registered members. Please welcome our newest member, Nards.
52 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Cannot remove malware (6)06-01-2009 14:30:24 (phill)
Error message (1)06-01-2009 14:23:27 (Touch)
Virus stopping AVG and spybot from running (7)06-01-2009 14:17:45 (Touch)
Have I a machine infection? (9)06-01-2009 14:14:36 (Touch)
How to restore missing control panel and properties (1)06-01-2009 14:07:24 (Touch)