Well the DL was very fast. Making a log wasn't hard and while it may have created a log in it's own folder I saved a copy where I knew it would be. I don't see anything that looks like a legal problem anyway.  I ran analyze, but that just took me to the Hi jack This site.

here is the list.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:57:15 AM, on 7/13/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Juno\exec.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Juno\exec.exe
C:\Program Files\Juno\qsacc\x1exec.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =*
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =;;localhost;*;*;*;*;;*;*;*;;;*;*;<local>
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\Juno\SearchEnh1.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\Juno\qsacc\X1IEBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Juno Toolbar Helper - {FE3098B1-04A3-41fd-8CA9-BEA39CB14C87} - C:\Program Files\Juno\ucreg.dll
O3 - Toolbar: JunoBar - {5854FAC4-5BF0-47DD-B5A9-A5EA8CFF3CF4} - C:\Program Files\Juno\Toolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Juno_uoltray] C:\Program Files\Juno\exec.exe regrun
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\Juno\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\Juno\qsacc\appres.dll/227
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{B359C91F-52DC-42E6-BD43-F4D18F54D065}: NameServer =
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

End of file - 6596 bytes


Hi Mac,

I've done an analysis of your HJT log and most bad entries are associated with Juno which I will guess is your ISP. If that is true, then you must decide whether or not to correct these bad entries that I will list for you. Or, perhaps someone else will give more input.

Because Juno might be your ISP is why I have not given any individual recommendations.
If Juno is not your ISP, then all of the below can be fixed with HJT.

(There are 2 instances of some entries. This is why they are listed twice)

C:\Program Files\Juno\exec.exe

C:\Program Files\Juno\exec.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\Juno\SearchEnh1.dll

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
Unnecessary (deactivated) entry that can be fixed - Yahoo Companion!

O2 - BHO: Juno Toolbar Helper - {FE3098B1-04A3-41fd-8CA9-BEA39CB14C87} - C:\Program Files\Juno\ucreg.dll

O4 - HKCU\..\Run: [Juno_uoltray] C:\Program Files\Juno\exec.exe regrun

O17 - HKLM\System\CCS\Services\Tcpip\..\{B359C91F-52DC-42E6-BD43-F4D18F54D065}: NameServer =
This might be your ISP but please check to be sure. Both IP's resolve to Address: 21301 Burbank Boulevard.

Overview of running tasks :

System process   
Session Manager Subsystem

System process   
Microsoft Windows Logon Process

System process   
Windows Service Controller

System process   
Local Security Authority Service

System process   
Microsoft Service Host Process

System process   
Microsoft Service Host Process

avast! Antivirus

System process   
Microsoft Windows Explorer

Realtek HD Audio Sound Effect Manager

Sun Java Update Scheduler

avast! Antivirus

MSN Messenger

System process   
Alternative User Input Services

exec.exe                                                  [ related to Juno ]
Trojan Horse   
Death Zone Remote Admin Tool (trojan)    [ ]

System process   
Microsoft Printer Spooler Service

Apple Mobile Device Service

Java Quick Starter Service

NVIDIA Driver Helper Service

System process   
Microsoft Service Host Process

exec.exe                                                 [ related to Juno ]
Trojan Horse   
Death Zone Remote Admin Tool (trojan)    [ ]

x1exec.exe   [ related to Juno accelerator ]
Unknown task   
Unknown task           [ ]

Windows internet explorer

Windows internet explorer

Merijn Hijackthis


Yes, you will need to answer some questions about yr ISP (Internet Service Provider) which apparently is Juno
well. almost certainly is Juno - so far, as I can see, the entries are consistent with other HjT logs where Juno has been ISP
- whether you need the extent of commitment to Juno that you have is worth to find out

here is a link to help determine which Juno service you may be using

but since you are on dialup you may have to wait for DavidR on this one - and he know a bit more about Juno

other than that you can fix this entry
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
Unnecessary (deactivated) entry that can be fixed - Yahoo Companion!

to fix, put a check into the box beside the entry and go down left corner and click Fixed checked
run a scan to make sure the entry has been removed

you also have a few programs which are unnecessary to run at startup and will only slow down the computer
however best wait for some guidance about Juno - and deal with the other stuff

Other than that quite a reasonable log - do you run Apple mobile devices or was that already ob the computer
okay Mac_Muz,

if you are still there at the moment, otherwise whenever you can, lets help the guys out

Firstly tell us a bit about Juno and what arrangement you have with them
- just what you know about yr internet service contract

Secondly, lets take a first trip to the Registry - you just have to do what I say

go to Start -> Run  and type the following word into the box -> regedit
click OK - and this will take you to the Registry Editor

In the left hand pane under My Computer,
you should see five folders with boxes next to them and with an +  in each box
when you click the  +  in the box, the folder will expand to show other folders inside it

choose HKEY_CURRENT_USER - what you do is click the + and expand the folder
down the other folders inside it, select Software and expand it
likewise down the list, next expand Microsoft
and next expand Windows, and finally expand Current Version

niow go to Internet Settings and click the actual folder (this time, not the box with the + inside)
you will see that a list of values will be opened in the right-hand pane
look down this list and you should find a value that is titled ProxyEnable

go past the REG_DWORD on that line and tell us whether that value has (0) or (1) at the end of it

that's all you have to do for now  ;)
I have just now come back to read. I have only read to this point. I have done nothing. Juno is my dial up service. They take money from the bank once a month. Right clicking on the juno icon at my lower right, where also the avast icon is I can bring up systen info, which is below if that matters, and tells you any thing.

Client BuildID=2009.10.05.11
Client Version=A0892DJ.
Build MachineID=LAXWS7518
osVersionNumber=Service Pack 3
osVersionString=Windows XP
defaultBrowser="C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1"
procFamily=x86 Family 15 Model 107 Stepping 1
procType=AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
modemInitString01=AT &F E0 &C1 &D2 V1 S0=0\V1<cr>
modemModelName0=Lucent Win Modem
audProdName0=Realtek HD Audio output
audProdName1=Modem #0 Line Playback
videoCardDriverDesc0=NVIDIA GeForce 6100 nForce 405
videoCardDriverDesc2=NetMeeting driver
videoCardDriverDesc3=RDPDD Chained DD
defaultMailClient=Outlook Express

I fear at this point in the day I need to leave (drive a truck and deliver machines) When I get back I will do as told. If I get into something I don't understand, i will do nothing until told.

If I might ask what illness does this cause to the system? Just a day to day words of what is happening, and how i might understand, a sort of something to do until I get back, if you happen to feel like it.


  • Guest
Re: Avast folks, I made a mistake
« Reply #111 on: July 14, 2010, 09:30:26 PM »
Well I am back. I was looking over the list harder, and while I have hotmail, I do not use messenger for instant chat. I did not put that in the tower either. It could go away.

I am going to have lunch  ;D study some, look at things some, and see what i might do. What ever that is, is likely to be minimal.
Following the instructions to a 'T'
going past the REG_DWORD on that line is value   (1)

I have 'fixed' this line, and scanned. This is now gone.

 O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

Also I do have a cd copy of juno. I don't like juno much. They offer very poor quality pictures, which I have to right click and select any picture i want to see clearly.

Over time juno has priced themselves into Earth link prices. On the old system, once I had earth link. When that old system came out of storage (long term high heats and very colds) the monitor was fluky. With this tower i bought a new flat screen monitor. So maybe if there is either a cheaper and somewhat better service than juno, or a as costly service as juno with faster or better quality I could go that way too.

My old win 98 when it wasn't old about 2001 could do video like youtube. on dial up. For all I know NO dial up can do things like video at all anymore.

I am not juno loyal fer sure. All I use them for is to dial up. I don't use their e-mail, and I don't use their virus programs. I just dial up.

The proxy enable setting might be for a Juno service that speeds up your browsing by caching things on a proxy server. Changing it from 1 to 0 might result in a slower internet experience. Notice I said might, I only know that some dialup services do this.

yes Dch48. We have had Juno network hookups on the forum before and mostly people steer clear of the thread.

But the Juno setup would likely design to optimise a platform for dial-up users, as well as serve for use and sale of more stuff.
May be good to have have deeper commitment to Juno portal, and may not be
- much like the archetypal AOL dialup service circa 1999.

My worry was that Mac may have two proxies instated, perhaps one (IE?) not operational but still on record
I would uninstall Firefox anyway for starters, and Apple mobile device program(s), just to clear the playing field

I am real busy at the moment - perhaps you could help Mac_Muz here Dch48

there is this link

there is a page previous to this which I cannot get back to at the moment
- it offers three options to determine status of service, this page was one of the options
Just call me Mac, I am one. I did as was told. I am in no real hurry, things seem ok.

I do have IE 8 and fire fox. I use IE 8 more than Fire Fox. Fire Fox popped up first when i was using avast 4.7 pro, as i clicked to become involved with this thread on day 1. Evidently at one point, and maybe now for all I know fire fox is set as default.

All I use it for is coming here and getting the down loads I am told to get from here.

I can place everything into IE8 and remove fire fox.

On juno, before this tower was on line i placed the juno dc in the drive. I didn't try to install anything, but the drive started. I thought I backed out clean, but after removing the cd, and a re-boot juno icons were on the desk top.

When I placed the system on line juno didn't work, so I placed the cd back in the drive and ran it.

Is this why there are doubled items as:
C:\Program Files\Juno\exec.exe

C:\Program Files\Juno\exec.exe

I do not know what to call that. I have no term.

mkis, if nothing else thank you for the time.

I will look in often

You and Dch are nice guys, willing to help, I would be willing to turn the keys over on this system to either of you, if you ever wanted to drive.

I'll look in again in the AM.

Hi Mac, and thanks for clarify some issues.

okay maybe you can hand the keys over at some time, we have a program that is suitable.

but for the moment I think we have jumped far enough ahead of ourselves, perhaps a bit too far.

But for now, this thread of posts is the repair and maintenance record for yr computer - I'm just reading back through it now.

hello, back again. I havent read back all through the thread - just this page

okay lets catch up
post #106 CharleyO - this is the HjT log for now

1. You've Fix checked the following entry
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
Unnecessary (deactivated) entry that can be fixed - Yahoo Companion!

2. exec.exe will be a kind of keylogger that tracks and reports to Juno system control
The Juno service is then able to custom yr networked experience across its service range
- the way that the AOL portal used to do (I imagine)

3. As you say - you ran the install CD twice
- so probably need to reinstall the Juno package
- and we probably wait to see if we can first engage yr provider to configure the platform
- less will likely be better in yr case - but lets not upset the cart just yet

4. 1exec.exe - maybe a performance monitor runs on top of exec.exe
meant to boost connection, speed, whatever - not that important and can be deleted (later)

Now, check this site - and without clicking through see which icon resembes the one on yr system

so much for Juno for now - but any additional information welcome
- does the install CD have repair or uninstall options
My icon is the 2nd one down white trim divided blue with a green dot above, and black below the divider line. I did look thru to see about it and now I can't get to that page anymore. Don't know why.