Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
About 4 days ago my PC began showing a window when I shut down Windows (XP Professional). The window that comes up at shutdown notifies me that a program is shutting down, and gives me the option to whut it down, or wait until it shuts down.
The bar at the top of this window says "ShelllconHiddenWindow"
I updated Spybot and Adaware and ran (versions 1.3 and 1.05), only tracking cookies showed. I ran the virus scan on the Panda link (clean). Below is the result of Hijack this. Any ideas?
Logfile of HijackThis v1.99.0
Scan saved at 2:16:41 PM, on 1/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
I notice you have Musicmatch and I'm about 99.9% sure that an issue with it is triggering ShellIconHiddenWindow. (note that you are seeing Shell Icon in that window title rather than Shell lcon)
Try start=>run=>msconfig and stop MusicMatch from auto-running when you boot the PC. See if the problem goes away and you should not lose any of the MusicMatch functions.
Speaking of which, I see two trusted zone entries (015) for musicmatch.com. Why does it need to be trusted?
Thanks for the clairfication on the shell icon. I don't know what the difference is internal to the PC, but in standard English...it at least makes sense.
3 questions:
1) In msconfig, do I go to the startup tab, and uncheck the musicmatch?
2) if so, there are 3 files which are associated with Musicmatch. Do I uncheck them all?
3) Trusted zone. There really is no reason to have musicmatch.com in the trusted zone. But I don't see it listed in the Zonelabs trusted zone list. Is there somewhere else I need to clean this up? I am not familiar with the 015 nomenclature you use.
I would say all three, and I wouldn't have musicmatch in my trusted zone of IE. The difference between ZA and IE trusted zones is that when musicmatch is in the IE's Trusted Zone, and your Trusted Zone settings are at the default settings, they could install and run whatever they please. Since it would be connected to and going through IE, whatever they put in would get past ZA as it would be actually IE accessing the internet.
I believe they are listed twice as they are in the registry twice, under the Keys of HKCU and HKLM, and this tells me it wasn't your doing.
I would definitely remove these two item using HJT, just check them and click on Fix.
You could remove these two in Msconfig, they are not needed.
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
Rename the file realsched.exe to realsched.old, and this entry will not reappear the next time you use RealPlayer.