This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Pair Of Problems

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ive been having ongoing problems with Windows XP on my laptop. First when booting the display hangs at the welcome screen for an extended period of time
before going to the desktop screen. At the desktop only my wallpaper photo appears, no Icons will appear untill I do a Ctrl-Alt-Del and then close the box. System CPU is shown as 100% for very brief moment but returns to normal after closing the box. In addition I am now getting Tickle ads popping up when using IE. It seems to be getting worse. Adaware and Spybot have not solved the problem. Thanks for reading. My hijack log is below

Chuck

Logfile of HijackThis v1.99.0
Scan saved at 8:16:25 AM, on 2/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\minilog.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\System32\wh2ml.exe
C:\WINDOWS\System32\wh2ml.exe
C:\WINDOWS\System32\wh2ml.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\System32\mmcbase.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.comcast.net"); (C:\Documents and Settings\Chuck Wyss\Application Data\Mozilla\Profiles\default\hiqze261.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\Chuck Wyss\Application Data\Mozilla\Profiles\default\hiqze261.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A78860C8-EE1A-46DF-A97F-E3E6D433E80B} - C:\WINDOWS\SYSTEM32\x5n.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O5 "LPT1:" /M "Stylus C82"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\RunOnce: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe /k
O4 - HKCU\..\Run: [mmcbase] C:\WINDOWS\System32\mmcbase.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe /k
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {2EEC936C-8E27-445E-AD63-68D54AE5E758} (RTC_20050101.RTC) - http://www.iastore.com/RTC/Install/invRTC.CAB
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {64D01C7F-810D-446E-A07E-365764235644} (AtlAtomadersCtlAttrib Class) - http://kraisoft.com/files/realone/atomaders.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E80DCA85-7810-4F7B-AC74-330B634B6756} (RTC_20041001.RTC) - http://www.iastore.com/RTC/Install/invRTC.CAB
O23 - Service: pcAnywhere Host Service - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Basic Logging Client - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\minilog.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Hi Chuck, Welcome to TomCoyote forum. I see no antivirus software running in this logfile? It is computer suicide to go online anymore without one. If you need a free version here are three to choose from. I suggest AVG, the first one.
http://free.grisoft.com/freeweb.php
http://www.avast.com/eng/avast_4_home.html
http://store.ca.com/dr/v2/ec_main.entry25?…5715&CID=179825

I also wish to give you these two links in the event you need them in the future:
SP2 CD
http://www.microsoft.com/windowsxp/downloa…us/default.mspx
What you should know
http://www.microsoft.com/windowsxp/sp2/sp2_whattoknow.mspx


I have a located a couple of items that can't be identified. If you do not know what they are we will remove them. You can search for them if you wish and take a look at the properties of the item, they are more than likely random named trojans. If you can't find them in search, means they are hidden and we will need to enable hidden files to get to them anyway:
Use this link to enable Hidden files for your Operating System: http://www.xtra.co.nz/help/0,,4155-1916458,00.html
C:\WINDOWS\System32\wh2ml.exe
C:\WINDOWS\System32\wh2ml.exe
C:\WINDOWS\System32\wh2ml.exe
C:\WINDOWS\System32\mmcbase.exe

Open Task Manager then the Processes Tab, locate and end process on these:
wh2ml.exe
mmcbase.exe


Scan with HijackThis and check the box in front of these line items:

O2 - BHO: (no name) - {A78860C8-EE1A-46DF-A97F-E3E6D433E80B} - C:\WINDOWS\SYSTEM32\x5n.dll
Adtomi adware variant
O4 - HKCU\..\Run: [mmcbase] C:\WINDOWS\System32\mmcbase.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML

Close all programs but HJT and all browser windows then click on "Fix Checked"

RIGHT click on Start then click on Explore. Locate and delete these files:

C:\WINDOWS\System32\wh2ml.exe >>> file

C:\WINDOWS\System32\mmcbase.exe >>> file

Clean Like this: Start, Run type "cleanmgr" without the quotes then ok. Check and remove anything windows locates. Empty the recycle binb and restart the computer. Post a new log along with your comments, use the following two links to stay in this same thread.

When replying to your topic, please use the
http://forums.tomcoyote.org/style_images/1/t_reply.gif
button NOT the
http://forums.tomcoyote.org/style_images/1/t_new.gif
button.
Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php
Thanks for the info
I successfully performed the removal of the 2 files mmcbase.exe and wh2ml.exe.
mmcbase.exe may have been part of a program that had other assoicated files with it. mmc.exe is microsoft management console. What is does I have no idea.
So far I have not seen the annoying popup that has plaged me for the past 2 weeks. My bootup is still stuck in that when starting XP I get the welcome screen then the desktop wall paper but no icons until I do an ctrl alt del and then close the box.

You did make a good call in the fact that indeed I have no anti virus software running. I do run fire wall protection on all my comps 4 at home and 2 at work and do online scans at trend.com but have never been able to have good repeatable success with the retail crap now on the market. I'll try some of the versions that you have posted and see what happenes.

Thanks for the help so far
here is my hijackthis log

Logfile of HijackThis v1.99.0
Scan saved at 9:57:05 AM, on 2/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\minilog.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.comcast.net"); (C:\Documents and Settings\Chuck Wyss\Application Data\Mozilla\Profiles\default\hiqze261.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\Chuck Wyss\Application Data\Mozilla\Profiles\default\hiqze261.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O5 "LPT1:" /M "Stylus C82"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKCU\..\Run: [mmcbase] C:\WINDOWS\SYSTEM32\mmcbase.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: D-link AirPlus G DWL-G120 Wireless USB.lnk = ?
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {2EEC936C-8E27-445E-AD63-68D54AE5E758} (RTC_20050101.RTC) - http://www.iastore.com/RTC/Install/invRTC.CAB
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {64D01C7F-810D-446E-A07E-365764235644} (AtlAtomadersCtlAttrib Class) - http://kraisoft.com/files/realone/atomaders.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E80DCA85-7810-4F7B-AC74-330B634B6756} (RTC_20041001.RTC) - http://www.iastore.com/RTC/Install/invRTC.CAB
O23 - Service: pcAnywhere Host Service - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Basic Logging Client - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\minilog.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

Let me know if there is more crap to clean

Thanks
CHuck
Hi Chuck, It looks like you missed this item:
O4 - HKCU\..\Run: [mmcbase] C:\WINDOWS\SYSTEM32\mmcbase.exe
Since you already removed the .exe, just remove the line with HJT. It looks to be running, so you may need to end process or HJT might not be able to fix the line.

Your log is clean, Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

I encourage you to get some realtime virus/trojan protection onboard. I install AVG Free on many computers and it does a great job, the price is also right. Your ZoneAlarm which I also run on my computers will not protect you against those items. Good luck, and safe surfing.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI