This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

In-laws Computer Loaded W/spyware

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hoping you can help, and let me just apologize for my computer ignorance up front. My inlaws have a major problem w/pop up ads (spyware?) and several folders added to favorites and taskbar. I loaded Ad-aware and Spy Bot and did scan. Lots of things found…ad aware found LOTS and could not remove all. I'm not currently at their computer but hope to help them again later this week. Assistance would be GREATLY appreciated! PS - not sure if the problem may have been w/McAfee expiration…several of their protections are showing very low.
Hi seatangl.

I'm 'KotaGuy and I am going to see if I can help you with this situation.

When you get the chance to work on the infected computer again, this is what I would like you to do.

I would like you to do a few online scans for me. Please do scans at TrendMicro Housecall, eTrust AntiVirus Web Scanner, and Windows Security Trojan Scan.

Let them fix anything they find, rebooting between each scan. Please note, and let me know about, anything the online scans found and could not fix.

Next, download and install Ad-Aware and Spybot S&D. Visit this page for proper configuration. Run and scan with both, letting them fix whatever they find. Remember to reboot between each scan.

Now download HijackThis. Extract it to its own folder(eg: C:\Program Files\HJT\HijackThis.exe). This is extremely important! HijackThis creates backup files and cannot do that if run from inside a Temp folder, zip/rar archive, CD, etc. Please make sure it is in its own folder.

Run and scan with HijackThis, DON'T FIX ANYTHING YET!!! Copy and paste the log into a reply here.
Thanks for your help KotaGuy! Hope that I'm getting this reply posted in the right place. I ran the following as requested: (1) TrendMicro Housecall Found 12 Viruses. All were listed as "non-cleanable". As best I can tell, all were addressed somehow with the exception of 3 C:\WINDOWS/SYSTEM32\picvr\psvr.exe C:\WINDOWS/SYSTEM32\expcfgx(3).exe C:\WINDOWS/SYSTEM32\gidihost.exe …said, "unable to clean because currently in use"… (2) AntiVirus Web Scanner Unable to run, prompt "Starting signature update. Please wait … Connecting to FTP server:" never cleared allowing for scan (3) Windows Security Trojan Scan- ok (4) Ad-Aware Found objects - received prompt that said, "Some objects could not be removed c:\WINDOWS\SYSTEM32\n?lookup.exe (5) Spybot S&D Ran, objects found/deleted ok I wasn't successful in downloading Hijackthis. I created a separate folder in c:\Program Files\HJT, but couldn't open and kept receiving a message from McAfee stating "Virus Detected" c:\Program Files\HJT\hijackthis.zip. I'll wait to hear what you suggest next. Again, thanks so much for your help and patience w/my lack of computer savvy!!!!
Do one more online scan for me please, Panda ActiveScan. Again, note anything that could not be cleaned.

Download and run CWShredder. Press Fix.

Download and run Stinger.

Try downloading HJT from here.

See if you can run HijackThis. If you can, post a log please, if not, let me know.
Morning KotaGuy… Ran the (1) Panda ActiveScan, found 54 infceted files. Copy of report below: Incident Status Location Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\System32\nsvsvc\nsvsvc.exe Virus:Bck/Agent.KO No disinfected Operating system Adware:Adware/Apropos No disinfected C:\WINDOWS\system32\gdihost.exe Adware:Adware/Apropos No disinfected C:\WINDOWS\system32\expcfgx(3).exe Adware:Adware/PurityScan No disinfected C:\Documents and Settings\Len Weikum\Application Data\eetu.exe Adware:Adware/Hotbar No disinfected C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll Adware:Adware/eZula No disinfected C:\WINDOWS\system32\sysfile.dll Adware:Adware/SaveNow No disinfected C:\DOCUME~1\LENWEI~1\LOCALS~1\Temp\vmstmp\vmstmp.exe Adware:Adware/nCase No disinfected Windows Registry Adware:Adware/Hotbar No disinfected C:\Documents and Settings\Len Weikum\Application Data\ShopperReports Adware:Adware/Apropos No disinfected C:\Program Files\cxtpls Adware:Adware/SideSearch No disinfected C:\Program Files\sep Adware:Adware/IPInsight No disinfected C:\WINDOWS\farmmext.ini Adware:Adware/WUpd No disinfected C:\WINDOWS\Downloaded Program Files\PrevAdX.dll Adware:Adware/BroadcastPC No disinfected Windows Registry Adware:Adware/PurityScan No disinfected C:\Documents and Settings\Len Weikum\Application Data\eetu.exe Adware:Adware/PurityScan No disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\!update.exe Adware:Adware/nCase No disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\Del66.tmp Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\i20.tmp Virus:Trj/Multidropper.QW Disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\RAZR.exe Adware:Adware/DelFinMedia No disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\rm05040901.Stub.exe Adware:Adware/SideSearch No disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\SEPInst.exe Adware:Adware/Apropos No disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\temp.fr19A5 Adware:Adware/WUpd No disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\temp.fr4CEA Adware:Adware/Apropos No disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\temp.frA581 Virus:Trj/Startpage.FE Disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\twc\installer\bin\AddFavorites.vbs Virus:Trj/Downloader.BBB Disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\vmstmp\vmstmp.exe Virus:Trj/Bhotcher.A Disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temp\WBCM_Installer.exe Adware:Adware/PurityScan No disinfected C:\Documents and Settings\Len Weikum\Local Settings\Temporary Internet Files\Content.IE5\EYDU4Q93\!update-1784[1].0000 Adware:Adware/Envolo No disinfected C:\Documents and Settings\Nonie Weikum\Local Settings\Temp\AutoUpdate0\setup.inf Adware:Adware/Minibug No disinfected C:\Program Files\AIM\Sysfiles\WxBug.EXE Adware:Adware/Minibug No disinfected C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll Adware:Adware/BroadcastPC No disinfected C:\Program Files\bpc_search\bpc2_re_inst.exe Adware:Adware/BroadcastPC No disinfected C:\Program Files\bpc_search\bpcv2_rem.exe Adware:Adware/BroadcastPC No disinfected C:\Program Files\Common Files\Java\bpc2_re_inst.exe Adware:Adware/BroadcastPC No disinfected C:\Program Files\Common Files\Java\bpt.cfg Adware:Adware/BroadcastPC No disinfected C:\Program Files\Common Files\Java\bptre.exe Adware:Adware/DelFinMedia No disinfected C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe Adware:Adware/WUpd No disinfected C:\Program Files\Preview AdService\PrevAdKeep.exe Adware:Adware/Hotbar No disinfected C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll Adware:Adware/Hotbar No disinfected C:\Program Files\SpamBlockerUtility\bin\4.6.1.0\Contact.dll Adware:Adware/Hotbar No disinfected C:\Program Files\SpamBlockerUtility\bin\4.6.1.0\SbWallpaper.dll Virus:Trj/Tofger.AT No disinfected C:\WINDOWS\cerbmod.dll Adware:Adware/Hotbar No disinfected C:\WINDOWS\Downloaded Program Files\HbInstIE.dll Adware:Adware/WinAD No disinfected C:\WINDOWS\Downloaded Program Files\PrevAdX.dll Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\Pynix.inf Virus:Trj/Imiserv.D Disinfected C:\WINDOWS\systb.exe Adware:Adware/SAHAgent No disinfected C:\WINDOWS\SYSTEM32\bln02nqv.exe Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM32\delfin.dll Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM32\expcfgx(3).exe Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM32\gdihost.exe Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM32\nsvsvc\nsv.ocx Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM32\nsvsvc\nsvsvc.exe Virus:Bck/Agent.KO Disinfected C:\WINDOWS\SYSTEM32\picsvr\picsvr.exe Adware:Adware/BroadcastPC No disinfected C:\WINDOWS\Temp\bpc_inst.exe (2) downloaded/ran CWShredder…no CoolWeb Search found (woo hoo!!!!!) (3) downloaded/ran Stinger…said # of clean files: 106063 (4) attempted to download/run HijackThis…still detects as virus. Thanks for continued help!
Hmmm. I'm confsued as to why Mcafee keeps detecting HJT as a virus :blink: You mentioned their virus protections were out of date… how old is the installation of Mcafee? Is the program itself a few years old? Try something for me… disable Mcafee or uninstall it… doesnt much matter now as the computer has many infections. If its an older version of the product, it would be best to uninstall it anyways as the scanning engine would be old and unable to catch most of the newer strains of virus/malware. If you have to uninstall it, don't worry, I'll point you in the direction to a few good free scanners. Once Mcafee is disabled/uninstalled, try running HijackThis. If you can, post a log, if not… let me know! :D
KotaGuy,
Disabling McAfee seemed to work…here's the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 10:55:44 AM, on 4/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\support.com\bin\tgcmd.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\wys.exe
C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbWeatherOnTray.exe
C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbOEAddOn.exe
C:\PROGRA~1\SPAMBL~1\Bin\461~1.0\SBInst.exe
C:\Program Files\McAfee.com\MPS\mscifapp.exe
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\AIM\aim.exe
C:\WINDOWS\System32\n?lookup.exe
C:\Documents and Settings\Len Weikum\Application Data\eetu.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbSrv.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\system32\hyppo.exe
C:\WINDOWS\system32\icfntcls.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CxtPls\CxtPls.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: (no name) - {00000000-DD60-0064-6EC2-6E0100000000} - (no file)
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: (no name) - {060D212B-E4E3-CF3B-EC68-B9EEFFF7BD99} - C:\WINDOWS\System32\lbyxrmf.dll
O2 - BHO: FlashEnhancer Extender - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - c:\Program Files\Flen\flen.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: ShprRprts - {2A8A997F-BB9F-48F6-AA2B-2762D50F9289} - C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SpamBlockerUtility - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbHostIE.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: SpamBlockerUtility - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbHostIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [180ax] c:\docume~1\lenwei~1\locals~1\temp\180ax.exe
O4 - HKLM\..\Run: [Preview AdService] C:\Program Files\Preview AdService\PrevAdServ.exe
O4 - HKLM\..\Run: [BPT] "C:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 - HKLM\..\Run: [hZGlbA] C:\windows\system32\hZGlbA.exe
O4 - HKLM\..\Run: [Spool] "C:\WINDOWS\System32\wys.exe" /startup
O4 - HKLM\..\Run: [BPCv2] C:\Program Files\bpc_search\BPCv2.exe
O4 - HKLM\..\Run: [FlenCPY] "C:\Program Files\Common Files\Java\flencpy.exe"
O4 - HKLM\..\Run: [WeatherOnTray] C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbWeatherOnTray.exe
O4 - HKLM\..\Run: [SpamBlocker] C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbOEAddOn.exe
O4 - HKLM\..\Run: [Spam Blocker for Outlook Express] C:\PROGRA~1\SPAMBL~1\Bin\461~1.0\SBInst.exe
O4 - HKLM\..\Run: [kipegooh] C:\WINDOWS\System32\gpghfkoe.exe
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [4F5W34P] icfntcls.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Lou6RQj6i] hyppo.exe
O4 - HKCU\..\Run: [Jouiyq] C:\WINDOWS\System32\n?lookup.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Len Weikum\Application Data\eetu.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: ShopperReports - Compare travel rates - {946B3E9E-E21A-49c8-9F63-900533FAFE14} - C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: ShopperReports - Compare product prices - {E77EDA01-3C56-4a96-8D08-02B42891C169} - C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,7…pdatePortal.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (SbInstObj) - http://installs.spamblockerutility.com/ins…ckerutility.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

Thanks!
Excellent! Got something I can work with now :D Still strange that Mcafee detected HJT as a virus… how old is the Mcafee installation anyways? As I said… if it's old, you should uninstall it as the scanning engine is outdated. Anyways… this is going to take a little bit for me to go through a formulate a fix for you. Lots of nasty stuff in the log. Will reply as soon as I can!
KotaGuy, My in-laws got their computer about a year ago (probably March or April of last year) so the McAfee would have been loaded around that time. Think it was done online. When all this mess first started I looked at the McAfee and it showed the virus stuff had expired. I downloaded the free 30-day McAfee trial thinking that it would help protect in the interim. Thanks SOOOOOOOOO much for all of your help! ")
OK! Got some work for you to do :D

Print this out for reference during the fix.

Download and install CCleaner.

Make sure no files are hidden. To do this:

1. Click Start.
2. Open My Computer.
3. Select the Tools menu and click Folder Options.
4. Select the View Tab.
5. Under the Hidden files and folders heading select Show hidden files and folders.
6. Uncheck the Hide protected operating system files (recommended) option.
7. Click Yes to confirm.
8. Click OK.

Hit Ctrl+Alt+Delete to bring up the Task Manager. End Task the following:

wys.exe
SbWeatherOnTray.exe
SbOEAddOn.exe
SBInst.exe
nsvsvc.exe
n?lookup.exe
eetu.exe
SbSrv.exe
AutoUpdate.exe
hyppo.exe
icfntcls.exe
CxtPls.exe


Goto Add/Remove Programs in the Control Panel. Uninstall any of the following you see(some may not be there):

While You Surf
Spam Blocker Utility
ShopperReports
WildTangent
Preview AdService
Ebates_MoeMoneyMaker
WeatherBug


Run and scan with HijackThis. With all other browsers and windows closed, place a check beside the following and Fix:

O2 - BHO: (no name) - {00000000-DD60-0064-6EC2-6E0100000000} - (no file)
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: (no name) - {060D212B-E4E3-CF3B-EC68-B9EEFFF7BD99} - C:\WINDOWS\System32\lbyxrmf.dll
O2 - BHO: FlashEnhancer Extender - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - c:\Program Files\Flen\flen.dll
O2 - BHO: ShprRprts - {2A8A997F-BB9F-48F6-AA2B-2762D50F9289} - C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: SpamBlockerUtility - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbHostIE.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: SpamBlockerUtility - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbHostIE.dll
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [180ax] c:\docume~1\lenwei~1\locals~1\temp\180ax.exe
O4 - HKLM\..\Run: [Preview AdService] C:\Program Files\Preview AdService\PrevAdServ.exe
O4 - HKLM\..\Run: [BPT] "C:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 - HKLM\..\Run: [hZGlbA] C:\windows\system32\hZGlbA.exe
O4 - HKLM\..\Run: [Spool] "C:\WINDOWS\System32\wys.exe" /startup
O4 - HKLM\..\Run: [BPCv2] C:\Program Files\bpc_search\BPCv2.exe
O4 - HKLM\..\Run: [FlenCPY] "C:\Program Files\Common Files\Java\flencpy.exe"
O4 - HKLM\..\Run: [WeatherOnTray] C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbWeatherOnTray.exe
O4 - HKLM\..\Run: [SpamBlocker] C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbOEAddOn.exe
O4 - HKLM\..\Run: [Spam Blocker for Outlook Express] C:\PROGRA~1\SPAMBL~1\Bin\461~1.0\SBInst.exe
O4 - HKLM\..\Run: [kipegooh] C:\WINDOWS\System32\gpghfkoe.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [4F5W34P] icfntcls.exe
O4 - HKCU\..\Run: [Lou6RQj6i] hyppo.exe
O4 - HKCU\..\Run: [Jouiyq] C:\WINDOWS\System32\n?lookup.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Len Weikum\Application Data\eetu.exe
O9 - Extra button: ShopperReports - Compare travel rates - {946B3E9E-E21A-49c8-9F63-900533FAFE14} - C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll
O9 - Extra button: ShopperReports - Compare product prices - {E77EDA01-3C56-4a96-8D08-02B42891C169} - C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (SbInstObj) - http://installs.spamblockerutility.com/ins…ckerutility.cab


You can actually fix the rest of the 016's if you wish. They will reinstall if needed the next time you visit the websites.

Now, boot into Safe Mode. To do this:

1. Reboot your computer.
2. Tap the F8 button as your computer is booting to bring you to the Advanced Options Menu.
3. Select Safe Mode and press Enter.

Search for and delete these folders if found:

C:\Program Files\SpamBlockerUtility
C:\Program Files\Flen
C:\Program Files\ShopperReports
C:\Program Files\WildTangent
C:\Program Files\Preview AdService
C:\Program Files\Bpt
C:\Program Files\bpc_search
C:\Program Files\AutoUpdate
C:\Program Files\Ebates_MoeMoneyMaker
C:\Program Files\AWS
C:\WINDOWS\System32\nsvsvc

Search for and delete these files:

C:\Documents and Settings\\Local Settings\temp\180ax.exe
C:\Documents and Settings\\Application Data\eetu.exe
C:\WINDOWS\System32\gah95on6.exe
C:\windows\system32\hZGlbA.exe
C:\WINDOWS\System32\wys.exe
C:\WINDOWS\System32\gpghfkoe.exe
C:\WINDOWS\System32\n?lookup.exe
C:\Program Files\Common Files\Java\flencpy.exe
icfntcls.exe
hyppo.exe


NOTE!!: When searching for n?lookup.exe in the \System32 folder, examine the results of the search carefully. In that folder is a legit file called nslookup.exe. This is a Microsoft file and has a filesize of 70.0 KB (71,680 bytes). When you get the results of this search back, right click on the files, click Properties, then the Version tab to see what company or vendor the file is from. Do not delete the file from Microsoft!

Run CCleaner. Under Windows tab check Internet Explorer, Windows Explorer, and System. Then click Run Cleaner.

Browse to C:\Windows\Prefetch. Delete all files in the Prefetch folder. Empty the Recycle Bin.

Reboot Windows normally and post a new log please.
KotaGuy,
Whew…scary stuff…hopefully followed your instructions correctly. There were a few files that I didn't find when doing the searches and/or things I couldn't delete from the remove Add/Remove Programs in control panel. Here's the HJT log after running the stuff you gave me to do.

Logfile of HijackThis v1.99.1
Scan saved at 3:54:26 PM, on 4/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\system32\wscntfy.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\support.com\bin\tgcmd.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\McAfee.com\MPS\mscifapp.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Len Weikum\Local Settings\Temporary Internet Files\Content.IE5\P8S9CUO9\HijackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

Thanks, and I'll wait to here what to do next. ")
Nice…. looking lots better. You're doing great! How is the computer running?

But remember…

C:\Documents and Settings\\Local Settings\Temporary Internet Files\Content.IE5\P8S9CUO9\HijackThis[1].exe


Don't run HijackThis from a Temp directory… please run it from its own folder, that way it can create the backups it needs.

With that said…

Scan with HijackThis, with all browsers and windows closed, place a check beside the following and Fix:

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

Also, I missed something from your last log… search for and delete:

C:\WINDOWS\SYSTEM32\notepad.exe

NOTE!!: When doing this search, you may find an entry for C:\WINDOWS\NOTEPAD.exe. Do NOT delete that copy… it is legit. Delete only the copy found in C:\WINDOWS\SYSTEM32\notepad.exe.

Reboot, scan with HijackThis and post a new log please.
I keep getting confused w/the HJT. On my computer at home it seems like the path is easier to follow than on this machine…I keep saving the program to its own folder in c: drive but when I go to run it from there, it's only the logs so I have to use it from the links you've provided? Ran the last batch of "to do's" you sugessted…here's the HJT log. Not as familiar w/this machine, but it seems to be running faster and there's no pop up's (WOO HOO!!!)

Logfile of HijackThis v1.99.1
Scan saved at 4:54:24 PM, on 4/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\McAfee.com\MPS\mscifapp.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\PROGRA~1\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

As always….THANKS!!!
Good Work! That is a CLEAN log! :D

Now, reset your System Restore Points. This will ensure a clean backup to roll back to if needed. To do this:

1. Right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Check the "Turn off System Restore" or "Turn off System Restore on all drives"

Reboot your computer, follow the steps above, this time unchecking the "Turn off System Restore" and reboot.

Now… about the AntiVirus situation…. if they aren't going keep their susbscriptions up to date, Mcafee is probably not the best solution as this will happen again. I would go with a free solution. Try AVG AntiVirus Free Ed.. Install it, update it, do a full system scan, let it clean anything it finds. With the amount of stuff that had infected this machine, there may be remnants left that haven't been totally cleaned yet. You may want to do one or two of the previous online scans as well, just in case. If you go with AVG(it is a very good AntiVirus program), uninstall Mcafee as you may get conflicts between the two. That or disable Mcafee's resident(always active) AV scanner.

If you do uninstall Mcafee, you will probably lose the Firewall protection. In this case, download and install the free version of ZoneAlarm.

I also recommend downloading and installing SpywareBlaster, SpywareGuard, and IE-SPYAD. All the programs are free and can be updated so remember to do so! You can grab the programs from the links in my sig. Installing these will go a long way in preventing this from happening again. It is, of course, no guarantee :P

You may also want to visit the links named "Understanding Spyware" and "How did I get Infected?", some good information for you.

Other than that… remember to update Windows Components, your protection programs, scan often, and…

Surf Safe!
THANK YOU KOTAGUY!!!! Can't tell you how much I appreciate your expertise and patience (not to mention you made me look like a hero to my inlaws…that can't hurt ") You and TomCoyote Forums are invaluable!!! I'll get w/my inlaws and try to figure out the best way to procede w/antivirus protection. Seatangl ")

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI