This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Locks Up #2

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please review my HJT log because my computer locks up while surfing using internet explorer

Logfile of HijackThis v1.99.1
Scan saved at 11:58:50 PM, on 2/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\All Users\Desktop\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=AdSubtract:4445
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {C9E5B780-CC52-11D9-B474-005004685109} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {C9E5B780-CC52-11D9-B474-005004685109} - (no file) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hi jayberns.

Important: Could you please let me know whether, or not, this computer has been connected to the other one I'm helping you with.

————————————————————-

There are a couple of items, shown in your log, which we need to sort out. However, I don't think that these are connected with your IE problem.

First, we need to uninstall a program. Please go to Start -> Control Panel -> Add or Remove Programs and uninstall the following programs, if they are present. Don't worry if they're not there.
  • Moe Money Maker (it could be called Ebates Money Maker or something similar - if in doubt, stop and ask)
  • Microsoft AntiSpyware (just checking, I think that it's already been uninstalled)
———————————————————-

AdSubtract

You have a line in the log showing this as a proxy server, but I can't see that the program is running (I'm not familiar with this software, so I don't know what to expect).

Please let me know:
  • Whether you use this at the moment
  • Whether it has been uninstalled
  • If installed or uninstalled recently, whether this coincides with your IE problem
  • Anything further about this program that you consider relevant
———————————————————-

Run HijackThis and click Scan and then check (tick) the following, if present (don't worry if any are missing):

O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {C9E5B780-CC52-11D9-B474-005004685109} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {C9E5B780-CC52-11D9-B474-005004685109} - (no file) (HKCU)

Close down all programs, browsers and other open windows. Make sure that only the above items are checked and then click on Fix checked.

Click on Start then My Computer, find the following folder (highlighted in red) and delete it, if present. Please let me know if there are any problems with this.
  • C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\
———————————————————

IEFix

Please download IEFix from here and follow the instructions on that page.

———————————————————–

ATF Cleaner by Atribune ©

Download ATF Cleaner by Atribune © from here : http://www.atribune.org/ccount/click.php?id=1
This is a stand-alone program that does not need to be installed. Save it to a convenient location and make a shortcut on your desktop. Using this program will remove temporary files, temporary internet files and cookies from your system, which will mean that any scans will run faster.
  • Make sure that all browser windows are closed
  • Double-click the shortcut on your desktop to run the program.
  • Under Main, choose Select All
  • Untick Prefetch
  • Click Empty Selected
  • If you use Firefox browser,
    • Click Firefox at the top and choose Select All
    • Click on Empty Selected
    • NOTE: If you would like to keep any saved passwords, please untick that option.
  • Click Exit to close.
  • If you use Opera browser,
    • Click Opera at the top and choose Select All
    • Click on Empty Selected
    • NOTE: If you would like to keep any saved passwords, please untick that option.
  • Click Exit to close.
——————————————————–

AVG Anti-Spyware:

If you already have this program installed, please update it as detailed below.

Please note that you must uninstall all versions of Ewido anti-spyware before installing this program.

Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open. Do not run a scan yet.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
You will need to change the following settings:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under How to act? click Recommended actions and select Quarantine from the menu.
You can now close AVG Anti-Spyware. Do not scan yet.

You will need to reboot your computer into Safe Mode for the next steps. It would be a good idea for you to print these instructions, as you will not have access to the internet.

Important: If you have an always on connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode. I suggest that you print out these instructions.

Boot to Safe Mode. To do this:
  • Restart your computer.
  • Continually tap the F8 button as your computer is booting (a menu appears).
  • Use up-arrow key to select Safe Mode and press Enter.
Close all open windows and then start AVG Anti-Spyware, which you downloaded earlier
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act? - make sure that Quarantine is selected.
    • Under How to scan? - All checkboxes should be ticked.
    • Under Possibly unwanted software - All checkboxes should be ticked.
    • Under Reports - Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan? - Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit.
——————————————————-

Reboot in Normal Mode.

——————————————————-

Please post, as a reply to this thread:
  • The information about AdSubtract
  • The AVG Anti-Spyware report
  • A new HijackThis log
Please also let me know how the computer is running. Is it still locking up when browsing with Internet Explorer?
Could not find Moe Money Maker or Ebates Money Maker

Adsubtract is a pop ad blocker, I'm not using it at the moment, is has not been unistalled and it was installed and working long before my current IE problem.

The IE problem persists, but If I launch AOL9.0 i can surf the web. Though my entire system is slow and the performance monitor routinely is showing 100% cpu usage. So system reboot takes 15 minutes but CPU usage stays very high for probably 30 minutes after reboot even though no applications appear to be running. I used msconfig to eliminate all programs that start upon booting up but that doesn't help.

Thanks for all your help and patience. I would have gotten back to you sooner but work has been brutal recently.

Joel

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 4:06:29 PM 2/17/2007

+ Scan result:



HKLM\SOFTWARE\AutoLoader -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\AutoLoader\qFtk1JMlaKaJ -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\AutoLoader\qFty1JMlaKaJ -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Apropos -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Apropos\Client -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Apropos\Client\Cookies -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data\net -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data\net\adintelligence -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data\net\adintelligence\acc.adintelligence.net/ -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data\net\contextplus -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data\net\contextplus\adchannel.contextplus.net/services/AdChannelServer -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Apropos -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Apropos\Client -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Apropos\Client\Cookies -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data\net -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data\net\adintelligence -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data\net\adintelligence\acc.adintelligence.net/ -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data\net\contextplus -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data\net\contextplus\adchannel.contextplus.net/services/AdChannelServer -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Apropos -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Apropos\Client -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Apropos\Client\Cookies -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Apropos\Client\Cookies\Data -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Apropos\Client\Cookies\Data\net -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Apropos\Client\Cookies\Data\net\adintelligence -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Apropos\Client\Cookies\Data\net\adintelligence\acc.adintelligence.net/ -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Apropos\Client\Cookies\Data\net\contextplus -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Apropos\Client\Cookies\Data\net\contextplus\adchannel.contextplus.net/services/AdChannelServer -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Apropos -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Apropos\Client -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Apropos\Client\Cookies -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Apropos\Client\Cookies\Data -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Apropos\Client\Cookies\Data\net -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Apropos\Client\Cookies\Data\net\adintelligence -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Apropos\Client\Cookies\Data\net\adintelligence\acc.adintelligence.net/ -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Apropos\Client\Cookies\Data\net\contextplus -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Apropos\Client\Cookies\Data\net\contextplus\adchannel.contextplus.net/services/AdChannelServer -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\LocalNRDDll.LocalNRDDllObj -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\LocalNRDDll.LocalNRDDllObj.1 -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\LocalNRDDll.LocalNRDDllObj\CLSID -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\LocalNRDDll.LocalNRDDllObj\CurVer -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\WINDOWS\LOCALNRD.DLL -> Adware.BiSpy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\CSBB -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\CSBB\Loader -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\CSBB\contextsidebar -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\CSBB\mirrorunder -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\CSBB\resolvers -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\CSBB\ronsidebar -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\CSBB\sidebar -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\CSBB\spidersidebar -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\CSBB\urlsidebar -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CSBB.CSBBCore -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CSBB.CSBBCore.1 -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CSBB.CSBBCore\CLSID -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CSBB.CSBBCore\CurVer -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\intexp -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\intexp\Config -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\intexp\MyFileSystem2 -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\intexp -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\intexp\Config -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\intexp\MyFileSystem2 -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\intexp -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\intexp\Config -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\intexp\MyFileSystem2 -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\intexp -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\intexp\Config -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\intexp\MyFileSystem2 -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Bundles -> Adware.SecondThought : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Bundles -> Adware.SecondThought : Cleaned with backup (quarantined).
HKU\S-1-5-20\Software\Bundles -> Adware.SecondThought : Cleaned with backup (quarantined).
HKU\S-1-5-21-1220945662-1580436667-842925246-1004\Software\Bundles -> Adware.SecondThought : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Joel Bernstein\Cookies\joel bernstein@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.19:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.21:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.22:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.10:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.20:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.25:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.26:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.27:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.29:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.23:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.24:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.25:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\Default User\4glrs3cs.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.18:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.19:C:\Documents and Settings\Joel Bernstein\Application Data\Mozilla\Profiles\default\tlfc73hi.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\WINDOWS\HTMLHELP.HTM -> Worm.VB.nei : Cleaned with backup (quarantined).


::Report end

HJT Log
Logfile of HijackThis v1.99.1
Scan saved at 4:22:11 PM, on 2/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\wanmpsvc.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\All Users\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=AdSubtract:4445
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
You appear to have installed AVG 7 since your last post. This means that you have two real-time antivirus programs running (AVG and McAfee). This is a bad idea. It causes conflicts and other serious problems. It is also counter-productive. You get less protection, not more! Please uninstall one of them immediately.

——————————————————-

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download AproposFix

Save it to your desktop but do NOT run it yet.

Then please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Once in Safe Mode, please double-click aproposfix.exe and unzip it to the desktop. Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.

When the tool is finished, please reboot back into normal mode, and post a new HijackThis log, along with the entire contents of the log.txt file in the aproposfix folder.
Thanks for your help.

HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 2:46:54 PM, on 2/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Common Files\AOL\ACS\acsd.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\All Users\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=AdSubtract:4445
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{14E41242-69D5-4910-B120-7F23E73FBAC3}: NameServer = 205.188.146.145
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Log.txt

Log of AproposFix v1.1

************

Running from directory:
C:\Documents and Settings\All Users\Desktop\hijackthis\aproposfix\aproposfix

************



Registry entries found:


************

No service found!

Removing hidden folder:
No folder found!

Deleting files:


Backing up files:
Done!

Removing registry entries:

REGEDIT4


Done!

Finished!
Hi jayberns.

I'm a bit worried that there may be some more malware lurking, although nothing shows in the HijackThis log. If something was wrong with IE, I would have expected IEFix to sort it out. Let's run a couple of scans.

—————————————————————–

F-Secure's BlackLight
  • Create a new folder, named Blacklight, in the root of your main drive (usually Local Disk (C:)
  • Download F-Secure's BlackLight from here and save it into this folder.
  • Log off from the internet and disconnect your modem cable.
  • Go to Start= >Run, copy and paste the following into the text box and hit OK: "C:\Blacklight\blbeta.exe" /expert
  • The F-Secure Blacklight Beta window should open.
    • Accept the agreement and click OK.
    • Click the Scan button to begin.
    • Important: Leave the PC idle while the scan takes place.
    • When it has completed, click the Close button.
  • A text file, fsbl-date/time, will be saved in the Blacklight folder, copy and paste this into your next post.
—————————————————————

Download WinPFind2.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind2 on your desktop.
  • Open the WinPFind2 folder and double-click on winpfind2.exe to start the program.
  • Keep the standard settings.
  • In the AddOn Options group (on the right-hand side) click the checkboxes for:
    • awf.def
    • HKCU_IEDesktop.def
    • Jobs.def
    • Policies.def
    • SID_Run_Policies.def
  • Now click the Run All Scans button on the toolbar.
  • When the scans are complete click the Simple Report button in the lower right-hand corner to create a report file. Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Copy the report and paste it as a reply to this thread.

————————————————————

Please post:
  • The Blacklight report
  • The WinPFind2 report (you may need to split this into separate posts to avoid it being cut off).
  • A new HijackThis log
Due to a lack of a responce this topic is now closed.

If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

To help keep your PC clean follow the recommendations here by shelf life.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI