Thanks Jared

Thanks, I just followed your directions exactly, and I think it worked, because I haven't had a single popup so far. Though it was weird: AdAware under safe mode removed maybe 4 cookies total, from system and smart scan. Maybe it was disabling the system restore and erasing the temp internet files that did it? Maybe I should not enable system restore now?

How can I prevent this spyware infestation from happening again? Where can I get a good free firewall? The problem is, I have a shared internet connection, and I stupidly did not give it adequate protection. Not sure how I should do that now.

Again, thanks a lot. Your directions were really excellent.

Here's the new Hijack Log:

Logfile of HijackThis v1.99.1
Scan saved at 8:47:09 PM, on 4/5/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\NETGEAR\MA111 CONFIGURATION UTILITY\WLANCFG4.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\MPLAYER.EXE
C:\WINDOWS\MPLAYER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [r72S36g] MCICCONF.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [awt2RWMmj] MAIPACK.EXE
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0
O4 - Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll

Comments

  • jaredjared College Station, TX Icrontian
    edited April 2005
    No problem man. Glad I could be of some help. :D.

    Most likely what happened is your computer made a system restore point when it was infected. Basically meaning it may have archived/duplicated some spyware related files that it thought was necessary for a system restore. By disabling this, your computer figured 'hey there is no need to restore so I don't need any of these extra files anymore!' and it no longer safe gaurds them (this is why its a pain to remove infected files from system restore). Some stuff can also get stuck in your temp files and it doesn't hurt to clean those anyways.

    As far as not getting any more bugs. The best thing I would recommend is not using Internet Explorer. I know its a hard habit to break but IE is just a GIANT target for spyware. With all the exploits/active x etc, it is really easy to pick up some nasty stuff. Try using Firefox. It is an alternative browser that is honestly just better than IE. In general it is usually faster and is MUCH safer. When people switch to Firefox they find that it is pretty hard to get reinfected with spyware. It has a plethera of nice features with security to boot. Just click the button in my signature and you can find out some more information on it.

    Lastly you can just inform yourself. One of the best defenses is just having a basic knowlege on how this crap works and how you get it. Click the 'Prevent Infection' link in my sig and there is a nice little article that will explain spyware in a nutshell to you.

    Anyways, glad I could help you out. I am going to go ahead and close this thread since your issue was resolved. If you have anymore questions feel free to PM me.

    Thanks. :mullet:
This discussion has been closed.