that sure did clean a lot..
next
Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.
that sure did clean a lot..
next
Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.
I Am A Proud Member of ASAP Since 2004
To Ride, Shoot Straight And Speak TheTruth
HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
530TX+
Adaptec Easy CD Creator 4
Ad-Aware SE Personal
Adobe Acrobat 4.0, 5.0
Adobe Download Manager 1.2 (Remove Only)
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0
Adobe® Photoshop® Album Starter Edition 3.0
AIM Toolbar
AOL Instant Messenger
AVG Anti-Spyware 7.5
Backyard Football 2002
Camfrog Video Chat 3.71 (remove only)
CardRd81
ccCommon
CCHelp
CCScore
CR2
DeductionPro 2005-06
D-Link PCI Fast Ethernet Adapter
dvdSanta 4.00
EasyRecovery Professional
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSCT
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTUTOR
ESSvpaht
ESSvpot
GdiplusUpgrade
GE 98067 MiniCam Pro
Google Toolbar for Internet Explorer
HijackThis 1.99.1
HLPCCTR
HLPIndex
HLPPDOCK
HLPRFO
Hotfix for MDAC 2.53 (KB911562)
HP Memories Disc
HP Photosmart Essential
HP Software Update
HP Software Update
ImageMate CompactFlash USB (SDDR-31) Ver. 5.05
InCD
Inspiration 6
Internet Explorer Q903235
Internet Worm Protection
J2SE Runtime Environment 5.0 Update 5
Java 2 Runtime Environment, SE v1.4.2_04
Java 2 Runtime Environment, SE v1.4.2_05
Java Media Framework 2.1.1e
KCsaver1_PC Screen Saver
KCsaver2_PC Screen Saver
Kodak EasyShare software
KSU
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
Macromedia Shockwave Player
Microsoft Internet Explorer 6 SP1
Microsoft Money 2005
Microsoft Office 2000 SR-1 Disc 2
Microsoft Office 2000 SR-1 Professional
Microsoft XML Parser and SDK
MRU-Blaster v1.5 (Database 7/19/2003)
MSN Gaming Zone
MSN Messenger 7.0
MSXML 4.0 SP2 (KB927978)
Napster
Napster Burn Engine
Nero PhotoShow Express
Nero Suite
NeroMIX
NeroVision Express Content
Network Play System (Patching)
Norton AntiVirus 2005
Norton AntiVirus 2005 (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton WMI Update
Norton WMI Update
Notifier
NTI Backup NOW!
NTI CD-Maker 2000 Professional
OTtBP
OTtBPSDK
PCDLNCH
PhotoParade Player
Photosmart 140,240,7200,7600,7700,7900 Series
Presto! PageManager
Presto! PageType
QuickTime
RealPlayer Plus
RoadRash
RollerCoaster Tycoon
Saitek Gaming Extensions
Security Update for Windows 2000 (KB904706)
Security Update for Windows 2000 (KB923689)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
SFR
SFR2
SimCoaster
SMC Barricade Print Server Monitor
SPBBC
Spybot - Search & Destroy 1.4
SpywareBlaster v3.4
Symantec
Symantec Script Blocking Installer
SymNet
TaxCut 2003
TaxCut 2004
TaxCut Deluxe 2005
The Playa
The Sims Unleashed
TroopLedger Millennium Demo
TroopMaster 2005
Update Rollup 1 for Windows 2000 SP4
VCAMCEN
Viewpoint Media Player
VistaShuttle
VPRINTOL
Wal-Mart Music Downloads Store
WeatherBug
Wild Photo Effects
Window Washer 5
Windows 2000 Hotfix - KB329115
Windows 2000 Hotfix - KB883939
Windows 2000 Hotfix - KB891781
Windows 2000 Hotfix - KB893756
Windows 2000 Hotfix - KB896423
Windows 2000 Hotfix - KB896424
Windows 2000 Hotfix - KB896688
Windows 2000 Hotfix - KB896727
Windows 2000 Hotfix - KB899587
Windows 2000 Hotfix - KB899588
Windows 2000 Hotfix - KB899589
Windows 2000 Hotfix - KB900725
Windows 2000 Hotfix - KB901017
Windows 2000 Hotfix - KB901214
Windows 2000 Hotfix - KB902400
Windows 2000 Hotfix - KB904368
Windows 2000 Hotfix - KB905414
Windows 2000 Hotfix - KB905495
Windows 2000 Hotfix - KB905749
Windows 2000 Hotfix - KB905915
Windows 2000 Hotfix - KB908519
Windows 2000 Hotfix - KB908523
Windows 2000 Hotfix - KB908531
Windows 2000 Hotfix - KB911280
Windows 2000 Hotfix - KB911567
Windows 2000 Hotfix - KB912812
Windows 2000 Hotfix - KB912919
Windows 2000 Hotfix - KB913580
Windows 2000 Hotfix - KB914388
Windows 2000 Hotfix - KB914389
Windows 2000 Hotfix - KB916281
Windows 2000 Hotfix - KB917008
Windows 2000 Hotfix - KB917159
Windows 2000 Hotfix - KB917422
Windows 2000 Hotfix - KB917537
Windows 2000 Hotfix - KB917736
Windows 2000 Hotfix - KB917953
Windows 2000 Hotfix - KB918439
Windows 2000 Hotfix - KB918899
Windows 2000 Hotfix - KB920213
Windows 2000 Hotfix - KB920670
Windows 2000 Hotfix - KB920683
Windows 2000 Hotfix - KB920685
Windows 2000 Hotfix - KB920958
Windows 2000 Hotfix - KB921398
Windows 2000 Hotfix - KB921883
Windows 2000 Hotfix - KB922582
Windows 2000 Hotfix - KB922616
Windows 2000 Hotfix - KB922760
Windows 2000 Hotfix - KB923191
Windows 2000 Hotfix - KB923414
Windows 2000 Hotfix - KB923694
Windows 2000 Hotfix - KB923980
Windows 2000 Hotfix - KB924191
Windows 2000 Hotfix - KB924270
Windows 2000 Hotfix - KB925454
Windows 2000 Hotfix - KB925486
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows Media Player system update (9 Series)
WinZip
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
Zoom Ethernet ADSL Modem
I noticed that I have many ESS* files.
I do not know what they are, I will not delete until I here from you.
Thanks again!
hi
sorry for the late reply, i seem to have lost the email notification of your reply
this item wonders me:
C:\Program Files\Newhp
do you know anything about such program ?
it reminds me of something, to make sure its not waht i suspect it to be:
Download and Save Blacklight to your desktop:
Double-click blbeta.exe then accept the agreement, click > scan then > next
You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).
Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there
I Am A Proud Member of ASAP Since 2004
To Ride, Shoot Straight And Speak TheTruth
HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Hi,
At first, the BlackLight program would not work due to debug privilage not given to the administrator group.
I set the local policy to grant this privilage and the program ran.
You were right!
Black Light found 4154 hidden items, many of them located in the hidden folder Newhp.
Here is the log:
However, the log is much too long!
The text that you have entered is too long (827178 characters). Please shorten it to 20000 characters long.
It would take about 40 posts to list it all.
Here is the first chunk of it and the last part of it, the middle looks similar
01/16/07 16:52:34 [Info]: BlackLight Engine 1.0.55 initialized
01/16/07 16:52:34 [Info]: OS: 5.0 build 2195 (Service Pack 4)
01/16/07 16:52:34 [Note]: 7019 4
01/16/07 16:52:34 [Note]: 7005 0
01/16/07 16:52:39 [Note]: 7006 0
01/16/07 16:52:39 [Note]: 7011 964
01/16/07 16:52:39 [Note]: 7026 0
01/16/07 16:52:39 [Note]: 7026 0
01/16/07 16:52:55 [Note]: FSRAW library version 1.7.1021
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\ace.dll
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\AI_13-11-2005.log
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\AI_14-11-2005.log
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\AI_15-11-2005.log
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\AI_16-11-2005.log
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\AI_17-11-2005.log
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\AI_19-11-2005.log
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\0000001c_43781360_000385a6
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\0000001c_43781cde_000347b8
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00000029_43683769_00007d0c
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00000029_436852a4_000a3c19
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00000029_436de9b8_0009b31c
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00000029_43738af0_000b4fd9
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00000029_437aba3c_00045a09
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00000029_437d34c0_000a0b68
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00000035_4373826b_000e1f26
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00000035_4377e816_0009f470
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
01/16/07 16:53:01 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00000035_4377f7d0_0006f1cb
01/16/07 16:53:01 [Note]: 7002 0
01/16/07 16:53:01 [Note]: 7003 1
01/16/07 16:53:01 [Note]: 10002 3
Here is the last part of the log:
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00007f4f_436dd256_00088428
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\000019d9_437d35ca_00066a4b
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\000072a6_437ec020_000bf8c9
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00005af1_437aba54_0003cf34
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00007ac2_437ac359_000753a3
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00007b44_4377f7f9_0009115e
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00005a70_437ecd8f_000728b3
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\000078fe_437acf3e_000ad17b
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\0000323b_4377f4da_0000ae1e
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\000037e6_436c3aa9_000d1b24
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\000037e6_4377e829_00004979
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00005753_437d356a_000623b8
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\0000323b_4377e6cb_0005e40e
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\00005af1_43683773_000af241
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\0000323b_43683969_000a35dc
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:50 [Info]: Hidden file: c:\Program Files\Newhp\Cache\0000323b_436c397a_000b0854
01/16/07 16:54:50 [Note]: 7002 0
01/16/07 16:54:50 [Note]: 7003 1
01/16/07 16:54:50 [Note]: 10002 3
01/16/07 16:54:51 [Info]: Hidden file: c:\Program Files\Newhp\data.bin
01/16/07 16:54:51 [Note]: 7002 0
01/16/07 16:54:51 [Note]: 7003 1
01/16/07 16:54:51 [Note]: 10002 3
01/16/07 16:54:51 [Info]: Hidden file: c:\Program Files\Newhp\mssexl32.exe
01/16/07 16:54:51 [Note]: 7002 0
01/16/07 16:54:51 [Note]: 7003 1
01/16/07 16:54:51 [Note]: 10002 3
01/16/07 16:54:51 [Info]: Hidden file: c:\Program Files\Newhp\robskeys.exe
01/16/07 16:54:51 [Note]: 7002 0
01/16/07 16:54:51 [Note]: 7003 1
01/16/07 16:54:51 [Note]: 10002 3
01/16/07 16:54:51 [Info]: Hidden file: c:\Program Files\Newhp\WinGenerics.dll
01/16/07 16:54:51 [Note]: 7002 0
01/16/07 16:54:51 [Note]: 7003 1
01/16/07 16:54:51 [Note]: 10002 3
01/16/07 17:00:55 [Info]: Hidden file: c:\WINNT\system32\iepkbdfi.exe
01/16/07 17:00:55 [Note]: 7002 0
01/16/07 17:00:55 [Note]: 7003 1
01/16/07 17:00:55 [Note]: 10002 1
01/16/07 17:01:33 [Info]: Hidden file: c:\WINNT\system32\drivers\sysdasup.sys
01/16/07 17:01:33 [Note]: 7002 0
01/16/07 17:01:33 [Note]: 7003 1
01/16/07 17:01:33 [Note]: 10002 1
01/16/07 17:02:28 [Note]: 2000 1012
01/16/07 17:02:28 [Note]: 2000 1012
01/16/07 17:02:28 [Note]: 2000 1012
yep.
thats a rootkit, its called apropos.
luckily a great spyware expert, Swandog46 has made a removal tool for it=>
Please download AproposFix from here:
http://swandog46.geekstogo.com/aproposfix.exe
Save it to your desktop but do not run it yet.
Now reboot into Safe Mode.
This can be done tapping the F8 key as soon as you start your computer
You will be brought to a menu where you can choose to boot into safe mode.
Make sure you choose the option without networking support.
Once in Safe Mode, please double-click aproposfix.exe and unzip it to the desktop.
Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.
When the tool is finished, please reboot back into normal mode, and post a new HijackThis log.
Also post the entire contents of the log.txt file in the aproposfix folder.
I Am A Proud Member of ASAP Since 2004
To Ride, Shoot Straight And Speak TheTruth
HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
by the way thanks for sticking with me
I Am A Proud Member of ASAP Since 2004
To Ride, Shoot Straight And Speak TheTruth
HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
You have been a big help!!
I am also learning about these files too.
Please keep up the good work you do for everyone!
Here is the Apropos Fix Log File:
Log of AproposFix v1.1
************
Running from directory:
C:\Documents and Settings\Administrator\Desktop\aproposfix
************
Registry entries found:
[HKEY_LOCAL_MACHINE\Software\CzPeFAv7bkFD]
@="502526zDEEDEEFEqK0Mk.e1DEEDTGEnZeekE5B56v:KJEu4z8v45E5B5ur572F5B5"
"Device"="\\\\.\\Z3n5TlNo"
"DriverPath"="C:\\WINNT\\system32\\drivers\\sysdasup.sys"
"DriverName"="snpspti"
"HideUninstallerName"="C:\\Program Files\\Newhp\\mssexl32.exe"
"UninstallerPath"="C:\\WINNT\\system32\\hpzb2res.exe"
"UninstallerRegKey"="HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{53E4A5B6-81BE-4888-883C-EFD60A7238CE}"
"UninstallerParams"="/CTUN"
"ServerAddress"="adchannel.contextplus.net"
"LegalNote"="http://adchannel.contextplus.net/legal-note/nonbranded.html"
"PartnerId"="CP.IST2"
"InstallationId"="{Xc0c0da0-8200-7dfe-bc3b-41bc01e4ccb1}"
"PageFiltering"=dword:00000001
"ClientName"="C:\\Program Files\\Newhp\\robskeys.exe"
"AutoUpdater"="C:\\WINNT\\system32\\iepkbdfi.exe"
************
Removing hidden service:
Service snpspti removed.
Removing hidden folder:
Deletion of folder Newhp succeeded!
Deleting files:
Deletion of file C:\WINNT\system32\drivers\sysdasup.sys succeeded!
Deletion of file C:\WINNT\system32\iepkbdfi.exe succeeded!
Deletion of file C:\WINNT\system32\hpzb2res.exe succeeded!
Backing up files:
Done!
Removing registry entries:
REGEDIT4
[-HKEY_CURRENT_USER\Software\CzPeFAv7bkFD]
[-HKEY_LOCAL_MACHINE\Software\CzPeFAv7bkFD]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{53E4A5B6-81BE-4888-883C-EFD60A7238CE}]
Done!
Finished!
Here is the updated HiJack This log file:
Logfile of HijackThis v1.99.1
Scan saved at 8:38:23 PM, on 1/17/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\HPZipm12.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\ImageMate CompactFlash USB\SandIcon.Exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\PROGRA~1\Ahead\NEROPH~2\data\xtras\mssysmgr.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Documents and Settings\Downloads\HiJack This\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SandIcon] C:\ImageMate CompactFlash USB\SandIcon.Exe
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\system32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~2\data\xtras\mssysmgr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} -
O16 - DPF: {1CE17C82-8DE2-4EF6-ACF9-3A8B21830475} -
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tech...l/LSSupCtl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} -
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://www.support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {52A5CD24-64C6-4BAF-A4EC-4D13F451763F} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1137974238274
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...l/SymAData.cab
O16 - DPF: {DB6D4758-0AC3-4B84-A239-D9D4B3F61A2E} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} - http://h30043.www3.hp.com/ps/en/check/qdiagh.cab?322
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: hpdj00 - Unknown owner - C:\DOCUME~1\Bob\LOCALS~1\Temp\hpdj00.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: ptssvc - KODAK - C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
I ran the BlackLight program again to see the change in the log file.
No hidden files were detected.
Thanks again for your help.
The log file is below:
01/17/07 20:44:21 [Info]: BlackLight Engine 1.0.55 initialized
01/17/07 20:44:21 [Info]: OS: 5.0 build 2195 (Service Pack 4)
01/17/07 20:44:22 [Note]: 7019 4
01/17/07 20:44:22 [Note]: 7005 0
01/17/07 20:44:26 [Note]: 7006 0
01/17/07 20:44:26 [Note]: 7011 1576
01/17/07 20:44:26 [Note]: 7026 0
01/17/07 20:44:27 [Note]: 7026 0
01/17/07 20:44:37 [Note]: FSRAW library version 1.7.1021
01/17/07 20:51:26 [Note]: 2000 1012
01/17/07 20:51:26 [Note]: 2000 1012
01/17/07 20:51:26 [Note]: 2000 1012
01/17/07 20:52:46 [Note]: 7007 0
While I was at it, I ran the AVG spyware again.
Log was clean, except for a few cookies that I didn't delete before I ran it.
Thanks!
Here is the log:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:07:39 PM 1/17/2007
+ Scan result:
C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Administrator\Cookies\administrator@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\Michael\Cookies\michael@adrevolver[3].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Michael\Cookies\michael@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Matthew\Cookies\matthew@media.fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Matthew\Cookies\matthew@searchportal.information[1].txt -> TrackingCookie.Information : No action taken.
C:\Documents and Settings\Michael\Cookies\michael@image.masterstats[1].txt -> TrackingCookie.Masterstats : No action taken.
C:\Documents and Settings\Michael\Cookies\michael@perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
::Report end