This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT Log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm new to your forum. I've been fighting with NewDotNet for the past week. I've run CWshredder; S&D; and AdAware latest and greatest. All Windows, McAfee, AdSubtract, qand ZoneAlarm programs are up to date. Please review following HJT log and confirm that I'm clean. Thanks, Jim M

Logfile of HijackThis v1.99.1
Scan saved at 4:54:10 PM, on 11/19/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
e:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\CTsvcCDA.exe
C:\WINNT\System32\svchost.exe
E:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\WINNT\system32\gearsec.exe
e:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
E:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
e:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
E:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
E:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINNT\system32\stisvc.exe
e:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
e:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
E:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
E:\Program Files\Logitech\iTouch\iTouch.exe
E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\Program Files\Logitech\MouseWare\system\em_exec.exe
E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
E:\Program Files\ATI Multimedia\main\launchpd.exe
E:\Program Files\ATI Multimedia\main\ATIDtct.EXE
E:\RECYCLER\NPROTECT\00000083.exe
E:\program files\interMute\AdSubtract\AdSub.exe
E:\program files\OLYMPUS\CAMEDIA Master 4.1\CM_camera.exe
E:\program files\E-Color\Colorific\hgcctl95.exe
E:\program files\Palm\HOTSYNC.EXE
E:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe
E:\program files\ArcSoft\Media Card Companion\MCC Monitor.exe
E:\program files\Norton SystemWorks\Norton GoBack\GBTray.exe
E:\Program Files\Microsoft Office\Office\1033\msoffice.exe
E:\program files\Caere\PageKeeper30\system\PKJobs.exe
E:\program files\QUICKENW\QWDLLS.EXE
e:\Program Files\Caere\PageKeeper30\SYSTEM\PKSlapi.exe
e:\Program Files\Caere\PageKeeper30\SYSTEM\PKTOPASS.EXE
E:\program files\E-Color\True Internet Color\TICIcon.exe
E:\program files\WinZip\WZQKPICK.EXE
E:\program files\ScanSoft\NaturallySpeaking\Program\natspeak.exe
E:\program files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
G:\Hijackthis\Hijackthis 1_99_1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1048
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - e:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - e:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AdSubtract Toolbar - {F14AABDD-0232-4e5a-9B52-4178AC0A62B5} - C:\WINNT\system32\adsubtb.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [MMTray] e:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [zBrowser Launcher] e:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ATIPTA] e:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Zone Labs Client] e:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Ad-Aware] "E:\program files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe" +c
O4 - HKCU\..\Run: [ATI Launchpad] "E:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] E:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [AWMON] "E:\RECYCLER\NPROTECT\00000083.exe"
O4 - Startup: AdSubtract.lnk = E:\program files\interMute\AdSubtract\AdSub.exe
O4 - Startup: Dragon NaturallySpeaking.lnk = E:\program files\ScanSoft\NaturallySpeaking\Program\natspeak.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\program files\adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AdSubtract.lnk = E:\program files\interMute\AdSubtract\AdSub.exe
O4 - Global Startup: Billminder.lnk = E:\program files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: CAMEDIA Master.lnk = E:\program files\OLYMPUS\CAMEDIA Master 4.1\CM_camera.exe
O4 - Global Startup: Colorific.lnk = E:\program files\E-Color\Colorific\hgcctl95.exe
O4 - Global Startup: HotSync Manager.lnk = E:\program files\Palm\HOTSYNC.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = E:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = E:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = E:\program files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Monitor.lnk = E:\program files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Norton GoBack.lnk = E:\program files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: PageKeeper Jobs.lnk = E:\program files\Caere\PageKeeper30\system\PKJobs.exe
O4 - Global Startup: Quicken Startup.lnk = E:\program files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: SonnReg.lnk = E:\program files\E-Color\Registration\SonnReg.exe
O4 - Global Startup: True Internet Color Icon.lnk = E:\program files\E-Color\True Internet Color\TICIcon.exe
O4 - Global Startup: WinZip Quick Pick.lnk = E:\program files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Dictionary - http://files.db3nf.com/scripts/ie.htm
O8 - Extra context menu item: &Encyclopedia - http://files.db3nf.com/scripts/ie-e.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &ieSpell Options - res://e:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: AdSubtract: Bypass Site - res://E:\program files\interMute\AdSubtract\AdSub.exe/360
O8 - Extra context menu item: AdSubtract: Cloak Image - res://E:\program files\interMute\AdSubtract\AdSub.exe/361
O8 - Extra context menu item: AdSubtract: Report Site - res://E:\program files\interMute\AdSubtract\AdSub.exe/359
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Check &Spelling - res://e:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - e:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - e:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - e:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - e:\Program Files\ieSpell\iespell.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - E:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122944027218
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122946697203
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O20 - Winlogon Notify: ATINotify - logonnfy.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - e:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - E:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT\system32\gearsec.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: Norton Ghost - Symantec Corporation - E:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - e:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Hello Jim M, welcome to the forum. Sorry about the delay in responding :( If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread.
LDTate, thanks for the reply. A current logfile follows.
Jim M


Logfile of HijackThis v1.99.1
Scan saved at 9:01:09 PM, on 12/5/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
e:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\CTsvcCDA.exe
C:\WINNT\System32\svchost.exe
E:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\WINNT\system32\gearsec.exe
E:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
E:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
e:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
E:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINNT\system32\stisvc.exe
e:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
e:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
e:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
E:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
E:\Program Files\Logitech\iTouch\iTouch.exe
E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\Program Files\Logitech\MouseWare\system\em_exec.exe
E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
E:\Program Files\ATI Multimedia\main\launchpd.exe
E:\Program Files\ATI Multimedia\main\ATIDtct.EXE
E:\RECYCLER\NPROTECT\00000083.exe
E:\program files\interMute\AdSubtract\AdSub.exe
E:\program files\OLYMPUS\CAMEDIA Master 4.1\CM_camera.exe
E:\program files\E-Color\Colorific\hgcctl95.exe
E:\program files\Palm\HOTSYNC.EXE
E:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe
E:\program files\ArcSoft\Media Card Companion\MCC Monitor.exe
E:\program files\Norton SystemWorks\Norton GoBack\GBTray.exe
E:\Program Files\Microsoft Office\Office\1033\msoffice.exe
E:\program files\Caere\PageKeeper30\system\PKJobs.exe
e:\Program Files\Caere\PageKeeper30\SYSTEM\PKTOPASS.EXE
e:\Program Files\Caere\PageKeeper30\SYSTEM\PKSlapi.exe
E:\program files\QUICKENW\QWDLLS.EXE
E:\program files\E-Color\True Internet Color\TICIcon.exe
E:\program files\WinZip\WZQKPICK.EXE
E:\program files\ScanSoft\NaturallySpeaking\Program\natspeak.exe
C:\Program Files\Internet Explorer\iexplore.exe
G:\Hijackthis\Hijackthis 1_99_1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1175
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - e:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - e:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AdSubtract Toolbar - {F14AABDD-0232-4e5a-9B52-4178AC0A62B5} - C:\WINNT\system32\adsubtb.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [MMTray] e:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [zBrowser Launcher] e:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ATIPTA] e:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Zone Labs Client] e:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Ad-Aware] "E:\program files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe" +c
O4 - HKCU\..\Run: [ATI Launchpad] "E:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] E:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [AWMON] "E:\RECYCLER\NPROTECT\00000083.exe"
O4 - Startup: AdSubtract.lnk = E:\program files\interMute\AdSubtract\AdSub.exe
O4 - Startup: Dragon NaturallySpeaking.lnk = E:\program files\ScanSoft\NaturallySpeaking\Program\natspeak.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\program files\adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AdSubtract.lnk = E:\program files\interMute\AdSubtract\AdSub.exe
O4 - Global Startup: Billminder.lnk = E:\program files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: CAMEDIA Master.lnk = E:\program files\OLYMPUS\CAMEDIA Master 4.1\CM_camera.exe
O4 - Global Startup: Colorific.lnk = E:\program files\E-Color\Colorific\hgcctl95.exe
O4 - Global Startup: HotSync Manager.lnk = E:\program files\Palm\HOTSYNC.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = E:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = E:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = E:\program files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Monitor.lnk = E:\program files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Norton GoBack.lnk = E:\program files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: PageKeeper Jobs.lnk = E:\program files\Caere\PageKeeper30\system\PKJobs.exe
O4 - Global Startup: Quicken Startup.lnk = E:\program files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: SonnReg.lnk = E:\program files\E-Color\Registration\SonnReg.exe
O4 - Global Startup: True Internet Color Icon.lnk = E:\program files\E-Color\True Internet Color\TICIcon.exe
O4 - Global Startup: WinZip Quick Pick.lnk = E:\program files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Dictionary - http://files.db3nf.com/scripts/ie.htm
O8 - Extra context menu item: &Encyclopedia - http://files.db3nf.com/scripts/ie-e.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &ieSpell Options - res://e:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: AdSubtract: Bypass Site - res://E:\program files\interMute\AdSubtract\AdSub.exe/360
O8 - Extra context menu item: AdSubtract: Cloak Image - res://E:\program files\interMute\AdSubtract\AdSub.exe/361
O8 - Extra context menu item: AdSubtract: Report Site - res://E:\program files\interMute\AdSubtract\AdSub.exe/359
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Check &Spelling - res://e:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - e:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - e:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - e:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - e:\Program Files\ieSpell\iespell.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - E:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122944027218
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122946697203
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O20 - Winlogon Notify: ATINotify - logonnfy.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - e:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - E:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT\system32\gearsec.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: Norton Ghost - Symantec Corporation - E:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - e:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
SpySweeper keeps finding a file which is masked to the operating system which it suspects is a rootkit variant. During reboot I momentarily get a DOS screen which advises that the system was unable to eliminate the file and then continues to boot into Windows.
MS MalWare did not find anything. After I emptied the Recycle bin and Norton Protected files, RootKitRevealer identifies 26 discrepancies, all associated with NProtect directories. I will be away from this computer for the next couple of days. Thanks for taking the time to help. Jim M

RootKitRevealer identifies 26 discrepancies

Can you look in the RootKitRevealer and find the text file that's has the results of the scan and post it?
Here ya go. C:\RECYCLER\NPROTECT 12/6/2005 8:41 AM 0 bytes Hidden from Windows API. C:\RECYCLER\NPROTECT\00000000 12/6/2005 5:24 AM 22.28 MB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000001 12/6/2005 5:24 AM 4.78 MB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000002 12/6/2005 5:24 AM 1.50 MB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000003 12/6/2005 5:33 AM 2.13 MB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000004 12/6/2005 5:45 AM 387.92 KB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000005 12/6/2005 5:46 AM 165.33 KB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000006 12/6/2005 5:47 AM 61.97 KB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000007 12/6/2005 5:48 AM 2.24 KB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000008 12/6/2005 5:48 AM 1.14 KB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000009 12/6/2005 8:41 AM 22.28 MB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000010 12/6/2005 8:41 AM 4.78 MB Hidden from Windows API. C:\RECYCLER\NPROTECT\00000011 12/6/2005 8:41 AM 1.50 MB Hidden from Windows API. C:\RECYCLER\NPROTECT\NPROTECT.LOG 12/5/2005 11:14 AM 631.38 KB Hidden from Windows API. E:\RECYCLER\NPROTECT 12/6/2005 5:23 AM 0 bytes Hidden from Windows API. E:\RECYCLER\NPROTECT\NPROTECT.LOG 12/5/2005 11:14 AM 631.38 KB Hidden from Windows API. F:\RECYCLER\NPROTECT 12/5/2005 11:16 AM 0 bytes Hidden from Windows API. F:\RECYCLER\NPROTECT\NPROTECT.LOG 12/5/2005 11:14 AM 631.38 KB Hidden from Windows API. G:\RECYCLER\NPROTECT 12/5/2005 11:24 PM 0 bytes Hidden from Windows API. G:\RECYCLER\NPROTECT\NPROTECT.LOG 12/5/2005 11:14 AM 631.38 KB Hidden from Windows API. H:\RECYCLER\NPROTECT 12/5/2005 11:16 AM 0 bytes Hidden from Windows API. H:\RECYCLER\NPROTECT\NPROTECT.LOG 12/5/2005 11:14 AM 631.38 KB Hidden from Windows API. M:\RECYCLER\NPROTECT 12/6/2005 5:23 AM 0 bytes Hidden from Windows API. M:\RECYCLER\NPROTECT\NPROTECT.LOG 12/5/2005 11:14 AM 631.38 KB Hidden from Windows API. N:\RECYCLER\NPROTECT 12/5/2005 11:16 AM 0 bytes Hidden from Windows API. N:\RECYCLER\NPROTECT\NPROTECT.LOG 12/5/2005 11:14 AM 631.38 KB Hidden from Windows API.
Those are all in different partitions / drives and in C:\RECYCLER\NPROTECT. All of the Drives / partitions other then C are all empty with only the log. NPROTECT.LOG I'd try and delete those in C: Hows it running?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI