Step 1: I could not remove Search Enhancer Toolbar
I could not remove Viewpoint Tool Bar
Step 2: I may have done wrong. I did not disable anti-virus before
running. That note was at the end of the procedure.
Step 3: I installed Spyware Blaster under this user. When I log on
under different users I can not access this program.
Program files are locked from all but Kathy user.
Step 4: No Windows Critical updates. It just wants to update to
SP3.
Step 5: Took three attemps before downloading Hijackthis
Deckard's System Scanner v20071014.68
Run by Kathy on 2008-06-05 10:16:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
39: 2008-06-05 15:16:59 UTC - RP1269 - Deckard's System Scanner Restore Point
38: 2008-06-04 13:21:40 UTC - RP1268 - Software Distribution Service 3.0
37: 2008-06-03 18:00:58 UTC - RP1267 - System Checkpoint
36: 2008-06-02 17:49:46 UTC - RP1266 - Removed Google Toolbar for Internet Explorer
35: 2008-06-01 18:06:43 UTC - RP1265 - System Checkpoint
-- First Restore Point --
1: 2008-05-07 16:58:16 UTC - RP1231 - Will not resort
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Kathy.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:23:17 AM, on 6/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust Internet Security Suite\eTrust Anti-Spam\QSP-2.1.215.15\QOELoader.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust Personal Firewall\ca.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Kathy\Desktop\Deckers System Scan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Kathy.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: TBSB02751 - {25875464-7327-417C-8264-902D99CF6FD1} - C:\Program Files\Search Enhancer Toolbar\enhancer.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O3 - Toolbar: (no name) - {BFB5F154-9212-46F3-B547-AC6106030A54} - (no file)
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust Anti-Spam\QSP-2.1.215.15\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\CA\eTrust Internet Security Suite\eTrust Personal Firewall\ca.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Search - ?p=ZJxdm027YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) -
http://ipgweb.cce.hp.com/rdqcpqdktp/downloads/sysinfo.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by105fd.bay105.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -
http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/wuweb_site.cab?1188587238265
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1188587230843
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://63.98.136.49/activex/AxisCamControl.ocx
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) -
http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 8008 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 VETFDDNT (VET Floppy Boot Sector Monitor) - c:\windows\system32\drivers\vetfddnt.sys <Not Verified; Computer Associates International, Inc.; Computer Associates Antivirus>
R1 VET-FILT (VET File System Filter) - c:\windows\system32\drivers\vet-filt.sys <Not Verified; Computer Associates International, Inc.; Computer Associates Antivirus>
R1 VETMONNT (VET File Monitor) - c:\windows\system32\drivers\vetmonnt.sys <Not Verified; Computer Associates International, Inc.; Computer Associates Antivirus>
R1 VET-REC (VET File System Recognizer) - c:\windows\system32\drivers\vet-rec.sys <Not Verified; Computer Associates International, Inc.; Computer Associates Antivirus>
R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path Manager® (32-bit)>
R3 Afc (PPdus ASPI Shell) - c:\windows\system32\drivers\afc.sys <Not Verified; Arcsoft, Inc.; Arcsoft(R) ASPI Shell>
R3 DSproct - c:\program files\dellsupport\gtaction\triggers\dsproct.sys <Not Verified; Gteko Ltd.; processt>
S0 AFPAnsi (Alfa File Protector Ansi) - c:\windows\system32\drivers\afpansi.sys (file missing)
S3 DrvFltIp - c:\program files\bulletproofsoft.com\advancedpersonalfirewall\drvfltip.sys (file missing)
S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 sprtsvc_dellsupportcenter (SupportSoft Sprocket Service (dellsupportcenter)) - c:\program files\dell support center\bin\sprtsvc.exe /service /p dellsupportcenter
S4 Automatic LiveUpdate Scheduler - "c:\program files\symantec\liveupdate\aluschedulersvc.exe" (file missing)
S4 LiveUpdate - "c:\progra~1\symantec\liveup~1\lucoms~1.exe" (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-06-04 02:09:03 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2008-05-23 13:52:02 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-05-05 and 2008-06-05 -----------------------------
2008-06-04 07:54:42 0 d-------- C:\ie-spyad_zo
2008-06-04 07:46:32 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-04 07:46:05 0 d-------- C:\Program Files\SpywareBlaster
2008-06-03 13:37:32 0 d-------- C:\Program Files\Panda Security
2008-05-27 10:06:21 0 d-------- C:\Phillip
2008-05-26 07:43:02 0 d-------- C:\Documents and Settings\Matt\Application Data\Google
2008-05-24 17:32:14 0 d-------- C:\Program Files\QuickTime
2008-05-18 18:20:37 0 d-------- C:\Documents and Settings\Kathy\Application Data\Publish Providers
2008-05-18 18:20:03 0 d-------- C:\Documents and Settings\Kathy\Application Data\Sony
2008-05-18 18:15:57 0 d-------- C:\Program Files\Sony
2008-05-18 18:07:06 0 d-------- C:\Documents and Settings\Kathy\Application Data\Sony Setup
2008-05-18 18:06:55 0 d-------- C:\Program Files\Sony Setup
2008-05-18 15:09:25 0 d-------- C:\Documents and Settings\Kathy\Application Data\Ulead Systems
2008-05-07 13:42:00 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-05-07 13:42:00 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-05-07 13:42:00 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-05-07 13:42:00 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-05-07 13:42:00 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-05-07 13:42:00 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-05-07 13:42:00 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-05-07 13:42:00 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-05-07 13:41:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-07 07:46:45 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-05-07 07:46:45 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-05-07 07:46:45 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-05-07 07:46:44 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-05-07 07:46:44 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-05-07 07:46:44 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-05-07 07:46:44 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-05-07 07:46:43 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-05-06 21:08:15 691545 --a------ C:\WINDOWS\unins000.exe
2008-05-06 21:08:15 2546 --a------ C:\WINDOWS\unins000.dat
-- Find3M Report ---------------------------------------------------------------
2008-06-05 10:23:01 0 d-------- C:\Program Files\Trend Micro
2008-06-03 13:18:29 0 d-------- C:\Documents and Settings\Kathy\Application Data\Viewpoint
2008-06-03 13:18:26 0 d-------- C:\Program Files\Viewpoint
2008-06-02 12:49:57 0 d-------- C:\Program Files\Google
2008-06-02 12:01:09 0 d-------- C:\Program Files\Punch! Ultimate Deck
2008-06-02 11:59:09 0 d-------- C:\Program Files\AutoCAD LT 97
2008-05-27 14:39:50 0 d-------- C:\Program Files\exPressit S.E. 2.1
2008-05-27 12:43:45 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-14 16:15:41 0 d-------- C:\Program Files\AIMTunes
2008-05-07 13:42:13 0 d-------- C:\Program Files\Best Buy Rhapsody
2008-05-07 13:40:39 0 d-------- C:\Program Files\Yahoo!
2008-05-07 13:40:35 0 d-------- C:\Documents and Settings\Kathy\Application Data\Real
2008-05-07 10:26:23 0 d-------- C:\Program Files\Real
2008-05-07 10:26:23 0 d-------- C:\Program Files\Common Files
2008-05-07 10:22:24 0 d-------- C:\Documents and Settings\Kathy\Application Data\Adobe
2008-05-07 10:21:02 0 d-------- C:\Program Files\Lavasoft
2008-04-16 21:22:06 4 --a------ C:\WINDOWS\system32\F9C5E7
2008-03-09 10:19:38 249856 --a------ C:\WINDOWS\system32\pdfmona.dll <Not Verified; TODO: <Company name>; TODO: <Product name>>
2008-03-09 10:19:38 51716 --a------ C:\WINDOWS\system32\pdf995mon.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25875464-7327-417C-8264-902D99CF6FD1}]
C:\Program Files\Search Enhancer Toolbar\enhancer.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [09/11/2006 05:40 AM]
"ISUSScheduler"="c:\program files\common files\installshield\updateservice\issch.exe" [09/11/2006 05:40 AM]
"NWEReboot"="" []
"QOELOADER"="C:\Program Files\CA\eTrust Internet Security Suite\eTrust Anti-Spam\QSP-2.1.215.15\QOELoader.exe" [07/31/2007 10:24 AM]
"CaAvTray"="C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe" [07/31/2007 10:24 AM]
"CAVRID"="C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe" [07/31/2007 10:24 AM]
"Zone Labs Client"="C:\Program Files\CA\eTrust Internet Security Suite\eTrust Personal Firewall\ca.exe" [06/03/2005 05:39 AM]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 10:24 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/19/2008 02:10 PM]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [11/15/2007 10:23 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 11:37 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:00 AM]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 11:09 AM]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [09/11/2006 05:40 AM]
"Aim6"="" []
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [11/15/2007 10:23 AM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/18/2006 09:05 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"=0 (0x0)
"DisableTaskMgr"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"=0 (0x0)
"StartMenuLogoff"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Automatic LiveUpdate Scheduler"=2 (0x2)
"MDM"=2 (0x2)
"DSBrokerService"=3 (0x3)
"LiveUpdate"=3 (0x3)
-- End of Deckard's System Scanner: finished at 2008-06-05 10:24:51 ------------