Hello,
Every time I start I.E. to a blank page or use it for a while a popup will be displayed. I have spyware installed but I am baffled to what it is. I have ran spybot, adware, Norton virus scan, and have nothing unauthorized starting up in the system registry. I have absolutely no idea of what the spyware is. Below is the scan from HijackThis, I would appreciate anyone being able to tell me what spyware I have installed.
Thank you very much for your help,
Bill
------------HijackThis Scan
Logfile of HijackThis v1.99.0
Scan saved at 1:14:56 AM, on 1/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon
.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\AutoMate 5\Am5HkWnd.exe
C:\Program Files\SpellCheckAnywhere\s
a.exe
C:\PROGRA~1\Infra\REMSEL~1
.EXE
C:\Program Files\Dell\AccessDirect\da
dapp.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\iPod\bin\iPodManager
.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.e
xe
C:\Program Files\I8kfanGUI\I8kfanGUI.
exe
C:\Program Files\Chameleon Clock\ChamClock.exe
C:\Program Files\AdSubtract PRO\adsub.exe
C:\Program Files\Weather Watcher\ww.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\3M\PSNotes\PSNOTES.E
XE
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\BCMWLT
RY.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EX
E
C:\Program Files\AutoMate 5\AutoMate5Svc.exe
C:\WINDOWS\System32\inetsr
v\inetinfo
.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\Program Files\No-IP\DUC20.exe
C:\WINDOWS\System32\PGPsdk
Serv.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\Program Files\ElectricArcLLC\Telef
fect\tfx.e
xe
C:\WINDOWS\system32\??rss.
exe
C:\PROGRA~1\MOZILL~1\firef
ox.exe
C:\Documents and Settings\Billy\Desktop\hij
ackthis\Hi
jackThis.e
xe
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = http=AdSubtract:4444
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIE
Helper.dll
O2 - BHO: (no name) - {3588A1C3-6752-1C83-5132-4
83624EAFCE
0} - C:\WINDOWS\system32\mmyg.d
ll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-0
00874180BB
3} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-0
0400523e39
a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
2.dll
O2 - BHO: Onfolio Helper - {ba727652-f90e-4d82-9ce4-9
8766dffc37
5} - C:\Program Files\Onfolio\onfoliox.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
09B6AD74AC
C} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-0
0400523e39
a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: Onfolio - {1fea1109-9f65-4fdc-aec5-0
33f6cc6064
1} - mscoree.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O4 - HKLM\..\Run: [AutoMate5] C:\Program Files\AutoMate 5\Am5HkWnd.exe
O4 - HKLM\..\Run: [RunSpellCheckAnywhere] C:\Program Files\SpellCheckAnywhere\s
a.exe
O4 - HKLM\..\Run: [Remote Selector] C:\PROGRA~1\Infra\REMSEL~1
.EXE startup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\da
dapp.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager
.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\pri
ntray.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.e
xe"
O4 - HKCU\..\Run: [i8kfangui] C:\Program Files\I8kfanGUI\I8kfanGUI.
exe /startup
O4 - HKCU\..\Run: [HomeAlarm] C:\Program Files\Chameleon Clock\ChamClock.exe
O4 - HKCU\..\Run: [AdSubtract PRO] "C:\Program Files\AdSubtract PRO\adsub.exe"
O4 - HKCU\..\Run: [WeatherWatcher] C:\Program Files\Weather Watcher\ww.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.E
XE
O4 - Startup: Post-it® Software Notes.lnk = C:\Program Files\3M\PSNotes\PSNOTES.E
XE
O4 - Startup: Tray Icon.lnk = C:\WINDOWS\system32\BCMWLT
RY.EXE
O4 - Global Startup: Shortcut to tfx.exe.lnk = C:\Program Files\ElectricArcLLC\Telef
fect\tfx.e
xe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
2.dll/cmse
arch.html
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXco
ntext.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
2.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
2.dll/cmca
che.html
O8 - Extra context menu item: Capture &Image To Onfolio... - res://C:\Program Files\Onfolio\Onfolio.Wind
owsResourc
es.dll/Add
EntryFromD
ocumentEle
ment.html
O8 - Extra context menu item: Capture &Page To Onfolio... - res://C:\Program Files\Onfolio\Onfolio.Wind
owsResourc
es.dll/Add
LinkEntryF
romDocumen
t.html
O8 - Extra context menu item: Capture &Snippet To Onfolio... - res://C:\Program Files\Onfolio\Onfolio.Wind
owsResourc
es.dll/Add
EntryFromD
ocumentSel
ection.htm
l
O8 - Extra context menu item: Capture &Target To Onfolio... - res://C:\Program Files\Onfolio\Onfolio.Wind
owsResourc
es.dll/Add
EntryFromD
ocumentEle
ment.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
2.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
2.dll/cmtr
ans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\j2re1.4.2_01\bi
n\npjpi142
_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\j2re1.4.2_01\bi
n\npjpi142
_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
6} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillFo
rms.html
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
6} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillFo
rms.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-0
0400523e39
a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo
olbar.html
O9 - Extra 'Tools' menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-0
0400523e39
a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo
olbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F
4B6BB65D5D
F} - C:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F
4B6BB65D5D
F} - C:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-0
0002E6CEF2
B} - C:\PROGRA~1\NEOTRA~1\NTXto
olbar.htm (HKCU)
O16 - DPF: {001EE746-A1F9-460E-80AD-2
69E088D6A0
1} (Infotl Control) -
http://site.ebrary.com/support/plugins/ebraryRdr.cabO16 - DPF: {01A88BB1-1174-41EC-ACCB-9
63509EAE56
B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CABO16 - DPF: {03F998B2-0E00-11D3-A498-0
0104B6EB52
E} (MetaStreamCtl Class) -
https://components.viewpoint.com/adobe/MTSInstallers/MetaStream3.cab?url=http://www.adobe.com/products/atmosphere/downloadplayernow.htmlO16 - DPF: {0E5F0222-96B9-11D3-8997-0
0104BD12D9
4} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CABO16 - DPF: {11260943-421B-11D0-8EAC-0
000C07D88C
F} (iPIX ActiveX Control) -
http://www.ipix.com/download/ipixx.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093883993588O23 - Service: Adobe LM Service - Unknown - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.
exe
O23 - Service: AutoMate 5 - Unisyn Software, LLC - C:\Program Files\AutoMate 5\AutoMate5Svc.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: FTP Voyager Scheduler - Unknown - C:\Program Files\RhinoSoft.com\FTP Voyager\FVSchedulerNT.exe
O23 - Service: iPod Service - Apple Computer, Inc - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exe
O23 - Service: PDEngine - Unknown - C:\Program Files\Raxco\PerfectDisk\PD
Engine.exe
O23 - Service: PDScheduler - Unknown - C:\Program Files\Raxco\PerfectDisk\PD
Sched.exe
O23 - Service: PGPsdkService - PGP Corporation - C:\WINDOWS\System32\PGPsdk
Serv.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WLTRYSVC - Unknown - C:\WINDOWS\System32\wltrys
vc.exe C:\WINDOWS\System32\bcmwlt
ry.exe (file missing)