This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Proactive Computer User At Wits End

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:rant: My computer system is severely infected with every conceivable type of malware, spyware, browser hijack, trojan etc. After using Spybot, Desktop Armor and Webroot Spy Sweeper, my system is verging on total meltdown. My taskbar has been affected (when I minimize a screen such as an internet webpage or other program, the minimized icon does not show along the taskbar) Below is a list of the HiJack This System Log. Thank you for your expertise and help - without you -I would have no one to turn to.


Logfile of HijackThis v1.98.2
Scan saved at 6:32:22 PM, on 11/27/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\WINDOWS\appvj.exe
C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\WINDOWS\system32\sysiz32.exe
C:\PROGRA~1\Toolbar\TBPSSvc.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Gary\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {2F1D33AC-0064-E874-1148-32D75B7B52B1} - C:\WINDOWS\system32\sysjr32.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [sysiz32.exe] C:\WINDOWS\system32\sysiz32.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: TFTP2408
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.static.topconverting.com
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll (file missing)
O20 - AppInit_DLLs: mad.dll
Yikes.

Click here to download Ad-Aware SE and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Click "Start", select "Perform Full System scan" and "Next" to start the scan. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done. Next, download the Lavasoft VX2 cleaner plug-in into AAW SE from here

Close Ad-Aware SE and Ad-Watch (if running). Download the file to your desktop, double-click it to run it and it will install into AAW itself. Open AAW, go to add ons and run the tool. Let me know if it removed anything.

Then, click here to download LSPFix. Extract the program from the zip file and run it, make sure you click the "I know what I'm doing" button. Select aklsp.dll and using the right-pointing 'arrows' and move all instances of aklsp.dll it mentions to the Remove (RHS) side but leave everything else (it might already be over there when you open LSPFix). Repeat exactly for calsp.dll. Click the 'Finished' button (if you exit with the X at top right nothing happens).

Also, click here to download ServiceFilter, a little script by rand1038 that reveals potential unauthorised running services in your system. Download, unzip and double-click ServiceFilter.vbs (you may need to enable your antivirus program to run the file). This script will create a text file named Post_This.txt in the same folder as the script itself has been saved - copy and paste the contents of Post_This.txt in your next reply here.

Rescan with HJT and post a new log here so that any remnants can be removed manually.
My computer is verging closer to serious meltdown and is fighting for it's life!! Pardon the melodramatic tone, but the problems are getting worse…

I recently followed instructions I received from this site. I posted a HiJack This Log and was told to download and execute the following procedures:

- AdAware SE
- LavaSoft VX2 Cleaner Plug-in
- LSP Fix
- ServiceFilter (a script by rand1038 that reveals potential unauthorized running services in your system)

This crap is aggressive and getting worse. I am using a new web browser called Opera - as most of this malware seems to be tied into Internet Explorer. Even though I do not activate IE - all this stuff is still popping up.

As of today, December 5, I am posting 2 Different Logs for review:

- The Post_This Log from the ServiceFilter program AND
- The HiJack This Log


****Thank you again to all the moderators who generiously give their time to helping us out. We truly do appreciate it*****

POST_THIS LOG:

The script did not recognize the services listed below.
This does not mean that they are a problem.

To copy the entire contents of this document for posting:
At the top of this window click "Edit" then "Select All"
Next click "Edit" again then "Copy"
Now right click in the forum post box then click "Paste"

########################################

ServiceFilter 1.1
by rand1038

Microsoft Windows XP Professional
Version: 5.1.2600
Dec 5, 2004 5:33:55 PM


—> Begin Service Listing <—

Unknown Service # 1
Service Name: NWCWorkstation
Display Name: Client Service for NetWare
Start Mode: Auto
Start Name: LocalSystem
Description: Provides access to file and print resources on NetWare …
Service Type: Share Process
Path: c:\windows\system32\svchost.exe -k netsvcs
State: Running
Process ID: 1088
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service #2
Service Name: SwPrv
Display Name: MS Software Shadow Copy Provider
Start Mode: Manual
Start Name: LocalSystem
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this …
Service Type: Own Process
Path: c:\windows\system32\dllhost.exe /processid:{b117a303-4f39-48d4-b3b7-df7851d43d2b}
State: Stopped
Process ID: 0
Started: False
Exit Code: 1077
Accept Pause: False
Accept Stop: False

Unknown Service # 3
Service Name: TBPSSvc
Display Name: WebSeach Toolbar support NT service
Start Mode: Auto
Start Name: LocalSystem
Description: This service supports and maintains WebSeach …
Service Type: Own Process
Path: c:\progra~1\toolbar\tbpssvc.exe
State: Running
Process ID: 984
Started: True
Exit Code: 0
Accept Pause: True
Accept Stop: True

Unknown Service # 4
Service Name: WinToolsSvc
Display Name: WinTools for IE service
Start Mode: Auto
Start Name: LocalSystem
Description: …
Service Type: Own Process
Path: c:\program files\common files\wintools\wtoolss.exe
State: Running
Process ID: 1252
Started: True
Exit Code: 0
Accept Pause: True
Accept Stop: True

Unknown Service # 5
Service Name: WZCBDLService
Display Name: WZCBDL Service
Start Mode: Auto
Start Name: LocalSystem
Description: …
Service Type: Share Process
Path: c:\program files\wzcbdl service\wzcbdls.exe
State: Start Pending
Process ID: 1400
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: False

Unknown Service # 6
Service Name: ZESOFT
Display Name: ZESOFT
Start Mode: Auto
Start Name: LocalSystem
Description: ZESoft …
Service Type: Own Process
Path: c:\windows\zeta.exe
State: Stopped
Process ID: 0
Started: False
Exit Code: 0
Accept Pause: False
Accept Stop: False

Unknown Service # 7
Service Name: � %AFå ¤À¨
Display Name: Workstation NetLogon Service
Start Mode: Auto
Start Name: LocalSystem
Description: …
Service Type: Share Process
Path: c:\windows\appvj.exe /s
State: Running
Process ID: 468
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

—> End Service Listing <—

There are 85 Win32 services on this machine.
7 were unrecognized.

Script Execution Time: 1.3125 seconds.


______________________________________________________

HIJACK THIS LOG:

Logfile of HijackThis v1.98.2
Scan saved at 5:35:18 PM, on 12/5/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Toolbar\TBPSSvc.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\WINDOWS\appvj.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jucheck.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
C:\WINDOWS\System32\yaorww.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\WINDOWS\system32\appyc.exe
C:\WINDOWS\System32\tibs3.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\yegszusn.exe
C:\WINDOWS\System32\winupdt.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\winupdt.exe
C:\WINDOWS\TEMP\ICD2.tmp\svcmm32.exe
C:\WINDOWS\System32\SahAgent.exe
C:\Program Files\CashBack\bin\cashback.exe
C:\Program Files\NaviSearch\bin\nls.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\WINDOWS\System32\umedkkuk\khehalg.exe
C:\WINDOWS\System32\myfxlgaj\rmdsf.exe
C:\WINDOWS\System32\tpfhqg\lwnng.exe
C:\WINDOWS\System32\yocq\vyieip.exe
C:\Documents and Settings\Gary\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {2F1D33AC-0064-E874-1148-32D75B7B52B1} - C:\WINDOWS\system32\sysjr32.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {9FC9288E-3AEC-5DB2-660E-A974B08930EC} - C:\WINDOWS\System32\nfswlbfq\nodkijlg.dll
O4 - HKLM\..\Run: [sysiz32.exe] C:\WINDOWS\system32\sysiz32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [appyc.exe] C:\WINDOWS\system32\appyc.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
O4 - HKLM\..\Run: [USB controller] "C:\WINDOWS\TEMP\ICD2.tmp\svcmm32.exe" /startup
O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\System32\SahAgent.exe
O4 - HKLM\..\Run: [khehalg] C:\WINDOWS\System32\umedkkuk\khehalg.exe
O4 - HKLM\..\Run: [rmdsf] C:\WINDOWS\System32\myfxlgaj\rmdsf.exe
O4 - HKLM\..\Run: [lwnng] C:\WINDOWS\System32\tpfhqg\lwnng.exe
O4 - HKLM\..\Run: [vyieip] C:\WINDOWS\System32\yocq\vyieip.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: TFTP2408
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} - http://www.2nd-thought.com/files/install007.exe
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297B} - http://d2.aaa1screensavers.com/affiliates/10027/rist.exe
O16 - DPF: {EBBD88E5-C372-469D-B4C5-1FE00352AB9B} - http://www.ouchvideo.com/mmviewer_ic.cab
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O20 - AppInit_DLLs: mad.dll
This has to be one of the most infected computers I have ever seen!

First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall Shop-at-Home Agent and TV Media.

You don't appear to have any permanent protection against Viruses and Trojans.

Go here to download the free version of Grisoft's AVG AntiVirus program. Go here here to download the free version of Emsisoft's a2 AntiTrojan program.

Install both programs, check for updates and scan your system allowing them to remove whatever they find.

Reboot into Safe Mode by tapping F8 after the BIOS has loaded. Then, click Start>Control Panel, double-click on Administrative Tools then on Services. Look for a service called Wintools for IE Service. Double-click it to open, then click the Stop button and change the 'Startup type' to Disabled. Do the same for these services also:

WebSeach Toolbar support NT service
ZESOFT
Workstation NetLogon Service


Press CTRL>ALT>DEL to bring up the Task Manager. In the Processes tab, look for WToolsA.exe, WToolsS.exe and WSup.exe. If any or all of these exist, right-click on each one and select End Process Tree and answer affirmatively to any confirmation questions.

Go back to Control Panel, click Add/Remove Programs. If there is an uninstaller for Wintools, try running it.

Click Start>Run, type cmd and click 'OK'. At the prompt, type regsvr32 /u /s "C:\Program Files\Toolbar\toolbar.dll" then . Then type exit to close the command prompt window.

Now delete these directories:

C:\Program Files\Common Files\WinTools <– folder
C:\Program Files\Toolbar <– folder

Reboot back into Normal Mode when done. Rescan with HJT, post a new log and we'll tackle the rest of it.
Well my fears were confirmed with your last post - my computer is severly infected indeed. I went ahead and followed all of your instructions given in your last post. Please make not of the following things that occured through the process of executing these instructions:

- The "Shop-at-Home Agent" and "TV Media" agent were not listed under the Add or Remove Programs section of the Control Pannel. There were a variety of other programs listed on there that I could easily identify as malware, however after removing them from the section, they often return with a vengence.

- I did download and scan/remove items with the AVG and a2 programs.

- I disabled the "WebSearch Toolbar support NT service" and "Workstation NetLogon Service," but was unable to locate the "ZESOFT." However I did disable an item listed as "WZCBDL." This conspicuous item has been under the Add or Remove Programs section for quite some time, even after I attemped to remove it.

- No "Wintools" program could be found under the Add or Remove Programs section

- Finally, after entering in the prompt you gave, the only files I located were:
C:\Program Files\Common Files - but that's where it ended - there was no "Win Tools" folder. There was not a "Toolbar" folder either in the Program Files.

Listed below is an updated HJT Log. Thank you again for your patience and willingness to help. I will certainly be making a donation to the site when I get paid next.
_______________________________
Logfile of HijackThis v1.98.2
Scan saved at 3:57:44 AM, on 12/6/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\DOCUME~1\Gary\LOCALS~1\Temp\ICD6.tmp\svcmm32.exe
C:\WINDOWS\System32\yaorww.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jucheck.exe
C:\Program Files\Bcpc\bcpc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\SED\SED.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\System32\winupdt.exe
C:\WINDOWS\gmicdgn.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
C:\Program Files\a2\a2guard.exe
C:\Program Files\VBouncer\VirtualBouncer.exe
C:\PROGRA~1\COMMON~1\tsa\ts2.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\winupdt.exe
C:\Documents and Settings\Gary\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.ht…count_id=146189
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.ht…count_id=146189
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.ht…count_id=146189
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dll
O2 - BHO: Flash Enhancer - {7CD20E91-1F31-41da-8379-479EA31DF969} - c:\Program Files\XML\XML.dll
O3 - Toolbar: Search - {3B43B76E-2F31-4D76-5C63-BC3ACD29A09C} - C:\WINDOWS\Rzhujwsb.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\PROGRA~1\ISTbar\istbar.dll
O4 - HKLM\..\Run: [sysiz32.exe] C:\WINDOWS\system32\sysiz32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [appyc.exe] C:\WINDOWS\system32\appyc.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [atllc.exe] C:\WINDOWS\system32\atllc.exe
O4 - HKLM\..\Run: [USB controller] "C:\DOCUME~1\Gary\LOCALS~1\Temp\ICD6.tmp\svcmm32.exe" /startup
O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [BCPC] "C:\Program Files\Bcpc\bcpc.exe"
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common Files\Java\bcre.exe"
O4 - HKLM\..\Run: [Xcpy1] "C:\Program Files\Common Files\Java\Xcpy1.exe"
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [SxDJjCxKp] C:\WINDOWS\gmicdgn.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [fwpur] C:\WINDOWS\fwpur.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - Startup: Virtual Bouncer.lnk = C:\Program Files\VBouncer\VirtualBouncer.exe
O4 - Global Startup: TFTP2408
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} - http://www.2nd-thought.com/files/install007.exe
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297B} - http://d2.aaa1screensavers.com/affiliates/10027/rist.exe
O16 - DPF: {EBBD88E5-C372-469D-B4C5-1FE00352AB9B} - http://www.ouchvideo.com/mmviewer_ic.cab
O20 - AppInit_DLLs: mad.dll



:unsure:
Let's clean you up a bit, some of this will return and we'll have to deal with it separately.

Press Control-Alt-Del to enter the Task Manager. Click on the Processes tab and end the following processes:

svcmm32.exe
yaorww.exe
bcpc.exe
SED.exe
istsvc.exe
gmicdgn.exe
optimize.exe
tsm2.exe
VirtualBouncer.exe
ts2.exe
winupdt.exe


Exit the Task Manager when finished. Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.ht…count_id=146189
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.ht…count_id=146189
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.ht…count_id=146189
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lzpwz.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dll
O3 - Toolbar: Search - {3B43B76E-2F31-4D76-5C63-BC3ACD29A09C} - C:\WINDOWS\Rzhujwsb.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\PROGRA~1\ISTbar\istbar.dll
O4 - HKLM\..\Run: [sysiz32.exe] C:\WINDOWS\system32\sysiz32.exe
O4 - HKLM\..\Run: [appyc.exe] C:\WINDOWS\system32\appyc.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [atllc.exe] C:\WINDOWS\system32\atllc.exe
O4 - HKLM\..\Run: [USB controller] "C:\DOCUME~1\Gary\LOCALS~1\Temp\ICD6.tmp\svcmm32.exe" /startup
O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [BCPC] "C:\Program Files\Bcpc\bcpc.exe"
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common Files\Java\bcre.exe"
O4 - HKLM\..\Run: [Xcpy1] "C:\Program Files\Common Files\Java\Xcpy1.exe"
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [SxDJjCxKp] C:\WINDOWS\gmicdgn.exe
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [fwpur] C:\WINDOWS\fwpur.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} - http://www.2nd-thought.com/files/install007.exe
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297B} - http://d2.aaa1screensavers.com/affiliates/10027/rist.exe
O16 - DPF: {EBBD88E5-C372-469D-B4C5-1FE00352AB9B} - http://www.ouchvideo.com/mmviewer_ic.cab
O20 - AppInit_DLLs: mad.dll

Find and delete the following:

C:\WINDOWS\system32\sysiz32.exe
C:\WINDOWS\system32\appyc.exe
C:\WINDOWS\System32\tibs3.exe
C:\PROGRAM FILES\Toolbar\ <– folder
C:\WINDOWS\system32\atllc.exe
C:\Documents and Settings\Gary\Local Settings\Temp\ICD6.tmp\svcmm32.exe
C:\WINDOWS\System32\stcloader.exe
C:\WINDOWS\System32\winupdtl.exe
C:\Program Files\TV Media\ <– folder
C:\Program Files\Bcpc\ <– folder
C:\Program Files\Common Files\Java\bcre.exe
C:\Program Files\Common Files\Java\Xcpy1.exe
C:\Program Files\SED\ <– folder
C:\Program Files\ISTsvc\ <– folder
C:\WINDOWS\gmicdgn.exe
c:\program files\180solutions\ <– folder
C:\WINDOWS\fwpur.exe
C:\Program Files\Common Files\tsa\ <– folder
C:\WINDOWS\System32\yaorww.exe
C:\Program Files\VBouncer\ <– folder
C:\Program Files\Internet Optimizer\ <– folder
c:\windows\zeta.exe
c:\windows\appvj.exe

Reboot when done, rescan with HJT and post a new log here.
Thanks for the ongoing support. I followed the instructions given in your last post, but was unable to locate some of the files or running processes you listed to delete from the C drive. You will notice in my latest HJT Log - that 2 entries continue to reappear after being deleted. Specifically the "TVMEDIA" program will not delete. I attempted to delete the folder under the Program Files section of the C Drive. I get an error message saying "TVM is being used by another person or program." So this one is a nasty!! Also the 015 Trusted Zone continues to be listed. I'm also not sure where to locate some of the running processes you asked me to delete. Some of them were not located under the specified sections.

Thanks again for your help =)

Logfile of HijackThis v1.98.2
Scan saved at 12:50:58 AM, on 12/7/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\yaorww.exe
C:\Program Files\a2\a2guard.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jucheck.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Documents and Settings\Gary\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: Flash Enhancer - {7CD20E91-1F31-41da-8379-479EA31DF969} - c:\Program Files\XML\XML.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: TFTP2408
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_In…/dwnldr_ext.cab
O16 - DPF: {DBAE7000-01EC-4162-8FEB-8A27AC937CA0} (HDPluginCtrl Class) - http://webpdp.gator.com/4/download/hdplugi…ndle43v5d33.cab
O20 - AppInit_DLLs: mad.dll
Please post another service filter log. TVMedia is a pain to remove - let's get rid of all the other pests then deal with that one. Are you noticing any improvement :P
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI