This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help--received no response last time.

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The about:blank homepage has taken over my browser. Also I get popups all the time and there are words underlined in blue on every page I go to as if to indicate a link, but when clicked on, they go to a search engine of some sort. I have Norton 2004/Internet Security which keeps detecting a Trojan, and I have Trojan Hunter and Adware SE Personal and neither of these seem to be doing the trick. Please help….the first time I posted I didn't get any response. Following is my log file. Thank you. Logfile of HijackThis v1.99.1 Scan saved at 5:18:42 PM, on 7/29/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\00THotkey.exe C:\WINDOWS\System32\TFNF5.exe C:\WINDOWS\System32\TPWRTRAY.EXE C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe C:\WINDOWS\System32\ezSP_Px.exe C:\Program Files\ltmoh\Ltmoh.exe C:\WINDOWS\apimv.exe C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe C:\WINDOWS\System32\TDispVol.exe C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE C:\Program Files\TOSHIBA\TouchED\TouchED.Exe C:\toshiba\ivp\ism\pinger.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Synaptics\SynTP\CPad\cPadFstR.Exe C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\WINDOWS\netkq32.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe C:\WINDOWS\DvzCommon\DvzMsgr.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\Program Files\Palm\HOTSYNC.EXE C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Alexis\Desktop\IEXPLORE.EXE C:\Documents and Settings\Alexis\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\xgqwy.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\xgqwy.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\xgqwy.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\xgqwy.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\xgqwy.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\xgqwy.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Class - {5ADBC662-7902-CAC4-D18A-CD699FB2A6CD} - C:\WINDOWS\system32\apiuv32.dll O2 - BHO: Class - {88CA47DE-D491-40E1-D009-5594D634627D} - C:\WINDOWS\sysix.dll O2 - BHO: Class - {96DF800A-C660-BD6C-1D33-EC8F6FA48462} - C:\WINDOWS\msrl.dll O2 - BHO: GDS module - {A084A565-B09B-4e4c-A497-7CC50AEAB2A7} - C:\WINDOWS\gds5.dll (file missing) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O2 - BHO: Class - {D4FA2EA7-F9B4-4CE8-32A4-AEF3FF5672AD} - C:\WINDOWS\d3fn.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 03 O4 - HKLM\..\Run: [TDispVol] TDispVol.exe O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [cPadFstR] C:\Program Files\Synaptics\SynTP\CPad\cPadFstR.Exe O4 - HKLM\..\Run: [cPadAlarm] C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe O4 - HKLM\..\Run: [netkq32.exe] C:\WINDOWS\netkq32.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe" O4 - HKLM\..\Run: [iplu32.exe] C:\WINDOWS\iplu32.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE O4 - Startup: PowerReg Scheduler.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: DataViz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: officejet 6100.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe02a.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apimv.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing) O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Thank you for responding. I downloaded and applied Service Pack 1a. Following is my fresh log file. In addition to the about:blank homepage and the popups, every time I try to start internet exlorer from my desktop it tells me I need to send an error report and closes it, so I have to start it from the start menu. Logfile of HijackThis v1.99.1 Scan saved at 12:46:55 PM, on 7/30/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\System32\wuauclt.exe C:\WINDOWS\System32\00THotkey.exe C:\WINDOWS\System32\TFNF5.exe C:\WINDOWS\System32\TPWRTRAY.EXE C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe C:\WINDOWS\System32\ezSP_Px.exe C:\Program Files\ltmoh\Ltmoh.exe C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe C:\WINDOWS\System32\TDispVol.exe C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE C:\Program Files\TOSHIBA\TouchED\TouchED.Exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Synaptics\SynTP\CPad\cPadFstR.Exe C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\WINDOWS\apimv.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\DvzCommon\DvzMsgr.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\Program Files\Palm\HOTSYNC.EXE C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\toshiba\ivp\ism\ivpsvmgr.exe C:\WINDOWS\netkq32.exe C:\WINDOWS\explorer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Alexis\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mzhrm.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mzhrm.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\mzhrm.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mzhrm.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mzhrm.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\mzhrm.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: GDS module - {A084A565-B09B-4e4c-A497-7CC50AEAB2A7} - C:\WINDOWS\gds5.dll (file missing) O2 - BHO: Class - {A81BCDA3-15E4-11AF-47AC-CDE1A5CE4A3C} - C:\WINDOWS\addvo.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O2 - BHO: Class - {C6986EF5-1C46-9B24-BB5A-1DD4D86BF05C} - C:\WINDOWS\system32\atlgb32.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 03 O4 - HKLM\..\Run: [TDispVol] TDispVol.exe O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [cPadFstR] C:\Program Files\Synaptics\SynTP\CPad\cPadFstR.Exe O4 - HKLM\..\Run: [cPadAlarm] C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe O4 - HKLM\..\Run: [netkq32.exe] C:\WINDOWS\netkq32.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe" O4 - HKLM\..\Run: [iplu32.exe] C:\WINDOWS\iplu32.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE O4 - Startup: PowerReg Scheduler.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: DataViz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: officejet 6100.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe02a.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apimv.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing) O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Print out these instructions as most of the steps need to be done in Safe Mode and you won't be able to go online.

Do this so you can see hidden files and folders - click here to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double-click the xphidden.reg and when asked to merge say yes.

Click here to download About:Buster and unzip it to your desktop. Don´t run it yet.

Click here to download System Security Suite. Extract it from the zip file into a folder.

Click here to download ewido security suite - it is a trial version of the program. Install ewido security suite - when installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". Launch ewido, there should be an icon on your desktop double-click it and the program will now go to the main screen - you will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed. If you are having problems with the updater, you can use this link to manually update ewido. Do NOT run a scan yet.

Next, go to Start->Run and type Services.msc then hit Ok. Scroll down and find the service called "Network Security Service". When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.

Reboot into Safe Mode by tapping F8 after the BIOS has loaded.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mzhrm.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mzhrm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\mzhrm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mzhrm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mzhrm.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\mzhrm.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: GDS module - {A084A565-B09B-4e4c-A497-7CC50AEAB2A7} - C:\WINDOWS\gds5.dll (file missing)
O2 - BHO: Class - {A81BCDA3-15E4-11AF-47AC-CDE1A5CE4A3C} - C:\WINDOWS\addvo.dll
O2 - BHO: Class - {C6986EF5-1C46-9B24-BB5A-1DD4D86BF05C} - C:\WINDOWS\system32\atlgb32.dll
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [netkq32.exe] C:\WINDOWS\netkq32.exe
O4 - HKLM\..\Run: [iplu32.exe] C:\WINDOWS\iplu32.exe
O4 - Startup: PowerReg Scheduler.exe
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe02a.dll
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apimv.exe

Find and delete the following:

C:\WINDOWS\netkq32.exe
C:\WINDOWS\iplu32.exe
C:\WINDOWS\apimv.exe

Now double click AboutBuster.exe that you downloaded earlier. Click Start then click OK. This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

Next open ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin (do not open any folders or open the windows control panel while the scan is in progress).
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.

Reboot back into Normal Mode. Click here to download cwsuninst.zip. Extract cwsuninst.reg from the zip file and save it to the desktop. When done, double-click the cwsuninst.reg and when asked to merge say yes.

Open System Security Suite and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

Scan again with HijackThis. Post your logs from HijackThis, About:Buster and Ewido Security Suite in your next reply.
Thanks for your help. I followed all your instructions. 3 of the entries were not there for me to delete in the hijack log, and the part that said mzhrm.dll was replaced by nrxwy.dll in the ones I did delete. The first two in the updated log that start with R1 were not there when I ran it in safe mode. Also, I couldn't find iplu32.exe. Following are my updated logs from HijackThis, About:Buster, and Ewido Security Suite. Logfile of HijackThis v1.99.1 Scan saved at 11:18:16 AM, on 7/31/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe C:\WINDOWS\System32\00THotkey.exe C:\WINDOWS\System32\TFNF5.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\System32\TPWRTRAY.EXE C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe C:\WINDOWS\System32\ezSP_Px.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\ltmoh\Ltmoh.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\System32\TDispVol.exe C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE C:\Program Files\TOSHIBA\TouchED\TouchED.Exe C:\toshiba\ivp\ism\pinger.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Synaptics\SynTP\CPad\cPadFstR.Exe C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\DvzCommon\DvzMsgr.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\Program Files\Palm\HOTSYNC.EXE C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Alexis\Desktop\IEXPLORE.EXE C:\Documents and Settings\Alexis\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nrxwy.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nrxwy.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 03 O4 - HKLM\..\Run: [TDispVol] TDispVol.exe O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [cPadFstR] C:\Program Files\Synaptics\SynTP\CPad\cPadFstR.Exe O4 - HKLM\..\Run: [cPadAlarm] C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE O4 - Startup: PowerReg Scheduler.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: DataViz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: officejet 6100.lnk = ? O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apimv.exe (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing) O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe AboutBuster 5.0 reference file 28 Scan started on [7/30/2005] at [11:30:49 PM] ———————————————— Removed Stream! C:\WINDOWS\$_hpcst$.hpc:kudtvq Removed Stream! C:\WINDOWS\$_hpcst$.hpc:lhlqbr Removed Stream! C:\WINDOWS\Blue Lace 16.bmp:xgtrs Removed Stream! C:\WINDOWS\bootstat.dat:fabgcb Removed Stream! C:\WINDOWS\BRGVARS.INI:tqtcwx Removed Stream! C:\WINDOWS\Coffee Bean.bmp:ekmxjt Removed Stream! C:\WINDOWS\dcwkz.dat:zsnewj Removed Stream! C:\WINDOWS\DtcInstall.log:eerbtz Removed Stream! C:\WINDOWS\explorer.scf:wcdfkd Removed Stream! C:\WINDOWS\FaxSetup.log:wecgvc Removed Stream! C:\WINDOWS\FeatherTexture.bmp:puvkmf Removed Stream! C:\WINDOWS\Gone Fishing.bmp:gsklny Removed Stream! C:\WINDOWS\iis6.log:ehhrkq Removed Stream! C:\WINDOWS\imxrt.txt:wiaeeb Removed Stream! C:\WINDOWS\KB824141.log:bxhpgh Removed Stream! C:\WINDOWS\KB828741.log:txacak Removed Stream! C:\WINDOWS\KB834707-IE6-20040929.115007.log:rnvygi Removed Stream! C:\WINDOWS\KB835732.log:ckavkw Removed Stream! C:\WINDOWS\KB839643.log:coodas Removed Stream! C:\WINDOWS\KB839645.log:wkiuic Removed Stream! C:\WINDOWS\KB841356.log:wtleuq Removed Stream! C:\WINDOWS\KB841873.log:lcljzz Removed Stream! C:\WINDOWS\KB841873.log:mkaoug Removed Stream! C:\WINDOWS\KB842773.log:awdaeo Removed Stream! C:\WINDOWS\KB887822.log:flluxr Removed Stream! C:\WINDOWS\lfhlm.dat:hllrxk Removed Stream! C:\WINDOWS\lrtnf.log:ayzfet Removed Stream! C:\WINDOWS\LUINSTALL.LOG:qnoyve Removed Stream! C:\WINDOWS\msdfmap.ini:avgckn Removed Stream! C:\WINDOWS\msgsocm.log:zcdycn Removed Stream! C:\WINDOWS\nokoe.log:cfauir Removed Stream! C:\WINDOWS\ntwpb.txt:vgszkc Removed Stream! C:\WINDOWS\ocgen.log:rdvmfq Removed Stream! C:\WINDOWS\ocgen.log:swzhnx Removed Stream! C:\WINDOWS\ocmsn.log:hsfbcs Removed Stream! C:\WINDOWS\ODBC.INI:oiftsd Removed Stream! C:\WINDOWS\OEWABLog.txt:ztyofv Removed Stream! C:\WINDOWS\oroqd.log:hjxyun Removed Stream! C:\WINDOWS\Q310601.log:yqmcwn Removed Stream! C:\WINDOWS\Q311889.log:qjehzx Removed Stream! C:\WINDOWS\Q312368.log:laftgk Removed Stream! C:\WINDOWS\Q315754.log:kcdps Removed Stream! C:\WINDOWS\Q323255.log:pehryb Removed Stream! C:\WINDOWS\Q324096.log:towdzc Removed Stream! C:\WINDOWS\Q324380.log:draqco Removed Stream! C:\WINDOWS\Q326830.log:ifzwbl Removed Stream! C:\WINDOWS\Q328940.log:hzsrhl Removed Stream! C:\WINDOWS\Q828026.log:jnhzpg Removed Stream! C:\WINDOWS\Q828026.log:mukuyg Removed Stream! C:\WINDOWS\QUICKEN.INI:bvtaqz Removed Stream! C:\WINDOWS\QuickInstall.INI:waynnv Removed Stream! C:\WINDOWS\REGLOCS.OLD:bnserj Removed Stream! C:\WINDOWS\REGLOCS.OLD:slnzox Removed Stream! C:\WINDOWS\Rhododendron.bmp:ovjnwf Removed Stream! C:\WINDOWS\River Sumida.bmp:fiaygn Removed Stream! C:\WINDOWS\Santa Fe Stucco.bmp:teeqqz Removed Stream! C:\WINDOWS\SchedLgU.Txt:mirnqv Removed Stream! C:\WINDOWS\setup.log:qjlica Removed Stream! C:\WINDOWS\setupact.log:fjbskf Removed Stream! C:\WINDOWS\setuperr.log:uvddqq Removed Stream! C:\WINDOWS\sjuxr.txt:crzgts Removed Stream! C:\WINDOWS\SynInst.log:cyfyat Removed Stream! C:\WINDOWS\TSession.reg:qqroiq Removed Stream! C:\WINDOWS\tvpnh.log:duffdc Removed Stream! C:\WINDOWS\vbaddin.ini:jqjtda Removed Stream! C:\WINDOWS\vbaddin.ini:mfpuah Removed Stream! C:\WINDOWS\VBCTL3D.INI:jjiecg Removed Stream! C:\WINDOWS\win.ini:hpqcyd Removed Stream! C:\WINDOWS\WindowsUpdate.log:cfehle Removed Stream! C:\WINDOWS\WindowsUpdate.log:tfdgeh Removed Stream! C:\WINDOWS\winnt256.bmp:mgygst Removed Stream! C:\WINDOWS\wmeho.txt:ipyplq Removed Stream! C:\WINDOWS\xpsp1hfm.log:ehilme Removed Stream! C:\WINDOWS\xzouz.txt:cumiyx Removed Stream! C:\WINDOWS\ylboh.log:csxcql Removed Stream! C:\WINDOWS\yqwaq.log:vtphsv Removed Stream! C:\WINDOWS\zapvm.log:bqaknc Removed Stream! C:\WINDOWS\_default.pif:abekyt ———————————————— Removed File! : C:\Windows\bzrhx.dat Removed File! : C:\Windows\dmuaf.dll Removed File! : C:\Windows\fabwq.dat Removed File! : C:\Windows\gnsdy.dat Removed File! : C:\Windows\ihqvs.dat Removed File! : C:\Windows\jmihj.dat Removed File! : C:\Windows\nrxwy.dll Removed File! : C:\Windows\vlqvi.dat Removed File! : C:\Windows\wcwja.dat Removed File! : C:\Windows\wtnux.dat Removed File! : C:\Windows\xnacu.dat Removed File! : C:\Windows\ymhax.dat Removed File! : C:\Windows\zvrny.dat Removed File! : C:\Windows\zxqsk.dll Removed File! : C:\Windows\System32\bexwy.dat Removed File! : C:\Windows\System32\eyryo.dat Removed File! : C:\Windows\System32\httmw.dll Removed File! : C:\Windows\System32\ihazk.dat Removed File! : C:\Windows\System32\lnubt.dat Removed File! : C:\Windows\System32\ltbai.dat Removed File! : C:\Windows\System32\mzopf.dat Removed File! : C:\Windows\System32\pmwnj.dat Removed File! : C:\Windows\System32\rfyuf.dat Removed File! : C:\Windows\System32\sqhqg.dat Removed File! : C:\Windows\System32\xetso.dat Removed File! : C:\Windows\System32\xnnki.dat Removed File! : C:\Windows\System32\xwhxi.dat ———————————————— Scan was COMPLETED SUCCESSFULLY at 11:31:52 PM ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 8:37:53 AM, 7/31/2005 + Report-Checksum: A150975E + Scan result: HKLM\SOFTWARE\Classes\CLSID\{01198741-DBE0-E6F4-9DBE-877B61FB1D1D} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{05BCCFDC-9678-9095-77E8-18289DB38257} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0661C16F-8ED8-1431-8A0B-2C95C6994589} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{151272FB-2CD4-E387-93B1-F52B2911D0EE} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1D232F9D-941D-5CD9-732F-8F6EC1977CF2} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1DE20533-9118-BF9A-A6C6-F8E881A5FD4B} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{37D770DC-7684-506E-506F-B70AAFEB6F95} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5B7E5C2F-7668-51A3-BA8C-F6B376755AF9} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6D793FE9-8675-897B-589B-5BCAB9D3CFEF} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{841CB982-C366-4290-3F00-95A1A5F3C340} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9320654E-9DD7-7B4E-FD11-BE169AC706F5} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A9629E20-9B59-1F5F-58AE-E699D9122E1F} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C75B8795-6012-883F-06EE-5F1501763CFE} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{EAB9C89C-A224-B071-97DC-24A78995DD29} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{ECEAF197-B6EF-9E38-0846-FF3BB03983AD} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F80F0D50-2D6C-75C3-606A-3DFE0F4FC5D0} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW -> Spyware.CoolWebSearch : Cleaned with backup C:\Documents and Settings\Alexis\Cookies\alexis@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup C:\Documents and Settings\Alexis\Cookies\alexis@buycom.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\Alexis\Cookies\alexis@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup C:\Documents and Settings\Alexis\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Alexis\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Alexis\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Alexis\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Alexis\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Alexis\Desktop\hijackthis\backups\backup-20050730-231845-199.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\A4W.INI:bergry -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addpt.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addvo.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addyh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appcq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appgb32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appqz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlcd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\cfosl.txt:mlupmw -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\cfosl.txt:raaqhq -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\control.ini:vwloq -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3fj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3pz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\DIPLOMA.INI:slgrrm -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ievj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iplf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipnu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iptl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcmz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ModemLog_TOSHIBA Software Modem.txt:idyxkv -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mstx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\nthw32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntwpb.txt:agetyj -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntwpb.txt:vjwtng -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ODBC.INI:shxyst -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\orun32.ini:jlfrep -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\Satellite.scr:wlserq -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysdy.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysql32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system.ini:uslkga -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system.ini:veavyi -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32:efaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup C:\WINDOWS\system32\addvi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addvs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addwy32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appmp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\appol.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlnz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlpa32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlvf.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crac32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crii.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\d3bu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3xq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\iekx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipxw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\javaia.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mshx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msoq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntpd.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\sdkev.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdkzb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\windm.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winik32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winit32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winqo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winww32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\T30DebugLogFile.txt:rbrkbo -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\taslc.txt:rdtwbk -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\taslc.txt:uyqlud -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ToshDefs.reg:irvoan -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ToshDefs.reg:ntwpbc -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ToshDefs.reg:owlbtt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\utksb.txt:ljjdo -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\windl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winsx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\wvtno.txt:cgcndt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\xzouz.txt:akcwjm -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:adgxwu -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:aiumqz -> Spyware.SearchPage : Cleaned with backup C:\WINDOWS\_default.pif:aqytrm -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:asjvgz -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:bjduag -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:blqktf -> Spyware.SearchPage : Cleaned with backup C:\WINDOWS\_default.pif:cbegjp -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:cjvcbl -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:cplfxe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:cufvhs -> Spyware.SearchPage : Cleaned with backup C:\WINDOWS\_default.pif:dfmoid -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:dhgclf -> Spyware.SearchPage : Cleaned with backup C:\WINDOWS\_default.pif:dkxkqf -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:dmjmhs -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:dulbtw -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:dyjukk -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:edvlcl -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:ejecwq -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:elprxn -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:exjzzp -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:eyozsy -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:ezfsga -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:fmipan -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:fmnqcx -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:fsdptg -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:fsljuf -> Spyware.SearchPage : Cleaned with backup C:\WINDOWS\_default.pif:gbjvqb -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:gibmjt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:gindpn -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:ginqax -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:gjrpel -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:gmkluc -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\_default.pif:goezbu -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:goleca -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:gttojh -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:guyier -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:haawqs -> Spyware.SearchPage : Cleaned with backup C:\WINDOWS\_default.pif:hoidtj -> Spyware.SearchPage : Cleaned with backup C:\WINDOWS\_default.pif:hrcavh -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:ijhpmj -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\_default.pif:ikmif -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\_default.pif:irqhmp -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\_default.pif:iucsxl -> Spyware.SearchPage : Cleaned with backup C:\WINDOWS\_default.pif:jaxlib -> Spyware.SearchPage : Cleaned with backup ::Report End
Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nrxwy.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nrxwy.dll/sp.html#37049
O4 - Startup: PowerReg Scheduler.exe
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apimv.exe (file missing)


Exit HijackThis when done. Reboot, rescan with HijackThis and post a new log here.
Due to inactivity this topic will be closed. If you need this topic reopened, please email the moderating team - be sure to include the address of the thread and the name you posted under.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI