This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Homepage Hijacked

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hopefully someone can help me with this. I was watching a video when a message came on saying my version of Windows Media needed a codec so I said yes and now my home page is this promo for adware. The program is called Perfect Codec and I tried deleting the program and it said access denied. I then tried Tom's Hijack program and still the program will not go away. There are two *.exe files. One is isamini.exe and the other is isamonitor.exe which is the homepage. How do I get rid of these? They wouldn't delete no matter what I tried. Can someone out there help. I'm kinda of new to this kind of thing. Thanks! Randy
Randy Ebey :D

Welcome to Tom Coyote

I need to see a Hijackthis log in order to evaluate your system and see what you have going on as far as malware.

You can download HJT from either this link or the link in my signature at the bottom of the page. Download it to your desktop, then click on it to install, follow the prompts, by defaut it will install in C:\Program Files\Hijackthis.
Hijackthis 1.99.1
Its important that Hijackthis is installed in its own permanent folder for backup purposes.


Then….
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread.
  • Please use the [external image: Posted Image] Button and not the New Topic Button
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Ken545,
Thank you so much for your help.
I'm not too smart when it comes to computers. The instructions you gave me were great!
I really hope you can help.

Thanks again,
Randy

Logfile of HijackThis v1.99.1
Scan saved at 2:47:27 PM, on 11/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\Program Files\Perfect Codec\isamonitor.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Creative\SBLive\Program\CTAvTray.EXE
C:\Program Files\Perfect Codec\isamini.exe
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jucheck.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = clearwire
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1700E5C1-37EC-4C1C-B722-049FF60BD2AC} - blank (file missing)
O2 - BHO: (no name) - {192c5b4a-3efd-40c7-9f99-c472deb8efc0} - C:\Program Files\Perfect Codec\isaddon.dll
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\KDP5a9c.dll
O2 - BHO: (no name) - {8BC6346B-FFB0-4435-ACE3-FACA6CD77816} - blank (file missing)
O2 - BHO: Core Library - {F281FFC7-6C63-4bf9-83F2-AB7A6157B109} - C:\WINDOWS\System32\kdpupd.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Protection Bar - {bf1ced2c-4b3f-4079-a330-864eda5a4cff} - C:\Program Files\Perfect Codec\iesplugin.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CTAvTray] C:\Program Files\Creative\SBLive\Program\CTAvTray.EXE
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\KDP5a9c.dll"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\RunOnce: [CTAVTray] C:\Program Files\Creative\SBLive\Program\CTAvStub.EXE EAX.AVI
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MS lsass Startup] lsass135.exe
O4 - HKCU\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\KDP5a9c.dll"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {563EC66E-5A1B-51D2-1DB0-5080C83DA4EB} - ms-its:mhtml:file://C:ie.mht!http://69.50.164.12/exp/mht/sext07.chm::/MegaInstaller.exe
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5FE56B62-4717-4A7A-B3B5-DA6C3578B043}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: SharedDLLs - C:\WINDOWS\system32\lvn0095me.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Randy :D

You did well :thumbup:

You have multiple infections on this computer :( You where duped into downloading this fake codec Perfect Codec You can read about it here.

http://sunbeltblog.blogspot.com/2006/11/pe…fake-codec.html


You may want to print out all these instructions as we have a lot of work to do, take your time and don't let it intimidate you. We are going to try and get this all at once, but it may take several tries.


These programs are part of what got you into trouble, remove them via the Add-Remove Programs in the Control Panel

C:\Program Files\AWS
C:\Program Files\BearShare
C:\Program Files\Kazaa



We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.



Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run Ewido and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.




Please download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop. <– Dont run it yet





Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode




Once in Safe Mode, open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt




Still in Safemode… This can take the better part of an hour

IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • Ewido will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5

Reboot normally, open HJT Scan Only, check all these and click on Fix Checked. Some of these will be gone.

O2 - BHO: (no name) - {1700E5C1-37EC-4C1C-B722-049FF60BD2AC} - blank (file missing)
O2 - BHO: (no name) - {192c5b4a-3efd-40c7-9f99-c472deb8efc0} - C:\Program Files\Perfect Codec\isaddon.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\KDP5a9c.dll
O2 - BHO: (no name) - {8BC6346B-FFB0-4435-ACE3-FACA6CD77816} - blank (file missing)
O2 - BHO: Core Library - {F281FFC7-6C63-4bf9-83F2-AB7A6157B109} - C:\WINDOWS\System32\kdpupd.dll

O3 - Toolbar: Protection Bar - {bf1ced2c-4b3f-4079-a330-864eda5a4cff} - C:\Program Files\Perfect Codec\iesplugin.dll (file missing)

O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\KDP5a9c.dll"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKCU\..\Run: [MS lsass Startup] lsass135.exe
O4 - HKCU\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\KDP5a9c.dll"

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {563EC66E-5A1B-51D2-1DB0-5080C83DA4EB} - ms-its:mhtml:file://C:ie.mht!http://69.50.164.12/exp/mht/sext07.chm::/MegaInstaller.exe

O20 - Winlogon Notify: SharedDLLs - C:\WINDOWS\system32\lvn0095me.dll




Look for and delete these files, you may have to boot back to safemode to remove them.

C:\Program Files\AWS
C:\Program Files\Perfect Codec
C:\Program Files\BearShare


C:\WINDOWS\System32\KDP5a9c.dll
C:\WINDOWS\System32\kdpupd.dll
C:\WINDOWS\System32\KDP5a9c.dll
C:\WINDOWS\system32\lvn0095me.dll

These two you will have to look for, they can be in C:\, C:\windows or C:\windows\system32

lsass135.exe
servic.exe
<– Watch out for this one, check the spelling , do not delete services.exe



Run this system cleaner

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up



Let me see the Smitfraud log, the AVG log and a New HJT log please.
Dear Ken545,
Wow this was quite the job, but I got my homepage page back and I think everything is back if not better. I can not express how grateful I am to you for your help. My computer is not a toy; I work at home as a medical transcriber and I work off the internet. I also use the net to do most of my bill paying (this I did stop once "Perfect Codec" got a hold of me).

Anyway thank you, thank you, thank you for everything. With Thanksgiving coming up this is going to be a short paycheck with the doctors out of the office, but I PROMISE I will make a donation as soon as I can.

Okay, back to business. Some of the files after everything was done I could not find they are:

KDPa9C.dll (by the way you listed this twice)
kdpup.dll
lsass135.exe (there is a lsass.exe and lsass(3).exe
servic.exe

I did everything in order as far as the logs except, I forgot to run the HJT log until last. Here they are:

SMITFRAUDFIX

SmitFraudFix v2.122

Scan done at 0:18:43.43, Sat 11/18/2006
Run from C:\Documents and Settings\Randy\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\jbtazy.dll Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\Perfect Codec\ Deleted
C:\Program Files\VirusBursters\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

AVG

AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 1:51:57 AM 11/18/2006

+ Scan result:



C:\WINDOWS\system32\lclspl.dll -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{00C9D850-244D-11E1-B3C9-10805E499D95} -> Adware.ContextuAd : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\SPM1316.SPM1316 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\SPM1316.SPM1316.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\SPM1316.SPM1316\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP487\A0098334.dll -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ISTbarISTbar -> Adware.HotBar : Cleaned with backup (quarantined).
C:\WINDOWS\isrvs\isearch.xpi/chrome/isearch.jar/content/isearch/isearch.js -> Adware.ISearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1801674531-562591055-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7FDCEDCF-77C8-46AE-B0E8-D40C6D1E5158} -> Adware.MegaSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1801674531-562591055-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FDCEDCF-77C8-46AE-B0E8-D40C6D1E5158} -> Adware.MegaSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP491\A0100798.exe -> Adware.NoName : Cleaned with backup (quarantined).
C:\WINDOWS\system32\KDP5a9c.dll -> Adware.SafeGuard : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114092.exe -> Adware.SurfAcc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114122.exe -> Adware.SurfAcc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP518\A0107284.exe -> Adware.SurfAccuracy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114121.exe -> Adware.SurfAccuracy : Cleaned with backup (quarantined).
C:\WINDOWS\btxkhf.exe -> Adware.SurfAccuracy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
HKU\S-1-5-21-1801674531-562591055-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8FB8EB3-183B-4598-924D-86F0E5E37085} -> Adware.WhyPPC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP562\A0114735.dll -> Downloader.Small.dzp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113629.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113644.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113654.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113664.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113675.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113691.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113839.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114127.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114170.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114179.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114195.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114205.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114218.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114277.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114292.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114309.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114320.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114364.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114415.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114452.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114462.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP561\A0114634.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP561\A0114644.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP561\A0114654.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP562\A0114694.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP562\A0114720.dll -> Downloader.Zlob.atg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP562\A0114737.exe -> Downloader.Zlob.awz : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113631.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113646.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113656.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113666.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113677.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113692.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113840.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114128.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114171.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114180.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114199.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114206.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0114219.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114278.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114293.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114310.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114321.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114365.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114416.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114453.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP560\A0114463.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP561\A0114635.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP561\A0114645.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP561\A0114655.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP562\A0114695.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP562\A0114736.exe -> Downloader.Zlob.axa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E490B644-BA14-4205-99D4-C6FDCF434034}\RP559\A0113681.exe -> Downloader.Zlob.axf : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\on-line.exe -> Dropper.Small.xu : Cleaned with backup (quarantined).
C:\Documents and Settings\Randy\Cookies\randy@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Randy\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Randy\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Randy\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Randy\Cookies\randy@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.

HJT REPORT (Was done after everything was done)

Logfile of HijackThis v1.99.1
Scan saved at 1:45:38 PM, on 11/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\Program Files\Creative\SBLive\Program\CTAvTray.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jucheck.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Randy\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = clearwire
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CTAvTray] C:\Program Files\Creative\SBLive\Program\CTAvTray.EXE
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [CTAVTray] C:\Program Files\Creative\SBLive\Program\CTAvStub.EXE EAX.AVI
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5FE56B62-4717-4A7A-B3B5-DA6C3578B043}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)

Dude, you're a genius to figure all this out, but you did teach me a lot. Again, I can not express enough how much I appreciate your help. There's a special place in heaven for people like you!!

Randy :)
Hello Randy :D

You stated in your first post that you where new to this all, let me tell ya , you did one heck of a good job :thumbup: I quess you can see now how important it is to be extremely careful on what you click on and what you download.


Your HJT log looks 100% clean :thumbup: but just a couple of small issues to take care of. Your Java is out of date and it could be leaving a hole open for this garbage to get it, so we are going to update your Java.

The second being is that on your original log, you had an entry for a Look2me infection and even though its gone, part of it could still be present, so we are going to run a quick tool to make sure its gone.

If you look in your Panda report, you can see a ton of bad stuff that is in your System Restore program which means that if you ever use it to revert your system back to a previous date that you take the risk of reinfecting yourself all over again, so we are going to flush it all out and create a brand new Restore Point.

After what you just accomplished, all this is going to be a piece of cake :P


Lets start by opening AVG Anti Spyware and going to the Quarantine folder and removing it all, nothing in there you need to keep on your system.


These instructions will walk you through flushing out System Restore and its is extremely important that you create a new Restore Point

Turn off System Restore.
  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Reboot your System

Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Create a new Restore Point <– Very Important
  • Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
    You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this


  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Java website and download and install the update.
  • Java Runtime Environment (JRE) 5.0 Update 9 <–This is what you need to download and install.
  • Then after install you can verify your installation here Sun Java Verify




Now run Combofix, let me see the report along with a New HJT log and if all is well I have some free programs for you to install that will help keep you more secure.




Please download ComboFix by sUBs from either of these two locations

BleepingComputerComboFix
TechSupportForumComboFix
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply along with a new HJT log please.
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


Randy, I am not looking at any Anti Virus Programs running :thumbdown: After you post back I can link you to a free one unless you want to go out and purchase one.
Hi Ken545,
Thanks again for your continued help.
Yes, I would like a free program to keep my computer safe.
Here are the logs you requested.

ComboFix

Randy - 06-11-18 22:26:26.14 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Randy\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-10-18 to 2006-11-18 ))))))))))))))))))))))))))))))))))


2006-11-18 00:18 3,780 –a—— C:\WINDOWS\system32\tmp.reg
2006-11-17 23:02 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-18 21:47 767,488 ——— C:\WINDOWS\system32\WMVSENCD.dll
2006-10-18 21:47 656,896 ——— C:\WINDOWS\system32\WMVXENCD.dll
2006-10-18 21:47 613,376 ——— C:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 535,040 ——— C:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 21:47 38,400 ——— C:\WINDOWS\system32\wpdshextres.dll
2006-10-18 21:47 317,440 ——— C:\WINDOWS\system32\MP4SDECD.dll
2006-10-18 21:47 295,936 ——— C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 284,160 ——— C:\WINDOWS\system32\PortableDeviceApi.dll
2006-10-18 21:47 259,072 ——— C:\WINDOWS\system32\MPG4DECD.dll
2006-10-18 21:47 259,072 ——— C:\WINDOWS\system32\MP43DECD.dll
2006-10-18 21:47 212,992 ——— C:\WINDOWS\system32\MFPLAT.dll
2006-10-18 21:47 2,603,008 ——— C:\WINDOWS\system32\WpdShext.dll
2006-10-18 21:47 199,168 ——— C:\WINDOWS\system32\PortableDeviceWMDRM.dll
2006-10-18 21:47 166,912 ——— C:\WINDOWS\system32\PortableDeviceTypes.dll
2006-10-18 21:47 133,632 ——— C:\WINDOWS\system32\WPDShServiceObj.dll
2006-10-18 21:47 132,096 ——— C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
2006-10-18 21:47 130,048 ——— C:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 101,888 ——— C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2006-10-18 21:47 1,574,912 ——— C:\WINDOWS\system32\WMVENCOD.dll
2006-10-18 21:47 1,543,680 ——— C:\WINDOWS\system32\WMVDECOD.dll
2006-10-18 21:47 1,382,912 ——— C:\WINDOWS\system32\WMVSDECD.dll
2006-10-18 20:00 249,856 ——— C:\WINDOWS\system32\drmupgds.exe
2006-10-18 20:00 17,408 ——— C:\WINDOWS\system32\wpdshextautoplay.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-18 22:10 ——– d——– C:\Program Files\Java
2006-11-18 22:09 ——– d——– C:\Program Files\Common Files\Java
2006-11-18 22:09 ——– d——– C:\Program Files\Common Files
2006-11-18 00:27 ——– d——– C:\Program Files\NZSearch
2006-11-17 23:08 ——– d——– C:\Documents and Settings\Randy\Application Data\Lavasoft
2006-11-17 23:02 ——– d——– C:\Program Files\Grisoft
2006-11-17 14:55 ——– d——– C:\Program Files\Hijackthis
2006-11-17 03:38 ——– d——– C:\Program Files\MyWay
2006-11-16 16:43 ——– d——– C:\Program Files\NetZero
2006-11-15 03:02 ——– d——– C:\Program Files\Internet Explorer
2006-11-15 01:28 ——– d——– C:\Program Files\Symantec
2006-11-15 01:28 ——– d——– C:\Program Files\Common Files\Symantec Shared
2006-11-15 01:17 ——– d——– C:\Program Files\Norton AntiVirus
2006-11-11 23:49 ——– d——– C:\Program Files\MTV Networks
2006-11-11 19:34 ——– d——– C:\Program Files\TryMedia
2006-11-11 19:33 ——– d——– C:\Program Files\PopCap Games
2006-11-11 17:14 ——– d——– C:\Program Files\Windows Media Player
2006-11-11 17:14 ——– d——– C:\Program Files\Windows Media Connect 2
2006-11-11 17:00 ——– d——– C:\Program Files\Common Files\Real
2006-11-11 16:59 ——– d——– C:\Documents and Settings\Randy\Application Data\Real
2006-11-11 14:28 ——– d——– C:\Documents and Settings\Randy\Application Data\Symantec
2006-10-21 10:51 194376 –a—— C:\Documents and Settings\Randy\Application Data\shb.dat
2006-10-18 21:58 8704 –a—— C:\WINDOWS\system32\wdfmgr.exe
2006-10-18 21:58 8704 –a—— C:\WINDOWS\system32\uwdf.exe
2006-10-18 21:47 99840 –a—— C:\WINDOWS\system32\wmpshell.dll
2006-10-18 21:47 991744 –a—— C:\WINDOWS\system32\drmv2clt.dll
2006-10-18 21:47 937984 –a—— C:\WINDOWS\system32\wmnetmgr.dll
2006-10-18 21:47 8231936 –a—— C:\WINDOWS\system32\wmploc.dll
2006-10-18 21:47 757248 –a—— C:\WINDOWS\system32\wmadmod.dll
2006-10-18 21:47 7168 –a—— C:\WINDOWS\system32\asferror.dll
2006-10-18 21:47 63488 –a—— C:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 21:47 629760 –a—— C:\WINDOWS\system32\wpd_ci.dll
2006-10-18 21:47 603648 –a—— C:\WINDOWS\system32\WMSPDMOD.dll
2006-10-18 21:47 542720 –a—— C:\WINDOWS\system32\blackbox.dll
2006-10-18 21:47 429056 –a—— C:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 21:47 414208 –a—— C:\WINDOWS\system32\msscp.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wmvdmod.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\WMVADVE.DLL
2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\WMVADVD.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wmsdmod.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wdfapi.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\MPG4DMOD.dll
2006-10-18 21:47 4096 ——— C:\WINDOWS\system32\MP4SDMOD.dll
2006-10-18 21:47 4096 ——— C:\WINDOWS\system32\MP43DMOD.dll
2006-10-18 21:47 37376 –a—— C:\WINDOWS\system32\wmdmps.dll
2006-10-18 21:47 35840 –a—— C:\WINDOWS\system32\wpdconns.dll
2006-10-18 21:47 356352 –a—— C:\WINDOWS\system32\wpdsp.dll
2006-10-18 21:47 348672 –a—— C:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 21:47 33792 –a—— C:\WINDOWS\system32\wmdmlog.dll
2006-10-18 21:47 321536 –a—— C:\WINDOWS\system32\mswmdm.dll
2006-10-18 21:47 314880 –a—— C:\WINDOWS\system32\wmpdxm.dll
2006-10-18 21:47 276992 –a—— C:\WINDOWS\system32\audiodev.dll
2006-10-18 21:47 27136 –a—— C:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 21:47 2450944 –a—— C:\WINDOWS\system32\wmvcore.dll
2006-10-18 21:47 242688 –a—— C:\WINDOWS\system32\wmpasf.dll
2006-10-18 21:47 229376 –a—— C:\WINDOWS\system32\cewmdm.dll
2006-10-18 21:47 227328 –a—— C:\WINDOWS\system32\wmerror.dll
2006-10-18 21:47 222208 –a—— C:\WINDOWS\system32\wmasf.dll
2006-10-18 21:47 211456 –a—— C:\WINDOWS\system32\qasf.dll
2006-10-18 21:47 204288 –a—— C:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 21:47 179712 –a—— C:\WINDOWS\system32\msnetobj.dll
2006-10-18 21:47 175616 –a—— C:\WINDOWS\system32\mspmsp.dll
2006-10-18 21:47 1661440 –a—— C:\WINDOWS\system32\wmpencen.dll
2006-10-18 21:47 157184 –a—— C:\WINDOWS\system32\wmidx.dll
2006-10-18 21:47 154624 –a—— C:\WINDOWS\system32\wpdmtp.dll
2006-10-18 21:47 1329152 –a—— C:\WINDOWS\system32\WMSPDMOE.dll
2006-10-18 21:47 11264 –a—— C:\WINDOWS\system32\LAPRXY.dll
2006-10-18 21:47 1117696 –a—— C:\WINDOWS\system32\WMADMOE.dll
2006-10-18 20:03 100864 –a—— C:\WINDOWS\system32\logagent.exe
2006-10-18 20:00 38528 –a—— C:\WINDOWS\system32\drivers\wpdusb.sys
2006-10-13 06:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll
2006-10-08 21:25 ——– d——– C:\Program Files\LimeWire
2006-10-08 09:13 ——– d——– C:\Program Files\Winamp
2006-10-02 15:28 312128 ——— C:\WINDOWS\system32\msdelta.dll
2006-09-29 12:02 ——– d——– C:\Program Files\Real
2006-09-28 20:13 95344 ——— C:\WINDOWS\system32\WUDFCoinstaller.dll
2006-09-28 19:00 82944 ——— C:\WINDOWS\system32\drivers\WudfRd.sys
2006-09-28 18:56 55808 ——— C:\WINDOWS\system32\WudfSvc.dll
2006-09-28 18:56 316416 ——— C:\WINDOWS\system32\WUDFx.dll
2006-09-28 18:56 165376 ——— C:\WINDOWS\system32\WudfPlatform.dll
2006-09-28 18:56 146432 ——— C:\WINDOWS\system32\WudfHost.exe
2006-09-28 18:55 77568 ——— C:\WINDOWS\system32\drivers\WudfPf.sys
2006-09-25 17:58 23856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2006-09-19 13:04 ——– d——– C:\Program Files\Logitech
2006-09-19 13:03 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-09-19 13:00 ——– d——– C:\Program Files\DivX
2006-09-12 23:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-08-25 09:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-24 21:47 129784 ——— C:\WINDOWS\system32\pxafs.dll
2006-08-24 21:47 115880 ——— C:\WINDOWS\system32\pxinsi64.exe
2006-08-21 06:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 03:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"ares"="\"C:\\Program Files\\Ares\\Ares.exe\" -h"
"spc_w"="\"C:\\Program Files\\NZSearch\\nzspc.exe\" -w"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"Disc Detector"="C:\\Program Files\\Creative\\ShareDLL\\CtNotify.exe"
"UpdReg"="C:\\WINDOWS\\Updreg.exe"
"AHQInit"="C:\\Program Files\\Creative\\SBLive\\Program\\AHQInit.exe"
"AudioHQ"="C:\\Program Files\\Creative\\SBLive\\AudioHQ\\AHQTB.EXE"
"CTAvTray"="C:\\Program Files\\Creative\\SBLive\\Program\\CTAvTray.EXE"
"BCMSMMSG"="BCMSMMSG.exe"
"LogitechGalleryRepair"="C:\\Program Files\\Logitech\\ImageStudio\\ISStart.exe"
"LogitechImageStudioTray"="C:\\Program Files\\Logitech\\ImageStudio\\LogiTray.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"CTAVTray"="C:\\Program Files\\Creative\\SBLive\\Program\\CTAvStub.EXE EAX.AVI"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-11-18 22:28:47.01
C:\ComboFix.txt … 06-11-18 22:28

HJT

Logfile of HijackThis v1.99.1
Scan saved at 10:39:24 PM, on 11/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\Program Files\Creative\SBLive\Program\CTAvTray.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Randy\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = clearwire
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CTAvTray] C:\Program Files\Creative\SBLive\Program\CTAvTray.EXE
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [CTAVTray] C:\Program Files\Creative\SBLive\Program\CTAvStub.EXE EAX.AVI
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5FE56B62-4717-4A7A-B3B5-DA6C3578B043}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)

Randy :)
Good Morning Randy :D

Combofix did not pick up Look2me :thumbup: The rest of your log looks fine :thumbup:


Here are two Free Anti Virus programs, JUST INSTALL ONE…WITH AV..MORE IS NOT BETTER.

Free Avast 4 HomeEdition
Avira AntiVir® Personal Edition Classic



How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
    Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE- Spyad IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox Browser It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.


Thanks for stopping by Tom Coyote , I'm glad I was able to help you. :D
Ken545, Thanks for the anit-virus programs (I chose and downloaded Avast) and your information packet with tutorials. It is all valuable information. This whole ordeal has taught me alot and I will not be caught exposed again. I was using Symantec, but it slowed my system down so much I got frustrated one day and just deleted it. Big mistake and I paid the price. I have already spread the word to my boss and fellow transcribers to Hijactthis and how great you are. Thank you again for all your hard work and one on one service you provided. A couple of more questions. One is concerning watching videos which is how this all started. Watching TV on my computer is a great tool for me. It allows me to watch broadcasted shows when I choose to watch them instead of being tied to a certain time to turn on the TV or popping a tape into the VCR. I have a problem with CBS. They give me the option of using Windows Media or Realtime. If I choose Realtime nothing happens at all. If I choose Windows Media it begins, but then knocks me out, sometimes with the audio still going or sometimes it will knock me completely out of my browser. CBS uses a program called Innertube. I thought that this would be corrected after all these problems were fixed, but it is still doing it. Any ideas? Another thing is when I was using Symantec it advised to turn off my Microsoft firewall. I was afraid to this and this is probably why my system ran so slow. It is ever okay to turn this firewall off if I have a good anti-virus program installed like Avast? Thanks again for your help. Randy :)
Randy,

What most likely slowed your system down with Symantec is if you installed the entire security suite. They do tend to bog you down, myself I use just a stand alone AV from Norton and the free firewall from Zone Alarm.

You should only have one Firewall also, so if you install Zone Alarm or another 3rd party firewall its recommended that you turn off the windows firewall.

In Catagory View
Go to Start> Control Panel> Security Center> Manage Security Settings and turn it on or off.

In Classic View
Go to Start> Control Panel > Windows Firewall and turn it on or off


As far as codecs, thats a tough call, its my understanding that if you keep your Widows Media Player up to date it will have the latest codecs. Windows Updates also will update the security of WMP. I have never been a big fan of Real Player, it uses losts of resources. But if you like it, there may be a difference between the free player and the paid version. Don't know, you may try contacting them by email for some answers.
Microsoft Codecs

Windows Media Player 10


I am not big into the music and video streaming , here are some sites that you can post to for some help, they will know more about it than I do.


Windows Tech Support Forums

Tom Coyote <– Our own forum
PcPitStop <– You can take your system in for a checkup here.
Bleeping Computer <–Good XP Forum
Windows Helpnet <– Excellent XP Forum
Hardwareguys <– Another good one


IE Freezes
It's Not Always Malware
Speedup Windows
TechBuilder
Windows Tips
Techruler
Kellys Korner


Try this for Real Player support
http://service.real.com/main.html

http://real.lithium.com/real/



This one is for WMP
http://forums.mozillazine.org/viewtopic.php?t=206216

Good luck Randy, been a pleasure to help you and thank you for the nice comments and for the word or mouth advertising.

Ken :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI