This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

secure32.html

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run Spyware Detector, Spyware Doctor and Spybot and cannot stop the hijacking of my IE. Can you please assist me? My HijackThis log is below. Thank you very much.
Scott

Logfile of HijackThis v1.99.1
Scan saved at 5:43:51 PM, on 1/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Gateway\EzTune\DTSRVC.exe
C:\Scott's Programs\Spyware Doctor\sdhelp.exe
C:\Program Files\SpywareDetector\SDService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\SpywareDetector\SDSystemTray.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\ATI Multimedia\main\ATISched.EXE
C:\Program Files\ATI Multimedia\main\launchpd.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\The Jungle Media Center\The Jungle Media Center.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\appchk.exe
C:\Scott's Programs\Spyware Doctor\swdoctor.exe
C:\Scott's Programs\iPod\Updater\iPod\bin\iPodService.exe
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\Program Files\WallpaperToy\Wallpapertoy.Exe
C:\Program Files\Portrait Displays\Pivot Software\floater.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Scott Collins\My Documents\1Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R3 - URLSearchHook: (no name) - {164B9E9A-C824-22D4-E31B-A5B92DEE7DAF} - NukeSpan.dll (file missing)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Scott's Programs\Spybot - Search & Destroy\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\SCOTT'~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\SCOTT'~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\system32\autosys.exe
O4 - HKLM\..\Run: [SystemTraySD] C:\Program Files\SpywareDetector\SDSystemTray.exe
O4 - HKLM\..\Run: [SDAutoLiveupdate] C:\Program Files\SpywareDetector\LiveUpdateSD.exe -AUTO
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [The Jim Rome Show] C:\Program Files\The Jungle Media Center\The Jungle Media Center.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [appchk.exe] C:\WINDOWS\system32\appchk.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Scott's Programs\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\WallpaperToy\Wallpapertoy.Exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\SCOTT'~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Scott's Programs\Bodog Poker\BPGame.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161827233919
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://phoenixcon.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A3380357-9A2A-41C3-A474-7F6B2B2737C4}: NameServer = 69.50.161.130
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: SDNotify - C:\Program Files\SpywareDetector\SDNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Gateway\EzTune\DTSRVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Scott's Programs\iPod\Updater\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Scott's Programs\Spyware Doctor\sdhelp.exe
O23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
You have a couple of entries in your log that point to files on your PC that I would like to have checked - if they are still present.

Please go to Jotti's and click on the Browse… button at the top and navigate to the following files in turn, and then click on Submit:

C:\WINDOWS\system32\autosys.exe
C:\WINDOWS\system32\appchk.exe


When all the scans have been completed, please copy and paste the results into your next reply.

If this site is busy, try VirusTotal: Click the Browse … button at the top, navigate to the file and double click it and then click the Send button.

You may need to set Windows to show All Hidden Files and Folders - Instructions can be found here.
* These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after you have done.
*

Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
I have gone through the steps you requested and the information is below. Thank you!! For AUTOSYS.EXE Scan taken on 02 Jan 2007 23:07:58 (GMT) AntiVir Found HEUR/Crypted ArcaVir Found Trojan.Downloader.Small.Edu Avast Found nothing AVG Antivirus Found Downloader.Generic3.ELL BitDefender Found DeepScan:Generic.Malware.Ssp!.10031DEE ClamAV Found nothing Dr.Web Found Trojan.StartPage.1769 F-Prot Antivirus Found Possibly a new variant of W32/new-malware!Maximus F-Secure Anti-Virus Found Trojan-Downloader.Win32.Small.edu Fortinet Found W32/Small.EDU!tr.dldr Kaspersky Anti-Virus Found Trojan-Downloader.Win32.Small.edu NOD32 Found probably unknown NewHeur_PE (probable variant) Norman Virus Control Found W32/DLoader.BNPV VirusBuster Found novirus:Packed/FSG VBA32 Found Trojan.StartPage.1769 For APPCHK.EXE Scan taken on 02 Jan 2007 23:09:58 (GMT) AntiVir Found WORM/VB.DY.5 ArcaVir Found Worm.Vb.Dy Avast Found nothing AVG Antivirus Found Worm/VB.ADU BitDefender Found Win32.Worm.VB.DO ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Worm.Win32.VB.dy Fortinet Found W32/VB.DY!worm Kaspersky Anti-Virus Found Worm.Win32.VB.dy NOD32 Found probably unknown NewHeur_PE (probable variant) Norman Virus Control Found W32/VBWorm.AGH VirusBuster Found Worm.VB.YLH VBA32 Found Worm.Win32.VB.dy HERE IS THE UNINSTALL LIST FROM HJT: 2Wire Wireless Client Adobe Acrobat 5.0 Adobe Flash Player 9 ActiveX Ai Picture Utility v8 Apple Software Update APSW Instant Convertor ArcSoft PhotoStudio 5 ATI - Software Uninstall Utility ATI Control Panel ATI Decoder ATI Display Driver ATI Multimedia Center 9.03 ATI Remote Wonder 1.4 Azureus Bodog Poker Version 2.3.3.7 Canon CanoScan Toolbox 4.1 CanoScan LiDE20,30 Manual Codec Pack - All In 1 6.0.3.0 Cypress USB Mass Storage Driver Installation dBpowerAMP iTunes Encode dBpowerAMP Monkeys Audio Codec dBpowerAMP Mp4 Codec dBpowerAMP Music Converter Dell Digital Jukebox Driver Dell Media Experience Dell Solution Center Disk Cleaner (remove only) DVDSentry eMusic - 50 Free MP3 offer EzTune ffdshow (remove only) GiPo@MoveOnBoot 1.9.5 GUIDE PLUS+™ for Windows® System - ATI HijackThis 1.99.1 Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Imation Disk Manager II Service Intel® 537EP V9x DF PCI Modem Intel® Extreme Graphics Driver Intel® PRO Network Adapters and Drivers Intel® PROSet Internet Explorer Default Page iPod for Windows 2006-06-28 iTunes J2SE Runtime Environment 5.0 Update 6 J2SE Runtime Environment 5.0 Update 9 Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Java 2 Runtime Environment, SE v1.4.2_06 LimeWire 4.12.6 Microsoft .NET Framework 1.1 Microsoft ActiveSync 3.5 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft Streets and Trips Microsoft User-Mode Driver Framework Feature Pack 1.0 Modem Event Monitor Modem Helper Modem On Hold NoAdware v4.0 OmniPage SE PartyPoker Pivot Software PowerDVD PowerISO PQ DVD to iPod Video Suite (remove only) QuickTime RealPlayer RiskII SBC Yahoo! Applications SBC Yahoo! DSL Home Networking Installer SBC Yahoo! Login Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB926255) Shockwave Sonic RecordNow! Deluxe Sonic Update Manager Sound Blaster Live! Spybot - Search & Destroy 1.4 Spyware Detector Spyware Doctor 4.0 SpywareBlaster v3.5.1 The Jungle Media Center TomTom HOME Tweakui Powertoy for Windows XP Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) USB Storage Adapter FX (SM1) Viewpoint Manager (Remove Only) Viewpoint Media Player Wallpaper Changer for Windows XP WD Backup WD Diagnostics WD Firewire HID Driver Winamp (remove only) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Encoder 9 Series Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Service Pack 2 WinRAR archiver
Your log doesn't appear to show a software firewall installed - if you have one, and i've missed it, please ignore this.
If you are relying the firewall that comes with Service Pack 2, then you need to install one. While the SP2 firewall is better than nothing, it doesn't monitor outgoing traffic, so anything malicious on your computer can 'phone home' at will.

There are a few free firewalls available.
Zone Alarm: Available here.
Kerio: Available here.
Outpost: Available here.

It is important to note that you should only have one firewall installed at a time, but you can download both to your Desktop and install each in turn to see which one you prefer.

Understanding and Using Firewalls: http://www.bleepingcomputer.com/tutorials/tutorial60.html

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.
If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website:

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.
  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is…" - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG Anti-Spyware will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) You will need to know how to boot into Safe Mode.
Instructions can be found here.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) End Running Processes through Task Manager.
To do this:
Press and hold CTRL and Alt and tap Delete. This will open Task Manager.
If it is not selected, click on the 'Processes' Tab.
Scroll down and locate any/all of the following (if you cannot find one or more, don't worry):

autosys.exe
appchk.exe


Click on each one you can find to highlight it, and then click on 'End Process'
There may be more than one entry in Task Manager for a particular file, so be sure to check.


2) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R3 - URLSearchHook: (no name) - {164B9E9A-C824-22D4-E31B-A5B92DEE7DAF} - NukeSpan.dll (file missing)

O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\system32\autosys.exe
O4 - HKCU\..\Run: [appchk.exe] C:\WINDOWS\system32\appchk.exe


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

3) Boot into Safe Mode.

4) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

5) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

6) Go to Start > Control Panel > Internet Options.

For I.E. 6 - under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

For I.E. 7 - under Browsing History, click delete…
Under Temporary Internet Files, click Delete files…

7) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

8) Remove any/all of the following files/folders that you can find:

Files

c:\secure32.html
C:\WINDOWS\system32\autosys.exe
C:\WINDOWS\system32\appchk.exe


As an example:
To delete C:\WINDOWS\system32\filetogo.bye
Double click the My Computer icon on your Desktop or in the Start Menu.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on filetogo.bye and from the menu that appears, click on 'Delete'


9) Boot into Normal Mode.

Post a new HJT log (run in Normal Mode), the AVG A-S log AND a description of how your PC is running.

You are free to ignore this bit, but I see from your log that you have Windows Media Player 11 installed. As I haven't got round to upgrading mine yet, is it worth the download?
Noviciate,

That seems to have fixed the Hijacking of IE. I am able to change the start page, close IE and re-open to the proper page. I have copied the HJT log and AVG A-S log below. Hopefully we are good from now on. That is such a huge relief!!! THANK YOU VERY MUCH FOR YOUR HELP!!!!

By the way, I have the Windows XP firewall and my internet connection has firewall as well. I will try out one of the ones you suggested though, and make sure to just use one of them. As far as WMP 11 goes, I like it much better. I would upgrade when you get the chance. Just don't install all the toolbars and garbage that comes with it.

Logfile of HijackThis v1.99.1
Scan saved at 8:18:52 PM, on 1/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Scott's Programs\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Gateway\EzTune\DTSRVC.exe
C:\Scott's Programs\Spyware Doctor\sdhelp.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\SpywareDetector\SDService.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\SpywareDetector\SDSystemTray.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Scott's Programs\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\ATI Multimedia\main\ATISched.EXE
C:\Program Files\ATI Multimedia\main\launchpd.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\The Jungle Media Center\The Jungle Media Center.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Scott's Programs\Spyware Doctor\swdoctor.exe
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\Program Files\Portrait Displays\Pivot Software\floater.exe
C:\Program Files\WallpaperToy\Wallpapertoy.Exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Scott's Programs\iPod\Updater\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Scott Collins\My Documents\1Temp\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Scott's Programs\Spybot - Search & Destroy\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\SCOTT'~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\SCOTT'~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SystemTraySD] C:\Program Files\SpywareDetector\SDSystemTray.exe
O4 - HKLM\..\Run: [SDAutoLiveupdate] C:\Program Files\SpywareDetector\LiveUpdateSD.exe -AUTO
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Scott's Programs\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [The Jim Rome Show] C:\Program Files\The Jungle Media Center\The Jungle Media Center.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Scott's Programs\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\WallpaperToy\Wallpapertoy.Exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\SCOTT'~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Scott's Programs\Bodog Poker\BPGame.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161827233919
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://phoenixcon.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A3380357-9A2A-41C3-A474-7F6B2B2737C4}: NameServer = 69.50.161.130
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: SDNotify - C:\Program Files\SpywareDetector\SDNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Scott's Programs\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Gateway\EzTune\DTSRVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Scott's Programs\iPod\Updater\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Scott's Programs\Spyware Doctor\sdhelp.exe
O23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 8:10:16 PM 1/2/2007

+ Scan result:



HKLM\SOFTWARE\Classes\CLSID\{037FA2F8-372A-C652-77FF-F23198522B67} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{04260088-0FF5-E8D6-15E7-93202B39B4A3} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{07E20718-C02E-2C0D-FBD2-B4FA16861EBA} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{0B7DA733-FF81-0853-67C8-61DE180DAB2D} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{117089AA-D3C6-C679-D791-5088F7B82125} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{125B75A2-9C0C-5684-0068-F77EFA15D99E} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{18E1732F-77F2-2029-71E8-F3E634ABC0AA} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{1CC5DC68-DEC2-29FA-06F2-100BA964602B} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{208770B8-DA7A-E673-A78D-ED9E5E585C23} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{21E654F5-CF30-4A95-C97F-98763D1324F9} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{21F30B0F-16FA-61F4-5AEB-935E5BA41A18} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{2627C43B-FB1D-F815-04DA-3D4D787AEB82} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{349E1E95-2B1A-6197-C0B2-772F2AD2A94E} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{34AA1510-CBD7-2EFC-3684-44FA741EB872} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{38EE9684-D257-A538-1F82-16D8794C8BD7} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{3EABA831-C199-1C8C-CB89-0279588D64D6} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{3F508203-C722-9913-5AE6-D4D6D529B196} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{41EE75E8-DF9A-E7DC-52D8-1F0CEABDABFA} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{424D322F-007D-619B-BC17-63F3201B9FED} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{433B812D-C2D5-F83D-9B48-A30CDA52F0FB} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{45736553-04ED-49CB-04D0-785B325B6E17} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{47CF0D84-64D8-D3F0-DBD8-09D910B3172B} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{4B1013E8-F567-66FB-F819-618EA93458EB} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{4B10B566-F6FE-697C-E2DB-B1F47BCE745A} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{4D49B597-3C99-F507-3EF4-196320283DFA} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{4D7AAE7E-60D8-7CE4-E215-285680E2A5E4} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{4DF5116B-0DFE-9D51-AA17-CE70AC5E652D} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{50B91207-4289-28BE-FC70-4CE72F0402CB} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{50CF1CA4-BAC9-318B-D8F3-18958B04D18A} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{5395C6CC-9119-AA2E-B008-2D31A543B883} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{55BE37F8-1985-13E8-CD9B-5D824C0086C6} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{5B89B544-2CD4-BECD-52DB-1A7286CB0AF6} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{60D3C2DA-22CF-E589-2EF0-062330D46C5E} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{622A8F48-1987-BE0C-846F-5F54337E3897} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{6456D760-0959-2338-4E2B-BCEADA470C19} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{65092628-B7AE-5F20-935D-33C3AE5AF909} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{6BA66987-2CBD-7E8B-149E-DBD4784AEDA3} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{6C2A592C-2CEB-91F6-ABFC-8A6CAA196309} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{6C99280C-4B42-597B-BF9C-421EE5B510FF} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{7913E589-C40D-754E-8F22-0E5C2FBCC151} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{7FDF80D6-8DD1-87AC-455C-99F26D3210FB} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{800DD44A-1A43-4B30-5E8B-4B4290DD31A1} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{90BB89A8-5B4A-68E8-7401-A7595938B8F3} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{9B02CB83-DCD2-2DB6-02DC-2D81D1BE1FE7} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{9B8370DE-3827-C593-696F-5ABBF960082E} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{9D392CE1-0E98-05C3-BB34-7FC5B9D8D07E} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{A0E42DCF-5616-B378-BA75-97FF635FC66C} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{A1366D01-84C0-2558-F68D-17874321A0CE} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{ABD7967C-3F51-655C-C22D-34A94C9679EE} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{B3395380-CDFA-D6F8-F22B-68D2608D3EC5} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{BEE5AE94-A804-E8A2-F6F9-E353C5F4CD12} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{CAF4D771-8A18-BC86-F551-A768543394E9} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{CE625DD3-CBD8-8AF1-9FFB-1F765070A92A} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{D4B62290-D1BC-E419-EF26-71766EF1A30E} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{DA4037FC-0EFF-1D1A-B604-A395A32309EF} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{DFA3BBC8-EFA1-7FBB-E4CA-7AE61A38A78D} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{E2A72A5A-5904-FEE1-9CF2-43DE47B6318F} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{E2E41960-AAF3-3478-138E-C014604FCA45} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{E68315F1-B546-67BA-D301-A1A15F225655} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{EB61BCEC-B087-FF9D-2125-EF1B13DEF033} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{FB2B91F2-20FB-CDCE-D34A-E50E5910E44F} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{FEE3991F-A9A9-FEB5-A46D-D1B381BB004A} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1665065967-4027193692-935174450-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3205B60-1D3F-AADD-01D0-77FF30CC211B} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott Collins\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Parser.class-113a2080-6f23abfc.class -> Adware.CWS : Cleaned with backup (quarantined).
C:\Scott's Programs\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\WINDOWS\WINNT.BMP:qwdaf -> Downloader.Agent.bc : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\autosys.exe -> Downloader.Small.edu : Cleaned with backup (quarantined).
C:\~WRF0409.tmp -> Downloader.Zlob.al : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\LogFiles\M0131400.so -> Dropper.Small.ahb : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott Collins\agony.sys -> Rootkit.Agony : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\agony.sys -> Rootkit.Agony : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\winsecurityxp\rk.exe -> Rootkit.Agony : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq34.tmp -> TrackingCookie.Paycounter : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq35.tmp -> TrackingCookie.Xxxcounter : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5.tmp -> TrackingCookie.Xxxcounter : Cleaned.
C:\WINDOWS\SYSTEM32\LogFiles\S1021800.so -> Trojan.Agent.ix : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\appchk.exe -> Worm.VB.dy : Cleaned with backup (quarantined).


::Report end
Normally you could go and do something more useful with your time, but the AVG A-S logs shows a few nasties that I wouldn't want to have had on my system. I'd like you to run some scans just to make sure that all the slime has been removed.

Please download GMER Rootkit Detector from any of the following links:
GMER
GMER
GMER
  • Unzip it and double click the gmer.exe file
  • Select rootkit tab.
  • Make sure all the boxes on the right of the screen are checked,
    EXCEPT for ‘Show All’.
  • Press scan.
  • When it has finished press Copy & post back the log it makes.
  • Repeat the process with the Autostarts tab (Behind the ">>>" Tab) and do the same there.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download AVG Anti-Rootkit Beta from here and save it to your Desktop.
  • Close all open programs as this will require a reboot.
  • Double click AVG_AntiRootkit_1.0.0.13.exe to install the program.
    (By default this will be to C:\Program Files\GRISOFT\AVG Anti-Rootkit Beta.)
  • Once the program has installed, you will be prompted to reboot - please allow this to happen.
  • When the PC has rebooted, click the AVG Anti-Rootkit Beta shortcut that is now on your desktop.
  • Click Perform in-depth search and put your feet up as this can take a while.
  • Once the scan has completed, if any files have been detected, click Save result to file and save the log to somewhere convenient.
If anything has been detected, copy and paste the log into your next reply. If not, just let me know.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

1) Download F-Secure's BlackLight from here and save it to your Desktop.

2) Log off from the internet and disconnect your modem cable.

3) Go to Start > Run, copy and paste the following into the text box and hit OK:
"%userprofile%\desktop\blbeta.exe" /expert

The F-Secure Blacklight Beta window should open.
  • Accept the agreement and click Next >.
  • Click the Scan button to begin.
  • Leave the PC idle while the scan takes place.
  • When it has completed, click the Close button.
  • A text file, fsbl-date/time, will be saved onto your Desktop - copy and paste this into your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

IMPORTANT - A new version of the Kaspersky Online Scanner was released on August 8, 2006. If you have installed a previous version then you need to go to Add/Remove Programs and remove any entries for Kaspersky Online Scanner before you proceed.
* Close all Internet Explorer windows before doing this.

Go here and click the Kaspersky Online Scanner button.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded click Next.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with one more HJT log - let me know if the PC is misbehaving as well.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
I have downloaded GMER Rootkit Detector and I have tried running it twice. Every time I run it, it gets about 50% done and I get a blue screen saying: "A problem has been detected and windows has been shut down to prevent damage to your computer. If this screen apears again, follow these steps: Check to be sure you have adequate disk space. If a driver is identified in the Stop message, disable the driver or check with the manufacturer for driver updates. Try changing video adapters. Check with your hardware vendor for any BIOS updates. Disable BIOS memory options such as caching or shadowing. If you need to use safe mode to remove or disable components, restart your computer, press F8 to selecct Advanced Startup Options, and then select Safe Mode." I have adequate disk space, GMER Rootkit Detector is the only thing open and running. I do not see a driver identified. The only thing it lists under Technical Information is: "***STOP: 0x0000008E (0x0000005, 0x00300020, 0xB1757CF0, 0x00000000)" I cannot perform the rest of the steps you tried until I get this resolved. Thank you.
It could be either a compatibility issue, in which case there isn't a lot that can be done about it, or you could have a nasty onboard which is messing with the scan. Skip the GMER scan and run the rest.
I'll go ahead and perform the rest of the steps you requested after GMER scan. Just so you know, when I first open up GMER scan this is what says:

"Warning!!!!
GMER has found system modification, which might have been caused by ROOTKIT activity. Do you want to fully scan your system?"

This is what is in the log when I first open GMER.

GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-03 15:37:36
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey

SYSENTER \??\C:\WINDOWS\system32:lzx32.sys B2E39C4E

Code \??\C:\WINDOWS\system32:lzx32.sys pIofCallDriver

—- Devices - GMER 1.0.12 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 82FD31D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 82FD31D8

—- Services - GMER 1.0.12 —-

Service C:\WINDOWS\system32:lzx32.sys (*** hidden *** ) [SYSTEM] pe386 <– ROOTKIT !!!

—- EOF - GMER 1.0.12 —-
You appear to have a rootkit on your system. I'll be better informed after the rest of the scans come in, but I would treat your PC as though it were still infected as i'm pretty sure it is. It is treatable, but not with the usual scanners you will have come across.
Here are the Logs you requested. I think the file C:\WINDOWS\system32:lzx32.sys may be an issue. I got another blue screen again. AVG ANTI-ROOTKIT BETA LOG (this was the only file it found) C:\WINDOWS\system32:lzx32.sys BLBETA LOG: (fsbl-date/time) file log. 01/03/07 16:12:27 [Info]: BlackLight Engine 1.0.55 initialized 01/03/07 16:12:27 [Info]: OS: 5.1 build 2600 (Service Pack 2) 01/03/07 16:12:27 [Note]: 7019 4 01/03/07 16:12:27 [Note]: 7005 0 01/03/07 16:12:37 [Note]: 7006 0 01/03/07 16:12:37 [Note]: 7022 0 01/03/07 16:12:37 [Note]: 7011 1200 01/03/07 16:12:37 [Note]: 7026 0 01/03/07 16:12:38 [Note]: 7026 0 01/03/07 16:12:47 [Note]: FSRAW library version 1.7.1021 01/03/07 17:12:43 [Note]: 7007 0

AVG ANTI-ROOTKIT BETA LOG (this was the only file it found)
C:\WINDOWS\system32:lzx32.sys

That's the one we're looking for.

The first step is to run AVG Anti-Rootkit Beta again, but this time when the results of the scan appear, ensure that the checkbox to the left of the entry is checked and then click Remove selected items.
If AVG A-R Beta needs the PC rebooted. please let it.

Next, run HJT and click on Open the Misc Tools section.
  • Click the Open ADS Spy… button.
  • Uncheck "Quick scan (Windows base folder only)"
  • Click the Scan button to the left of the Save log… button.
  • When the scan has completed, you should see an entry like this: C:\WINDOWS\system32 : lzy32.sy_
  • Check this box and then click Remove selected.
Finally, I want you to boot into Safe Mode and run another AVG A-S scan, just like before. You will need to clean out the temp files first to cut down on the length of the scan.

When you've done all that, i'll have the AVG log and another HJT log as well.
Let me know how the PC is behaving, and any problems you had and how it all went. This nasty should go very quietly with these tools, but you can never tell!
OK, I have run AVG Anti-Rootkit Beta again, and removed the C:\WINDOWS\system32 : lzy32.sy_ entry. I then went into Safe Mode and ran AVG A-S scan just like before, applied all and saved the log files for both AVG A-S and HJT. Below are the latest log files. Everything seems to be running fine, and after I rebooted, I ran AVG A-S scan again in normal windows mode and it did not find anything. It looks like we may have conquered the problem…..hopefully. I can't tell you how thankful I am for all of your assistance. You rock!! ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 7:30:23 PM 1/3/2007 + Scan result: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP863\A0101019.exe -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP863\A0101018.exe -> Downloader.Small.edu : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP863\A0101014.sys -> Rootkit.Agony : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP863\A0101015.sys -> Rootkit.Agony : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP863\A0101016.exe -> Rootkit.Agony : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP863\A0101017.exe -> Worm.VB.dy : Cleaned with backup (quarantined). ::Report end HJT ADSSPY LOG: C:\Documents and Settings\All Users\Application Data\TEMP : DFC5A2B2 (177 bytes) C:\Documents and Settings\All Users\Application Data\TEMP : DFC5A2B2 (177 bytes) C:\Documents and Settings\Scott Collins\Favorites\FAVORITES\Yahoo! Personals.url : favicon (318 bytes) C:\Documents and Settings\Scott Collins\Favorites\Fifth Generation iPod resets when playing some mono MP3 songs and podcasts.url : favicon (7782 bytes) C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\All things iPod, iTunes and beyond iLounge.url : favicon (1406 bytes) C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\Apple - Support - iPod - Battery Replacement.url : favicon (7782 bytes) C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\Apple - Support - iTunes.url : favicon (7782 bytes) C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\http–depot.info.apple.com-.url : favicon (7782 bytes) C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\Tips and tricks to get the most out of your iPod's battery.url : favicon (7782 bytes) C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\Updating iPod.url : favicon (7782 bytes) C:\Documents and Settings\Scott Collins\Favorites\ISA Home.url : favicon (15086 bytes) C:\Documents and Settings\Scott Collins\Favorites\Microsoft Web Sites\Microsoft Office Downloads Home Page.url : favicon (2862 bytes) C:\Documents and Settings\Scott Collins\Favorites\Microsoft Web Sites\Microsoft Update.url : favicon (25214 bytes) C:\Documents and Settings\Scott Collins\Favorites\MISC\Funny News - Funny Stories - Strange and Bizarre News Stories and Funny Pictures.url : favicon (1150 bytes) C:\Documents and Settings\Scott Collins\Favorites\MISC\G4 - Filter.url : favicon (1406 bytes) C:\Documents and Settings\Scott Collins\Favorites\MISC\G4 - Podcasts.url : favicon (1406 bytes) C:\Documents and Settings\Scott Collins\Favorites\MISC\GSN - The Network For Games.url : favicon (766 bytes) C:\Documents and Settings\Scott Collins\Favorites\MISC\thatvideosite.com.url : favicon (894 bytes) C:\Documents and Settings\Scott Collins\Favorites\MISC\UselessJunk.com.url : favicon (318 bytes) C:\Documents and Settings\Scott Collins\Favorites\MISC\Yahoo! Video.url : favicon (6598 bytes) C:\Documents and Settings\Scott Collins\Favorites\Phoenix Contact\PHOENIX CONTACT - Website.url : favicon (1406 bytes) C:\Documents and Settings\Scott Collins\Favorites\Phoenix Contact\Relay Selection Website.url : favicon (1406 bytes) C:\Documents and Settings\Scott Collins\Favorites\phun.org - phun.com - Adult Entertainment Portal.url : favicon (1406 bytes) C:\Documents and Settings\Scott Collins\Favorites\SOUNDS\The MovieWavs Page.url : favicon (10806 bytes) C:\Documents and Settings\Scott Collins\Favorites\SOUNDS\Wavsite.com - Over 4000 movie sounds.url : favicon (318 bytes) C:\Documents and Settings\Scott Collins\Favorites\Space\Cassini-Huygens Home.url : favicon (2238 bytes) C:\Documents and Settings\Scott Collins\Favorites\Space\NASA - Home.url : favicon (1406 bytes) C:\Documents and Settings\Scott Collins\Favorites\Space\Official NASA GLAST Website.url : favicon (318 bytes) C:\Documents and Settings\Scott Collins\Favorites\Space\Spitzer Space Telescope.url : favicon (9366 bytes) C:\Documents and Settings\Scott Collins\Favorites\TomTom Go 910\TomTom, portable GPS car navigation systems.url : favicon (766 bytes) C:\Documents and Settings\Scott Collins\Favorites\Welcome to TomCoyote.url : favicon (3638 bytes) C:\Scott's Programs\RiskII\RiskII.exe : {3249205F-BE39-C90B-71D6-E475866DBF15} (173 bytes) C:\WINDOWS\$_hpcst$.hpc : ybchua (11736 bytes) C:\WINDOWS\002278_.tmp : ofgdv (0 bytes) C:\WINDOWS\AC3API.INI : qcumoc (4870 bytes) C:\WINDOWS\BOOTSTAT.DAT : sdhrbt (11736 bytes) C:\WINDOWS\cdplayer.ini : leswvv (4870 bytes) C:\WINDOWS\EXPLORER.SCF : xezzqx (4870 bytes) C:\WINDOWS\lkdes.txt : lnhjio (4870 bytes) C:\WINDOWS\ODBCINST.INI : mbsia (0 bytes) C:\WINDOWS\ODBCINST.INI : wtgkl (0 bytes) C:\WINDOWS\SchedLgU.Txt : gqqjbd (4870 bytes) C:\WINDOWS\setupapi.log.1.old : waqwna (11736 bytes) C:\WINDOWS\winamp.ini : fuaqj (0 bytes) C:\WINDOWS\_DEFAULT.PIF : awmtr (0 bytes) C:\WINDOWS\_DEFAULT.PIF : buhoj (0 bytes) C:\WINDOWS\_DEFAULT.PIF : ccysg (0 bytes) C:\WINDOWS\_DEFAULT.PIF : cplwdy (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : dlokrh (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : dwdaa (0 bytes) C:\WINDOWS\_DEFAULT.PIF : ehjbgi (4870 bytes) C:\WINDOWS\_DEFAULT.PIF : exqlo (0 bytes) C:\WINDOWS\_DEFAULT.PIF : eyqdan (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : fzecuv (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : gosok (0 bytes) C:\WINDOWS\_DEFAULT.PIF : iimaft (4870 bytes) C:\WINDOWS\_DEFAULT.PIF : jrwbc (0 bytes) C:\WINDOWS\_DEFAULT.PIF : jtunp (0 bytes) C:\WINDOWS\_DEFAULT.PIF : loqwmy (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : lwbjhz (4870 bytes) C:\WINDOWS\_DEFAULT.PIF : nifqwy (11152 bytes) C:\WINDOWS\_DEFAULT.PIF : oabofm (4870 bytes) C:\WINDOWS\_DEFAULT.PIF : ohopiu (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : oozji (0 bytes) C:\WINDOWS\_DEFAULT.PIF : qqbvdj (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : rullo (0 bytes) C:\WINDOWS\_DEFAULT.PIF : soozwa (0 bytes) C:\WINDOWS\_DEFAULT.PIF : swqwep (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : sxehu (0 bytes) C:\WINDOWS\_DEFAULT.PIF : txnyy (0 bytes) C:\WINDOWS\_DEFAULT.PIF : uqejgi (4870 bytes) C:\WINDOWS\_DEFAULT.PIF : vaqjlk (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : vmhytk (4870 bytes) C:\WINDOWS\_DEFAULT.PIF : vpuduo (11736 bytes) C:\WINDOWS\_DEFAULT.PIF : xzaiux (4870 bytes) C:\WINDOWS\_DEFAULT.PIF : yawqpy (4870 bytes) C:\WINDOWS\_DEFAULT.PIF : zhzvce (4870 bytes) C:\WINDOWS\_DEFAULT.PIF : zoimhl (0 bytes)
Your computer is probably clean now, but I would like you to run an online scan to make sure. Run through the following and post accordingly :

IMPORTANT - A new version of the Kaspersky Online Scanner was released on August 8, 2006. If you have installed a previous version then you need to go to Add/Remove Programs and remove any entries for Kaspersky Online Scanner before you proceed.
* Close all Internet Explorer windows before doing this.

Go here and click the Kaspersky Online Scanner button.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded click Next.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

I would also like you to run GMER as per the earlier instructions and let me have the logs that are produced.
I have everything closed, but when I click on the link below it takes me to the proper website. Then I click on the Kaspersky Online Scanner button it takes me to the agreement page. I click on accept and it begins to start the online scanner. Then I get a an "install via active x the file: kavwebscan_unicode.cab". When I click on it to allow the install of Active X Control it just takes me back to the agreement page but there is not link at the bottom to click accept. So I am stalled in this spot. I do not have a previous version loaded, I checked the add/remove programs. I do not know what to do from here. Thank you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI