Some software programs such as Evidence eraser, spyware avenger, Virus Hunter security and others automatically install themselve on my pc after I remove them with adaware and spybot. I have lost control of my machine. I have tried to install virus protection, but the pc will not let me. Below is my hijackthis log...
Logfile of HijackThis v1.99.1
Scan saved at 3:53:38 PM, on 2/20/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\soft.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software
Update\HPWuSchd2.exe
C:\WINNT\system32\hphmon05.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\nthv32.exe
C:\WINNT\sdkks.exe
C:\WINNT\isrvs\desktop.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\Guicku.exe
C:\WINNT\system32\danint35.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\12.tmp.exe
C:\WINNT\system32\wsxsvc\wsxsvc.exe
C:\WINNT\system32\winupdt.exe
C:\winnt\system32\msnavc32.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\winnt\system32\saie.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\WINNT\system32\wincjdk32.exe
C:\WINNT\system32\bolialui.exe
C:\WINNT\system32\sysmonnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\prutqct.exe
C:\Program Files\43dupf1q\43dupf1q.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\system32\prutqct.exe
C:\WINNT\system32\tibs5.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\winnt\system32\kzzyntg.exe
c:\winnt\system32\packager.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\metro.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINNT\kytkd.dll/sp.html#10001
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page
=
res://C:\WINNT\kytkd.dll/sp.html#10001
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
about:blank
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
res://C:\WINNT\kytkd.dll/sp.html#10001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINNT\kytkd.dll/sp.html#10001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page
=
res://C:\WINNT\kytkd.dll/sp.html#10001
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
res://C:\WINNT\kytkd.dll/sp.html#10001
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
res://C:\WINNT\kytkd.dll/sp.html#10001
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: run=C:\WINNT\system32\soft.exe
O2 - BHO: (no name) - {23084635-3EC2-B4F8-38A4-30AE7AA197C1} -
C:\WINNT\system32\apioi.dll
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} -
C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
O2 - BHO: CControl Object -
{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -
C:\Program Files\E2G\IeBHOs.dll
O2 - BHO: (no name) - {B75F75B8-93F3-429D-FF34-660B206D897A} -
C:\WINNT\system32\boln.dll
O2 - BHO: (no name) - {D544FBEE-0A03-0AE8-F1E9-1F3BC0B4FA42} -
C:\WINNT\netsm32.dll
O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41}
-
C:\WINNT\EliteSideBar\EliteSideBar 08.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ADUserMon] C:\Program
Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program
Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program
Files\Iomega\DriveIcons\deskup.exe
/IMGSTART
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program
Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program
Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program
Files\Hewlett-Packard\HP
Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINNT\system32\hphmon05.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] C:\Program
Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [sdkks.exe] C:\WINNT\sdkks.exe
O4 - HKLM\..\Run: [tibs5] C:\WINNT\system32\tibs5.exe
O4 - HKLM\..\Run: [Web Service] C:\WINNT\system32\sm.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINNT\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINNT\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [kzzyntg] c:\winnt\system32\kzzyntg.exe
O4 - HKLM\..\Run: [antiware] c:\winnt\system32\eliteewc32.exe
O4 - HKLM\..\Run: [version] C:\WINNT\system32\Vqtsfa.exe
O4 - HKLM\..\Run: [secure] C:\WINNT\system32\Guicku.exe
O4 - HKLM\..\Run: [s7rW3FO] danint35.exe
O4 - HKLM\..\Run: [12.tmp]
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\12.tmp.exe 0
10001
O4 - HKLM\..\Run: [12.tmp.exe]
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\12.tmp.exe
1 10001
O4 - HKLM\..\Run: [ntechin] C:\WINNT\system32\n20050308.exe
O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINNT\system32\winupdt.exe
O4 - HKLM\..\Run: [43dupf1q] C:\Program
Files\43dupf1q\43dupf1q.exe
O4 - HKLM\..\Run: [fkighc] C:\WINNT\system32\fkighc.exe
O4 - HKLM\..\Run: [App32dll] C:\winnt\system32\msnavc32.exe
lee0105
O4 - HKLM\..\Run: [WinTask driver] C:\WINNT\system32\wintask.exe
O4 - HKLM\..\Run: [nsmsdc] C:\WINNT\system32\nsmsdc.exe
O4 - HKLM\..\Run: [IST Service] C:\Program
Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [saie] c:\winnt\system32\saie.exe
O4 - HKLM\..\Run: [Systems Restart] Rundll32.exe boln.dll,
DllRegisterServer
O4 - HKLM\..\Run: [ctyr] c:\winnt\ctyr.exe
O4 - HKLM\..\Run: [7.tmp]
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7.tmp.exe 0
10001
O4 - HKLM\..\RunOnce: [nthv32.exe] C:\WINNT\system32\nthv32.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft
Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Web Service] C:\WINNT\system32\sm.exe
O4 - HKCU\..\Run: [dw06RPi5U] bolialui.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINNT\system32\sysmonnt
O4 - HKCU\..\Run: [prutqct] C:\WINNT\system32\prutqct.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft
Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program
Files\WinZip\WZQKPICK.EXE
O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
O10 - Unknown file in Winsock LSP:
c:\winnt\system32\winlspak.dll
O10 - Unknown file in Winsock LSP:
c:\winnt\system32\winlspak.dll
O10 - Unknown file in Winsock LSP:
c:\winnt\system32\winlspak.dll
O10 - Unknown file in Winsock LSP:
c:\winnt\system32\winlspak.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.addictivetechnologies.com
O15 - Trusted Zone: *.addictivetechnologies.net
O15 - Trusted Zone: *.admin2cash.biz
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.bettersearch.biz
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.crazywinnings.com
O15 - Trusted Zone: *.f1organizer.com
O15 - Trusted Zone: *.finefind.nettraffic2cash.biz
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.newiframe.biz
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.pizdato.biz
O15 - Trusted Zone: *.private-dialer.biz
O15 - Trusted Zone: *.private-iframe.biz
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.sp2fu**ed.biz
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.topconverting.com
O15 - Trusted Zone: *.vse-moe.biz
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.05p.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.scoobidoo.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: 206.161.125.149 (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone,
should be
Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone,
should be
Internet Zone (HKLM)
O16 - DPF: v3cab - http://searchmiracle.com/cab/1.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer
Class) -
http://www.addictivetechnologies.net/DM0/cab/15yf09fg.cab
O16 - DPF: {EB623776-492A-42CA-9571-3AA39F58530B} -
http://www.alwaysupdatednews.com/install/aun_0010.exe
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E}
-
C:\WINNT\isrvs\mfiltis.dll
O23 - Service: Logical Disk Manager Administrative Service
(dmadmin) -
VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Iomega App Services - Iomega Corporation -
C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc.
-
C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP -
C:\WINNT\system32\HPZipm12.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_)
- Iomega
Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
O23 - Service: Remote Procedure Call (RPC) Helper
(%AF夶À¨) - Unknown
owner - C:\WINNT\system32\javanb.exe (file missing)