I originally had the Trojan Startpage.19.AO and posted a topic on that, but used the advice found in this forum and it appears to be gone. Ran Cleanup, Ad-aware SE, CWShredder, Spybot, Ewido, Trojan Hunter, AVG. Startpage appears to be gone and now be replaced by Downlaoder.Agent.
I have spent hours on this and am getting frustrated.
Now when I just rebooted from Safe Mode, AVG says I have Trojan Horse Downloader.Agent.AQU, though the last letter changes occasionally - it was AQW 5 minutes ago. Every 30 seconds a new warning comes from AVG with a new filename indicated. They are all located in the c:\Windows folder - eg: c:\Windows\msmm32.dll
Here is my Hijack This log.
Logfile of HijackThis v1.99.1
Scan saved at 9:23:48 AM, on 15/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\atlwe32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
e:\Program Files\ewido\security suite\ewidoctrl.exe
e:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\GEARSec.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
E:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
E:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
E:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\alg.exe
E:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
E:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
E:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\Winamp\winampa.exe
C:\NOSPY.ORG\start1.exe
C:\WINDOWS\ierp32.exe
e:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
E:\Program Files\PeerGuardian2\pg2.exe
E:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
C:\Program Files\Wireless Device\Wireless Mouse\MouseAp.exe
E:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
E:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\Wireless Device\Wireless Keyboard\osd.exe
E:\Program Files\WinZip\WZQKPICK.EXE
E:\Program Files\SpamBayes\bin\sb_tray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
e:\Program Files\Real\RealPlayer\RealPlay.exe
F:\FTPRoot\usr\Zip Files\Virus Trojan Spyware etc\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\dgugf.dll/sp.html#17702
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dgugf.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\dgugf.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\dgugf.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dgugf.dll/sp.html#17702
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\dgugf.dll/sp.html#17702
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\dgugf.dll/sp.html#17702
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = www.google.com.au
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = www.google.com.au
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {02D4A6D4-9A5A-9DD8-7DD4-5C2F02AD2717} - C:\WINDOWS\system32\ntsv32.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {0FC10DA6-621C-EEAE-0E43-CB4CCFC5B848} - C:\WINDOWS\system32\winpg.dll (file missing)
O2 - BHO: Class - {137FBD76-C94E-29D8-CB88-FB29E07E3C8E} - C:\WINDOWS\system32\crca32.dll (file missing)
O2 - BHO: Class - {14B627E8-FA46-6393-8D1A-01478E0D9C0A} - C:\WINDOWS\ntmx32.dll (file missing)
O2 - BHO: Class - {14CE5B7A-6546-0088-A736-F486C8A0A93F} - C:\WINDOWS\msek32.dll (file missing)
O2 - BHO: Class - {19AA31BF-1750-E89C-CB6E-11F9A6477CE9} - C:\WINDOWS\system32\d3ki32.dll (file missing)
O2 - BHO: Class - {262B7B86-55DB-32CD-522E-D1E8CDEC3BFE} - C:\WINDOWS\system32\netjt32.dll (file missing)
O2 - BHO: Class - {2D86D49A-0E10-CAE7-291B-D83BA5AD0087} - C:\WINDOWS\ntyh.dll (file missing)
O2 - BHO: Class - {30938316-DC58-DA9C-B4D3-C652FBD3DBEF} - C:\WINDOWS\addab.dll (file missing)
O2 - BHO: (no name) - {3DEE124E-EBB2-00C2-E596-DBCA1510C177} - (no file)
O2 - BHO: Class - {4CB9FE89-C678-F47B-2F95-B7988A0FC10D} - C:\WINDOWS\system32\netra.dll (file missing)
O2 - BHO: Class - {4D1C7E59-FDEE-E7E8-D0E4-2CA28A50B796} - C:\WINDOWS\ieyg32.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Class - {568F19C5-53C8-85F1-FD40-5AC40D3DE0DA} - C:\WINDOWS\system32\javagd.dll (file missing)
O2 - BHO: Class - {5899D6C8-2875-45AF-8736-13BE0C3BA5EC} - C:\WINDOWS\system32\addlo32.dll (file missing)
O2 - BHO: Class - {6C7405AE-7CE7-A0CE-827C-F77DFA449D8D} - C:\WINDOWS\system32\appua32.dll (file missing)
O2 - BHO: Class - {78545376-8241-C7E5-C71F-6A2E42322ADF} - C:\WINDOWS\system32\netpa.dll (file missing)
O2 - BHO: Class - {7A00499E-BCBB-B127-9B94-C5DF5086E096} - C:\WINDOWS\nethx32.dll (file missing)
O2 - BHO: Class - {7B315180-F3AA-843E-BFD5-2B630CDC0D67} - C:\WINDOWS\netev32.dll (file missing)
O2 - BHO: Class - {7D80F0E3-D853-E15E-FD62-366068538F6E} - C:\WINDOWS\system32\ieqn32.dll (file missing)
O2 - BHO: Class - {7E678766-5C45-3E67-EFD2-B3449A8C2A69} - C:\WINDOWS\winnk.dll (file missing)
O2 - BHO: Class - {85D798A6-2F83-A50C-5B26-F3BCDD880ABD} - C:\WINDOWS\crih.dll (file missing)
O2 - BHO: Class - {A010DBE2-CC3D-9634-88DD-0AC37058D49B} - C:\WINDOWS\system32\netei32.dll (file missing)
O2 - BHO: Class - {A4C18C6B-56A7-927D-630C-D7557B18963E} - C:\WINDOWS\system32\mstl.dll (file missing)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Class - {AF02D6F5-E10D-4B29-B7AB-E057280C0CDC} - C:\WINDOWS\system32\d3gh.dll (file missing)
O2 - BHO: Class - {B1226024-595B-F768-1697-EFEE2A97E5C8} - C:\WINDOWS\system32\sysmk.dll (file missing)
O2 - BHO: Class - {B990B770-D62A-B542-EDA6-516033B76258} - C:\WINDOWS\javafz.dll (file missing)
O2 - BHO: Class - {C012ED91-D21E-BC95-430B-8D4A44A3BDA5} - C:\WINDOWS\system32\ipyu.dll (file missing)
O2 - BHO: Class - {C3AAEC67-F763-AFDD-7B89-B292B7DC615D} - C:\WINDOWS\system32\netaq32.dll (file missing)
O2 - BHO: Class - {C4790940-96EC-3F25-4A2F-F6BF035B6FD5} - C:\WINDOWS\system32\sysep.dll (file missing)
O2 - BHO: (no name) - {C8004A51-B1C6-2B52-CE97-BA80D6D6C5DB} - (no file)
O2 - BHO: Class - {CAE597FF-4125-1680-10FC-D57418898CD3} - C:\WINDOWS\javags32.dll (file missing)
O2 - BHO: Class - {D883F4CC-A8EE-9040-1995-5458D21F8391} - C:\WINDOWS\system32\netnu32.dll (file missing)
O2 - BHO: Class - {D9C0B1C1-84B5-7F4A-70E8-5A3C089B2899} - C:\WINDOWS\system32\sdkxr.dll (file missing)
O2 - BHO: Class - {E3BB58FA-9E29-5453-8515-DD85FF9C16C7} - C:\WINDOWS\system32\ienw32.dll (file missing)
O2 - BHO: Class - {F0D80D9E-EC18-2B52-399F-E70AEDFC8E18} - C:\WINDOWS\winef32.dll (file missing)
O2 - BHO: Class - {F3264A95-EA02-5435-7C3B-CC1A6BECFC5B} - C:\WINDOWS\atlog.dll (file missing)
O2 - BHO: Class - {F3DF3C5A-2566-083E-2CA1-07FE7B5682F8} - C:\WINDOWS\system32\sdkga32.dll (file missing)
O2 - BHO: Class - {F7C42564-EA95-5F04-2382-4C97CB847F28} - C:\WINDOWS\sdkgz32.dll (file missing)
O2 - BHO: Class - {FE13BDB7-4403-0563-A91B-7E8970E72CF7} - C:\WINDOWS\system32\ipsf32.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - e:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Omnipage] E:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Norton Ghost 9.0] E:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SmcService] E:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MimBoot] e:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "e:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AnyDVD] "e:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] e:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mswc.exe] C:\WINDOWS\system32\mswc.exe
O4 - HKLM\..\Run: [mslb32.exe] C:\WINDOWS\system32\mslb32.exe
O4 - HKLM\..\Run: [d3zn32.exe] C:\WINDOWS\d3zn32.exe
O4 - HKLM\..\Run: [STARTPAGE] C:\NOSPY.ORG\start1.exe
O4 - HKLM\..\Run: [winsj.exe] C:\WINDOWS\system32\winsj.exe
O4 - HKLM\..\Run: [ScriptSentry] e:\Script Sentry\ScriptSentry.exe /check
O4 - HKLM\..\Run: [ierp32.exe] C:\WINDOWS\ierp32.exe
O4 - HKLM\..\Run: [THGuard] "E:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PeerGuardian] e:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [supervisor.exe] C:\WINDOWS\supervisor.exe
O4 - Startup: SpamBayes Tray Icon.lnk = E:\Program Files\SpamBayes\bin\sb_tray.exe
O4 - User Startup: SpamBayes Tray Icon.lnk = E:\Program Files\SpamBayes\bin\sb_tray.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Enable Wireless Keyboard Driver.lnk = C:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
O4 - Global Startup: Enable Wireless Optical Mouse Driver.lnk = C:\Program Files\Wireless Device\Wireless Mouse\MouseAp.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = E:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: NkvMon.exe.lnk = E:\Program Files\Nikon\NkView6\NkvMon.exe
O4 - Global Startup: WinZip Quick Pick.lnk = E:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Download &this page with WebCloner - E:\Program Files\ProductsFoundry\WebCloner Pro 2.4\addthis.htm
O8 - Extra context menu item: Download all &images with WebCloner - E:\Program Files\ProductsFoundry\WebCloner Pro 2.4\addimg.htm
O8 - Extra context menu item: Download all &links with WebCloner - E:\Program Files\ProductsFoundry\WebCloner Pro 2.4\addurl.htm
O8 - Extra context menu item: Download selected images with WebCloner - E:\Program Files\ProductsFoundry\WebCloner Pro 2.4\addselimgs.htm
O8 - Extra context menu item: Download selected links with WebCloner - E:\Program Files\ProductsFoundry\WebCloner Pro 2.4\addsellinks.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: WebCloner - {ADFCCE65-DF10-46fd-B04A-53CCBE2A0795} - E:\Program Files\ProductsFoundry\WebCloner Pro 2.4\WebCloner.exe
O9 - Extra 'Tools' menuitem: &WebCloner - {ADFCCE65-DF10-46fd-B04A-53CCBE2A0795} - E:\Program Files\ProductsFoundry\WebCloner Pro 2.4\WebCloner.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1131673724281
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\atlwe32.exe" /s (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - e:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - e:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Norton Ghost - Symantec Corporation - E:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - E:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe