Running windows xp. I run Spysweeper and Spybot in safe mode. They both find spyware and they both remove it. At least they say they removed them. I run the removal again they find the exact same spyware. I have them remove it and run it again and they find it again. I'm not rebooting or doing anything out of the ordinary. I just run the removal and then run it again. The spyware is never removed. Here's what highjacker shows.
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\cisvc.
exe
C:\WINDOWS\System32\CTsvcC
DA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\crvv32.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSP
Sv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cidaem
on.exe
C:\WINDOWS\system32\cidaem
on.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\WINDOWS\system32\sysza3
2.exe
C:\WINDOWS\Tasks\keyabr.ex
e
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\wuaucl
t.exe
C:\Documents and Settings\Beth Bergman\My Documents\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.dellnet.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\
wmxye.dll/
sp.html#96
676
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
wmxye.dll/
sp.html#96
676
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://C:\WINDOWS\system32\
wmxye.dll/
index.html
#96676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = res://C:\WINDOWS\system32\
wmxye.dll/
index.html
#96676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = res://C:\WINDOWS\system32\
wmxye.dll/
sp.html#96
676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\
wmxye.dll/
sp.html#96
676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
wmxye.dll/
sp.html#96
676
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://C:\WINDOWS\system32\
wmxye.dll/
index.html
#96676
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINDOWS\system32\
wmxye.dll/
sp.html#96
676
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINDOWS\system32\
wmxye.dll/
sp.html#96
676
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {5E9652E0-BFA3-B81B-DA74-0
9BF6CC428A
7} - C:\WINDOWS\croz.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IM
JPMIG.EXE"
/Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] "C:\WINDOWS\ime\imkr6_1\IM
EKRMIG.EXE
"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe " /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpobnz08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\System32\Shdocv
w.dll
Thanks
Dick