I have tried Ad-Aware, CWShredder, Spybot, Hijack this!, Updated Windows and Norton. It always seems to come back.
Here is the log from Hijack This
Logfile of HijackThis v1.97.7
Scan saved at 12:56:13 PM, on 7/19/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\System32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\System32\inetsr
v\inetinfo
.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\javads32.exe
C:\WINDOWS\System32\MsgSys
.EXE
C:\WINDOWS\System32\atipta
xx.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Logitech\QCDriver3\L
VCOMS.EXE
C:\Program Files\Logitech\ImageStudio
\LogiTray.
exe
C:\WINDOWS\System32\devldr
32.exe
D:\Quick Time\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\WINDOWS\system32\d3aj32
.exe
C:\Program Files\ICQPlus\vplus.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
BackWeb-88
76480.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.
exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\WINDOWS\System32\rundll
32.exe
C:\Documents and Settings\Darc\Desktop\Hija
ckThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
hbpzm.dll/
sp.html#96
676
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://hbpzm.dll/index.html
#96676
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://hbpzm.dll/index.html
#96676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
hbpzm.dll/
sp.html#96
676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = res://hbpzm.dll/index.html
#96676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = res://C:\WINDOWS\system32\
hbpzm.dll/
sp.html#96
676
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: (no name) - {0B7CFD10-5930-D230-8AE6-6
3D005DFAA5
4} - C:\WINDOWS\system32\winjv3
2.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\L
VCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio
\ISStart.e
xe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio
\LogiTray.
exe
O4 - HKLM\..\Run: [Regx10EXE] <REMOTEPATH_HERE>\ATIX10.e
xe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Quick Time\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [d3aj32.exe] C:\WINDOWS\system32\d3aj32
.exe
O4 - HKCU\..\Run: [ICQ Plus] "C:\Program Files\ICQPlus\vplus.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.e
xe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
BackWeb-88
76480.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.
exe
O4 - HKLM\..\RunOnce: [d3ol.exe] C:\WINDOWS\d3ol.exe
O4 - HKLM\..\RunOnce: [javads32.exe] C:\WINDOWS\javads32.exe
O4 - HKLM\..\RunOnce: [sdkbk32.exe] C:\WINDOWS\sdkbk32.exe
O4 - HKLM\..\RunOnce: [addzp.exe] C:\WINDOWS\addzp.exe
O4 - HKLM\..\RunOnce: [atljr.exe] C:\WINDOWS\atljr.exe
O4 - HKLM\..\RunOnce: [javaqg32.exe] C:\WINDOWS\javaqg32.exe
O4 - HKLM\..\RunOnce: [d3ux.exe] C:\WINDOWS\d3ux.exe
O4 - HKLM\..\RunOnce: [crpz32.exe] C:\WINDOWS\crpz32.exe
O4 - HKLM\..\RunOnce: [ntul32.exe] C:\WINDOWS\ntul32.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
LDMConf.ex
e
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra button: ATI TV (HKLM)
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {00B71CFB-6864-4346-A978-C
0A14556272
C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {2917297F-F02B-4B9D-81DF-4
94B6333150
B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cabO16 - DPF: {2B323CD9-50E3-11D3-9466-0
0A0C970049
8} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cabO16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exeO16 - DPF: {8E0D4DE5-3180-4024-A327-4
DFAD1796A8
D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cabO16 - DPF: {917623D1-D8E5-11D2-BE8B-0
0104B06BDE
3} (CamImage Class) -
http://webcam02.lugano.ch/activex/AxisCamControl.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37513.7990162037O16 - DPF: {A8F2B9BD-A6A0-486A-9744-1
8920D89842
9} (ScorchPlugin Class) -
http://www.sibelius.com/download/software/win/ActiveXPlugin.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F
385591623A
F} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/SolitaireShowdown.cab--------------------------
-
I have tried to remove these followin lines and it still comes back
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
hbpzm.dll/
sp.html#96
676
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://hbpzm.dll/index.html
#96676
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://hbpzm.dll/index.html
#96676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
hbpzm.dll/
sp.html#96
676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = res://hbpzm.dll/index.html
#96676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = res://C:\WINDOWS\system32\
hbpzm.dll/
sp.html#96
676
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
Please help