I ran adware, spybot, and antivirus but none of them remove it.
what can I do? here is my hijack this log

Logfile of HijackThis v1.97.7
Scan saved at 3:32:53 PM, on 3/10/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\msdtc.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\System32\snmp.exe
c:\program files\timbuktu pro\tb2launch.exe
c:\program files\timbuktu pro\tb2pro.exe
C:\WINDOWS\NetopiaRC\Tb2RCAssist.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\System32\mspmspsv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\mqsvc.exe
c:\program files\timbuktu pro\TNOTIFY.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\program files\timbuktu pro\tb2logon.exe
C:\WINDOWS\SYSTEM32\3cmlink.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\SYSTEM32\3cshtdwn.exe
C:\WINDOWS\SYSTEM32\3cmlink.exe
C:\WINDOWS\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe
C:\PROGRA~1\IPMONI~1\IPMonitor.exe
C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe
C:\Program Files\No-IP\DUC20.exe
C:\GeoCenter\DMCenter.exe
C:\PROGRA~1\MICROS~3\Office\OUTLOOK.EXE
C:\WINDOWS\SynCor.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\administrator\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT READER 5\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {FA0286CF-E520-49BE-B9C4-5C985CC501B6} - C:\WINDOWS\x8rod.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Tb2initPath] "c:\program files\timbuktu pro\tb2init.exe"
O4 - HKLM\..\Run: [TLogonPath] "c:\program files\timbuktu pro\tb2logon.exe"
O4 - HKLM\..\Run: [3c1807pd] C:\WINDOWS\SYSTEM32\3cmlink.exe RunServices \Device\3cpipe-3c1807pd
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\Program Files\\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [f899MCESF] C:\WINDOWS\imWl2X.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKCU\..\Run: [IPMonitor] C:\PROGRA~1\IPMONI~1\IPMonitor.exe
O4 - HKCU\..\Run: [IP Monitor] C:\Program Files\IPMonitor\IPMonitor.exe
O4 - HKCU\..\Run: [Sbse] C:\Documents and Settings\administrator\Application Data\umnr.exe
O4 - Startup: DUC20.lnk = C:\Program Files\No-IP\DUC20.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {4FDF3696-5078-4952-868C-CEEB9683B8C4} (DownloadFile Control) -
O16 - DPF: {5508547B-4F40-4005-AE0C-343C985DACE1} (WebCamX Control) -
O16 - DPF: {6AEFE48C-FB6C-4C27-A161-A0BF3438537E} (Live() Control) -
O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} (LiveX(v6.0)) -
O16 - DPF: {B1773A76-5F0E-46C6-B611-FB4E8704D9E9} (PlayBackX Control) -
O16 - DPF: {BF5E26B7-7087-4C2D-B0BA-0098F7CBED6B} (LiveX() Control) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{99E4CDDA-0311-4876-8A22-7FCF3F67F94F}: NameServer =

Dani AI

Generated

A short, practical cleanup plan that builds on ’s advice (fix the suspicious startup/BHO entries and remove the AutoUpdate folder) and explains what to do next if those steps don’t finish the job.

Droppers are designed to install other malware and hide their payloads, so an on‑screen scan or a single AV run often won’t fully remove everything. Treat this as a persistence/backdoor problem rather than a simple adware cleanup. (malwarebytes.com)

Immediate actions (containment + scan)

  • Isolate the PC: unplug Ethernet and turn off Wi‑Fi so the infection can’t call home or spread. Containment is a first priority in incident handling. (csrc.nist.rip)
  • Boot into Safe Mode (or use a rescue environment) and run current, on‑demand scanners — start with Malwarebytes/AdwCleaner and then run a Microsoft on‑demand scanner/MSRT or a full AV scan. If the machine can’t download tools safely, fetch installers on a clean PC and transfer by USB. (help.malwarebytes.com)

Remove persistence and browser hijacks

  • Use a modern startup/persistence viewer (Microsoft Sysinternals Autoruns) to find and disable/delete Run keys, services, scheduled tasks, Winlogon/IE add‑ons and BHOs. Autoruns shows far more autostart locations than msconfig and is the right tool for manual cleanup. (learn.microsoft.com)
  • Note: HijackThis was useful historically, but contemporary helper forums and responders now prefer current tools (FRST, Autoruns, on‑demand scanners) and guided logs for safe repairs. (bleepingcomputer.com)

When to stop chasing and reimage

  • If persistence returns, unknown services remain, or sensitive credentials were used on the machine, back up only user data (scan it from another clean system), wipe/reimage the drive and reinstall OS/apps from known‑good media. After cleanup or rebuild, change passwords using a known‑clean device and enable MFA where possible. Reimaging is a standard part of incident recovery when eradication can’t be guaranteed. (csrc.nist.rip)

Cautions: don’t run multiple real‑time AVs at once; keep logs of what you remove; if the machine holds sensitive business data or you suspect lateral movement, escalate to a professional incident responder.

Run HJT again & get it to fix these entries;

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

O2 - BHO: (no name) - {FA0286CF-E520-49BE-B9C4-5C985CC501B6} - C:\WINDOWS\x8rod.dll

O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"

O16 - DPF: {4FDF3696-5078-4952-868C-CEEB9683B8C4} (DownloadFile Control) -

O16 - DPF: {5508547B-4F40-4005-AE0C-343C985DACE1} (WebCamX Control) -

O16 - DPF: {6AEFE48C-FB6C-4C27-A161-A0BF3438537E} (Live() Control) -

O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} (LiveX(v6.0)) -

O16 - DPF: {B1773A76-5F0E-46C6-B611-FB4E8704D9E9} (PlayBackX Control) -

O16 - DPF: {BF5E26B7-7087-4C2D-B0BA-0098F7CBED6B} (LiveX() Control) -

I ran a search for these two but came up with nothing, so I don't know what they are; usually anything you don't recognise is suspicious, but wait to see if anyone else knows what they are B4 doing anything about them.

O4 - HKCU\..\Run: [Sbse] C:\Documents and Settings\administrator\Application Data\umnr.exe

O4 - Startup: DUC20.lnk = C:\Program Files\No-IP\DUC20.exe

Reboot then go to C:\Program Files\AutoUpdate\AutoUpdate.exe & delete the folder.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.