Open Microsoft AntiSpyware and send a suspected spyware
report from the Tools
Menu.
For maximum effectiveness, proceed as follows:
Update your Microsoft Antispyware definitions. Is your
antivirus application also up to date?
Restart the machine in safe mode and Login as Administrator
Do a full, deep scan with Microsoft Antispyware (and,
ideally, your antivirus as well)
Download
http://www.lavasoftusa.com/support/download/
and on the left panel, look for add-on, download the fix
for VX2.
This is what I found (You better download HijackThis and
run it)
Variant: Pynix is one of the last of the VX2/Host
variants
File Name: pynix.dll
CLSID: {00000000-DD60-0064-6EC2-6E0100000000}
MD5: 5bd94bb7d4a9a6624612a6eb7f801151
Components: Pynix.dll, Pynix.inf, Pynix.cab, polall1p.exe,
thnall1p.exe
File Locations:
download.abetterinternet.com/download/cabs/PYNXDLL/pynix.ca
b
download.abetterinternet.com/download/cabs/PYNXDLL/polall1p
..exe
static.callinghome.biz/download/cabs/THNALL1P/thnall1p.exe
Registry Entries:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Explorer\Browser Helper Objects\{00000000-DD60-0064-
6EC2-6E0100000000}]
**
[HKEY_CLASSES_ROOT\CLSID\{00000000-DD60-0064-6EC2-
6E0100000000}]
@="PynixObj Class"
[HKEY_CLASSES_ROOT\CLSID\{00000000-DD60-0064-6EC2-
6E0100000000}\InprocServer32]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\Pynix.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{00000000-DD60-0064-6EC2-
6E0100000000}\ProgID]
@="Pynix.PynixObj.1"
[HKEY_CLASSES_ROOT\CLSID\{00000000-DD60-0064-6EC2-
6E0100000000}\Programmable]
[HKEY_CLASSES_ROOT\CLSID\{00000000-DD60-0064-6EC2-
6E0100000000}\TypeLib]
@="{09049e4f-8d9e-4c8a-a952-5baf1a115c59}"
[HKEY_CLASSES_ROOT\CLSID\{00000000-DD60-0064-6EC2-
6E0100000000}\VersionIndependentProgID]
@="Pynix.PynixObj"
**
[HKEY_CLASSES_ROOT\Interface\{94984402-B480-45C7-AD2D-
84E5EB52CFCD}]
@="IPynixDllObj"
[HKEY_CLASSES_ROOT\Interface\{94984402-B480-45C7-AD2D-
84E5EB52CFCD}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_CLASSES_ROOT\Interface\{94984402-B480-45C7-AD2D-
84E5EB52CFCD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_CLASSES_ROOT\Interface\{94984402-B480-45C7-AD2D-
84E5EB52CFCD}\TypeLib]
@="{09049E4F-8D9E-4C8A-A952-5BAF1A115C59}"
"Version"="1.1"
**
[HKEY_CLASSES_ROOT\PynixDll.PynixDllObj]
@="Pynix Functional Class"
[HKEY_CLASSES_ROOT\PynixDll.PynixDllObj\CLSID]
@="{00000000-DD60-0064-6EC2-6E0100000000}"
[HKEY_CLASSES_ROOT\PynixDll.PynixDllObj\CurVer]
@="PynixDll.PynixDllObj.1"
**
[HKEY_CLASSES_ROOT\PynixDll.PynixDllObj.1]
@="PynixObj Class"
[HKEY_CLASSES_ROOT\PynixDll.PynixDllObj.1\CLSID]
@="{00000000-DD60-0064-6EC2-6E0100000000}"
**
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}]
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1]
@="PynixDll 1.1 Type Library"
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1\0]
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1\0\win32]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\Pynix.dll"
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1\FLAGS]
@="0"
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1\HELPDIR]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\"
**
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}]
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1]
@="PynixDll 1.1 Type Library"
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1\0]
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1\0\win32]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\Pynix.dll"
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1\FLAGS]
@="0"
[HKEY_CLASSES_ROOT\TypeLib\{09049E4F-8D9E-4C8A-A952-
5BAF1A115C59}\1.1\HELPDIR]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\"
**
[HKEY_CURRENT_USER\Software\Pynix]
"PYI2d3OfSInst"="{F7BA28A1-78BE-483B-842D-4A588E027D16}"
"PYC2n3trMsgSDisp"=dword:00000032
"PYT2o3pListSPos"=dword:00000000
"PYs2t3icky1S"="lflshdt%3D1107813726%26lstlogdt%3D20050207%
260%3D%26cntp%3Dcable%26"
"PYs2t3icky2S"="fstcidt%3D1107813726382%260%3D%26"
"PYs2t3icky3S"="0"
"PYs2t3icky4S"="0"
"PYC1o2d3eOfSFinalAd"="0"
"PYT2i3m4eOfSFinalAd"="0"
"PYD2s3tSSEnd"="'>-,ÀÀÍ,fÌ,f<SÔOYÕZͶ^"Ì>o"
"PY2N3a4tionSCode"="US"
"PYP2D3om"=".?"-^?'?",<^YÌ'Y"
"PYI2n3ProgSCab"=dword:00000000
"PYI2n3ProgSEx"=dword:00000000
"PYI2n3ProgSLstest"=dword:00000000
"PYL2a3stSSChckin"=dword:0000041a
"PYB2D3om"=">??ZS>">??"S-ÜT?ZTf<T?Á?."
"PYC2u3rrentSMode"=dword:00000001
"PYC2n3tFyl"=dword:00000000
"PYM2o3deSSync"=dword:0000000b
"PYT2h3rshSBath"=dword:00002710
"PYT2h3rshSysSInf"=dword:000007d0
"PYT2h3rshSCheckSIn"=dword:0000002d
"PYT2h3rshSMots"=dword:00000064
"PYL2n3Title"=dword:0000001e
"PYI2g3noreS"="Tf
"PYS2t3atusOfSInst"="roger"
**
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-DD60-
0064-6EC2-6E0100000000}]
@="PynixObj Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-DD60-
0064-6EC2-6E0100000000}\InprocServer32]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\Pynix.dll"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-DD60-
0064-6EC2-6E0100000000}\ProgID]
@="Pynix.PynixObj.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-DD60-
0064-6EC2-6E0100000000}\Programmable]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-DD60-
0064-6EC2-6E0100000000}\TypeLib]
@="{09049e4f-8d9e-4c8a-a952-5baf1a115c59}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-DD60-
0064-6EC2-6E0100000000}\VersionIndependentProgID]
@="Pynix.PynixObj"
**
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94984402-
B480-45C7-AD2D-84E5EB52CFCD}]
@="IPynixDllObj"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94984402-
B480-45C7-AD2D-84E5EB52CFCD}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94984402-
B480-45C7-AD2D-84E5EB52CFCD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94984402-
B480-45C7-AD2D-84E5EB52CFCD}\TypeLib]
@="{09049E4F-8D9E-4C8A-A952-5BAF1A115C59}"
"Version"="1.1"
**
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PynixDll.PynixDllObj]
@="Pynix Functional Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PynixDll.PynixDllObj\C
LSID]
@="{00000000-DD60-0064-6EC2-6E0100000000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PynixDll.PynixDllObj\C
urVer]
@="PynixDll.PynixDllObj.1"
**
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PynixDll.PynixDllObj.1
]
@="PynixObj Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PynixDll.PynixDllObj.1
\CLSID]
@="{00000000-DD60-0064-6EC2-6E0100000000}"
**
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1]
@="PynixDll 1.1 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1\0]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1\0\win32]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\Pynix.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1\FLAGS]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1\HELPDIR]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\"
**
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1]
@="PynixDll 1.1 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1\0]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1\0\win32]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\Pynix.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1\FLAGS]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{09049E4F-
8D9E-4C8A-A952-5BAF1A115C59}\1.1\HELPDIR]
@="C:\\DOCUME~1\\pjordan\\LOCALS~1\\Temp\\"
**
[HKEY_USERS\S-1-5-21-1993962763-1708537768-1850160755-1003
\Software\Pynix]
"PYI2d3OfSInst"="{F7BA28A1-78BE-483B-842D-4A588E027D16}"
"PYC2n3trMsgSDisp"=dword:00000032
"PYT2o3pListSPos"=dword:00000000
"PYs2t3icky1S"="lflshdt%3D1107813726%26lstlogdt%3D20050207%
260%3D%26cntp%3Dcable%26"
"PYs2t3icky2S"="fstcidt%3D1107813726382%260%3D%26"
"PYs2t3icky3S"="0"
"PYs2t3icky4S"="0"
"PYC1o2d3eOfSFinalAd"="0"
"PYT2i3m4eOfSFinalAd"="0"
"PYD2s3tSSEnd"="'>-,ÀÀÍ,fÌ,f<SÔOYÕZͶ^"Ì>o"
"PY2N3a4tionSCode"="US"
"PYP2D3om"=".?"-^?'?",<^YÌ'Y"
"PYI2n3ProgSCab"=dword:00000000
"PYI2n3ProgSEx"=dword:00000000
"PYI2n3ProgSLstest"=dword:00000000
"PYL2a3stSSChckin"=dword:0000041a
"PYB2D3om"=">??ZS>">??"S-ÜT?ZTf<T?Á?."
"PYC2u3rrentSMode"=dword:00000001
"PYC2n3tFyl"=dword:00000000
"PYM2o3deSSync"=dword:0000000b
"PYT2h3rshSBath"=dword:00002710
"PYT2h3rshSysSInf"=dword:000007d0
"PYT2h3rshSCheckSIn"=dword:0000002d
"PYT2h3rshSMots"=dword:00000064
"PYL2n3Title"=dword:0000001e
"PYI2g3noreS"="Tf
"PYS2t3atusOfSInst"="roger"