What follows is a blow for blow account of the last month so if it's too long, please just skip down to the hijack log (I have tried running all the programs you recommended, Ad-aware was the one that seems to get stuck on a temp file all the time, javascript:emoticon(':(',%20'smid_1') and everytime it runs it throws up new bugs that are picked up by Panda and Ewido javascript:emoticon(':confused:',%20'smid_8')).
BACKGROUND
I run XP. I never used the windows updates (so I never had SP2 or even SP1a I don’t think). I have SpyBot and SpyBlaster on the computer and I try and use Firefox principally though IE does get used. I have a belkin hardware firewall but no software firewall.
One month ago I began having a problem with lycos sidesearch. I removed it by using the trial version of spysweeper which has now expired. javascript:emoticon(':thumbsup:',%20'smid_17') Shortly after I began having problems with fake ‘you have spyware alerts.’ One would change the whole of my desktop to alert me of this obvious problem javascript:emoticon(':wacko:',%20'smid_20') (and also placed a red exclamation mark at the bottom right of my PC – I think this was the PS Guard spyware), the other which appeared later (after I ran Spybot and got rid of the PS Guard) just showed as a thin horizontal task bar at the top of my screen with a scrolling warning which when clicked tries to hijack my IE search page and direct me to bogus programs.javascript:emoticon(':whistling:',%20'smid_21')
REMEDIES ATTEMPTED X 3
So, I tried to run all the programs you’ve recommended as follows.
Clean up run successfully
Ad-aware SE unable to run
Spybot successfully picked up CWS and PS guard and others and cleaned out
CWShredder run ok and not picking up anything after running Spybot
Ewido installed and run successfully, removing around 200 threats. However everytime computer is turned back Ewido picks up 2.tmp or 3.tmp threat which I don’t think it is successfully clearing.
Trend Housecall – unable to properly install
Panda Activescan – installed successfully and detected threats – unsure if it cleared them initially since it began requesting that it be purchased to be properly activated – which I did not do
AVG run successfully picking up series of tmp Trojans and during the scan randomly opening the dos prompt and ms word
Trojan Hunter run successfully, nothing detected
The first time I ran the above sequence while offline. I then updated all the respective programs and ran all the above a second time. Ewido and Panda neutralized Adware/SpyFighter, SearchAid, AdClicker, DownloaderAgent.bc, Exploit/ByteVerify after which I did not re-encounter the troublesome banner described earlier. However I was still not able to successfully run Ad-aware which always seems to get blocked on certain local\temp\aawtmp files which I cannot find when I look for them. I actually tried to run Ad-aware several times, each time Panda kept picking up Trj/ClassLoader.U in different files. Also everytime I rebooted the computer Ewido kept picking up 2.tmp and 3.tmp.javascript:emoticon(':angry:',%20'smid_5')
After this, though I still think there's malware, I ran Windows Update SP1a but not SP2 as recommended.
Finally, I ran all the above programs in sequence AGAIN - only Ad-adware still does not seem to run.
Below are three ewido logs and the hijack log. Thank you very much for your help and sorry for the long winded story. javascript:emoticon(':help:',%20'smid_11')
EWIDO LOGS (three of them in order)
EWIDO LOG 1
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 9:34:53 PM, 1/1/2006
+ Report-Checksum: CD51331B
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW -> Spyware.CoolWebSearch : Cleaned with backup
[1512] C:\WINDOWS\system32\crqn32.exe -> Trojan.Agent.bi : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.205:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Estat : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Trafic : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.269:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.270:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.271:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.274:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.275:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.276:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.278:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.285:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.287:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.288:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.290:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\6n9f2k1c.Elza\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.255:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.258:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.259:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.262:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.263:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.264:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.300:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.303:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.340:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.341:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.342:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.353:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.355:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.359:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.360:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.361:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.362:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.363:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.365:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.367:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.368:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.381:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.383:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup
:mozilla.392:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.393:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.394:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.419:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.420:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.426:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.453:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.455:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.459:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.467:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.468:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.475:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.478:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.481:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.482:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.483:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.484:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.491:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.492:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.517:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.538:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.547:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.554:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.558:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.559:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.565:C:\Documents and Settings\Elza\Application Data\Mozilla\Firefox\Profiles\lx7bhevv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Invitato\Application Data\Mozilla\Firefox\Profiles\vsceuhas.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Ramy\Local Settings\Temp\3.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\Ramy\Local Settings\Temp\7.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\Ramy\Local Settings\Temp\__delete_on_reboot__2.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\Ramy\Local Settings\Temporary Internet Files\Content.IE5\6HI5IZ4D\pic[2].wmf -> Not-A-Virus.Exploit.Win32.IMG-WMF : Cleaned with backup
C:\Documents and Settings\Ramy\Local Settings\Temporary Internet Files\Content.IE5\SHUVK9AZ\start[1].exe -> Downloader.Small.cdd : Cleaned with backup
C:\ntdetecd.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\ntfull.exe -> Trojan.LowZones.df : Cleaned with backup
C:\WINDOWS\NDNuninstall6_98.exe -> Adware.NewDotNet : Cleaned with backup
C:\WINDOWS\prflbmsgp32.dll -> Downloader.Delf.yb : Cleaned with backup
::Report End
EWIDO LOG 2
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 9:56:36 PM, 1/1/2006
+ Report-Checksum: 7AB5FD51
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW -> Spyware.CoolWebSearch : Cleaned with backup
[768] C:\WINDOWS\iejt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\Documents and Settings\Ramy\Local Settings\Temp\3.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\Ramy\Local Settings\Temp\__delete_on_reboot__2.tmp -> Trojan.Small.ga : Cleaned with backup
::Report End
EWIDO LOG 3
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 2:26:15 PM, 1/3/2006
+ Report-Checksum: E9208B3E
+ Scan result:
C:\WINDOWS\iis6.log:kiirm -> Downloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB835732.log:vcuci -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\maxlink.ini:rctdh -> Downloader.Agent.bc : Cleaned with backup
C:\WINDOWS\setupact.log:lkqxo -> Downloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system.ini:wlbhk -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\WMSysPr9.prx:pwusf -> Downloader.Agent.td : Cleaned with backup
::Report End
HIJACK LOG
Logfile of HijackThis v1.99.1
Scan saved at 11:31:34 PM, on 1/3/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\panda software\panda platinum 2006 internet security\firewall\PNMSRV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\pavsrv51.exe
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\AntiSpam\pskmssvc.exe
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\AVENGINE.EXE
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\psimsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\TPSrv.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\apvxdwin.exe
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\SRVLOAD.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\WebProxy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Documents and Settings\Ramy\Desktop\HijackThis.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\avciman.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...B_PVER}&ar=home
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Class - {6D224D6C-9CD9-244E-1651-BCB09374072E} - C:\WINDOWS\system32\sysjc32.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [croe32.exe] C:\WINDOWS\croe32.exe
O4 - HKLM\..\Run: [5.tmp] C:\DOCUME~1\Ramy\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [6.tmp] C:\DOCUME~1\Ramy\LOCALS~1\Temp\6.tmp.exe
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\Ramy\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [6.tmp.exe] C:\DOCUME~1\Ramy\LOCALS~1\Temp\6.tmp.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\Inicio.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software - C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - PANDA SOFTWARE - C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\AntiSpam\pskmssvc.exe
O23 - Service: Panda Network Manager (PNMSRV) - Panda Software - c:\program files\panda software\panda platinum 2006 internet security\firewall\PNMSRV.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\psimsvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software - C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\TPSrv.exe
Thank you once again for taking so much time to review all this.javascript:emoticon(':unsure:',%20'smid_18')
rbad