hey that man. I found the site for the panada thing and i ran download CleanUp4.0
But when I ran Ewido, and i updated and scanned, I got an error message. It's one of those messages from microsoft that says "SecuritySuite.exe has encountered a problem and needs to close. We are soory for the inconvenience." It also gives me the option to send the error report to microsoft. It has the Ewido icon on the side too. It seems like I've been getting a bunch of these errors recently from various programs like QuickTime, or Internet explorer and stuff like that. strange. I got this error message when Ewido reached 100.00% in scanning, and on the bottom of Ewido it says "Clean "F:\WINDOWS\TEMP\_unin_.exe"" Yeah i dunno. well here is my panda scanner log and the HJT log.
Here is the panda online scanner one...
Incident Status Location
Spyware:Spyware/Cydoor No disinfected C:\WINDOWS\cdmxtras
Adware:Adware/eZula No disinfected Windows Registry
Adware:Adware/MyWay No disinfected C:\Program Files\MyWay
Adware:Adware/nCase No disinfected C:\WINDOWS\System32\FLEOK
Spyware:Spyware/Dyfuca No disinfected Windows Registry
Adware:Adware/BookedSpace No disinfected C:\DOCUME~1\EDOH~1\LOCALS~1\Temp\bs*.tmpbsx32
Adware:Adware/NetPals No disinfected C:\WINDOWS\System32\calsdr.dll
Adware:Adware/Apropos No disinfected C:\Program Files\cxtpls
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\System32\a.exe
Adware:Adware/AdDestroyer No disinfected C:\Documents and Settings\Ed Oh\Start Menu\Programs\AdDestroyer
Adware:Adware/VirtualBouncer No disinfected C:\WINDOWS\System32\swrt01.dll
Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Ed Oh\Application Data\tvm*.dll
Adware:Adware/SideSearch No disinfected Windows Registry
Adware:Adware/IPInsight No disinfected C:\DOCUME~1\EDOH~1\LOCALS~1\Temp\alchem.???
Adware:Adware/SideFind No disinfected Windows Registry
Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\smdat32m.sys
Adware:Adware/Tubby No disinfected C:\WINDOWS\System32\MTC.ini
Adware:Adware/SuperSpider No disinfected C:\Program Files\Q330994.exe
Spyware:Spyware/Whazit No disinfected C:\WINDOWS\System32\fiz1
Adware:Adware/CWS.Searchmeup No disinfected C:\WINDOWS\mstasks1.exe
Adware:Adware/InstaFinder No disinfected C:\Program Files\INSTAFINK
Adware:Adware/Adsmart No disinfected Windows Registry
Virus:Trj/Downloader.CFJ Disinfected Operating system
Adware:Adware/WinActive No disinfected C:\Documents and Settings\Dad\Local Settings\Temp\bz24.tmp[bz24.tmp]
Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Ed Oh\Application Data\tvmcwrd.dll
Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Ed Oh\Application Data\tvmknwrd.dll
Adware:Adware/MyWay No disinfected C:\Documents and Settings\Ed Oh\Desktop\Hijack this\backup-20040703-232913-564.dll
Adware:Adware/MyWay No disinfected C:\Documents and Settings\Ed Oh\Desktop\Hijack this\backup-20040703-232913-701.dll
Adware:Adware/Adblaster No disinfected C:\Documents and Settings\Ed Oh\Desktop\Hijack this\backup-20040703-232914-566.dll
Adware:Adware/Adblaster No disinfected C:\Documents and Settings\Ed Oh\Desktop\Hijack this\backup-20040703-232914-965.dll
Adware:Adware/P2PNetworking No disinfected C:\Documents and Settings\Ed Oh\Desktop\Hijack this\backups\backup-20050409-201830-391.dll
Adware:Adware/MyWay No disinfected C:\Documents and Settings\Ed Oh\Desktop\Hijack this\backups\backup-20050418-190708-619.dll
Adware:Adware/InstaFinder No disinfected C:\Documents and Settings\Ed Oh\Desktop\Hijack this\backups\backup-20050418-190708-943.dll
Adware:Adware/MyWay No disinfected C:\Documents and Settings\Ed Oh\Desktop\Hijack this\backups\backup-20050420-205915-831.dll
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\alchem.inf
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\alchem.ini
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\Belt.ini
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\conscorr.inf
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\conscorr.ini
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\II242.tmp
Adware:Adware/Adblaster No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\ngpw34.dll
Adware:Adware/Adblaster No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\ngsw31.dll
Adware:Adware/P2PNetworking No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\p2psetup.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\pch386.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\pch437.exe
Adware:Adware/MyWay No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\temp.fr9221\mysearch.cab
Adware:Adware/MyWay No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\temp.fr9221\mysearch.cab[mySetp.exe]
Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Ed Oh\Local Settings\Temp\tvmupdater.exe
Adware:Adware/SuperSpider No disinfected C:\m.exe
Adware:Adware/SuperSpider No disinfected C:\mssys.com
Possible Virus. No disinfected C:\Program Files\GameSpy Arcade\fpupdate.exe
Adware:Adware/InstaFinder No disinfected C:\Program Files\INSTAFINK\instafink.dll
Adware:Adware/SuperSpider No disinfected C:\Program Files\Q330994.exe
Adware:Adware/SuperSpider No disinfected C:\Q250204.exe
Adware:Adware/IPInsight No disinfected C:\WINDOWS\alchem.ini
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\cvchost.exe
Adware:Adware/Yahoo No disinfected C:\WINDOWS\Downloaded Program Files\ycomp5_0_2_7.dll
Adware:Adware/IPInsight No disinfected C:\WINDOWS\INF\alchem.inf
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\INF\biH.inf
Adware:Adware/IPInsight No disinfected C:\WINDOWS\INF\conscorr.inf
Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\polall1r.inf
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\msstasks.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\mssys.com
Adware:Adware/CWS.Searchmeup No disinfected C:\WINDOWS\mstasks1.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\mstaskss.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\msxmidi.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\rocky.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\runwin32.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\seksdialer.exe
Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\smdat32m.sys
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\sysdy.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM\system.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM\wmscrop.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\system.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM32\a.exe
Adware:Adware/NetPals No disinfected C:\WINDOWS\SYSTEM32\atiupdate5.exe
Possible Virus. No disinfected C:\WINDOWS\SYSTEM32\bH.dll
Adware:Adware/StatBlaster No disinfected C:\WINDOWS\SYSTEM32\biggie.exe
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\SYSTEM32\bridge.dll
Adware:Adware/NetPals No disinfected C:\WINDOWS\SYSTEM32\calsdr.dll
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM32\d2kpax.dll
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM32\d2kpax.exe
Spyware:Spyware/Whazit No disinfected C:\WINDOWS\SYSTEM32\fiz1
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM32\IF01.exe
Adware:Adware/KeenValue No disinfected C:\WINDOWS\SYSTEM32\in10b6.dll
Adware:Adware/VirtualBouncer No disinfected C:\WINDOWS\SYSTEM32\INNERADINSTALL.LOG
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM32\jac.dll
Spyware:Spyware/Whazit No disinfected C:\WINDOWS\SYSTEM32\kyf.dat
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM32\msxslab.dll
Adware:Adware/Tubby No disinfected C:\WINDOWS\SYSTEM32\MTC.ini
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\SYSTEM32\newdevin.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM32\services
Adware:Adware/NetPals No disinfected C:\WINDOWS\SYSTEM32\siae3123.exe
Adware:Adware/VirtualBouncer No disinfected C:\WINDOWS\SYSTEM32\SWRT01.dll
Adware:Adware/Adsmart No disinfected C:\WINDOWS\SYSTEM32\thun.dll
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\wininet32.exe
Adware:Adware/SuperSpider No disinfected C:\winspec.dat
Adware:Adware/Twain-Tech No disinfected F:\WINDOWS\INF\TWAINTEC.INF
Spyware:Spyware/Altnet No disinfected F:\WINDOWS\TEMP\asmfiles.cab[asm.exe]
Adware:Adware/Twain-Tech No disinfected F:\WINDOWS\TEMP\THI4B66.TMP\twaintec.inf
Spyware:Spyware/Altnet No disinfected F:\WINDOWS\TEMP\__unin__.exe
Adware:Adware/IPInsight No disinfected F:\WINDOWS\TEMP\alchem.cab[alchem.inf]
Adware:Adware/IPInsight No disinfected F:\WINDOWS\TEMP\alchem.cab[alchem.ini]
Adware:Adware/IPInsight No disinfected F:\WINDOWS\TEMP\alchem.inf
Adware:Adware/IPInsight No disinfected F:\WINDOWS\TEMP\alchem.ini
Virus:W32/Netsky.P.worm Disinfected F:\WINDOWS\Desktop\coh.zip[Inbox_5-14-2004][application.exe]
Virus:W32/Gibe.C.worm Disinfected F:\WINDOWS\Desktop\coh.zip[Old-Inbox-03-12-2004][Upgrade929.exe]
Adware:Adware/P2PNetworking No disinfected F:\WINDOWS\Desktop\hijack this\backup-20040614-220739-568.dll
Virus:W32/Netsky.P.worm Disinfected F:\WINDOWS\Temporary Internet Files\Content.IE5\8XUB056N\coh[1].zip[Inbox_5-14-2004][application.exe]
Virus:W32/Gibe.C.worm Disinfected F:\WINDOWS\Temporary Internet Files\Content.IE5\8XUB056N\coh[1].zip[Old-Inbox-03-12-2004][Upgrade929.exe]
Adware:Adware/MyWay No disinfected F:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
Adware:Adware/WebHancer No disinfected F:\Program Files\whInstall\whInstaller.ini
Adware:Adware/WebHancer No disinfected F:\Program Files\whInstall\whAgent.inf
Spyware:Spyware/Clipgenie No disinfected F:\Program Files\Support Software\SS2.DLL
Virus:W32/Verona.B Disinfected F:\save this stuff\email\inbox\In.mbx[~000964.@x@]
Virus:W32/Verona.B Disinfected F:\save this stuff\email\inbox\In.mbx[~000965.@x@]
Virus:W32/Verona.B Disinfected F:\save this stuff\email\inbox\In.mbx[~000966.@x@]
Virus:Exploit/iFrame Disinfected F:\save this stuff\email\inbox\In.mbx[~003567.@x@]
Virus:Exploit/iFrame Disinfected F:\save this stuff\email\inbox\In.mbx[~005386.@x@]
Spyware:Spyware/TVMedia No disinfected F:\TV Media\Tvm.exe
Here is the Hijack This log...
Logfile of HijackThis v1.99.1
Scan saved at 6:38:26 PM, on 5/6/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\STOPzilla!\SZServer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Ed Oh\Desktop\Hijack this\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.dellnet.com/O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\STOPzilla.exe /autostart
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Startup: Ubisoft register.lnk = C:\Program Files\Ubisoft\Register\schedule.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O16 - DPF: Yahoo! Chess -
http://download.game...nts/y/ct1_x.cabO16 - DPF: Yahoo! Graffiti -
http://download.game...ts/y/grt5_x.cabO16 - DPF: Yahoo! Pool 2 -
http://download.game...ts/y/potc_x.cabO16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) -
http://www.sarangccm...eX/AlwaysOn.CABO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcaf...64/mcinsctl.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by17fd.bay17....es/MsnPUpld.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefend...can8/oscan8.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO20 - Winlogon Notify: STOPzilla - C:\WINDOWS\SYSTEM32\IS3WLHandler.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: STOPzilla Service (szserver) - Unknown owner - C:\Program Files\Common Files\STOPzilla!\SZServer.exe
Well Thanks for all your help so far!