Hello Crusty,
Well done that is a vast improvement.
I don't know if it is all clear yet but we can now set the Homepage and browse without trouble. Now when I try to uninstall Shopping wizard, Search extender and Home search assistant they offer an uninstall form for cancellation. These are the latest logs you requested:-
Logfile of HijackThis v1.99.1
Scan saved at 15:09:13, on 16/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.blueyonder.co.uk/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1109253153456O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 12:43:43, 16/05/2005
+ Report-Checksum: 4240E9B8
+ Date of database: 16/05/2005
+ Version of scan engine: v3.0
+ Duration: 25 min
+ Scanned Files: 44214
+ Speed: 29.28 Files/Second
+ Infected files: 144
+ Removed files: 144
+ Files put in quarantine: 144
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\WINDOWS\naeyyl.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\kev & pauline@S150942[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\WINDOWS\SYSTEM32\winyu.exe -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\SYSTEM32\sdkqc.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\ippx32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\apiba32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\msxl.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\atlto32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\iehu.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\apprp32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\atlwy.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\d3ck.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\addgu32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\msns.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\crmo.dll -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\SYSTEM32\ipfz32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\winqn32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\msmq.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\winqx.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\d3gj32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\sdkpw.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\atlmc32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\crfs.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\ipmw32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\javadd.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\d3qi.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\d3kb32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\ntpw.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\SYSTEM32\addfn.exe -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\SYSTEM32\d3kp32.exe -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\SYSTEM32\ms0b920b.dll -> Spyware.Visiter -> Cleaned with backup
C:\WINDOWS\SYSTEM32\uhaa.dll -> TrojanDownloader.Small -> Cleaned with backup
C:\WINDOWS\SYSTEM32\sdkpr32.dll -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\zptzoh.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\xfyoel.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\msrj.dll -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\vcnsre.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\gdqvwv.txt -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\zejjqf.txt -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\hocajc.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\ealdjy.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\xyvvwa.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\tnyiqm.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\ahbwkn.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\pfxgsu.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\xjxfvr.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\zrxbpb.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\akkvae.dat -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\mwnleq.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\twvxxk.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\uparhn.dat -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\oxrlne.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\ccmiqy.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\msww.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\kcpsrt.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\mfzgez.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\sysgs.dll -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\mfcaq32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\bigswc.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\dlypjj.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\umgptx.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\wjihan.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\nadyhx.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\javanm.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\ipgs32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\fnejcv.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\gyxfpb.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\aapxpl.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\xmaemt.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\tnmlga.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\plvvcd.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\syskk.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\wqpevk.dat -> TrojanDropper.Small.tn -> Cleaned with backup
C:\WINDOWS\xtibpq.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\cvesww.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\mfcja32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\jzjayl.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\ldcxlr.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\sdkei32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\hueiwf.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\ifwfrl.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\netmn32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\byspkv.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\vbkmxb.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\ntyg.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\enlbhj.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\yzwxcq.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\kuhffe.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\lfabak.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\msek32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\kwekcr.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\lzpgpy.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\iees.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\wxkplv.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\grplpf.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\on-line.exe -> TrojanDropper.Crutop.a -> Cleaned with backup
C:\WINDOWS\eyxojc.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\mdciqi.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\jmitlw.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\msuz.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\nhnedo.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\claucs.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\cdzutp.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\egsqgw.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\ipns32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\ijqxzq.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\huiakl.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\appvd32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\jdvdyx.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\kofzle.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\sdkgi.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\fvkuia.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\ggdrvg.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\javaga32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\gktvdi.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\znerxp.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\addxh.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\sjddxo.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\lnvakv.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\sysgh32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\xqghwj.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\ytreiq.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\rdqita.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\sgbegh.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\mswe32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\mskj32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\winpo32.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\WINDOWS\eqcqnx.dat -> Trojan.Feat -> Cleaned with backup
C:\WINDOWS\ftnmae.dat -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\crfx.exe -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\WINDOWS\nettz32.exe -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP36\A0007109.exe -> TrojanDropper.Small.ja -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP40\A0010797.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP42\A0010828.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP43\A0010833.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP44\A0010870.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP44\A0011867.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP44\A0011885.exe -> Trojan.Agent.bi -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP44\A0011899.dll -> TrojanDropper.Small.tn -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP44\A0011918.dll -> Trojan.Feat -> Cleaned with backup
C:\System Volume Information\_restore{D7EF6DE3-119E-4422-A20F-925C00F0B878}\RP44\A0011928.exe -> TrojanDownloader.Agent.bq -> Cleaned with backup
C:\msx.exe -> TrojanDropper.Small.ja -> Cleaned with backup
C:\ms32.tmp -> TrojanDownloader.Small -> Cleaned with backup
C:\hjt\backups\backup-20050514-144308-940.dll -> Trojan.Feat -> Cleaned with backup
::Report End