Hi loophole,
Thanks again. I got everything right. I just got this ewido alert pop up all the time to clean one trojan, but when I click OK it wants to reboot. However, after restart it pops up again.
I am posting 3 logs. (HJT, About:buster and ewido)
Logfile of HijackThis v1.99.1
Scan saved at 3:33:01 PM, on 5/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\unzipped\hijackthis\HijackThis.exe
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {5BB66F6F-6BA4-ED53-05F3-F6ED2C204BED} - C:\WINDOWS\crnm32.dll
O2 - BHO: Class - {61F55B99-6BD7-C8CA-0AB9-97CFED9C0C6D} - C:\WINDOWS\crum.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Class - {CF3EF571-43E7-5C38-FDC9-6E168AF22B5A} - C:\WINDOWS\system32\netzi32.dll
O2 - BHO: Class - {F0FEAC69-B908-0A98-E707-86A79716D60E} - C:\WINDOWS\addvr32.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\WINDOWS\Downloaded Program Files\ycomp5_1_2_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [3Dlabs Taskbar Display Manager] C:\WINDOWS\System32\3DLman.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [*cabc] C:\WINDOWS\java\classes\cabc.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [crex32.exe] C:\WINDOWS\system32\crex32.exe
O4 - HKLM\..\Run: [w3oX3EW] ntknst.exe
O4 - HKLM\..\Run: [appgs.exe] C:\WINDOWS\system32\appgs.exe
O4 - HKLM\..\RunOnce: [appic.exe] C:\WINDOWS\system32\appic.exe
O4 - HKLM\..\RunOnce: [netwu32.exe] C:\WINDOWS\system32\netwu32.exe
O4 - HKLM\..\RunOnce: [sdkop.exe] C:\WINDOWS\system32\sdkop.exe
O4 - HKLM\..\RunOnce: [apibs32.exe] C:\WINDOWS\apibs32.exe
O4 - HKLM\..\RunOnce: [appsp32.exe] C:\WINDOWS\appsp32.exe
O4 - HKLM\..\RunOnce: [atlaw32.exe] C:\WINDOWS\atlaw32.exe
O4 - HKLM\..\RunOnce: [addhf32.exe] C:\WINDOWS\system32\addhf32.exe
O4 - HKLM\..\RunOnce: [ntwu32.exe] C:\WINDOWS\system32\ntwu32.exe
O4 - HKLM\..\RunOnce: [d3rx.exe] C:\WINDOWS\system32\d3rx.exe
O4 - HKLM\..\RunOnce: [javayy32.exe] C:\WINDOWS\system32\javayy32.exe
O4 - HKLM\..\RunOnce: [apitd.exe] C:\WINDOWS\apitd.exe
O4 - HKLM\..\RunOnce: [msut32.exe] C:\WINDOWS\msut32.exe
O4 - HKLM\..\RunOnce: [mfcqy32.exe] C:\WINDOWS\mfcqy32.exe
O4 - HKLM\..\RunOnce: [sysqw.exe] C:\WINDOWS\sysqw.exe
O4 - HKLM\..\RunOnce: [ipwd.exe] C:\WINDOWS\system32\ipwd.exe
O4 - HKLM\..\RunOnce: [atltx.exe] C:\WINDOWS\system32\atltx.exe
O4 - HKLM\..\RunOnce: [crrl.exe] C:\WINDOWS\crrl.exe
O4 - HKLM\..\RunOnce: [sdknn32.exe] C:\WINDOWS\system32\sdknn32.exe
O4 - HKLM\..\RunOnce: [mfckt.exe] C:\WINDOWS\mfckt.exe
O4 - HKLM\..\RunOnce: [syspl.exe] C:\WINDOWS\system32\syspl.exe
O4 - HKLM\..\RunOnce: [ntkv32.exe] C:\WINDOWS\ntkv32.exe
O4 - HKLM\..\RunOnce: [wined.exe] C:\WINDOWS\wined.exe
O4 - HKLM\..\RunOnce: [mfcvg32.exe] C:\WINDOWS\system32\mfcvg32.exe
O4 - HKLM\..\RunOnce: [iegj.exe] C:\WINDOWS\system32\iegj.exe
O4 - HKLM\..\RunOnce: [appuz.exe] C:\WINDOWS\appuz.exe
O4 - HKLM\..\RunOnce: [apiud.exe] C:\WINDOWS\system32\apiud.exe
O4 - HKLM\..\RunOnce: [ntwf32.exe] C:\WINDOWS\ntwf32.exe
O4 - HKLM\..\RunOnce: [apilr.exe] C:\WINDOWS\apilr.exe
O4 - HKLM\..\RunOnce: [javazd.exe] C:\WINDOWS\javazd.exe
O4 - HKLM\..\RunOnce: [ntrc.exe] C:\WINDOWS\ntrc.exe
O4 - HKLM\..\RunOnce: [winpc.exe] C:\WINDOWS\winpc.exe
O4 - HKLM\..\RunOnce: [netkm.exe] C:\WINDOWS\system32\netkm.exe
O4 - HKLM\..\RunOnce: [mfcov.exe] C:\WINDOWS\mfcov.exe
O4 - HKLM\..\RunOnce: [netfn32.exe] C:\WINDOWS\system32\netfn32.exe
O4 - HKLM\..\RunOnce: [apipj.exe] C:\WINDOWS\apipj.exe
O4 - HKLM\..\RunOnce: [crfe32.exe] C:\WINDOWS\system32\crfe32.exe
O4 - HKLM\..\RunOnce: [mfctz32.exe] C:\WINDOWS\system32\mfctz32.exe
O4 - HKLM\..\RunOnce: [iekq.exe] C:\WINDOWS\system32\iekq.exe
O4 - HKLM\..\RunOnce: [ieff.exe] C:\WINDOWS\system32\ieff.exe
O4 - HKLM\..\RunOnce: [javaet.exe] C:\WINDOWS\javaet.exe
O4 - HKLM\..\RunOnce: [addia32.exe] C:\WINDOWS\system32\addia32.exe
O4 - HKLM\..\RunOnce: [addfj.exe] C:\WINDOWS\addfj.exe
O4 - HKLM\..\RunOnce: [netsr32.exe] C:\WINDOWS\system32\netsr32.exe
O4 - HKLM\..\RunOnce: [winwk.exe] C:\WINDOWS\system32\winwk.exe
O4 - HKLM\..\RunOnce: [appdu32.exe] C:\WINDOWS\appdu32.exe
O4 - HKLM\..\RunOnce: [ipkt32.exe] C:\WINDOWS\ipkt32.exe
O4 - HKLM\..\RunOnce: [iend32.exe] C:\WINDOWS\iend32.exe
O4 - HKLM\..\RunOnce: [atlmw32.exe] C:\WINDOWS\system32\atlmw32.exe
O4 - HKLM\..\RunOnce: [mfcmj32.exe] C:\WINDOWS\mfcmj32.exe
O4 - HKLM\..\RunOnce: [atlyz32.exe] C:\WINDOWS\system32\atlyz32.exe
O4 - HKLM\..\RunOnce: [apiki32.exe] C:\WINDOWS\system32\apiki32.exe
O4 - HKLM\..\RunOnce: [iebc32.exe] C:\WINDOWS\iebc32.exe
O4 - HKLM\..\RunOnce: [sysvl32.exe] C:\WINDOWS\sysvl32.exe
O4 - HKLM\..\RunOnce: [sdkyg32.exe] C:\WINDOWS\system32\sdkyg32.exe
O4 - HKLM\..\RunOnce: [mfcdq32.exe] C:\WINDOWS\mfcdq32.exe
O4 - HKLM\..\RunOnce: [apimc.exe] C:\WINDOWS\system32\apimc.exe
O4 - HKLM\..\RunOnce: [ipae32.exe] C:\WINDOWS\system32\ipae32.exe
O4 - HKLM\..\RunOnce: [addct32.exe] C:\WINDOWS\system32\addct32.exe
O4 - HKLM\..\RunOnce: [apiqj32.exe] C:\WINDOWS\apiqj32.exe
O4 - HKLM\..\RunOnce: [netzv.exe] C:\WINDOWS\netzv.exe
O4 - HKLM\..\RunOnce: [mfcwq.exe] C:\WINDOWS\mfcwq.exe
O4 - HKLM\..\RunOnce: [crbw.exe] C:\WINDOWS\system32\crbw.exe
O4 - HKLM\..\RunOnce: [appkc32.exe] C:\WINDOWS\system32\appkc32.exe
O4 - HKLM\..\RunOnce: [javaic32.exe] C:\WINDOWS\system32\javaic32.exe
O4 - HKLM\..\RunOnce: [ntsj32.exe] C:\WINDOWS\system32\ntsj32.exe
O4 - HKLM\..\RunOnce: [ievs32.exe] C:\WINDOWS\ievs32.exe
O4 - HKLM\..\RunOnce: [javaox32.exe] C:\WINDOWS\system32\javaox32.exe
O4 - HKLM\..\RunOnce: [sysnk.exe] C:\WINDOWS\system32\sysnk.exe
O4 - HKLM\..\RunOnce: [crmw.exe] C:\WINDOWS\crmw.exe
O4 - HKLM\..\RunOnce: [apiov32.exe] C:\WINDOWS\apiov32.exe
O4 - HKLM\..\RunOnce: [javaom.exe] C:\WINDOWS\javaom.exe
O4 - HKLM\..\RunOnce: [mfcwx.exe] C:\WINDOWS\system32\mfcwx.exe
O4 - HKLM\..\RunOnce: [addah32.exe] C:\WINDOWS\system32\addah32.exe
O4 - HKLM\..\RunOnce: [addsl32.exe] C:\WINDOWS\system32\addsl32.exe
O4 - HKLM\..\RunOnce: [mfcck.exe] C:\WINDOWS\system32\mfcck.exe
O4 - HKLM\..\RunOnce: [mfcpx.exe] C:\WINDOWS\system32\mfcpx.exe
O4 - HKLM\..\RunOnce: [javatn32.exe] C:\WINDOWS\system32\javatn32.exe
O4 - HKLM\..\RunOnce: [crqn.exe] C:\WINDOWS\crqn.exe
O4 - HKLM\..\RunOnce: [ntau.exe] C:\WINDOWS\ntau.exe
O4 - HKLM\..\RunOnce: [winyu.exe] C:\WINDOWS\winyu.exe
O4 - HKLM\..\RunOnce: [addgy32.exe] C:\WINDOWS\system32\addgy32.exe
O4 - HKLM\..\RunOnce: [javapc32.exe] C:\WINDOWS\javapc32.exe
O4 - HKLM\..\RunOnce: [msvm32.exe] C:\WINDOWS\msvm32.exe
O4 - HKLM\..\RunOnce: [mshi32.exe] C:\WINDOWS\mshi32.exe
O4 - HKLM\..\RunOnce: [ienu32.exe] C:\WINDOWS\system32\ienu32.exe
O4 - HKLM\..\RunOnce: [crac32.exe] C:\WINDOWS\crac32.exe
O4 - HKLM\..\RunOnce: [winka32.exe] C:\WINDOWS\system32\winka32.exe
O4 - HKLM\..\RunOnce: [ieiv.exe] C:\WINDOWS\system32\ieiv.exe
O4 - HKLM\..\RunOnce: [addnv.exe] C:\WINDOWS\addnv.exe
O4 - HKLM\..\RunOnce: [winrf32.exe] C:\WINDOWS\system32\winrf32.exe
O4 - HKLM\..\RunOnce: [mskj.exe] C:\WINDOWS\mskj.exe
O4 - HKLM\..\RunOnce: [crze.exe] C:\WINDOWS\crze.exe
O4 - HKLM\..\RunOnce: [appmk.exe] C:\WINDOWS\appmk.exe
O4 - HKLM\..\RunOnce: [sdkvq32.exe] C:\WINDOWS\sdkvq32.exe
O4 - HKLM\..\RunOnce: [addkr32.exe] C:\WINDOWS\addkr32.exe
O4 - HKLM\..\RunOnce: [syscp.exe] C:\WINDOWS\system32\syscp.exe
O4 - HKLM\..\RunOnce: [sdkci32.exe] C:\WINDOWS\system32\sdkci32.exe
O4 - HKLM\..\RunOnce: [applo.exe] C:\WINDOWS\applo.exe
O4 - HKLM\..\RunOnce: [javagy32.exe] C:\WINDOWS\system32\javagy32.exe
O4 - HKLM\..\RunOnce: [apioj32.exe] C:\WINDOWS\system32\apioj32.exe
O4 - HKLM\..\RunOnce: [javayi.exe] C:\WINDOWS\javayi.exe
O4 - HKLM\..\RunOnce: [appbx32.exe] C:\WINDOWS\appbx32.exe
O4 - HKLM\..\RunOnce: [iezk32.exe] C:\WINDOWS\system32\iezk32.exe
O4 - HKLM\..\RunOnce: [d3so.exe] C:\WINDOWS\system32\d3so.exe
O4 - HKLM\..\RunOnce: [javaik.exe] C:\WINDOWS\system32\javaik.exe
O4 - HKLM\..\RunOnce: [d3cb.exe] C:\WINDOWS\system32\d3cb.exe
O4 - HKLM\..\RunOnce: [addux.exe] C:\WINDOWS\addux.exe
O4 - HKLM\..\RunOnce: [ntdv32.exe] C:\WINDOWS\ntdv32.exe
O4 - HKLM\..\RunOnce: [atlga.exe] C:\WINDOWS\system32\atlga.exe
O4 - HKLM\..\RunOnce: [apixy.exe] C:\WINDOWS\system32\apixy.exe
O4 - HKLM\..\RunOnce: [wincs32.exe] C:\WINDOWS\system32\wincs32.exe
O4 - HKLM\..\RunOnce: [mfcbn.exe] C:\WINDOWS\system32\mfcbn.exe
O4 - HKLM\..\RunOnce: [winuk32.exe] C:\WINDOWS\winuk32.exe
O4 - HKLM\..\RunOnce: [apizc32.exe] C:\WINDOWS\apizc32.exe
O4 - HKLM\..\RunOnce: [appmj32.exe] C:\WINDOWS\system32\appmj32.exe
O4 - HKLM\..\RunOnce: [ipwa32.exe] C:\WINDOWS\ipwa32.exe
O4 - HKLM\..\RunOnce: [msom.exe] C:\WINDOWS\system32\msom.exe
O4 - HKLM\..\RunOnce: [mfcsw32.exe] C:\WINDOWS\mfcsw32.exe
O4 - HKLM\..\RunOnce: [appnx.exe] C:\WINDOWS\system32\appnx.exe
O4 - HKLM\..\RunOnce: [ipgu.exe] C:\WINDOWS\ipgu.exe
O4 - HKLM\..\RunOnce: [winuw.exe] C:\WINDOWS\system32\winuw.exe
O4 - HKLM\..\RunOnce: [ipdc32.exe] C:\WINDOWS\system32\ipdc32.exe
O4 - HKLM\..\RunOnce: [appdq.exe] C:\WINDOWS\system32\appdq.exe
O4 - HKLM\..\RunOnce: [msik32.exe] C:\WINDOWS\system32\msik32.exe
O4 - HKLM\..\RunOnce: [d3ot.exe] C:\WINDOWS\system32\d3ot.exe
O4 - HKLM\..\RunOnce: [nettv32.exe] C:\WINDOWS\system32\nettv32.exe
O4 - HKLM\..\RunOnce: [crdo32.exe] C:\WINDOWS\crdo32.exe
O4 - HKLM\..\RunOnce: [netiq32.exe] C:\WINDOWS\netiq32.exe
O4 - HKLM\..\RunOnce: [apixf.exe] C:\WINDOWS\system32\apixf.exe
O4 - HKLM\..\RunOnce: [crpb32.exe] C:\WINDOWS\crpb32.exe
O4 - HKLM\..\RunOnce: [winut32.exe] C:\WINDOWS\system32\winut32.exe
O4 - HKLM\..\RunOnce: [mszb.exe] C:\WINDOWS\mszb.exe
O4 - HKLM\..\RunOnce: [ipmv32.exe] C:\WINDOWS\ipmv32.exe
O4 - HKLM\..\RunOnce: [crsi32.exe] C:\WINDOWS\system32\crsi32.exe
O4 - HKLM\..\RunOnce: [mfcag.exe] C:\WINDOWS\mfcag.exe
O4 - HKLM\..\RunOnce: [iedb.exe] C:\WINDOWS\system32\iedb.exe
O4 - HKLM\..\RunOnce: [sdkcr32.exe] C:\WINDOWS\system32\sdkcr32.exe
O4 - HKLM\..\RunOnce: [atlhl.exe] C:\WINDOWS\system32\atlhl.exe
O4 - HKLM\..\RunOnce: [iejo32.exe] C:\WINDOWS\system32\iejo32.exe
O4 - HKLM\..\RunOnce: [atlcl.exe] C:\WINDOWS\system32\atlcl.exe
O4 - HKLM\..\RunOnce: [ipgw.exe] C:\WINDOWS\ipgw.exe
O4 - HKLM\..\RunOnce: [javayw32.exe] C:\WINDOWS\system32\javayw32.exe
O4 - HKLM\..\RunOnce: [winfh32.exe] C:\WINDOWS\winfh32.exe
O4 - HKLM\..\RunOnce: [sdkuh.exe] C:\WINDOWS\system32\sdkuh.exe
O4 - HKLM\..\RunOnce: [ntbg32.exe] C:\WINDOWS\system32\ntbg32.exe
O4 - HKLM\..\RunOnce: [d3zt.exe] C:\WINDOWS\system32\d3zt.exe
O4 - HKLM\..\RunOnce: [ntty.exe] C:\WINDOWS\ntty.exe
O4 - HKLM\..\RunOnce: [sysav32.exe] C:\WINDOWS\system32\sysav32.exe
O4 - HKLM\..\RunOnce: [mfcyq.exe] C:\WINDOWS\system32\mfcyq.exe
O4 - HKLM\..\RunOnce: [ntds.exe] C:\WINDOWS\system32\ntds.exe
O4 - HKLM\..\RunOnce: [addrs32.exe] C:\WINDOWS\addrs32.exe
O4 - HKLM\..\RunOnce: [sysnu32.exe] C:\WINDOWS\system32\sysnu32.exe
O4 - HKLM\..\RunOnce: [msep32.exe] C:\WINDOWS\msep32.exe
O4 - HKLM\..\RunOnce: [addxj32.exe] C:\WINDOWS\addxj32.exe
O4 - HKLM\..\RunOnce: [addbe.exe] C:\WINDOWS\system32\addbe.exe
O4 - HKLM\..\RunOnce: [javaeu32.exe] C:\WINDOWS\javaeu32.exe
O4 - HKLM\..\RunOnce: [apinl.exe] C:\WINDOWS\system32\apinl.exe
O4 - HKLM\..\RunOnce: [mske.exe] C:\WINDOWS\mske.exe
O4 - HKLM\..\RunOnce: [apihe32.exe] C:\WINDOWS\apihe32.exe
O4 - HKLM\..\RunOnce: [nettx.exe] C:\WINDOWS\nettx.exe
O4 - HKLM\..\RunOnce: [appsa32.exe] C:\WINDOWS\system32\appsa32.exe
O4 - HKLM\..\RunOnce: [javaih32.exe] C:\WINDOWS\javaih32.exe
O4 - HKLM\..\RunOnce: [netqq.exe] C:\WINDOWS\system32\netqq.exe
O4 - HKLM\..\RunOnce: [d3oj.exe] C:\WINDOWS\system32\d3oj.exe
O4 - HKLM\..\RunOnce: [javaee.exe] C:\WINDOWS\system32\javaee.exe
O4 - HKLM\..\RunOnce: [apixv.exe] C:\WINDOWS\system32\apixv.exe
O4 - HKLM\..\RunOnce: [javafo32.exe] C:\WINDOWS\system32\javafo32.exe
O4 - HKLM\..\RunOnce: [ipzr.exe] C:\WINDOWS\system32\ipzr.exe
O4 - HKLM\..\RunOnce: [javawd32.exe] C:\WINDOWS\system32\javawd32.exe
O4 - HKLM\..\RunOnce: [appyz32.exe] C:\WINDOWS\system32\appyz32.exe
O4 - HKLM\..\RunOnce: [javauu32.exe] C:\WINDOWS\javauu32.exe
O4 - HKLM\..\RunOnce: [sdkdt32.exe] C:\WINDOWS\system32\sdkdt32.exe
O4 - HKLM\..\RunOnce: [ieic32.exe] C:\WINDOWS\system32\ieic32.exe
O4 - HKLM\..\RunOnce: [sysqq32.exe] C:\WINDOWS\system32\sysqq32.exe
O4 - HKLM\..\RunOnce: [ieug32.exe] C:\WINDOWS\ieug32.exe
O4 - HKLM\..\RunOnce: [ntry.exe] C:\WINDOWS\system32\ntry.exe
O4 - HKLM\..\RunOnce: [ipak.exe] C:\WINDOWS\ipak.exe
O4 - HKLM\..\RunOnce: [winau.exe] C:\WINDOWS\winau.exe
O4 - HKLM\..\RunOnce: [ieyn32.exe] C:\WINDOWS\ieyn32.exe
O4 - HKLM\..\RunOnce: [ipmq.exe] C:\WINDOWS\ipmq.exe
O4 - HKLM\..\RunOnce: [ievw32.exe] C:\WINDOWS\system32\ievw32.exe
O4 - HKLM\..\RunOnce: [sdkaq32.exe] C:\WINDOWS\sdkaq32.exe
O4 - HKLM\..\RunOnce: [d3fu.exe] C:\WINDOWS\system32\d3fu.exe
O4 - HKLM\..\RunOnce: [appje.exe] C:\WINDOWS\system32\appje.exe
O4 - HKLM\..\RunOnce: [iexk.exe] C:\WINDOWS\system32\iexk.exe
O4 - HKLM\..\RunOnce: [appvf32.exe] C:\WINDOWS\system32\appvf32.exe
O4 - HKLM\..\RunOnce: [ipah32.exe] C:\WINDOWS\system32\ipah32.exe
O4 - HKLM\..\RunOnce: [msep.exe] C:\WINDOWS\system32\msep.exe
O4 - HKLM\..\RunOnce: [sdkdc.exe] C:\WINDOWS\sdkdc.exe
O4 - HKLM\..\RunOnce: [apibp.exe] C:\WINDOWS\system32\apibp.exe
O4 - HKLM\..\RunOnce: [addad32.exe] C:\WINDOWS\addad32.exe
O4 - HKLM\..\RunOnce: [apitz.exe] C:\WINDOWS\system32\apitz.exe
O4 - HKLM\..\RunOnce: [d3df32.exe] C:\WINDOWS\system32\d3df32.exe
O4 - HKLM\..\RunOnce: [javanm.exe] C:\WINDOWS\system32\javanm.exe
O4 - HKLM\..\RunOnce: [winqv.exe] C:\WINDOWS\winqv.exe
O4 - HKLM\..\RunOnce: [ieuf.exe] C:\WINDOWS\system32\ieuf.exe
O4 - HKLM\..\RunOnce: [javask.exe] C:\WINDOWS\javask.exe
O4 - HKLM\..\RunOnce: [ntdp.exe] C:\WINDOWS\ntdp.exe
O4 - HKLM\..\RunOnce: [d3vq.exe] C:\WINDOWS\system32\d3vq.exe
O4 - HKLM\..\RunOnce: [javave.exe] C:\WINDOWS\system32\javave.exe
O4 - HKLM\..\RunOnce: [appno32.exe] C:\WINDOWS\system32\appno32.exe
O4 - HKLM\..\RunOnce: [winjy.exe] C:\WINDOWS\winjy.exe
O4 - HKLM\..\RunOnce: [addsj32.exe] C:\WINDOWS\addsj32.exe
O4 - HKLM\..\RunOnce: [ielm.exe] C:\WINDOWS\ielm.exe
O4 - HKLM\..\RunOnce: [ntoy.exe] C:\WINDOWS\system32\ntoy.exe
O4 - HKLM\..\RunOnce: [d3ce32.exe] C:\WINDOWS\system32\d3ce32.exe
O4 - HKLM\..\RunOnce: [addiy.exe] C:\WINDOWS\addiy.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [h077ROa6W] newend.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.../kavwebscan.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...meInstaller.exeO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.r...ip/RdxIE601.cabO16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
http://us.dl1.yimg.c.../yse/ymmapi.dllO16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) -
http://us.dl1.yimg.c...ebio5_1_2_0.cabO20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\netff.exe" /s (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
Scanned at: 3:06:15 PM on: 5/31/2005
-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 26
Removed Data Streams:
C:\WINDOWS\AMS2INST.LOG:lchdn
Removed 2 Random Key Entries
Removed! : C:\WINDOWS\rbmdu.dat
Removed! : C:\WINDOWS\system32\dqxrb.dat
Removed! : C:\WINDOWS\system32\hhbhq.dat
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 26
Removed Data Streams:
C:\WINDOWS\AMS2INST.LOG:lchdn
Attempted Clean Of Temp folder.
Pages Reset... Done!
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 7:06:43 PM, 5/31/2005
+ Report-Checksum: C17A3FFB
+ Date of database: 5/31/2005
+ Version of scan engine: v3.0
+ Duration: 104 min
+ Scanned Files: 69391
+ Speed: 11.07 Files/Second
+ Infected files: 87
+ Removed files: 87
+ Files put in quarantine: 87
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
D:\
E:\
F:\
+ Scan result:
C:\WINDOWS\addvr32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\addwx.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\atlax.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\atlxk.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\azqdb.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\bgyrt.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\cqljm.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\crbe32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\crnm32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\crum.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\cxysh.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\dklqh.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\206360.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\WindowsUpd4Container.dll -> TrojanDownloader.Agent.n -> Cleaned with backup
C:\WINDOWS\fsshu.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\WINDOWS\goskh.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\heklu.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\ieia32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\ippe.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\jumvf.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\jwdsm.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\knihi.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\llrgr.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\mfcdc32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\NDNuninstall5_20.exe -> Spyware.NewDotNet -> Cleaned with backup
C:\WINDOWS\NDNuninstall5_48.exe -> Spyware.NewDotNet -> Cleaned with backup
C:\WINDOWS\ovpmz.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\ptptf.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\pxajm.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\rooar.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\safri.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\svncn.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\addfw32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\addgy32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\apimc.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\barnf.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\cgqzr.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\chktrust.exe -> Spyware.Bargainbuddy -> Cleaned with backup
C:\WINDOWS\system32\crkq.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\ctkbd.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\egadm.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\fnwxf.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\fyxus.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\hhlzm.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\hnmif.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\hpjlv.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\HyperLinker3.exe -> Spyware.iSearch -> Cleaned with backup
C:\WINDOWS\system32\hznkv.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\ipfj32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\javaew.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\jcvgm.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\jytwx.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\ksjyq.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\netyf.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\netzi32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\nfkea.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\nmduq.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\qxtsw.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\rawzo.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\rsmyz.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\sdkdp.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\sdkrb32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\sysjq32.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\tdcbs.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\teuej.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\ukpzp.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\unregister.exe -> Spyware.VB.f -> Cleaned with backup
C:\WINDOWS\system32\viikx.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\system32\wined.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\winpa.dll -> TrojanDownloader.Agent.bc -> Cleaned with backup
C:\WINDOWS\system32\zhogc.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\tamad.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\tmuub.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\txkqb.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\ubeae.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\vchza.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\vmrdn.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\WINDOWS\vzifs.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\wapil.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\wdgtl.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\wggwm.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\wgtnm.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\wxgio.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\xcptn.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\WINDOWS\xirsr.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\yencw.dll -> Spyware.SearchPage -> Cleaned with backup
C:\WINDOWS\zbrlp.dll -> Spyware.SearchPage -> Cleaned with backup
::Report End