Here ya go i think we got it under control
Logfile of HijackThis v1.99.1
Scan saved at 12:07:16 AM, on 05/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\System32\Ati2evxx.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\Ati2evxx.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
F:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
F:\Program Files\D-Tools\daemon.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\Microsoft AntiSpyware\gcasServ.exe
F:\Program Files\Executive Software\Diskeeper\DkService.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\MSN Messenger\MsnMsgr.Exe
F:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
F:\Program Files\ewido\security suite\ewidoctrl.exe
F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
F:\Program Files\ewido\security suite\ewidoguard.exe
F:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
F:\WINDOWS\system32\wscntfy.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
F:\WINDOWS\system32\wuauclt.exe
F:\hjt\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
http://localhost:9100/proxy.pacO2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - F:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - F:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - F:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [ATIPTA] F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "F:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [gcasServ] "F:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [CloneCDTray] "F:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [WinampAgent] F:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "F:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Run Google Web Accelerator.lnk = F:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....467&clcid=0x409O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) -
https://support.micr...ActiveX/odc.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1112527199609O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - F:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - F:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - F:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - F:\Program Files\ewido\security suite\ewidoguard.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 11:48:36 PM, 04/06/2005
+ Report-Checksum: 5E8B0AB7
+ Date of database: 05/06/2005
+ Version of scan engine: v3.0
+ Duration: 81 min
+ Scanned Files: 151673
+ Speed: 31.08 Files/Second
+ Infected files: 70
+ Removed files: 70
+ Files put in quarantine: 70
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
F:\
H:\
+ Scan result:
F:\Documents and Settings\Chris\Cookies\chris@66693905[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@atdmt[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@bfast[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@bluestreak[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@cgi-bin[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@clickagents[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@fastclick[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@geocities[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@hitbox[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@linksynergy[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@mediaplex[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@realmedia[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@targetnet[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\chris@valueclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Chris\Local Settings\Temp\DHK\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
F:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Documents and Settings\Guest\Cookies\guest@realmedia[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\06049FE0-C165-4349-9590-59C89E\7FB73668-6999-48D7-B36D-3F87E7 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\0F0046C0-2602-47EE-B9E7-51ACA8\44DF8557-0308-4D17-A4D6-6C0511 -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\1C0AFCFD-9BDD-437E-A897-D185EB\3F57021F-F1F9-4A77-86A6-B6728B -> TrojanDownloader.IstBar -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\25170CDB-EE6C-4050-8D63-7F5B37\15B5F929-59D1-4AA3-95F5-F18DE7 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\25170CDB-EE6C-4050-8D63-7F5B37\624EDBD6-0DC0-4573-83BB-FEF285 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\25170CDB-EE6C-4050-8D63-7F5B37\79C152B0-D193-489A-88AD-1CFBFE -> Spyware.BetterInternet.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\255DBF0F-70EB-4EA5-A466-34B24F\B518EA6F-6996-40A1-BB95-F49EAC -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\35F02150-C9AF-46BB-900C-4CAA10\B2C7AF7D-D63D-48FF-A755-C09992 -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\35F02150-C9AF-46BB-900C-4CAA10\C0BF62B9-82E4-492F-84C7-A62846 -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\3C7F4CEA-EBF2-4BA0-AE46-9FDD30\0B86E7C3-35F9-46F0-8FFD-1F4A1F -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\407A86E6-2FBB-4810-9B48-E5C0B9\1441BB31-4F14-4A40-829F-690597 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\41CDE835-3F31-40AE-855F-39477F\692A71C5-3D15-4E4C-92BD-AC69CA -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\41CDE835-3F31-40AE-855F-39477F\BC69B9C3-14E3-43E7-83CF-B00BF6 -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\5D09FA91-1615-4CC6-B3E1-4889D9\E9F924D2-96AF-4A05-A06F-3885DF -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\61BCB238-CE23-4406-AF0D-741031\B9E21426-4929-4745-B256-154BD3 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\629A0420-63DB-4D6C-AF2F-D24045\12811E63-0A21-4DDB-9727-2D4FF1 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\6DDC6114-C063-4A25-8916-C06CE0\A61D3FF5-F99C-43F8-A556-DB8DCC -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\6F201BB1-7D90-4150-A3EB-AE10B0\13669C7D-6718-4641-BD7E-46DD20 -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\6F201BB1-7D90-4150-A3EB-AE10B0\5D185452-08EB-4711-9453-C71CA1 -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\7C7ACE4A-8F50-4C86-A6F3-EBBE0A\430EAF18-FF80-4798-988E-E824F6 -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\7CB41036-F96C-4890-A5F1-4A2C8E\ACD3EB5C-C3C7-4C9B-8B28-76680D -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\81131594-52D8-462D-8730-3B61DF\B12C8FDB-73AB-4119-A93A-FD6410 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\88E936F2-91DD-40BA-A3C2-57725C\A6EDB35E-082D-4242-9982-E3AEA8 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\9376F6BE-74B4-4A67-AEED-408441\FEFD55D1-B901-4380-AEF4-E7216F -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\A439AEB1-B4A4-4C0B-B34C-861A14\BE774561-00F7-4A2C-BD49-A2D941 -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\A75F680A-A36C-4266-AEE8-1103D8\7E3E2BD7-188B-4265-A810-62ECB8 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\A75F680A-A36C-4266-AEE8-1103D8\B7DE67B7-997C-46D4-8BEA-3FBA3A -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\A75F680A-A36C-4266-AEE8-1103D8\F8394EF8-8536-464C-A92D-EDC35E -> Spyware.BetterInternet.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\AC715F17-7139-4778-9B52-41F288\C3212692-602C-4F0D-8D7C-9ADA9E -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\C66EA343-67F6-4726-B13A-87FCFE\CCA66CB4-AEDD-4F5B-94DC-1D733D -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\C66EA343-67F6-4726-B13A-87FCFE\FB39D67B-8383-46F1-9B23-EA1CD2 -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\C9F9BE5E-D3AE-439F-8A59-D39F1E\FC8C242B-692C-4394-9024-0D094C -> Trojan.Agent.db -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\D544343B-AC2C-4641-81A1-0C57D4\651AAD32-B035-43FD-AA4C-38EB0E -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\D85D9471-A1CF-48CA-A6F5-22875F\1EDAA944-54CA-48CC-9F56-F369BB -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\D85D9471-A1CF-48CA-A6F5-22875F\9484158F-5E07-43BB-AF8E-839872 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\D85D9471-A1CF-48CA-A6F5-22875F\D921CEC5-F386-433C-AC76-3BEEC1 -> Spyware.BetterInternet.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\F070EFE4-8A8C-4349-80FA-8CE9F6\21AF5838-1C26-4269-9F0D-923AA2 -> Trojan.Stervis.c -> Cleaned with backup
F:\Program Files\Microsoft AntiSpyware\Quarantine\FC53DBB0-4955-448E-8BB6-270D0C\76B562CC-B671-418B-BD69-C75B09 -> Trojan.Agent.db -> Cleaned with backup
F:\WINDOWS\system32\qesrhbu.exe -> Trojan.Agent.cp -> Cleaned with backup
F:\WINDOWS\znpkrrpdz.exe -> Spyware.BetterInternet -> Cleaned with backup
::Report End
Thanks Again!