Ok. I did the all the steps and everything worked fine. So here is the new hijack log and the ewido report.
Logfile of HijackThis v1.99.1
Scan saved at 16:07:17, on 21.4.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\Program Files\ewido\security suite\ewidoctrl.exe
D:\Program Files\ewido\security suite\ewidoguard.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://searchmiracle.com/sp.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://searchmiracle.com/sp.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://searchmiracle.com/sp.phpR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.rahina.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://searchmiracle.com/sp.phpR3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - D:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll (file missing)
O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - D:\WINDOWS\EliteSideBar\EliteSideBar 08.dll (file missing)
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ajV7R] D:\WINDOWS\xkmtwp.exe
O4 - HKLM\..\Run: [ajV÷h$vùõš/‚²‘ÆßfÏD:\Program Files\ISTsvc\istsvc.exe] D:\WINDOWS\xkmtwp.exe
O4 - HKLM\..\Run: [Á³# é"h'þ9ÓœU3rŲWD:\Program Files\ISTsvc\istsvc.exe] D:\WINDOWS\xkmtwp.exe
O4 - HKLM\..\Run: [ASDPLUGIN] D:\WINDOWS\system32\finland.exe -N
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [etbrun] D:\windows\system32\eliteysz32.exe
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - D:\Program Files\SideFind\sidefind.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://ny.contentmatch.net (HKLM)
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) -
http://www.xxxtoolba...006_regular.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cabO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - D:\Program Files\ewido\security suite\ewidoguard.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 15:30:59, 21.4.2004
+ Report-Checksum: B03F9D97
+ Date of database: 21.4.2004
+ Version of scan engine: v3.0
+ Duration: 17 min
+ Scanned Files: 26489
+ Speed: 24.84 Files/Second
+ Infected files: 28
+ Removed files: 28
+ Files put in quarantine: 28
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
D:\
+ Scan result:
C:\System Volume Information\_restore{FF9F3E23-5FF8-43B4-A22A-E7A29546241B}\RP77\A0006990.exe -> TrojanDropper.PurityScan.g -> Cleaned with backup
C:\System Volume Information\_restore{FF9F3E23-5FF8-43B4-A22A-E7A29546241B}\RP77\A0007013.exe -> Spyware.WinAD.ab -> Cleaned with backup
C:\System Volume Information\_restore{FF9F3E23-5FF8-43B4-A22A-E7A29546241B}\RP85\A0007095.exe -> TrojanDropper.PurityScan.g -> Cleaned with backup
C:\System Volume Information\_restore{FF9F3E23-5FF8-43B4-A22A-E7A29546241B}\RP99\A0012212.exe -> TrojanDropper.PurityScan.g -> Cleaned with backup
C:\m1.exe -> TrojanDropper.PurityScan.g -> Cleaned with backup
C:\lc.exe -> Spyware.WinAD.ab -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@34419056[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@cgi-bin[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@exitexchange[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@fastclick[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@geocities[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@linkexchange[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@realmedia[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@tradedoubler[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@tribalfusion[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\mikko@xiti[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\mikko\Local Settings\Temp\djtopr1150.exe -> Spyware.TopMoxie -> Cleaned with backup
D:\Documents and Settings\mikko\Local Settings\Temp\jkill.exe -> Spyware.VX2 -> Cleaned with backup
D:\Documents and Settings\mikko\Local Settings\Temp\uninstall.exe -> Spyware.EliteBar.q -> Cleaned with backup
D:\temp\salmhook.dll -> Spyware.180solutions -> Cleaned with backup
D:\WINDOWS\EliteSideBar\EliteSideBar 08.dll -> Spyware.EliteBar.z -> Cleaned with backup
D:\WINDOWS\system32\ide21201.vxd -> Spyware.MediaPass -> Cleaned with backup
::Report End