---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 18:14:23, 8/6/2548
+ Report-Checksum: 8E07424F
+ Date of database: 8/6/2548
+ Version of scan engine: v3.0
+ Duration: 165 min
+ Scanned Files: 77686
+ Speed: 7.80 Files/Second
+ Infected files: 108
+ Removed files: 108
+ Files put in quarantine: 108
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
D:\
+ Scan result:
C:\WINDOWS\SYSTEM32\tksrv98.exe -> TrojanDownloader.Esepor.Q -> Cleaned with backup
C:\WINDOWS\SYSTEM32\tt_reco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\SYSTEM32\zgvexyw.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\WINDOWS\SYSTEM32\exul.exe -> Spyware.BargainBuddy.j -> Cleaned with backup
C:\WINDOWS\SYSTEM32\bbchk.exe -> Spyware.Bargainbuddy -> Cleaned with backup
C:\WINDOWS\SYSTEM32\sysupd1003.exe -> Spyware.Small.an -> Cleaned with backup
C:\WINDOWS\SYSTEM32\DrPMon.dll -> Trojan.Agent.db -> Cleaned with backup
C:\WINDOWS\satmat.exe -> TrojanDownloader.Stubby.d -> Cleaned with backup
C:\WINDOWS\UnstSA2.exe -> Spyware.Delf.r -> Cleaned with backup
C:\WINDOWS\bbchk.exe -> Spyware.Bargainbuddy -> Cleaned with backup
C:\WINDOWS\farmmext.exe -> Spyware.ConsCorr -> Cleaned with backup
C:\WINDOWS\svcproc.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\WINDOWS\Nail.exe -> Trojan.Nail -> Cleaned with backup
C:\WINDOWS\asjktcwksnq.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Program Files\SideFind\sfbho.dll -> Spyware.SideFind -> Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\8,4,2004_10,36,39.zip/powerscan.exe -> Spyware.PowerScan.b -> Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\8,4,2004_10,36,39.zip/istactivex.dll -> TrojanDownloader.Istbar.Gen -> Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\8,4,2004_10,36,39.zip/twaintec.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\8,4,2004_10,36,39.zip/XPlugin.dll -> TrojanDownloader.Esepor.u -> Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\8,4,2004_10,36,39.zip/preinstt.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\8,4,2004_10,36,39.zip/powerscan.exe -> Spyware.PowerScan.b -> Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\8,4,2004_10,36,39.zip/[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,9,2005_11,34,22.zip/preinstt.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preInsTT2.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec3.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preInsTT5.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec6.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preInsTT8.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec9.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preInsTT11.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec12.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec13.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preInsTT14.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec15.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/alchem17.exe -> TrojanDownloader.Alchemic -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/alchem18.exe -> TrojanDownloader.Alchemic -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec137.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preInsTT138.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/alchem139.exe -> TrojanDownloader.Alchemic -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec142.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preInsTT143.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/alchem144.exe -> TrojanDownloader.Alchemic -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec146.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preInsTT147.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec148.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preinstt149.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/twaintec151.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB7D.zip/preInsTT152.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/preinstt1.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/twaintec3.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/preInsTT4.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/preInsTT8.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/twaintec9.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/preInsTT13.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/twaintec14.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/preInsTT16.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/twaintec17.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/preInsTT21.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/twaintec22.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/twaintec26.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/preInsTT27.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/twaintec36.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/twaintec39.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/preInsTT40.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/twaintec42.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB11.zip/preInsTT43.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB12.zip/twaintec1.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB12.zip/preInsTT4.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB12.zip/twaintec6.dll -> Spyware.BiSpy.f -> Cleaned with backup
C:\Program Files\ScanSpyware v3.7\SSBackup\baB12.zip/preInsTT7.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\Documents and Settings\novica7\Cookies\[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\novica7\Cookies\[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP115\A0032791.dll -> Spyware.DlMax.a -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP115\A0032805.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP115\A0032819.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP116\A0032914.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP116\A0032984.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP117\A0033983.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP117\A0033985.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP117\A0034076.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP117\A0034160.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP117\A0034208.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP117\A0034242.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP117\A0034243.exe -> TrojanDownloader.Agent.ae -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP117\A0034244.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP118\A0034509.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP118\A0035509.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP118\A0035551.EXE -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP118\A0035552.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP119\A0035753.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP119\A0035768.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP119\A0035775.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP119\A0036775.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP119\A0036797.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP120\A0036802.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP121\A0036820.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP121\A0036821.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP122\A0036879.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP122\A0036880.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP131\A0037737.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP132\A0037749.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP132\A0038099.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP132\A0038100.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP132\A0038111.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{5D0F0990-DE7C-4851-97E6-6669BC2D8C39}\RP132\A0038113.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\Recycled\NPROTECT\00024244.exe -> TrojanDownloader.Esepor.ab -> Cleaned with backup
C:\Recycled\NPROTECT\00024253.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\NPROTECT\00024316.exe -> Trojan.Agent.cp -> Cleaned with backup
::Report End
---------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 18:17:31, on 8/6/2548
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\ewido\security suite\SecuritySuite.exe
C:\Documents and Settings\novica7\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.novica.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://best-search.c...v=6&aff=5172485
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*;<local>
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Coloreal Lite.lnk = C:\Program Files\WayTech\Coloreal\Coloreal Lite\COLOREALLITE.EXE
O4 - Global Startup: Coloreal Lite.lnk = C:\Program Files\WayTech\Coloreal\Coloreal Lite\COLOREALLITE.EXE
O4 - Global Startup: Harrap's Shorter.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O9 - Extra button: PhoenixNet - {2626e980-0453-11d7-9985-0020183ca38a} - http://www.seqdl.com...=65457&CID=9875 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://www.nuker.com...erInstaller.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9223BEE-9C0F-49BC-BD1D-EB837EE1650E}: Domain = domain
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9223BEE-9C0F-49BC-BD1D-EB837EE1650E}: NameServer = 203.146.0.20,203.146.0.30
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
---------------------------------------------------------
Thanks for your help!