A couple of the annoying pop-ups seem to be gone but I dont know if my PC is fixed yet.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Ewido scan log---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 2:21:50 PM, 7/12/2005
+ Report-Checksum: 389A26FF
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{0B4F9B2C-F81D-7C42-AE33-07F0FCB846EC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{46C8C875-7053-566F-B7DF-A8735884B10E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F704A16D-BA8A-0DD4-CB9E-F0FA4A957D8D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-507921405-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0519A9C9-064A-4CBC-BC47-D0EACD581477} -> Spyware.Icoo : Cleaned with backup
HKU\S-1-5-21-507921405-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -> Spyware.PopularScreensavers : Cleaned with backup
HKU\S-1-5-21-507921405-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{465A59EC-20E5-4FCA-A38A-E5EC3C480218} -> Spyware.Icoo : Cleaned with backup
HKU\S-1-5-21-507921405-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C886256C-7A63-4213-AD2F-02AD3735DF06} -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\john\Cookies\john@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\john\Cookies\
[email protected][1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\john\Cookies\
[email protected][1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\john\Cookies\john@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\john\Cookies\john@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\john\Cookies\john@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\john\Cookies\john@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\WINDOWS\winamp.ini:odxryx -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:thzigb -> TrojanDownloader.Agent.bc : Cleaned with backup
::Report End
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Kaspersky Log (I did My Computer scan, I dont know if that one was the right scan or not)
-------------------------------------------------------------------------------
KASPERSKY ANTI-VIRUS WEB SCANNER REPORT
Tuesday, July 12, 2005 15:13:56
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Anti-Virus Web Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 12/07/2005
Kaspersky Anti-Virus database records: 138074
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 55426
Number of viruses found: 13
Number of infected objects: 81
Number of suspicious objects: 0
Duration of the scan process: 1969 sec
Infected Object Name - Virus Name
C:\Program Files\ICOO Loader\My downloads\VideoC.exe Infected: Trojan-Downloader.Win32.WinShow.aw
C:\Program Files\Norton AntiVirus\Quarantine\588F413D.exe Infected: Trojan.Win32.TopAntiSpyware.n
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP85\A0061947.exe Infected: Trojan.Win32.Agent.ct
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP85\A0061948.exe Infected: not-a-virus:AdWare.MDH.a
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP85\A0061949.exe/InpB/SskBho.dll Infected: not-a-virus:AdWare.SurfSide.c
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP85\A0061949.exe/InpB/SskCore.dll Infected: not-a-virus:AdWare.TotalVelocity.aa
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP85\A0061949.exe/InpB/Ssk.exe Infected: Trojan.Win32.Agent.aj
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP85\A0061949.exe/InpB Infected: Trojan.Win32.Agent.aj
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP85\A0061949.exe Infected: Trojan.Win32.Agent.aj
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP86\A0063383.exe Infected: Trojan.Win32.Puper.l
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP86\A0063384.exe Infected: Trojan.Win32.Favadd.aa
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP86\A0063385.exe Infected: Trojan-Clicker.Win32.Agent.dj
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0064526.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0065526.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0065531.cfg:iiradf:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0065534.ini:odxryx:$DATA/data0001.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0065534.ini:odxryx:$DATA/data0002.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0065534.ini:odxryx:$DATA/data0003.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0065534.ini:odxryx:$DATA/data0004.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0065534.ini:odxryx:$DATA/data0005.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0065534.ini:odxryx:$DATA Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP97\A0066526.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0066541.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0067541.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0067545.cfg:iiradf:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0067547.ini:odxryx:$DATA/data0001.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0067547.ini:odxryx:$DATA/data0002.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0067547.ini:odxryx:$DATA/data0003.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0067547.ini:odxryx:$DATA/data0004.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0067547.ini:odxryx:$DATA/data0005.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0067547.ini:odxryx:$DATA Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068541.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068545.cfg:iiradf:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068547.ini:odxryx:$DATA/data0001.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068547.ini:odxryx:$DATA/data0002.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068547.ini:odxryx:$DATA/data0003.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068547.ini:odxryx:$DATA/data0004.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068547.ini:odxryx:$DATA/data0005.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068547.ini:odxryx:$DATA Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068553.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068557.cfg:iiradf:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068561.ini:odxryx:$DATA/data0001.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068561.ini:odxryx:$DATA/data0002.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068561.ini:odxryx:$DATA/data0003.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068561.ini:odxryx:$DATA/data0004.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068561.ini:odxryx:$DATA/data0005.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068561.ini:odxryx:$DATA Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068566.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068581.cfg:iiradf:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068657.dll/data0001.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068657.dll/data0002.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068657.dll/data0003.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068657.dll/data0004.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068657.dll/data0005.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068657.dll Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068665.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068669.cfg:iiradf:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068671.ini:odxryx:$DATA/data0001.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068671.ini:odxryx:$DATA/data0002.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068671.ini:odxryx:$DATA/data0003.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068671.ini:odxryx:$DATA/data0004.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068671.ini:odxryx:$DATA/data0005.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068671.ini:odxryx:$DATA Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068675.dll/data0001.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068675.dll/data0002.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068675.dll/data0003.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068675.dll/data0004.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068675.dll/data0005.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068675.dll Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068676.exe Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0068695.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0070776.exe Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0070777.exe Infected: Trojan.Win32.TopAntiSpyware.n
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0070778.ini:odxryx:$DATA/data0001.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0070778.ini:odxryx:$DATA/data0002.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0070778.ini:odxryx:$DATA/data0003.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0070778.ini:odxryx:$DATA/data0004.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0070778.ini:odxryx:$DATA/data0005.html Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0070778.ini:odxryx:$DATA Infected: not-a-virus:AdWare.SearchPage
C:\System Volume Information\_restore{3F3B0AA7-19ED-4895-A363-929157DB98CB}\RP98\A0070779.pif:thzigb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\UNAheadManual.cfg:iiradf:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
Scan process completed.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Normal HiJack LogLogfile of HijackThis v1.99.1
Scan saved at 3:16:03 PM, on 7/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\pspvideo9\pspvideo9.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\john\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jxnde.dll/sp.html#41646
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jxnde.dll/sp.html#41646
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.alltheweb.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jxnde.dll/sp.html#41646
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jxnde.dll/sp.html#41646
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jxnde.dll/sp.html#41646
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jxnde.dll/sp.html#41646
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jxnde.dll/sp.html#41646
R3 - Default URLSearchHook is missing
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {D1B2A675-458A-EE06-C3D2-3986E0634551} - C:\WINDOWS\system32\appjg32.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PSPVideo9] C:\Program Files\pspvideo9\pspvideo9.exe -t
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [appnd32.exe] C:\WINDOWS\appnd32.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\system32\hookdump.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Special HiJack LogAd-Aware SE Personal
Adobe Acrobat 4.0, 5.0
Adobe Acrobat 7.0.1 and Reader 7.0.1 Update
Adobe Download Manager 2.0 (Remove Only)
Adobe Photoshop CS
Adobe Reader 7.0
Anarchy Online and the Alien Invasion expansion pack
Anarchy Online Relay Chat
AOL Instant Messenger
Army Builder V2.2c
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Control Panel
ATI Display Driver
ATI HYDRAVISION
AviSynth 2.5
Battlefield 2 Demo
BitTorrent 3.4.2
Canon PIXMA iP1500
ccCommon
CleanUp!
Dell Digital Jukebox Driver
Dell DJ Explorer
EverQuest II
ewido security suite
FEAR Closed MP Beta
HijackThis 1.99.1
Home Search Assistent
Internet Worm Protection
iTunes
J2SE Runtime Environment 5.0 Update 2
Kaspersky Anti-Virus Web Scanner
LimeWire PRO 4.8.1
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Age of Empires II
Microsoft Age of Empires II: The Conquerors Expansion
Microsoft Office XP Professional with FrontPage
MSN Messenger 7.0
MSN Music Assistant
Musicmatch® Jukebox
Nero Suite
Norton AntiVirus 2005
Norton AntiVirus 2005 (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton WMI Update
NTI Backup NOW! 4 Trial
NTI CD & DVD-Maker 7 Platinum Trial
NVIDIA Drivers
PhotoShow Deluxe
PSP Video 9 1.41
RealPlayer
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896428)
SPBBC
Spybot - Search & Destroy 1.4
Spyware Doctor 3.2
Star Wars Republic Commando Demo
Symantec
Symantec Script Blocking Installer
SymNet
Update for Windows XP (KB898461)
Viewpoint Media Player
ViewSonic Monitor Drivers
WebSearch Tools
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WinRAR archiver
World of Warcraft
Yahoo! Internet Mail
Yahoo! Messenger
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I hope I did everything correctly and that it helps, thanks in advance.