Hi Tampa,
Did the best I could. "Cleanup" deleted 116,410 files for 1.6 GB of new space!!! It also asked me to restart to "complete the process" which I didn't because you still had things listed for me to do. Then got to work on Viewpoint. Deleted two entries in Add and Remove, a Viewpoint Manager and a Viewpoint Media Player. Then I couldn't find anything in Windows explorer under "program files\Viewpoint", but ran a search of all files and couldn't find so I moved on. Here is the new Hijack and Ewido scans. Any conflicts between McAfee and Ewido?? Should I delete Ewido after all the fixes are done, or what will it do? Thanks Rockyroo
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 1:32:43 PM, 7/24/2005
+ Report-Checksum: 2BEDEEEA
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{09CA52B3-703C-4B17-9690-C13F736E3DCD} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WareOut -> TrojanDownloader.Wareout : Cleaned with backup
HKLM\SOFTWARE\WareOut -> TrojanDownloader.Wareout : Cleaned with backup
HKU\S-1-5-21-1060284298-1343024091-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1060284298-1343024091-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{08BEC6AA-49FC-4379-3587-4B21E286C19E} -> Spyware.SBSoft : Cleaned with backup
HKU\S-1-5-21-1060284298-1343024091-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E246FAE-8420-11D9-870D-000C2917DE7F} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-1060284298-1343024091-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{467FAEB2-5F5B-4C81-BAE0-2A4752CA7F4E} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1060284298-1343024091-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\csplj.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\WINDOWS\SYSTEM32\igrfa.dll -> Spyware.SBSoft : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\rdgUS1862.exe -> Dialer.Generic : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\backups\backup-20050501-203514-854.dll -> Spyware.WinAD : Cleaned with backup
C:\Program Files\backups\backup-20050503-233750-514.dll -> Spyware.WinAD : Cleaned with backup
C:\Program Files\backups\backup-20050713-233650-996.dll -> Spyware.SBSoft : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP120\A0012586.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP120\A0012587.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP181\A0021818.dll -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP181\A0021825.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0022823.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0023823.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024823.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024828.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024834.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024840.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024845.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024853.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024860.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024865.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024876.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024884.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024885.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0024891.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0025890.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{EDB7D35D-F2B0-43F8-A80A-51C5909A504A}\RP182\A0025898.exe -> TrojanDropper.Vidro.p : Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 1:53:16 PM, on 7/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Documents and Settings\Robinson\Start Menu\Programs\Keyboard\MK9908.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.foxnews.com/O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [VortexTray] C:\WINDOWS\au30setp.exe 3
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: MK9908.lnk = C:\Documents and Settings\Robinson\Start Menu\Programs\Keyboard\MK9908.exe
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) -
http://install.homes...ive/HS_live.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcaf...83/mcinsctl.cabO16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1....loadManager.ocxO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcaf...,20/mcgdmgr.cabO23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe