---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:40:48 PM, 8/10/2005
+ Report-Checksum: FF3D7254
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} -> Spyware.NetNucleus : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{8A0DCBDA-6E20-489C-9041-C1E8A0352E75} ->
Spyware.NetNucleus : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\motoin -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
HKU\S-1-5-21-1085031214-1292428093-725345543-1003\Software\Mvu -> Spyware.Delfin : Cleaned with backup
[944] c:\windows\system32\judhht.exe -> Adware.BetterInternet : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Bug\Application Data\Mozilla\Firefox\Profiles\fdlpr13b.default\cookies.txt ->
Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\bug@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\bug@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\
[email protected][1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\bug@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\
[email protected][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\bug@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\bug@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\bug@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\bug@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\bug@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\bug@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\
[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\
[email protected][1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Bug\Cookies\
[email protected][2].txt -> Spyware.Cookie.Popuptraffic : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temp\bundle_mediamotor1004.exe -> Adware.Saha : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temp\cln1B5.tmp -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temp\Del16B.tmp -> TrojanDownloader.Small.asf : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temp\DelAB.tmp -> TrojanDownloader.Small.asf : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temp\res16C.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temp\resAC.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\8R21S9K4\abiuninst[1].exe ->
Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\8R21S9K4\aurora[1].exe -> Adware.BetterInternet
: Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\8R21S9K4\bundle_mediamotor1004[1].exe ->
Adware.Saha : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\A2GLYYV3\876029[1].exe -> Adware.SaveNow :
Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\FQNDKC41\Nail[1].exe -> Adware.BetterInternet :
Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\FQNDKC41\optimize[1].exe ->
TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\FQNDKC41\Poller[1].exe -> Adware.BetterInternet
: Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\FQNDKC41\stubinstaller4292[1].exe ->
TrojanDownloader.Small.asf : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\H9TBEQJ2\alien[1].cab/m67m.ocx ->
Spyware.MediaMotor : Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\H9TBEQJ2\DrPMon[1].dll -> Adware.BetterInternet
: Cleaned with backup
C:\Documents and Settings\Bug\Local Settings\Temporary Internet Files\Content.IE5\H9TBEQJ2\thin-143-1-x-x[1].exe ->
Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Bug\My Documents\Gaming STuff\DeerHunter2005_Setup-dm.exe -> Spyware.Trymedia : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe -> Spyware.Delfin : Cleaned with backup
C:\WINDOWS\876029.exe -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\bundle_mediamotor1004.exe -> Adware.Saha : Cleaned with backup
C:\WINDOWS\dinst.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\m67m.ocx -> Spyware.MediaMotor : Cleaned with backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\imgthin.exe -> TrojanDownloader.VB.if : Cleaned with backup
C:\WINDOWS\optimize.exe -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\WINDOWS\rkwjjn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\eliteevl32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\eliteker32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\judhht.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\vidctrl\vidctrl.exe -> Spyware.DelphinMediaViewer : Cleaned with backup
C:\WINDOWS\system32\ysbinstall_1000489_3.exe -> TrojanDownloader.IstBar.ja : Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 5:22:42 PM, on 8/10/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\CFusionMX\runtime\bin\jrunsvc.exe
C:\CFusionMX\db\slserver52\bin\swagent.exe
C:\CFusionMX\runtime\bin\jrun.exe
C:\CFusionMX\db\slserver52\bin\swstrtr.exe
C:\CFusionMX\db\slserver52\bin\swsoc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\PROGRA~1\AIM\aim.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Bug\My Documents\HJT\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.techbargains.com/F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://groups.msn.co...UC/MsnPUpld.cabO20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ColdFusion MX Application Server - Macromedia Inc. - C:\CFusionMX\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - C:\CFusionMX\db\slserver52\bin\swagent.exe
O23 - Service: ColdFusion MX ODBC Server - Unknown owner - C:\CFusionMX\db\slserver52\bin\swstrtr.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe