Ok...here's the HJT log....
Logfile of HijackThis v1.99.1
Scan saved at 6:04:14 PM, on 07/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\WINDOWS\System32\VTTimer.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\QuickTime\qttask.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\windows\system\hpsysdrv.exe
C:\PROGRA~1\COMMON~1\AOL\112008~1\EE\AOLHOS~1.EXE
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\COMMON~1\AOL\112008~1\EE\AOLServiceHost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Documents and Settings\Owner\Desktop\security suite\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\UnHackMe\hackmon.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\HJT\HijackThis.exe
C:\Program Files\Yahoo!\Antivirus\autodown.exe
and here is the Ewido log
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 5:51:50 PM, 07/25/2005
+ Report-Checksum: E56D9F95
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Ignored
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Ignored
C:\Documents and Settings\Owner\Cookies\owner@hitbox[2].txt -> Spyware.Cookie.Hitbox : Ignored
C:\Documents and Settings\Owner\Cookies\owner@overture[1].txt -> Spyware.Cookie.Overture : Ignored
C:\Documents and Settings\Owner\Local Settings\Temp\atrc8parb_.exe -> Adware.SAHA : Ignored
C:\Documents and Settings\Owner\Local Settings\Temp\liqp7c25q_.dll -> Adware.SAHA : Ignored
C:\Documents and Settings\Owner\Local Settings\Temp\RNNB7SFJ.dll -> Adware.SAHA : Ignored
HKLM\SOFTWARE\Classes\Interface\{205FF73A-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{205FF72E-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ISTbar -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\unebmm350 -> Spyware.MoneyMaker : Cleaned with backup
HKU\.DEFAULT\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
C:\a3643fds.exe/kansup.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\a3643fds.exe/kans.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\dffjj.exe/kans.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\dffjj.exe/kansup.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\578MXIUQ\Bridge-c139[1].cab/MediaGatewayX.dll -> Spyware.WinAD : Error during cleaning
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\578MXIUQ\d[1].exe/kans.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\578MXIUQ\d[1].exe/kansup.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\MAZTC8MX\lg[1].exe/kansup.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\MAZTC8MX\lg[1].exe/kans.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\180sainstallernusac.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\ICD1.tmp\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\ICD2.tmp\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\ICD3.tmp\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\ICD4.tmp\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\ICD5.tmp\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\ICD6.tmp\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\ICD7.tmp\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\THI71B1.tmp\imGiant.cab/imGiant.dll -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Owner\Local Settings\Temp\THI71B1.tmp\imGiant.dll -> Adware.BetterInternet : Cleaned with backup
C:\e5ygh.exe/kansup.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\e5ygh.exe/kans.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\g64fff4.exe/kansup.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\g64fff4.exe/kans.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\l9uk7fh.exe/kansup.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\l9uk7fh.exe/kans.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\lg.exe/kansup.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\lg.exe/kans.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc1.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc10.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc12.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc13.exe -> TrojanDropper.Agent.kd : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc14.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc15.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc16.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc19.exe -> TrojanDropper.Agent.kd : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\F3HISTSW.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\F3HTMLMU.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\F3POPSWT.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\F3PSSAVR.SCR -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\F3RESTUB.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\F3SCHMON.EXE -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\F3WPHOOK.DLL -> Spyware.Wesbar : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\M3OUTLCN.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\M3SKIN.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\bar\1.bin\MWSOESTB.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-75778774-2061035318-3407411993-1003\Dc22\SrchAstt\1.bin\MWSSRCAS.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\temp\180SAInstaller.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\HDPlugin1101.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\imGiant.dll -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\slipit.exe/dreese.exe -> TrojanDropper.Agent.kd : Cleaned with backup
C:\WINDOWS\split.exe/dreese.exe -> TrojanDropper.Agent.kd : Cleaned with backup
C:\WINDOWS\system32\2nse9n0v.dll -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\system32\cigwxy.dll -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\system32\msconfig32.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS\system32\Sxlhsn.exe -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\Temp\180sainstallersilsais1.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\WINDOWS\ucmoreiex.exe/UCMTSAIE.DLL -> Spyware.UCmore : Error during cleaning
C:\WINDOWS\ucmoreiex.exe/IUCMORE.DLL -> Spyware.UCmore : Error during cleaning
C:\xdf5r.exe/kansup.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
C:\xdf5r.exe/kans.reg -> Trojan.WinREG.LowZones.f : Error during cleaning
::Report End
I will await your reply!!
Seems to be running well!!
Do I have to keep all of this stuff on my computer?? Or can I get rid of some of it?
thanks again for all of your help!!!