hi there thanks for the help
Logfile of HijackThis v1.99.1
Scan saved at 11:14:39, on 29/07/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\RunDll32.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Messenger\msmsgs.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\georgina\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AVG7_CC] d:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] d:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.t...all/xscan60.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://spaces.msn.co...ad/MsnPUpld.cabO16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) -
http://www.gamehouse.com/ghdlctl.cabO16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) -
http://www.worldwinn...ck/bjattack.cabO16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) -
http://www.worldwinn...x/blockwerx.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
http://www.worldwinn...ed/wwlaunch.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) -
http://www.worldwinn...v45/sol/sol.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pdownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cabO16 - DPF: {C738EA53-97C2-441B-AC52-DFBC597BCBE5} (Chess Control) -
http://www.worldwinn...chess/chess.cabO16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) -
http://www.worldwinn...paint/paint.cabO16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} -
http://entimg.msn.co...snmusax2918.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{2D716C25-758B-42B3-B674-D4EFF29704A9}: NameServer = 213.249.130.100,212.50.160.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{9E12F912-1719-4A19-876B-9B8659A58DF1}: NameServer = 213.249.130.100,212.50.160.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{B7AFA374-C787-4A96-8CDF-248C6FC8CE73}: NameServer = 213.249.130.100,212.50.160.100
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
and the scan report from ewido
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:11:52, 29/07/2005
+ Report-Checksum: B41ABE69
+ Scan result:
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CLSID -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CurVer -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{99410CDE-6F16-42ce-9D49-3807F78F0287} -> Spyware.Zango : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{205FF73A-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2B0ECEAC-F597-4858-A542-D966B49055B9} -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD} -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\MediaAccX.Installer -> Spyware.WinAd : Cleaned with backup
HKLM\SOFTWARE\Classes\MediaAccX.Installer\CLSID -> Spyware.WinAd : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{205FF72E-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5B6689B5-C2D4-4DC7-BFD1-24AC17E5FCDA} -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -> Spyware.PopularScreensavers : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{99410CDE-6F16-42ce-9D49-3807F78F0287} -> Spyware.Zango : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-21-776561741-1060284298-1343024091-1003\Software\Netsetter -> Spyware.MarketScore : Cleaned with backup
HKU\S-1-5-21-776561741-1060284298-1343024091-1003\Software\Netsetter\OSSProxy -> Spyware.MarketScore : Cleaned with backup
HKU\S-1-5-21-776561741-1060284298-1343024091-1003\Software\Netsetter\OSSProxy\Settings -> Spyware.MarketScore : Cleaned with backup
HKU\S-1-5-21-776561741-1060284298-1343024091-1003\Software\WhenU -> Spyware.SaveNow : Cleaned with backup
C:\WINDOWS\system32\rk.exe -> Spyware.MarketScore : Cleaned with backup
C:\WINDOWS\system32\f3PSSavr.scr -> Spyware.MyWebSearch : Cleaned with backup
C:\WINDOWS\pss\DLHelperEXE.exeStartup -> Spyware.Thumper : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaAccX.dll -> Spyware.WinAD : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ClientAX.dll -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\F3HISTSW.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\F3PSSAVR.SCR -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\F3REPROX.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\F3RESTUB.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\F3SCHMON.EXE -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\F3WPHOOK.DLL -> Spyware.Wesbar : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\M3HTML.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\M3OUTLCN.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\M3PLUGIN.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\M3SKIN.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MyWebSearch\bar\3.bin\NPMYWEBS.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\MSN Messenger\riched20.dll -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP230\A0235016.dll -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP230\A0235017.exe -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP230\A0235030.EXE -> Spyware.Wesbar : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223639.exe -> Adware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223642.exe -> Adware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223652.dll -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223653.scr -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223655.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223658.SCR -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223659.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223660.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223661.EXE -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223663.DLL -> Spyware.Wesbar : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223664.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223665.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223666.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223667.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP217\A0223669.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP218\A0223689.EXE -> Spyware.Wesbar : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP227\A0230792.DLL -> TrojanDownloader.FunWeb.a : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP227\A0230811.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{629577A4-3779-480F-903E-A127E7F96268}\RP212\A0217491.DLL -> TrojanDownloader.FunWeb.a : Cleaned with backup
::Report End
and the scan report from active scan
Incident Status Location
Adware:adware/quicksearch No disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\Install.inf
Adware:adware/ncase No disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\clientax.inf
Adware:adware/funweb No disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\f3initialsetup1.0.0.8-2.inf
Spyware:spyware/betterinet No disinfected C:\WINDOWS\INF\banner.inf
Adware:adware/whenusearch No disinfected C:\PROGRAM FILES\COMMON FILES\WhenU
Adware:adware/wupd No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\MODULEUSAGE\C:/WINDOWS/DOWNLOADED PROGRAM FILES/MEDIAACCX.DLL
Adware:adware/mywebsearch No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MYWEBSEARCH BAR UNINSTALL
Adware:adware/zango No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ZANU
Adware:adware/savenow No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WUSN.1
Adware:adware/exactsearch No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ACTIVEX COMPATIBILITY\{53F066F0-A4C0-4F46-83EB-2DFD03F938CF}
Adware:adware/searchexe No disinfected HKEY_CLASSES_ROOT\Interface\{72423E8F-8011-11D2-BE79-00A0C9A83DA3}
Adware:adware/myway No disinfected HKEY_LOCAL_MACHINE\software\classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
Spyware:spyware/bargainbuddy No disinfected HKEY_CLASSES_ROOT\Interface\{71a27036-c7d8-11d2-bef8-525400dfb47a}
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\inf\banner.inf
Adware:Adware/nCase No disinfected C:\WINDOWS\Downloaded Program Files\clientax.inf
Adware:Adware/FunWeb No disinfected C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.8-2.inf
Adware:Adware/MyWay No disinfected D:\Program Files\backup-20040112-205033-906.dll
thanks very much for all your support.
fatlad