heres my hijackthis log:Logfile of HijackThis v1.99.1
Scan saved at 3:27:28 PM, on 8/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\rcdk.exe
C:\WINDOWS\system32\wuauclt.exe
c:\windows\system32\bfdacrw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\hukjmn.exe reg_run
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.4.1_02) -
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Plug-in 1.4.1_02) -
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
heres my ewido scan report:---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 3:15:28 PM, 8/4/2005
+ Report-Checksum: A4610EBE
+ Scan result:
HKLM\SOFTWARE\Classes\AppID\eZulaBootExe.EXE -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\{C0335198-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl\CLSID -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl\CurVer -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E1357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED11357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\NLS.UrlCatcher -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\NLS.UrlCatcher\CLSID -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516C2E3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52} -> Spyware.AdDestroyer : Cleaned with backup
HKU\S-1-5-21-1390067357-1770027372-839522115-1004\Software\eZula -> Spyware.eZula : Cleaned with backup
HKU\S-1-5-21-1390067357-1770027372-839522115-1004\Software\eZula\Setup -> Spyware.eZula : Cleaned with backup
HKU\S-1-5-21-1390067357-1770027372-839522115-1004\Software\eZula\Setup\ID -> Spyware.eZula : Cleaned with backup
HKU\S-1-5-21-1390067357-1770027372-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-1390067357-1770027372-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-1390067357-1770027372-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE188402-6EE7-4022-8868-AB25173A3E14} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-1390067357-1770027372-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-1390067357-1770027372-839522115-1004\Software\VB and VBA Program Settings\VBouncer -> Spyware.VirtualBouncer : Cleaned with backup
HKU\S-1-5-21-1390067357-1770027372-839522115-1004\Software\VB and VBA Program Settings\VBouncer\Settings -> Spyware.VirtualBouncer : Cleaned with backup
[808] c:\windows\system32\jnwrys.exe -> Adware.BetterInternet : Cleaned with backup
:mozilla.15:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.24:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.25:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.26:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.47:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.83:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.84:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.85:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.86:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.87:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.89:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.90:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.91:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.92:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.93:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.94:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.95:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.96:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.97:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.98:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.99:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.100:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.101:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.103:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.104:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.105:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.106:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.123:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.152:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.178:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.179:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.180:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.181:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.214:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.226:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.227:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.229:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.241:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Cqcounter : Cleaned with backup
:mozilla.259:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.269:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.286:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.299:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.305:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.308:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.309:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.310:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.311:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.312:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.321:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.335:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.367:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.393:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.399:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.400:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.401:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.418:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Adition : Cleaned with backup
:mozilla.420:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Adition : Cleaned with backup
:mozilla.442:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.446:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.466:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Weborama : Cleaned with backup
:mozilla.477:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
:mozilla.510:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.511:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Xhit : Cleaned with backup
:mozilla.512:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Xhit : Cleaned with backup
:mozilla.530:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.546:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Trafic : Cleaned with backup
:mozilla.571:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.664:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.702:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.723:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.724:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.725:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.726:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.727:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.728:C:\Documents and Settings\weStone\Application Data\Mozilla\Firefox\Profiles\mx7k3mbz.weStone\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\weStone\Cookies\westone@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\weStone\Desktop\l2mfix\backup.zip/mdvidctl.dll -> Spyware.Look2Me : Error during cleaning
C:\Documents and Settings\weStone\Desktop\l2mfix\backup.zip/nnprovau.dll -> Spyware.Look2Me : Error during cleaning
C:\Documents and Settings\weStone\Desktop\l2mfix\backup.zip/guard.tmp -> Spyware.Look2Me : Error during cleaning
C:\Program Files\eZula -> Adware.eZula : Cleaned with backup
C:\Program Files\eZula\eabh.dll -> Adware.eZula : Cleaned with backup
C:\Program Files\eZula\seng.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\bootstat.dat:hfyoh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\cfgmgr52.dll -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:kabaj -> TrojanDownloader.Agent.db : Cleaned with backup
C:\WINDOWS\Greenstone.bmp:pptzh -> TrojanDownloader.Agent.db : Cleaned with backup
C:\WINDOWS\KB828741.log:winfx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB840987.log:xjgkd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB841356.log:piylz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\kzvalw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\ntdtcsetup.log:ihual -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntdtcsetup.log:mwaow -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ocgen.log:xdwui -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Prairie Wind.bmp:onsxk -> TrojanDownloader.Agent.db : Cleaned with backup
C:\WINDOWS\regopt.log:bzfqe -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\regopt.log:hokdn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\regopt.log:htdxo -> TrojanDownloader.Agent.db : Cleaned with backup
C:\WINDOWS\River Sumida.bmp:fhorp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\River Sumida.bmp:zuwci -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setupact.log:qufop -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setupapi.log.0.old:jsayk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setuperr.log:soypw -> TrojanDownloader.Agent.db : Cleaned with backup
C:\WINDOWS\Sti_Trace.log:prwzm -> TrojanDownloader.Agent.db : Cleaned with backup
C:\WINDOWS\SYSTEM32\AUNPS2.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\conres.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\SYSTEM32\exp.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\WINDOWS\SYSTEM32\ezPopStub.exe -> Adware.eZula : Cleaned with backup
C:\WINDOWS\SYSTEM32\ezstub.exe -> Adware.EZula : Cleaned with backup
C:\WINDOWS\SYSTEM32\jnwrys.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\SYSTEM32\PopOops.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\SYSTEM32\PopOops2.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\SYSTEM32\rk.bin -> Spyware.RK : Cleaned with backup
C:\WINDOWS\SYSTEM32\SWLAD1.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\SYSTEM32\SWLAD2.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\SYSTEM32\wintask.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\WINDOWS\Windows Update.log:ieidp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\WindowsUpdate.log:bhvmx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\WindowsUpdate.log:dljfa -> TrojanDownloader.Agent.db : Cleaned with backup
C:\WINDOWS\WindowsUpdate.log:uftti -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winnt.bmp:kxngi -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winnt256.bmp:xefps -> TrojanDownloader.Agent.db : Cleaned with backup
C:\WINDOWS\Zapotec.bmp:esxmw -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Zapotec.bmp:tkklx -> TrojanDownloader.Agent.bq : Cleaned with backup
::Report End
just to let you know.. i wasn't able to go through the procedure shown below, since the random.exe was recreating and renaming itself everytime i would delete it's registry key. and i wasn't able to delete the file[s] itself manually since the file[s] was running at all times.
Locate and delete the following File in BOLD:
c:\windows\system32\random.exe (or whatever the name may have changed to, as noted above).
also the nail.exe seems to come back whenever i delete it. i think these reactions makes it seem prominent that my computer has been infected with a Qoologic infection, which i've encountered before. i have forgotten the process of eliminating this infection so it would be much appreciated if you would help me out.
Edited by weStone, 04 August 2005 - 01:39 PM.