Here is my log from Ewido Security Suite
wido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:34:36 AM, 8/3/2005
+ Report-Checksum: 8665742B
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{69753829-779C-45e7-9D8C-C79CE0989246} -> Spyware.iSearch : Cleaned with backup
[3052] C:\WINDOWS\system32\VMElSys.dll -> Spyware.Hijacker.Generic : Error during cleaning
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0020466.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0021521.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0021570.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0021622.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0021678.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0021724.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0021786.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0021840.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0021892.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0021951.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0022007.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP103\A0022179.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP103\A0022228.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP103\A0022282.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP104\A0022426.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP78\A0011481.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP78\A0011536.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP78\A0011592.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP78\A0011644.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP78\A0011692.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP78\A0011745.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP78\A0011802.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP78\A0011850.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP79\A0011909.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP81\A0012086.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP83\A0012328.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP84\A0012434.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0012500.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0012554.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0012605.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0012660.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0012709.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0012743.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0012774.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0012812.exe -> TrojanDownloader.Agent.fw : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP88\A0012873.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP90\A0015259.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0015296.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0015332.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP93\A0017470.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP93\A0017518.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP93\A0017578.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP93\A0018575.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP93\A0018610.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP95\A0018691.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP95\A0018731.exe -> TrojanDownloader.Agent.fw : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP95\A0018734.exe -> TrojanDownloader.Agent.fw : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0018769.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0018803.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0018837.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0018894.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0018943.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0018979.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0019943.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0019988.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0020032.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0020070.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0020114.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP98\A0020157.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP98\A0020226.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP99\A0020357.dll -> Spyware.Xawm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP99\A0020410.dll -> Spyware.Xawm : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\exe -> TrojanDownloader.Agent.fw : Cleaned with backup
C:\WINDOWS\SYSTEM32\532dsld.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\6TETRODLL.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\AAAsfer.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\AAMaam.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\aamDial.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\AAMDMP.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\AAMILCFG.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\AAMOSYCck.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ACCdsm.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ACCTRAC.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\acluctiv.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ads3duaAPI.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\AMap3d1a.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\amd5RX.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\amdsldETE.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\atdosce.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\atmidiAPE.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\atscoOM.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\CAP3SMDFVI.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\CAPR32CIA.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\CDFMPDIN.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\CLUEDADVP.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ctiUT.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\CTRACEiosr.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\CTRECAP.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\CTRNPNATSR.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\CTRrypt.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\CTsrvGH.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\d5im7ENG.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\d5TMbken.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\DITtl70.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\DMPAACK.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\DSLRORMF.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\DSMSTRS.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\dvpati2c.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\eamPTDL.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\eamVIC.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\EDITLM.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\edsAP.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\FIL3ABI.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\I3IAL3.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\i3TCOMPO.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ILEBIDI.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\KCTAUTHbo.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\KCTRBK.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ldpspNPN.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ldpUTOVM.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\ldWAVatt.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\liceuid.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\LRKCTMISC.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\LRSCIOD.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\md53TRE.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\MONSYC.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\MSED3D.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\msLMFne.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\mxthzdmim.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\mxTRghel.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\NCLPCbthc.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\NVdlhusd.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\O4SSERL32.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\o4svvvax.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\O4SWSERES.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ODISCA.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\PABKENlbca.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\PARDMIN.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\PCatlTML.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\PCSKMOEV.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\REDITDVP.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ROAPmban.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\RSEMFD.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\RSESN.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\rxyerril.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\sesrhsanui.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\SRAMatsr.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\srBGEN.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\srpcsrv32.dll -> Spyware.Xawm : Cleaned with backup
C:\WINDOWS\SYSTEM32\svDANCLENG.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\thCFGN.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\thkoad.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\THMGRESKP.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\THOLEPTEX.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ti3rx3.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\TIFPCP32.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\tl7SPRES.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\tlatme.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\TMCVI168.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\tmliios.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\tmp.exe -> Spyware.Perez.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\txfdb32.dll -> Spyware.Xawm : Cleaned with backup
C:\WINDOWS\SYSTEM32\UDITHZatq.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\USAPCI.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\VIESNPodm.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\viioNFM.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\VMEATTCMSM.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\VPACSVC.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\VTAbthstcl.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\VTAsrv.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\vutCAP.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\xprxvpsops.exe -> TrojanDropper.Small.oy : Cleaned with backup
C:\WINDOWS\SYSTEM32\__delete_on_reboot__VMElSys.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\telnet.exe -> TrojanDownloader.Agent.fw : Cleaned with backup
::Report End
Here is my Hijack this Log
Logfile of HijackThis v1.99.1
Scan saved at 1:31:49 AM, on 8/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\msdtc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\System32\vssvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\xpsp2fw.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Documents and Settings\Rene\Local Settings\Temporary Internet Files\Content.IE5\1JHY8HB8\HijackThis[1].exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://nonstopsearch.com/?a=2&b=test
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://nonstopsearch.com/?a=2&b=test
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://nonstopsearch.com/?a=2&b=test
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://nonstopsearch.com/?a=2&b=test
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nonstopsearch.com/?b=test
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://nonstopsearch.com/?a=2&b=test
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://nonstopsearch.com/?a=2&b=test
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://nonstopsearch.com/?a=2&b=test
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://nonstopsearch.com/?a=2&b=test
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://nonstopsearch.com/?a=2&b=test
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://nonstopsearch.com/?a=2&b=test
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {44671FC4-084A-D5AB-53E2-CE57DED3E534} - C:\WINDOWS\system32\PCUPDMI.exe (file missing)
O2 - BHO: (no name) - {3C8A6204-B469-7890-D052-615504857C1C} - C:\WINDOWS\System32\cnth.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Fast start] C:\WINDOWS\system32\ntnut.exe home
O4 - HKLM\..\Run: [XPSP2 Firewall] C:\WINDOWS\system32\xpsp2fw.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows Update Client ] C:\WINDOWS\system32\wuclient.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B8763AA3-20AF-41E2-9EC7-37C4B2814BB0}: NameServer = 205.188.146.145
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Provides three management service (FreeBSD) - Unknown owner - C:\WINDOWS\System32\dev32.exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Provides five management service (NetBSD) - Unknown owner - C:\WINDOWS\System32\dev32.exe (file missing)
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Thank you for your help