Hijack This:
Logfile of HijackThis v1.99.1
Scan saved at 2:49:13 PM, on 8/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\QWRtaW5pc3RyYXRvcgAA\command.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\System32\MsiExec.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\rundll32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ABBYY FineReader 5.0 Sprint\CAgent.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
C:\Program Files\Rebate Retriever\RebateRetriever.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
C:\WINNT\System32\dmsrio.exe
C:\WINNT\System32\dmsrio.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ei.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\System32\rundll32.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.exactsearch.net/sidesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ABBYY Community Agent] C:\Program Files\ABBYY FineReader 5.0 Sprint\CAgent.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [27Eh3sl] dswntprf.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [exp] C:\WINNT\System32\exp
O4 - HKLM\..\Run: [winsync] C:\WINNT\system32\papnaj.exe reg_run
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\system32\hkhanr.exe reg_run
O4 - HKLM\..\Run: [System service62] C:\WINNT\etb\pokapoka62.exe
O4 - HKLM\..\Run: [lanbrup] C:\WINNT\System32\lanbrup.exe
O4 - HKLM\..\Run: [Sysnet] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sysnet.exe
O4 - HKLM\..\Run: [ttupt] C:\WINNT\ttupt.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [LMPDPSRV] C:\WINNT\system32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
O4 - HKLM\..\Run: [ntdll.dll] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Rebate Retriever] C:\Program Files\Rebate Retriever\RebateRetriever.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [JwxnRiJsh] avwrib.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000105.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [Ibao] C:\Program Files\roal\ewaa.exe
O4 - HKCU\..\Run: [dmsrio] C:\WINNT\System32\dmsrio.exe
O4 - HKCU\..\Run: [ntdll.dll] C:\Program Files\CasStub\casstub.exe -run
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess - http://download.game...nts/y/ct2_x.cab
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.co...laxoInstall.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.co...rols/Rovion.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1123359988453
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (SbInstObj) - http://installs.spam...ckerutility.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.c...ers/play365.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.micro...rchsettings.cab
O20 - Winlogon Notify: MediaContentIndex - C:\WINNT\system32\mftext35.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\QWRtaW5pc3RyYXRvcgAA\command.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
First Ewido scan:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 2:10:24 PM, 8/7/2005
+ Report-Checksum: 4E66CBD
+ Scan result:
HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{175652E8-8BCC-47C4-B591-0D630F469C19} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -> Spyware.E2Give : Cleaned with backup
HKLM\SOFTWARE\Classes\Contact.Contacts -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Contact.Contacts\CLSID -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Contact.Contacts\CurVer -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\IeBHOs.Control -> Spyware.E2G : Cleaned with backup
HKLM\SOFTWARE\Classes\IeBHOs.Control\CLSID -> Spyware.E2G : Cleaned with backup
HKLM\SOFTWARE\Classes\IeBHOs.Control\CurVer -> Spyware.E2G : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{05080E6B-A88A-4CFD-8C3D-9B2557670B6E} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{20D21E02-8C1C-41FE-9826-DAB4C223436C} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{66291BEF-C867-43C0-A7B4-D13393814BCD} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8578D35E-C6C0-4808-9A80-0F6C29A2C423} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E1357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E2468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E5678} -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC190DA5-0187-4D99-B3AC-6C45EA1B9324} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED11357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED12468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED15678} -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\MediaAccess.Installer -> Spyware.WinAd : Cleaned with backup
HKLM\SOFTWARE\Classes\MediaAccess.Installer\CLSID -> Spyware.WinAd : Cleaned with backup
HKLM\SOFTWARE\Classes\MediaAccess.Installer\CurVer -> Spyware.WinAd : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{0DC5CD7C-F653-4417-AA43-D457BE3A9622} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516B2C3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516C2E3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516E2A3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5BA32D9E-F1BD-476C-AD42-97C9379A57A4} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{71EFE583-62FE-4419-9918-CA3B683F7B36} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -> Spyware.E2Give : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
HKU\S-1-5-21-1177238915-1078081533-725345543-500\Software\Mvu -> Spyware.Delfin : Cleaned with backup
HKU\S-1-5-21-1177238915-1078081533-725345543-500\Software\{12EE7A5E-0674-42f9-A76B-000000004D00} -> Spyware.BrowserAid : Cleaned with backup
[1320] C:\Program Files\E2G\IeBHOs.dll -> Spyware.E2Give : Error during cleaning
[1972] C:\Program Files\E2G\IeBHOs.dll -> Spyware.E2Give : Error during cleaning
:mozilla.16:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0F.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\Program Files\E2G\__delete_on_reboot__IeBHOs.dll -> Spyware.E2Give : Cleaned with backup
C:\Program Files\Mozilla Firefox\plugins\npzango.dll -> Spyware.WinAD : Cleaned with backup
C:\Program Files\roal\__delete_on_reboot__ewaa.exe -> TrojanDownloader.PurityScan.y : Cleaned with backup
:mozilla.12:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.13:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.14:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.22:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
:mozilla.23:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Doubleclick : Error during cleaning
:mozilla.25:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Atdmt : Error during cleaning
:mozilla.26:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Esomniture : Error during cleaning
:mozilla.27:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Esomniture : Error during cleaning
:mozilla.7:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.8:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.9:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.10:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.12:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.17:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.18:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.19:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.26:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.27:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.32:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
:mozilla.33:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
C:\WINNT\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\Downloaded Program Files\HbInstIE.dll.tcf -> Spyware.HotBar : Cleaned with backup
C:\WINNT\etb\xud_62.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINNT\icont.exe -> Spyware.AdURL : Cleaned with backup
C:\WINNT\mxpvsvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINNT\system32\bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINNT\system32\installer_MARKETING51.exe.tcf -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINNT\system32\АрpPatch\smss.exe -> Spyware.PurityScan : Cleaned with backup
C:\WINNT\visfxun.exe -> TrojanDownloader.VB.kd : Cleaned with backup
::Report End
second ewido scan report:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 2:41:34 PM, 8/7/2005
+ Report-Checksum: 9A1E2658
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -> Spyware.E2Give : Cleaned with backup
HKLM\SOFTWARE\Classes\IeBHOs.Control -> Spyware.E2G : Cleaned with backup
HKLM\SOFTWARE\Classes\IeBHOs.Control\CLSID -> Spyware.E2G : Cleaned with backup
HKLM\SOFTWARE\Classes\IeBHOs.Control\CurVer -> Spyware.E2G : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -> Spyware.E2Give : Cleaned with backup
[1320] C:\Program Files\E2G\IeBHOs.dll -> Spyware.E2Give : Error during cleaning
:mozilla.16:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6b2urk0d.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\E2G\__delete_on_reboot__iebhos.dll -> Spyware.E2Give : Cleaned with backup
:mozilla.12:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.13:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.14:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.22:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
:mozilla.23:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Doubleclick : Error during cleaning
:mozilla.25:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Atdmt : Error during cleaning
:mozilla.26:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Esomniture : Error during cleaning
:mozilla.27:C:\Program Files\support.com\backup\Co\cookies.txt\3051_57832a246_/cookies.txt -> Spyware.Cookie.Esomniture : Error during cleaning
:mozilla.7:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.8:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.9:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.10:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.12:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.17:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.18:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.19:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.26:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.27:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.32:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
:mozilla.33:C:\Program Files\support.com\backup\Co\cookies.txt\4863_534700cee_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
::Report End
Looking forward to getting these fixed.