Here is my Ewido Log,
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 8:07:10 PM, 8/16/2005
+ Report-Checksum: 79D7FF4
+ Scan result:
HKLM\SOFTWARE\Classes\Interface\{EEE4A2E5-9F56-432F-A6ED-F6F625B551E0} -> Dialer.Generic : Ignored
HKLM\SOFTWARE\Classes\TypeLib\{09CA52B3-703C-4B17-9690-C13F736E3DCD} -> Dialer.Generic : Ignored
HKLM\SOFTWARE\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0273F826-C153-4293-A001-2412221726BC} -> Spyware.LZIO : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A78CC2FF-6E4E-4556-B27C-D7C3A70D7A50} -> Spyware.Clickspring : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{339D8AFF-0B42-4260-AD82-78CE605A9543} -> Spyware.SideFind : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A36A5936-CFD9-4B41-86BD-319A1931887F} -> Spyware.SideFind : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{AA4939C3-DECA-4A48-A454-97CD587C0EF5} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{127ACE33-7EA8-45F0-8B55-EFE8B8068BEF} -> Spyware.CommonName : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\PerfectNav -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\hsb -> Spyware.Hotsearchbar : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\hsb\ccc -> Spyware.Hotsearchbar : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\hsb\eee -> Spyware.Hotsearchbar : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\hsb\rrr -> Spyware.Hotsearchbar : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\hsb\ttt -> Spyware.Hotsearchbar : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\hsb\www -> Spyware.Hotsearchbar : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00000000-10D6-4E5F-8F7F-29B32C1C0FC4} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00000000-167B-41BC-95FF-86A07B14712C} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00000000-2565-4C5B-A455-A74C8A2247AB} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00000000-64C4-4A64-9767-895AB4921E41} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00000EF1-0786-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0000607D-D204-42C7-8E46-216055BF9918} -> Spyware.TwainTech : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00D6A7E7-4A97-456F-848A-3B75BF7554D7} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0199DF25-9820-4BD5-9FEE-5A765AB4371E} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{086CEFD5-A88D-4981-8915-D51F04360ED1} -> Spyware.TrafficHog : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1C78AB3F-A857-482E-80C0-3A1E5238A565} -> Spyware.iSearch : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8B224779-3B0E-4FEA-8AE1-B66C20DD840F} -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} -> Spyware.DealHelper : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E8EAEB34-F7B5-4C55-87FF-720FAF53D841} -> Spyware.MidAddle : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-0000-47C5-A90F-2CDE8F7638DB} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-10D6-4E5F-8F7F-29B32C1C0FC4} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-167B-41BC-95FF-86A07B14712C} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-2565-4C5B-A455-A74C8A2247AB} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-64C4-4A64-9767-895AB4921E41} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000EF1-0786-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0000607D-D204-42C7-8E46-216055BF9918} -> Spyware.TwainTech : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0026AD90-C86F-4269-97F3-DAB4897C6D06} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00D6A7E7-4A97-456F-848A-3B75BF7554D7} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{016235BE-59D4-4CEB-ADD5-E2378282A1D9} -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0199DF25-9820-4BD5-9FEE-5A765AB4371E} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{086CEFD5-A88D-4981-8915-D51F04360ED1} -> Spyware.TrafficHog : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1C78AB3F-A857-482E-80C0-3A1E5238A565} -> Spyware.iSearch : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8B224779-3B0E-4FEA-8AE1-B66C20DD840F} -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} -> Spyware.DealHelper : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8EAEB34-F7B5-4C55-87FF-720FAF53D841} -> Spyware.MidAddle : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2000478354-162531612-725345543-1003\Software\PowerScan -> Spyware.PowerScan : Cleaned with backup
[1048] C:\WINDOWS\system32\whgjwhs.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
[1280] C:\WINDOWS\system32\lbralb.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
[1300] C:\WINDOWS\system32\whgjwhs.dll -> TrojanDownloader.Qoologic.n : Error during cleaning
[792] C:\WINDOWS\system32\kanok.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
:mozilla.10:C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\w4qxrv72.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.12:C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\w4qxrv72.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.14:C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\w4qxrv72.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.15:C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\w4qxrv72.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.17:C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\w4qxrv72.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.21:C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\w4qxrv72.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.22:C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\w4qxrv72.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.9:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.12:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.19:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.21:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.22:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.23:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.24:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.28:C:\Documents and Settings\owner\Application Data\Phoenix\Profiles\default\654y2gsg.slt\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-dbb525f-41cf39d0.class -> Trojan.ClassLoader.Dummy.d : Cleaned with backup
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\GetAccess.class-197aa512-1c1f18a3.class -> Trojan.ClassLoader.c : Cleaned with backup
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Gummy.class-3c42fb6b-5b9896ce.class -> Trojan.Java.Femad : Cleaned with backup
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\VerifierBug.class-4b9315b5-5ba08112.class -> Trojan.Byteverify : Cleaned with backup
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\VerifierBug.class-6b57f17e-16d9c315.class -> Trojan.Java.Femad : Cleaned with backup
C:\RECYCLER\S-1-5-21-2000478354-162531612-725345543-1003\Dc3\backup-20050816-191144-701.dll -> TrojanDownloader.Vivia.f : Cleaned with backup
C:\WINDOWS\bsx32 -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADBN1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADTMI1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVCTX2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASI2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASI50.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIB9894.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIC29667.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASICLRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASICLV.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASICP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASID12180.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIE17070.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIEP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIEPRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIEZ.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIF29819.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIF4502.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIFA15376.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIFWH29233.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIG21943.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIGT10102.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIH21180.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIH7853.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIHD.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASII21469.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIKAB.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIKAB2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIL18549.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASILS29399.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIM9740.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIMBC.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIOG19375.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIOT25456.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIPF1965.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIR21184.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIRCP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIRCPRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIRE20082.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIS24110.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIS31590.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASISS.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASISS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASISS2RE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASISSRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIT17011.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIT26116.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIW11211.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIWS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\AUTOS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BID1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BingoRoom1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\bspace.html -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARD2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CASH2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CW.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CW2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DATE4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DEBT1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DENT1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EML1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FAST1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FLWR1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FMND1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HEAL5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HEBE2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HERBS1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HOGAR2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HOMES3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INK1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INSUR4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\JOBS4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MORT3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MOVS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\NEWS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\OPPR2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SHOP2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SPEC1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TECH2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMP1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPC.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPD.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPET.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPF.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPFAM.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPFI.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPFIN.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPG.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPH.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPHL.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPJ.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPM.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPMTV.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPN.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPR.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPS.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPSHOP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPSP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPW.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TRVL4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TRVL6.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TV1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TVEN1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TVEN2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TVMX.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\UTONE2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\UTONE3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\VENUE1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WEBS1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WEBS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WOMEN2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WWW3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\XTFL2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ZNETGP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52.dll -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\dhp2.dll -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnUS2108.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\gdnUS2108.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\NDNuninstall6_30.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\nxpqsuxe.exe -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\sys2749.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2750.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3737.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3741.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3744.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3745.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3746.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3747.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3748.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3749.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4231.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4245.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4249.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys425.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys426.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys726.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys83.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys85.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\systb.exe.tcf -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\system\Loader.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\WINDOWS\system\svchost.dll -> Backdoor.Agent.iw : Cleaned with backup
C:\WINDOWS\system\svchost.exe -> Backdoor.Agent.iw : Cleaned with backup
C:\WINDOWS\system\svchosthook.dll -> Backdoor.Agent.iw : Cleaned with backup
C:\WINDOWS\system32\110328.exe -> TrojanDropper.Small.abx : Cleaned with backup
C:\WINDOWS\system32\149531.exe -> TrojanDropper.Small.aad : Cleaned with backup
C:\WINDOWS\system32\64wu86rd.exe.tcf -> Spyware.F1Organizer : Cleaned with backup
C:\WINDOWS\system32\9300_up.exe -> Worm.Sasser.D : Cleaned with backup
C:\WINDOWS\system32\abc.exe -> TrojanSpy.LdPinch.os : Cleaned with backup
C:\WINDOWS\system32\abirvalg32.dll -> TrojanProxy.Small.cn : Cleaned with backup
C:\WINDOWS\system32\adsnds37.exe.tcf -> Spyware.IEDriver : Cleaned with backup
C:\WINDOWS\system32\amstauth.exe -> TrojanDownloader.Agent.ro : Cleaned with backup
C:\WINDOWS\system32\augre.exe.tcf -> TrojanDownloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\axpfbho.exe -> Spyware.NoName.e : Cleaned with backup
C:\WINDOWS\system32\bKs.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\system32\bo.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\conres.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\cssrs.exe -> TrojanSpy.PdPinch : Cleaned with backup
C:\WINDOWS\system32\datadx.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\date.exe -> Backdoor.SdBot.md : Cleaned with backup
C:\WINDOWS\system32\gawyebn.exe.tcf -> TrojanDownloader.Vivia.l : Cleaned with backup
C:\WINDOWS\system32\init32m.exe.tcf -> TrojanDownloader.Agent.ho : Cleaned with backup
C:\WINDOWS\system32\istinstall_145938.exe.tcf -> TrojanDownloader.IstBar.er : Cleaned with backup
C:\WINDOWS\system32\latest.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\system32\mamma-ibis-ss.exe.tcf -> TrojanDownloader.Vivia.o : Cleaned with backup
C:\WINDOWS\system32\maxd1.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\ms.exe -> TrojanDownloader.Vb.Cw : Cleaned with backup
C:\WINDOWS\system32\NDrv.exe.tcf -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\system32\playa.exe -> Spyware.WinFetcher.b : Cleaned with backup
C:\WINDOWS\system32\protect1.exe.tcf -> Spyware.WinComm : Cleaned with backup
C:\WINDOWS\system32\SHAgentNew.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\svhost32.exe -> TrojanProxy.Agent.cj : Cleaned with backup
C:\WINDOWS\system32\symcsvc.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\system32\sztoice.exe.tcf -> TrojanDownloader.Apropo.k : Cleaned with backup
C:\WINDOWS\system32\thin-75-1-x-x.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\tmp.dat -> TrojanDownloader.Murlo.ar : Cleaned with backup
C:\WINDOWS\system32\vxgame1.exe -> TrojanDropper.Small.acg : Cleaned with backup
C:\WINDOWS\system32\vxgame2.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\system32\vxgame3.exe.tcf -> TrojanDownloader.Agent.ho : Cleaned with backup
C:\WINDOWS\system32\vxgame4.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\vxgamet2.exe -> Trojan.LowZones.y : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq1.exe -> TrojanDownloader.Small.bdz : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq5.exe -> TrojanDownloader.Small.awa : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq6.exe -> TrojanDownloader.Small.aux : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq7.exe -> TrojanDownloader.Small.atl : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq8.exe -> TrojanDownloader.Small.bdz : Cleaned with backup
C:\WINDOWS\system32\ykaby.dat -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\~update.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\vr_sys.dll -> TrojanSpy.LdPinch.os : Cleaned with backup
C:\WINDOWS\yhiymkmj.exe -> Spyware.BookedSpace : Cleaned with backup
::Report End
And here is my HJT Log as of this morning:
Logfile of HijackThis v1.99.1
Scan saved at 11:31:41 AM, on 8/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\System32\LzioMediaUpdater.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\tsimc\yoqw.exe
C:\DOCUME~1\owner\LOCALS~1\Temp\cxte.exe
C:\DOCUME~1\owner\LOCALS~1\Temp\AdNW.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\bkobjkxe\gxxau.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\ups.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\owner\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.savewealth.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.savewealth.comO1 - Hosts: 216.39.69.102 view.atdmt.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {77217950-5848-1F49-DD8E-2AADDB98E2A8} - C:\WINDOWS\system32\hbpkoppx\lsjerycu.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [LzioMediaUpdater] C:\WINDOWS\System32\LzioMediaUpdater.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [fklimo] C:\WINDOWS\system32\ciles\fklimo.exe
O4 - HKLM\..\Run: [lmrem] C:\WINDOWS\system32\hqovra\lmrem.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [yoqw] C:\WINDOWS\system32\tsimc\yoqw.exe
O4 - HKLM\..\Run: [ffjwhhv] C:\WINDOWS\system32\xnysuox\ffjwhhv.exe
O4 - HKLM\..\Run: [gxxau] C:\WINDOWS\system32\bkobjkxe\gxxau.exe
O4 - HKLM\..\Run: [daha] C:\WINDOWS\system32\bffivn\daha.exe
O4 - HKLM\..\Run: [shnin] C:\DOCUME~1\owner\LOCALS~1\Temp\cxte.exe
O4 - HKLM\..\Run: [SkyH2] C:\DOCUME~1\owner\LOCALS~1\Temp\yucjr.exe
O4 - HKLM\..\Run: [WindowsAds] C:\DOCUME~1\owner\LOCALS~1\Temp\AdNW.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\dsg4ds.exe reg_run
O4 - HKLM\..\Run: [version] C:\WINDOWS\system32\dlpcbeja.exe
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O21 - SSODL: System - {7631D6CB-DA0C-4C21-83C2-450B75DF36E4} - vr_sys.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: gxxaubkobjkxe - Unknown owner - C:\WINDOWS\system32\bkobjkxe\gxxau.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
TY again