Ok here goes...
Edit: I'll put ewido second and eScan first since thats the order I did it... >.< I hope it's normal for no action to be taken automaticly on eScan...
::eScan Log::File C:\WINDOWS\aconti.exe tagged as
not-a-virus:[bleep]-Dialer.Win32.ALifeDialer. No Action Taken.
File C:\WINDOWS\cpl2bkvl.exe tagged as
not-a-virus:AdWare.Sahat.ah. No Action Taken.
File
C:\WINDOWS\dsr.exe tagged as
not-a-virus:AdWare.ToolBar.ImiBar.h. No Action Taken.
File
C:\WINDOWS\gekhjf.exe tagged as not-a-virus:AdWare.BiSpy.w. No
Action Taken.
File C:\WINDOWS\system32\cpl2bkvl.ini tagged as
not-a-virus:AdWare.Sahat.ao. No Action Taken.
File
C:\WINDOWS\system32\InstallerV4.exe tagged as
not-a-virus:AdWare.SafeSurfing.o. No Action Taken.
File
C:\WINDOWS\system32\lanbruns.exe infected by
"Trojan-Downloader.NSIS.Agent.i" Virus. Action Taken: File
Deleted.
File C:\WINDOWS\system32\nsoA.dll tagged as
not-a-virus:AdWare.Beginto.c. No Action Taken.
File
C:\Documents and Settings\Landon\Local Settings\Temp\INV9.tmp
tagged as not-a-virus:AdWare.SafeSurfing.o. No Action Taken.
File C:\Documents and Settings\Landon\Local Settings\Temporary
Internet Files\Content.IE5\3V4AY8MB\SSInstaller[1].exe tagged
as not-a-virus:AdWare.SafeSurfing.o. No Action Taken.
File
C:\Documents and Settings\Landon\My Documents\Diablo
Hacks\install_cheat_001.exe infected by
"Trojan-Downloader.Win32.IstBar.ki" Virus. Action Taken: File
Deleted.
File C:\Documents and Settings\Landon\My
Documents\Instals and
Patches\diablo2lodv110_XwMyWdFxYxZoCeNy.zip infected by
"Trojan-Downloader.Win32.IstBar.ki" Virus. Action Taken: File
Deleted.
File C:\Documents and Settings\Landon\My
Documents\Instals and Patches\mirc616.exe tagged as
not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
File
C:\Program Files\Best online !\jor.exe tagged as
not-a-virus:[bleep]-Dialer.Win32.ALifeDialer. No Action Taken.
File C:\Program Files\mIRC\mirc.exe tagged as
not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
File
C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP15
4\A0087515.exe tagged as
not-a-virus:[bleep]-Dialer.Win32.ALifeDialer. No Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0095901.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0095919.exe tagged as not-a-virus:AdWare.ToolBar.ImiBar.h.
No Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0095920.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0095923.exe tagged as not-a-virus:AdWare.SafeSurfing.o. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0095942.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0095958.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0095968.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0095989.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0096008.exe tagged as not-a-virus:AdWare.SafeSurfing.o. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0096199.exe tagged as not-a-virus:AdWare.BetterInternet.o.
No Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0096201.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0096385.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0096454.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0096572.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0096603.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0098660.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0098671.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
0\A0098696.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0098717.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0098722.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0098745.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0098746.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0099745.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0099770.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0099771.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0099775.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0099787.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
1\A0099792.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
2\A0099869.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
2\A0099871.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
2\A0099881.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0099918.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0099927.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0099928.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0099934.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0099958.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0099995.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0100023.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0100026.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0100073.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
3\A0100075.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0100103.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0100136.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0100181.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0100182.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0100183.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0100184.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0100219.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0100229.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0100239.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101241.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101259.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101283.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101289.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101310.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101329.dll tagged as not-a-virus:AdWare.Sahat.ad. No Action
Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101330.exe tagged as not-a-virus:AdWare.Sahat.ai. No Action
Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101331.exe infected by "Backdoor.Win32.VB.pe" Virus. Action
Taken: File Renamed.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101332.dll tagged as not-a-virus:AdWare.ToolBar.ImiBar.h.
No Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101333.dll tagged as not-a-virus:AdWare.SafeSurfing.p. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101334.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101335.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101336.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101337.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101338.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101339.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101343.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101344.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101827.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101828.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101831.exe infected by "Trojan-Downloader.NSIS.Agent.i"
Virus. Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101834.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101844.dll tagged as not-a-virus:AdWare.SafeSurfing.p. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101845.exe tagged as not-a-virus:AdWare.BetterInternet. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101846.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101847.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101852.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101853.exe infected by "Trojan.Win32.Agent.gp" Virus.
Action Taken: File Deleted.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101857.dll tagged as not-a-virus:AdWare.BetterInternet.h.
No Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101883.exe tagged as not-a-virus:AdWare.SafeSurfing.n. No
Action Taken.
File C:\System Volume
Information\_restore{4B26E696-37A2-45CE-ADC4-BEFACD8A5F54}\RP17
4\A0101905.exe infected by "Trojan-Downloader.NSIS.Agent.i"
Virus. Action Taken: File Deleted.
File C:\WINDOWS\aconti.exe
tagged as not-a-virus:[bleep]-Dialer.Win32.ALifeDialer. No Action
Taken.
File C:\WINDOWS\cpl2bkvl.exe tagged as
not-a-virus:AdWare.Sahat.ah. No Action Taken.
File
C:\WINDOWS\Downloaded Program Files\Preloader.dll tagged as
not-a-virus:Downloader.Win32.OTXloader. No Action Taken.
File
C:\WINDOWS\dsr.exe tagged as
not-a-virus:AdWare.ToolBar.ImiBar.h. No Action Taken.
File
C:\WINDOWS\gekhjf.exe tagged as not-a-virus:AdWare.BiSpy.w. No
Action Taken.
File C:\WINDOWS\system32\cpl2bkvl.ini tagged as
not-a-virus:AdWare.Sahat.ao. No Action Taken.
File
C:\WINDOWS\system32\InstallerV4.exe tagged as
not-a-virus:AdWare.SafeSurfing.o. No Action Taken.
File
C:\WINDOWS\system32\nsoA.dll tagged as
not-a-virus:AdWare.Beginto.c. No Action Taken.
---------------------------------------------------------
ewido security suite - Scan report
--------------------------------------------------------- + Created on: 12:29:47 PM, 8/18/2005
+ Report-Checksum: 23B02058
+ Scan result:
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon -> Spyware.BetterInternet : Cleaned without backup
[1008] C:\WINDOWS\system32\DrPMon.dll -> Adware.BetterInternet : Cleaned without backup
[1204] VM_01200000 -> Adware.BetterInternet : Error during cleaning
[1536] C:\WINDOWS\system32\aygjco.exe -> Trojan.Agent.cp : Cleaned without backup
C:\Documents and Settings\Landon\Cookies\landon@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned without backup
C:\Documents and Settings\Landon\Cookies\
[email protected][1].txt -> Spyware.Cookie.Falkag : Cleaned without backup
C:\Documents and Settings\Landon\Cookies\landon@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned without backup
C:\Documents and Settings\Landon\Cookies\landon@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned without backup
C:\Documents and Settings\Landon\Cookies\landon@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned without backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned without backup
C:\Program Files\Best online !\jor.exe -> Dialer.Generic : Cleaned without backup
C:\WINDOWS\aconti.exe -> Dialer.Generic : Cleaned without backup
C:\WINDOWS\cpl2bkvl.exe -> Adware.SAHA : Cleaned without backup
C:\WINDOWS\Downloaded Program Files\Preloader.dll -> TrojanDownloader.OTXloader : Cleaned without backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned without backup
C:\WINDOWS\gekhjf.exe -> Adware.BetterInternet : Cleaned without backup
C:\WINDOWS\system32\nsoA.dll -> Spyware.Beginto : Cleaned without backup
::Report End
Logfile of HijackThis v1.99.1Scan saved at 12:32:33 PM, on 8/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\1117561990\ee\AOLHostManager.exe
C:\WINDOWS\arnvowf.EXE
C:\Program Files\Common Files\AOL\1117561990\ee\AOLServiceHost.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\twqclud.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPHipm11.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ewido\security suite\securitysuite.exe
C:\Program Files\MYIE2\MyIE.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\mucfbjg.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Landon\Desktop\Hijack Delete\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 211.185.39.3:8080
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1117561990\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Sysnet] C:\DOCUME~1\Landon\LOCALS~1\Temp\sysnet.exe
O4 - HKLM\..\Run: [arnvowf] C:\WINDOWS\arnvowf.EXE
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [htihhof] C:\WINDOWS\system32\mucfbjg.exe r
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00001016-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter16 Class) -
http://netmarble.net...NMStarter16.cabO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.t...all/xscan60.cabO16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} (AsyncDownloader Class) -
http://survey.otxres...m/Preloader.dllO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) -
http://go.microsoft....467&clcid=0x409O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1104702274968O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) -
http://12.111.130.38/activex/AMC.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/...ro.cab34246.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://pc.mywebexpc.../ra/ieatgpc.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/z...s/heartbeat.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zon...wn.cab31267.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\twqclud.exe
Thanks a TON for going through all this for me... XD I hope it turns out good...
Edited by Yumil, 18 August 2005 - 10:40 AM.