---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 6:02:34 PM, 8/18/2005
+ Report-Checksum: 9A13E35D
+ Scan result:
HKLM\SOFTWARE\Classes\IeBHOs.Control -> Spyware.E2G : Cleaned with backup
HKLM\SOFTWARE\Classes\IeBHOs.Control\CLSID -> Spyware.E2G : Cleaned with backup
HKLM\SOFTWARE\Classes\IeBHOs.Control\CurVer -> Spyware.E2G : Cleaned with backup
HKU\S-1-5-21-2230923689-1300003180-414440772-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -> Spyware.E2Give : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temp\ei.exe -> TrojanDownloader.Small.bgl : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temp\Temporary Internet Files\Content.IE5\0ATL45F7\ei[1].exe -> TrojanDownloader.Small.bgl : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\V9TZVKZE\ei[1].exe -> TrojanDownloader.Small.bgl : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\V9TZVKZE\kw[1].exe -> Spyware.EliteBar : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\V9TZVKZE\pokapoka63[1].exe -> Spyware.EliteBar : Cleaned with backup
C:\Documents and Settings\Patrick\Desktop\backups\backup-20050818-170028-301.dll -> Spyware.E2Give : Cleaned with backup
C:\Program Files\sdf.exe.tcf -> Spyware.Hijacker.Generic : Cleaned with backup
C:\RECYCLER\NPROTECT\00030814.ocx -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030815.dll -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030816.exe -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030817.EXE -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030819.ocx -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030820.dll -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030821.exe -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030822.EXE -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030824.ocx -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030825.dll -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030826.exe -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030828.EXE -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00030932.exe -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00035577.exe -> Spyware.Pacer : Cleaned with backup
C:\RECYCLER\NPROTECT\00035579.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\RECYCLER\NPROTECT\00035581.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\RECYCLER\NPROTECT\00035633.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\RECYCLER\NPROTECT\00035639.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00035640.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00035641.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00035642.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00035645.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00035646.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00035649.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00035650.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00035684.EXE -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00036599.EXE -> Spyware.VirtualBouncer.j : Cleaned with backup
C:\RECYCLER\NPROTECT\00036601.EXE -> Spyware.VirtualBouncer.j : Cleaned with backup
C:\RECYCLER\NPROTECT\00036602.EXE -> Spyware.VirtualBouncer : Cleaned with backup
C:\RECYCLER\NPROTECT\00036604.TCF -> Spyware.VirtualBouncer : Cleaned with backup
C:\RECYCLER\NPROTECT\00036609.EXE -> Spyware.VirtualBouncer : Cleaned with backup
C:\RECYCLER\NPROTECT\00036653.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00036654.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00036655.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00036660.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00036661.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00036662.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00036684.TCF -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00036687.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00036688.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00037352.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00037379.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00037380.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00037382.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00037383.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00037453.EXE -> TrojanDownloader.Small.aal : Cleaned with backup
C:\RECYCLER\NPROTECT\00037476.EXE -> TrojanDownloader.Small.aal : Cleaned with backup
C:\RECYCLER\NPROTECT\00037491.EXE -> TrojanDownloader.Small.aal : Cleaned with backup
C:\RECYCLER\NPROTECT\00037589.EXE -> Spyware.AproposMedia : Cleaned with backup
C:\RECYCLER\NPROTECT\00037597.TCF -> TrojanDownloader.Apropo.g : Cleaned with backup
C:\RECYCLER\NPROTECT\00037629.ocx -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00037630.dll -> Spyware.Delfin : Cleaned with backup
C:\RECYCLER\NPROTECT\00037648.VXD -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00037651.EXE -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00037654.EXE -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00037657.EXE -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00037669.DLL -> Spyware.VirtualBouncer : Cleaned with backup
C:\RECYCLER\NPROTECT\00037672.DLL -> Spyware.VirtualBouncer : Cleaned with backup
C:\RECYCLER\NPROTECT\00037693.DLL -> Spyware.VirtualBouncer : Cleaned with backup
C:\RECYCLER\NPROTECT\00037696.DLL -> Spyware.VirtualBouncer : Cleaned with backup
C:\RECYCLER\NPROTECT\00037717.SRG -> Spyware.BargainBuddy : Cleaned with backup
C:\RECYCLER\NPROTECT\00037720.EXE -> TrojanDropper.Agent.hl : Cleaned with backup
C:\RECYCLER\NPROTECT\00037747.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00037780.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00037781.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00037784.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00037785.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00037926.EXE -> TrojanDownloader.Small.aal : Cleaned with backup
C:\RECYCLER\NPROTECT\00037927.EXE -> TrojanDownloader.Small.aal : Cleaned with backup
C:\RECYCLER\NPROTECT\00037942.EXE -> TrojanDownloader.Small.aal : Cleaned with backup
C:\RECYCLER\NPROTECT\00037943.EXE -> TrojanDownloader.Small.aal : Cleaned with backup
C:\RECYCLER\NPROTECT\00038014.EXE -> TrojanDownloader.Small.aal : Cleaned with backup
C:\RECYCLER\NPROTECT\00038019.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00038050.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038052.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038069.exe -> TrojanDropper.Agent.hh : Cleaned with backup
C:\RECYCLER\NPROTECT\00038077.exe -> TrojanDropper.Agent.kd : Cleaned with backup
C:\RECYCLER\NPROTECT\00038079.EXE -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038083.EXE -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038104.TXT -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\RECYCLER\NPROTECT\00038159.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038160.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038162.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038163.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038164.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038165.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038166.TXT -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\RECYCLER\NPROTECT\00038200.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038201.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038202.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038203.EXE -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038206.EXE -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038210.EXE -> Spyware.Hijacker.Generic : Cleaned with backup
C:\RECYCLER\NPROTECT\00038227.ocx -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00038231.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038232.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038233.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038235.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038236.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038237.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038238.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038239.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038240.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038241.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00038242.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00038243.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00038244.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00038245.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00038246.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00038248.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038249.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038250.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038251.TXT -> Spyware.Cookie.Adserver : Cleaned with backup
C:\RECYCLER\NPROTECT\00038252.TXT -> Spyware.Cookie.Adserver : Cleaned with backup
C:\RECYCLER\NPROTECT\00038254.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038255.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038271.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00038283.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038285.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038294.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038295.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038363.TXT -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\RECYCLER\NPROTECT\00038367.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038368.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038369.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038374.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038376.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038377.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038378.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038493.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038495.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038497.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038498.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00038499.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52.dll -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\pcs_0026.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\pcs_0026.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\pcs_0026.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\pcs_0026.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\pcs_0026.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\oqbtubec.exe -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\system\qnguda.exe -> TrojanDownloader.Small.ayh : Cleaned with backup
C:\WINDOWS\system\UpdInst.exe -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cagbkend.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cxtpls_loader.exe -> TrojanDownloader.Apropo.ae : Cleaned with backup
C:\WINDOWS\system32\dgcpcsvc.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dist001.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\WINDOWS\system32\dnloader.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dwactfrm.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\iyudeb.exe -> TrojanDownloader.Agent.ro : Cleaned with backup
C:\WINDOWS\system32\kguser.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\migynth.exe.tcf -> Spyware.Apropos : Cleaned with backup
C:\WINDOWS\system32\mpimtf.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mxnsspc.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mzxparhd.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\NGMOD32.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\nsi8B.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\PSof1.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\system32\rym.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\SSK3_B5 Seedcorn 4.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\thin-138-1-x-x.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\wbpencen.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wintask.exe.tcf -> TrojanDownloader.Small.abd : Cleaned with backup
C:\WINDOWS\system32\wintask.exe8298.tcf -> TrojanDownloader.Small.abd : Cleaned with backup
::Report End
____________________________________________________________
Panda ActiveScan
Incident Status Location
Spyware:spyware/bargainbuddy No disinfected C:\WINDOWS\SYSTEM32\exclean.exe
Adware:adware/afaenhance No disinfected C:\WINDOWS\SYSTEM\QBUninstaller.exe
Adware:adware/bookedspace No disinfected C:\WINDOWS\cfgmgr52.ini
Dialer:dialer.bny No disinfected C:\WINDOWS\pcconfig.dat
Adware:adware/apropos No disinfected C:\PROGRAM FILES\Aprps
Adware:adware/consumeralertsystemNo disinfected C:\PROGRAM FILES\CasStub
Adware:adware/e2give No disinfected C:\PROGRAM FILES\E2G
Spyware:spyware/surfsidekick No disinfected C:\PROGRAM FILES\SurfSideKick 3
Adware:adware program No disinfected C:\WINDOWS\SYSTEM32\cache32dsrf4535dfs
Adware:adware/elitebar No disinfected C:\DOCUMENTS AND SETTINGS\PATRICK\FAVORITES\Casino & Carrers
Adware:adware/delfinmedia No disinfected Windows Registry
Adware:Adware/Apropos No disinfected C:\Documents and Settings\Matt\Local Settings\Temp\auf0.exe
Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Matt\Local Settings\Temp\i7B.tmp
Adware:Adware/DelFinMedia No disinfected C:\Documents and Settings\Matt\Local Settings\Temp\uptodater.exe
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\Matt\Local Settings\Temp\wrapperouter.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\BES3TXA5\webservice[2].htm
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\BES3TXA5\webservice[3].htm
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\CX2PE5MD\casino[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\CX2PE5MD\dating[1].bmp
Adware:Adware/Apropos No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\V9TZVKZE\auto_update[1].txt
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\V9TZVKZE\webservice[3].htm
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\V9TZVKZE\webservice[4].htm
Adware:Adware/Apropos No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\Y305AP8Z\AproposClientInstaller[1].exe
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\Y305AP8Z\drugs[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\Y305AP8Z\virus[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\Y305AP8Z\webservice[2].htm
Hacktool:Hacktool/Processor No disinfected C:\Documents and Settings\Patrick\Desktop\l2mfix\Process.exe
Hacktool:Hacktool/Processor No disinfected C:\Documents and Settings\Patrick\Desktop\l2mfix.exe[Process.exe]
Adware:Adware/Apropos No disinfected C:\Program Files\Aprps\ProxyStub.dll
Adware:Adware/PurityScan No disinfected C:\Program Files\totu\auso.exe
Possible Virus. No disinfected C:\Program Files\TrojanHunter 4.2\Tools\Process Viewer\ProcessViewer.exe
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\system\QBUninstaller.exe
Hacktool:Hacktool/Processor No disinfected C:\WINDOWS\system32\Process.exe
Possible Virus. No disinfected
____________________________________________________________________
Logfile of HijackThis v1.99.1
Scan saved at 7:37:56 PM, on 8/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\aim\aim.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Patrick\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.emachines.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.emachines.comO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWF0dAAA\command.exe (file missing)
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\CX2PE5MD\CWShredder[1].exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
When I ran the Hijack This program in safe mode some of the programs that you told me to get rid of were not there. I ran Hijack This before I ran ewido.
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe