---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:05:10 PM, 24/08/2005
+ Report-Checksum: BF08BF9E
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{7C559105-9ECF-42b8-B3F7-832E75EDD959} -> Spyware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\ISTx.Installer -> Spyware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\ISTx.Installer\CLSID -> Spyware.ISTBar : Ignored
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/istactivex.dll -> Spyware.ISTBar : Ignored
C:\WINDOWS\system32\lsfixss.exe -> Backdoor.Rbot : Ignored
C:\Documents and Settings\Yun-Yun\Local Settings\Temporary Internet Files\Content.IE5\W23L2R5Z\piks[1].ru -> Trojan.LowZones.bh : Ignored
C:\Documents and Settings\Yun-Yun\Local Settings\Temporary Internet Files\Content.IE5\EOJ2ID5R\pics[1].ru -> Spyware.Hijacker.Generic : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\
[email protected][2].txt -> Spyware.Cookie.Liveperson : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@statcounter[1].txt -> Spyware.Cookie.Statcounter : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@overture[2].txt -> Spyware.Cookie.Overture : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@atdmt[2].txt -> Spyware.Cookie.Atdmt : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@revenue[1].txt -> Spyware.Cookie.Revenue : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\
[email protected][1].txt -> Spyware.Cookie.Advertising : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@advertising[1].txt -> Spyware.Cookie.Advertising : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@xxxtoolbar[2].txt -> Spyware.Cookie.Xxxtoolbar : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\
[email protected][2].txt -> Spyware.Cookie.Pointroll : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\
[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@fastclick[2].txt -> Spyware.Cookie.Fastclick : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\
[email protected][1].txt -> Spyware.Cookie.Webtrendslive : Ignored
C:\Documents and Settings\Yun-Yun\Cookies\yun-yun@2o7[2].txt -> Spyware.Cookie.2o7 : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0001488.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0001496.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0003497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0004496.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0004497.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0005496.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0005497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0006496.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0006497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0007496.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0007497.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0008496.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0008497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0009496.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0009497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0011496.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0011497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0012497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0012498.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0013496.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0013497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0014499.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0014500.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0015496.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0015497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0016496.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0016497.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0019496.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0020501.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0020502.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0023510.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0023511.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0023512.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0024494.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0024495.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0027497.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0027498.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP4\A0027499.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP5\A0028509.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP5\A0028510.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP5\A0028515.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP5\A0028516.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0034224.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0034225.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0035065.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0035066.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0036065.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0036066.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0037065.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0037066.exe -> Spyware.Hijacker.Generic : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0038066.exe -> Trojan.LowZones.bh : Ignored
C:\System Volume Information\_restore{E1BE2210-8E1A-4C78-9101-12B73DCE7C6E}\RP6\A0038067.exe -> Spyware.Hijacker.Generic : Ignored
C:\drivelog.exe -> Spyware.Hijacker.Generic : Ignored
C:\msdc0m.exe -> Trojan.LowZones.bh : Ignored
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 9:08:49 PM, on 24/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
C:\WINDOWS\System32\lsfixss.exe
C:\WINDOWS\System32\jswTss.exe
C:\WINDOWS\System32\ccApp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFAGENT.EXE
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Documents and Settings\Yun-Yun\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
O4 - HKLM\..\Run: [BnCtest] lsfixss.exe
O4 - HKLM\..\Run: [Sonytest] jswTss.exe
O4 - HKLM\..\Run: [Service] ccApp.exe
O4 - HKLM\..\RunServices: [BnCtest] lsfixss.exe
O4 - HKLM\..\RunServices: [Sonytest] jswTss.exe
O4 - HKLM\..\RunServices: [Service] ccApp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcaf...84/mcinsctl.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcaf...,21/mcgdmgr.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe