I regularly use Adaware, Spybot abd PC'cillin. Usually with great results, bit this has me stumped. I have followed you "MustRead..." advice and here is my Hijack this and EWIDO logs:
Logfile of HijackThis v1.99.1
Scan saved at 12:29:00 PM, on 8/31/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe
C:\Program Files\Trend Micro\PC-cillin 2003\Pop3trap.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\The Cleaner\tcm.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Documents and Settings\Jerome\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\Pop3trap.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunOnce: [UninstallCOM] C:\WINDOWS\System32\PreUninstallCOM.exe /s
O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4E7BD74F-2B8D-469E-DEFA-EB76B1D5FA7D} - http://eztracks.aava...olbar/eztdl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay10...es/MsnPUpld.cab
O16 - DPF: {5F3B3060-09E0-44C6-86F7-BC7B02B57BEE} - http://downloads.sho...all_cpi1001.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7CDD074F-98A9-4DB4-9DD2-B6F26B5F30DA} (InstallerAX Class) - http://foxmovies.a.c...installerAX.cab
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.snapfish....pfishUpload.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://65.207.219.18...sCamControl.ocx
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterf...ds/Uploader.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.app.../ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.co...aploader_v6.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.micro...rchsettings.cab
O20 - Winlogon Notify: CSCSettings - C:\WINDOWS\system32\guard.tmp (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PC-cillin Personal Firewall (PccPfw) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 11:30:22 AM, 8/31/2005
+ Report-Checksum: 3F5581DE
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -> Spyware.GameSpyArcade : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{41700749-A109-4254-AF13-BE54011E8783} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -> Spyware.GameSpyArcade : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\tsvcin -> Spyware.Look2Me : Cleaned with backup
[1568] C:\Program Files\SurfSideKick 3\SskBho.dll -> Spyware.SurfSide : Cleaned with backup
[2140] C:\Program Files\SurfSideKick 3\SskBho.dll -> Spyware.SurfSide : Cleaned with backup
[2216] C:\Program Files\SurfSideKick 3\SskCore.dll -> Spyware.SurfSide : Cleaned with backup
C:\Documents and Settings\Jerome\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Jerome\Cookies\[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Downloaded Files\hijackthis\backup-20040729-215505-849.dll -> Spyware.OTXMedia : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\Common Files\Java\ftkcpy.cfg -> Spyware.FlashEnhancer : Cleaned with backup
C:\Program Files\Ftk\ftk.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\Program Files\Internet Explorer\Connection Wizard\task32.exe -> TrojanDownloader.Darpa.c : Cleaned with backup
C:\Program Files\SurfSideKick 3\Ssk.exe -> Spyware.SurfSide : Cleaned with backup
C:\Program Files\SurfSideKick 3\SskBho.dll -> Spyware.SurfSide : Cleaned with backup
C:\Program Files\SurfSideKick 3\SskCore.dll -> Spyware.SurfSide : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\gsda.dll -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\icont.exe -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\oplaoact.exe -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\system\UpdInst.exe -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\8gvi7acg.exe -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\system32\alsnt.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\asms.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\autiveds.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\azaol3j31.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\azaqlg1516.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\c2002cdmgf0a2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ceprops.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ckyptdll.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\csyptdll.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cxdxregt.exe -> Trojan.Zx.12 : Cleaned with backup
C:\WINDOWS\system32\d40mled11h0.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\d80m0id1e80.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dequery.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dn4401hqe.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dn4u01h9e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dnn0015me.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dseml.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dwdmo.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\en66l1js1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\fhdrclnr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\gp4sl3h71.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\gpr4l39q1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\h04mlah11d4.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\h0j4la1q1d.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\hcetmon.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\hl4s05h7e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\hr4s05h7e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\hrl8053ue.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\i2lo0c33ef.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\i624lgfq162e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\i6jqlg1516.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\i842liho184c.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\i8jq0i15e8.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\i8nm0i51e8.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\icrtrmgr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ikxrip.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\iM49.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\imclass.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ir4ol5h31.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ivmui.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\izsso.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\j44o0eh3eh4.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\jtno0753e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\k8260ifse8260.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kt28l7fu1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kt82l7lo1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kt86l7ls1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kt8ul7l91.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ktp6l77s1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\l4j80e1ueh.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\l6l60g3se6.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\l6n4lg5q16.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\LeisureBoxInst_ppi1a.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\lvjs0917e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\lvlu0939e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\lvn2095oe.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\m8lsli3718.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mniqtz32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mv8ol9l31.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mvn0l95m1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mvp8l97u1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mvrql9951.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\n28olcl31fq.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\n42u0ef9eh2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\n62ulgf9162.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\nsi12A.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\o4ro0e93eh.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\o8luli3918.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\p04u0ah9ed4.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\p46s0ej7eho.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\pzcn20.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\qBsf.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\s8puli7918.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\somedia.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\splwoa.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\SSK3_B5 Seedcorn 4.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\surobj.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\syimgvw.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\t48ulel91hq.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\uci.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\wxadmoe.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__5vmd29e4.exe -> Adware.Saha : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__pvdxregx.exe -> Trojan.Zx.12 : Cleaned with backup
C:\WINDOWS\Temp\w181609.Stub.exe -> TrojanDownloader.Delmed.a : Cleaned with backup
C:\WINDOWS\Temp\zxinst12.exe -> Trojan.Zx.12 : Cleaned with backup
::Report End
Any help will be greatly appreciated!
thanks
scott