Did all the steps of your previous post.
Still have wthe same issues: about blank popo up, win fixer plus a new one which says:
Retrieval of THotkey failed
Error code 0x00031402,0x00000002
Anyhow here is the Ewido log followed by the HJT log
EWIDO
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 6:53:27 PM, 9/4/2005
+ Report-Checksum: 6E18CD84
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{01198741-DBE0-E6F4-9DBE-877B61FB1D1D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{44A4F449-ADED-A513-8AE7-5A3DDF205F49} -> Spyware.CoolWebSearch : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc102.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc106.txt -> Spyware.Cookie.Weborama : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc11.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc122.txt -> Spyware.Cookie.Lop : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc130.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc16.txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc2.txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc24.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc30.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc31.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc32.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc33.txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc43.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc45.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc65.txt -> Spyware.Cookie.Lop : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc8.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc89.txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\RECYCLER\S-1-5-21-3285162853-4141216190-3951289022-1005\Dc92.txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\WINDOWS\addgx.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\addtf.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\addya.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\apifh32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\apirt.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\apppo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appqj32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\atid.ini:cmonzp -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\atlet.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlnm32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\atlsg.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\bootstat.dat:hmjug -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crjl.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\crxq32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\d3ck.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\d3cl32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\d3yr32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\dahvs.txt:eqwtbm -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\desktop.ini:ehalky -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:dxnlof -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\getwa.dat:evsmfk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\getwa.dat:hhicyd -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:zqveso -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Greenstone.bmp:vygqqp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\hfxkx.txt:azbitg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\hwmbu.dat:susgeh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iepk.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\iepu.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\ieuv.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\iewt.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\ipoo.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\ipun.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\javaij32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\javaqo32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\mfcav32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\mfcfs.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\mfcps32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\mfcwy.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\msvw.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\mszs.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\netvn32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\nthb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntyg32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\n_driyng.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\n_fyxuaw.txt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\n_hdydjc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\n_igobax.txt -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\n_kolrug.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\n_qkshgq.txt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\n_qpflhm.txt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\n_rvjrho.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\n_smsrgk.txt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:hmqxb -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\Prairie Wind.bmp:lqwggl -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\Prairie Wind.bmp:sgtqy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Q329048.log:digmbw -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\qilob.txt:zenana -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\REGLOCS.OLD:rfgnpc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Rhododendron.bmp:wdkzyj -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\River Sumida.bmp:sdvggc -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\Satellite.scr:diobb -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\sbgru.txt:kenmie -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:pedesl -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkve32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\smscfg.ini:xclsxu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\swupdate.ini:qdefze -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\system32:yuaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\system32\addec32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\apidb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\apioq32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\apiru32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\atlls.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\atlyp32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\creq.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\crik32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\crkw32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\crlm.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\croj.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\d3ed32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\d3oj32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\d3ru.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\iewq.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\ipeg.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\iplt32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\ipzo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\javagz.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\javatn.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\mfcry32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\msof32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\netao32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\neter.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\netgw32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\neton.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\netzx.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\ntni.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\ntxk.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\ntyc32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\sdktf32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\sdkwg32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\sdkwy32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\system32\winaz.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\T30DebugLogFile.txt:owuosz -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\Toshiba.bmp:behqvr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Toshiba.bmp:hwmbub -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Toshiba.bmp:szzjsh -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\TSession.reg:wgowmg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\tufbk.txt:lzjomr -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\vbaddin.ini:kgcrhu -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\vbaddin.ini:myhahy -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\vfhsb.txt:wnxpxh -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\vtuhi.dat:chuwjf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\wiaservc.log:ooquzs -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winiq.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\winkg32.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\winzw32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\WMSysPr9.prx:iuwhce -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:bcnmy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:bdelt -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:bdxid -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:bglte -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:bmuvz -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:bomyt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:cflenw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:ckqjh -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:cqomtf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:crgebk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:cwxomo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:dfgakk -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:divuen -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:dmlovr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:dwjrmf -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:eduram -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:emhbp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:erqhvk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:esnwq -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:ewrer -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:ezlla -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:fetud -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:ffzjj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:fqrqgp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:ftjao -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:gjkfwx -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:gmytx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:gtfxih -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:gxynhj -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:havvwi -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:hoqxn -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:ichqtu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:ippjk -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:iturny -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:jgeef -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:jqvhyu -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:kiuqj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:knswyf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:kzipv -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:likpkc -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:lltjsp -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:lqxcta -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:meygx -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:oenwdp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:oqaplo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:oqski -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:oqszbv -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:ormozo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:otycuz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:pbolyj -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:pgjzt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:pyvwn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:qgjiun -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:qibcc -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:qjmxh -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:qniip -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:qsjltw -> Trojan.Agent.em : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:quvsk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:rpsjm -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\WINDOWS\{233D3878-6152-4FE9-9402-AA104326305E}.dat:rrrct -> TrojanDownloader.Agent.bq : Cleaned with backup
::Report End
AND HERE IS THE HJT
Logfile of HijackThis v1.99.1
Scan saved at 6:58:44 PM, on 9/4/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Documents and Settings\Dad\Desktop\Protection\security suite\ewidoctrl.exe
C:\Documents and Settings\Dad\Desktop\Protection\security suite\ewidoguard.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\System32\TDispVol.exe
C:\WINDOWS\System32\TFNF5.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\Downloaded Program Files\UWFX5NetInstaller.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Handspring\HOTSYNC.EXE
C:\Documents and Settings\Dad\Desktop\Protection\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.vuxxgeych...fDszevKlAlu.htmR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.ltozamsrc...kvjR9Pg38Nk.htmR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\vualw.dll/sp.html#12047
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.findin.org/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.toshiba.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {FA742568-1B11-D6C6-83AC-90866C94CAEA} - C:\WINDOWS\ntpc32.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [TSysSMon] c:\toshiba\sysstability\tsyssmon.exe /detect
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\Program Files\Internet Explorer\IEXPLORE.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 03
O4 - HKLM\..\Run: [chin axis manager flag] C:\Documents and Settings\All Users\Application Data\City proc chin axis\Barb Bind.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [NI.UWFX5] "C:\WINDOWS\Downloaded Program Files\UWFX5NetInstaller.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.h.../qdiagh.cab?326O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Documents and Settings\Dad\Desktop\Protection\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Documents and Settings\Dad\Desktop\Protection\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com Personal Firewall Service (MpfService) - McAfee.com Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Thanks