thanks for your help sam
heres the two logs
Logfile of HijackThis v1.99.1
Scan saved at 9:24:48 AM, on 4/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\GetRight\getright.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Rob\My Documents\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.medion.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.aldi.comO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1601.0\msgr.en-us.en-au\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com
O16 - DPF: {0D62A517-E7C6-4E1F-A577-07D4AC549A48} (Progetto1.int_ver32) -
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zon...er.cab31267.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1097053507402O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cabO16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) -
http://messenger.zon...ot.cab31267.cabO16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) -
http://67.15.101.3/g...d8_2_0_0_23.cabO16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C2} (GameDesire Pool 9) -
http://67.15.101.3/g...d9_2_0_0_22.cabO16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) -
http://67.15.101.3/g...er_2_0_0_21.cabO18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:21:52 AM, 4/10/2005
+ Report-Checksum: 9A7F368A
+ Scan result:
HKLM\SOFTWARE\Classes\CtxPopup.IEObject -> Adware.CtxPopup : Cleaned with backup
HKLM\SOFTWARE\Classes\CtxPopup.IEObject\CLSID -> Adware.CtxPopup : Cleaned with backup
HKLM\SOFTWARE\Classes\CtxPopup.IEObject\CurVer -> Adware.CtxPopup : Cleaned with backup
HKLM\SOFTWARE\Classes\CtxPopup.IEObject.1 -> Adware.CtxPopup : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/internazionale_ver10.ocx\\.Owner -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/internazionale_ver10.ocx\\{AD0B8220-7DA4-4C0A-8532-B25A9F631D3D} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/objsafe.tlb\\.Owner -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/objsafe.tlb\\{AD0B8220-7DA4-4C0A-8532-B25A9F631D3D} -> Dialer.Generic : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\t2iww59j.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\rob@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\
[email protected][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\rob@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\rob@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\
[email protected][2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\rob@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\rob@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\
[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\rob@paycounter[2].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\
[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\rob@spylog[2].txt -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\rob@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Rob\Cookies\rob@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Rob\Local Settings\Temp\ICD10.tmp\internazionale_ver11.ocx -> Spyware.AdPowerZone : Cleaned with backup
C:\Documents and Settings\Rob\Local Settings\Temp\ICD11.tmp\internazionale_ver15.ocx -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Rob\Local Settings\Temp\ICD3.tmp\internazionale_ver10.ocx -> Spyware.AdPowerZone : Cleaned with backup
C:\Documents and Settings\Rob\Local Settings\Temp\ICD6.tmp\internazionale_ver10.ocx -> Spyware.AdPowerZone : Cleaned with backup
C:\Documents and Settings\Rob\Local Settings\Temp\ICD7.tmp\internazionale_ver10.ocx -> Spyware.AdPowerZone : Cleaned with backup
C:\Documents and Settings\Rob\Local Settings\Temp\ICD8.tmp\internazionale_ver10.ocx -> Spyware.AdPowerZone : Cleaned with backup
C:\Documents and Settings\Rob\Local Settings\Temp\ICD9.tmp\internazionale_ver11.ocx -> Spyware.AdPowerZone : Cleaned with backup
C:\Documents and Settings\Rob\My Documents\hijackthis\backups\backup-20050515-181335-135.dll -> Spyware.AdPowerZone : Cleaned with backup
C:\Documents and Settings\Rob\My Documents\hijackthis\backups\backup-20050515-181335-488.dll -> Spyware.AdPowerZone : Cleaned with backup
C:\Documents and Settings\Rob\My Documents\hijackthis\backups\backup-20050912-021416-991.dll -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Rob\My Documents\hijackthis\backups\backup-20051001-135537-261.dll -> Spyware.CtxPop : Cleaned with backup
C:\Documents and Settings\Rob\My Documents\sheep\gck_exile11.zip/start.exe -> TrojanDownloader.IstBar : Cleaned with backup
C:\Documents and Settings\Rob\My Documents\stuff\4PLAY_v5[1].0.19\crackit_v1.016.exe -> TrojanDownloader.IstBar.lu : Cleaned with backup
C:\Program Files\4play 50\crackit_v1.016.exe -> TrojanDownloader.IstBar.lu : Cleaned with backup
C:\Program Files\Common Files\owfi\owfia.exe -> TrojanDownloader.TSUpdate.l : Cleaned with backup
C:\Program Files\Common Files\owfi\owfip.exe -> Spyware.Xupiter : Cleaned with backup
C:\Program Files\SideFinda\sfbho.dll_tobedeleted_tobedeleted -> Spyware.SideFind : Cleaned with backup
::Report End