Ok. Here is the Ewido Scan log:
---------------------------------------------------------??
ewido security suite - Scan report??
---------------------------------------------------------??
??
+ Created on: 6:01:02 PM, 10/23/2005??
+ Report-Checksum: DAAC2922??
??
+ Scan result:??
??
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup??
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup??
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup??
HKU\S-1-5-21-1004336348-492894223-764733703-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup??
HKU\S-1-5-21-1004336348-492894223-764733703-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} -> Spyware.MoneyTree : Cleaned with backup??
HKU\S-1-5-21-1004336348-492894223-764733703-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -> Spyware.BargainBuddy : Cleaned with backup??
HKU\S-1-5-21-1004336348-492894223-764733703-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE188402-6EE7-4022-8868-AB25173A3E14} -> Spyware.BargainBuddy : Cleaned with backup??
HKU\S-1-5-21-1004336348-492894223-764733703-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\owner@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\owner@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\owner@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup??
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\!update.exe -> Backdoor.Rbot : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\131742_2896_2324_2904_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\i3D5.tmp -> Spyware.SurfSide : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_1C72.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_1EEF.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_25F0.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_39CE.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_39E.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_983A.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_AB11.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_C6DD.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_CF5B.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_D023.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_D39E.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_DA12.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_DA7E.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_F791.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temp\k_FF17.tmp -> Trojan.EliteBar.a : Cleaned with backup??
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\K1GX250N\!update-2695[1].0000 -> Backdoor.Rbot : Cleaned with backup??
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup??
C:\WINDOWS\ru.exe -> Spyware.PurityScan : Cleaned with backup??
C:\WINDOWS\system32\oins.exe -> Spyware.MediaTickets : Cleaned with backup??
??
??
::Report End
-----------------------------------------------------------------------------------------------------------
And the HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 6:06:15 PM, on 10/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\ups.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\Common Files\AOL\1108571488\ee\AOLHostManager.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\HPHipm11.exe
C:\Program Files\Common Files\AOL\1108571488\ee\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
c:\program files\common files\aol\1108571488\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1108571488\ee\AOLServiceHost.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1108571488\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~2\Office\1033\phdintl.dll/phdContext.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aol.com...kup/qdiagcc.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
https://objects.aol....83/mcinsctl.cabO16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) -
http://www.costcopho...ostcoUpload.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
https://objects.aol....,20/McGDMgr.cabO16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://moviefone.kon...ry/main/kdx.cabO20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
----------------------------------
So? Are we clean? Are we clean?