k. did that. here is the scan file:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:25:09 PM, 11/5/2005
+ Report-Checksum: EECCE64
+ Scan result:
HKLM\SOFTWARE\Classes\MediaPassX.Installer\CLSID\\ -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MediaPassX.dll\\.Owner -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MediaPassX.dll\\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -> Spyware.WinFavorites : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{BE8D0059-D24D-4919-B76F-99F4A2203647} -> Spyware.EliteBar : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Explorer Bars\{BE8D0059-D24D-4919-B76F-99F4A2203647} -> Spyware.EliteBar : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\1245516_500_176_12736_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\131280_2588_536_3684_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\1376544_2588_536_13996_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\196794_1788_484_4600_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\262290_832_1828_2676_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\262290_832_1828_4344_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\262414_7656_712_7884_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\327762_760_1828_2744_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\328224_8808_1300_8964_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\393488_876_1828_2656_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\459134_876_1828_4368_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\f1278828.exe -> TrojanDownloader.Qoologic.ac : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\i1E1.tmp -> Spyware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\i4.tmp -> Spyware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\k_26AF.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\k_4903.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\k_A97E.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\ms1B.tmp -> TrojanDropper.Agent.hn : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\un2.tmp -> Spyware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\uninstall.exe -> TrojanDownloader.IstBar.gi : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LN4NYHAA\mm[1].js -> Spyware.Chitika : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LN4NYHAA\mtrslib2[1].js -> TrojanDownloader.Small.ag : Cleaned with backup
C:\HJT\backups\backup-20050531-211927-993.dll -> Spyware.WinAD : Cleaned with backup
C:\Install.exe/trufkz.html -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Install.exe/x.bat -> Trojan.LowZones.f : Cleaned with backup
C:\Install.exe/kans.reg -> Trojan.WinREG.LowZones.f : Cleaned with backup
C:\Install.exe/kansup.reg -> Trojan.WinREG.LowZones.f : Cleaned with backup
C:\kans.reg -> Trojan.WinREG.LowZones.f : Cleaned with backup
C:\kansup.reg -> Trojan.WinREG.LowZones.f : Cleaned with backup
C:\Program Files\Cas\Client\casmf.dll -> Spyware.CASClient : Cleaned with backup
C:\Program Files\CasStub\casstub.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\temp\salmhook.dll -> Spyware.180Solutions : Cleaned with backup
C:\trufkz.html -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\miniclipGameLoader.dll -> Spyware.Retro64 : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\pcs_0031.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup
C:\WINDOWS\gbgptqq.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\93_app13.exe -> TrojanDropper.Agent.xw : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UTKZ1Z9Y\protector_update[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WH6X9WS9\protector_update[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\dist001.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\WINDOWS\system32\docnnnr.exe -> TrojanDownloader.Qoologic.ac : Cleaned with backup
C:\WINDOWS\system32\ebdnn.dll -> TrojanDownloader.Qoologic.ac : Cleaned with backup
C:\WINDOWS\system32\fgdjjjk.dll -> TrojanDownloader.Qoologic.ac : Cleaned with backup
C:\WINDOWS\system32\installer216.exe -> TrojanDownloader.Qoologic.al : Cleaned with backup
C:\WINDOWS\system32\msdioo.exe -> Trojan.Small.i : Cleaned with backup
C:\WINDOWS\system32\MTE2ODM6ODoxNg.exe -> Spyware.ISearch : Cleaned with backup
C:\WINDOWS\system32\sav2.exe -> TrojanDownloader.Agent.vp : Cleaned with backup
C:\WINDOWS\system32\SSK3_B5 Seedcorn 4.exe -> TrojanDropper.Small.qn : Cleaned with backup
C:\WINDOWS\system32\wvqaa.dat -> TrojanDownloader.Qoologic.ac : Cleaned with backup
C:\WINDOWS\tbzthle.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\x.bat -> Trojan.LowZones.f : Cleaned with backup
::Report End
k. that went fine. here is the new hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 9:37:04 PM, on 11/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM95\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [SpyBlocker] C:\Program Files\SpyBlocker Software\spyblocker.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) -
http://www.miniclip....pGameLoader.dllO16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) -
http://www.shockwave...mjolauncher.cabO16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) -
http://a532.g.akamai...0/Installer.exeO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://anu.popcap.co...aploader_v6.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG6 Service (AvgServ) - GRISOFT s.r.o - C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
thanks
-christine