hi Sari,
here are my logs:
HijackthisLogfile of HijackThis v1.99.1
Scan saved at 12:53:34 PM, on 4/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Documents and Settings\HP_Administrator\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} -
http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} -
http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} -
http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcaf...01/mcinsctl.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcaf...,26/mcgdmgr.cabO23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Panda ActivescanIncident Status Location
Adware:Adware/PurityScan Not disinfected C:\PROGRAM FILES\SCTA\CEUM.EXE
Spyware:spyware/surfsidekick Not disinfected C:\WINDOWS\SYSTEM32\bk.exe
Adware:adware/adlogix Not disinfected C:\WINDOWS\SYSTEM32\guarnset.exe
Adware:adware/emediacodec Not disinfected C:\WINDOWS\SYSTEM32\ldD90A.tmp
Adware:adware/maxifiles Not disinfected C:\WINDOWS\SYSTEM32\mmxp2passion.exe
Spyware:spyware/marketscore Not disinfected C:\WINDOWS\SYSTEM32\rk.bin
Adware:adware/secure32 Not disinfected C:\secure32.html
Adware:adware/dollarrevenue Not disinfected C:\WINDOWS\drsmartloadb1.dat
Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\uniq
Adware:adware/yazzlesudoku Not disinfected C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Yazzle Sudoku
Adware:adware/fchelp Not disinfected C:\PROGRAM FILES\EQAdvice
Potentially unwanted tool:application/winantivirus2006 Not disinfected C:\PROGRAM FILES\WinAntiVirus Pro 2006
Adware:adware/mediatickets Not disinfected Windows Registry
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\awtsp.dll
Virus:Trj/sosmyn.A Not disinfected C:\!KillBox\errorhandler.exe
Virus:Trj/Downloader.AYV Not disinfected C:\!KillBox\expload.exe
Virus:Trj/Downloader.AYV Not disinfected C:\!KillBox\real.exe
Spyware:Spyware/Dluca Not disinfected C:\!KillBox\wzdmg.exe
Virus:Trj/VB.KN Not disinfected C:\31567.exe
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\HP_Administrator\Desktop\backups\backup-20060330-065755-241.dll
Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\compwiz.exe
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{0D284675-137A-4B6A-ABC0-364F522CE88C}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{1AC3099B-0C15-4DE8-9C92-6286CE55CE1A}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{23516497-DDBE-47F0-AE67-C021F49D452E}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{2628238C-6A4B-4467-AFA0-6BAAF155D37A}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{57416304-E05F-40F5-A252-72A4CAA79E24}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{7EB81A24-2F2E-4D24-AC43-C34F8C80E7E2}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{8343E55F-785A-4BC3-B684-FCAA85C9C092}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{A9C50331-63B2-4909-9460-CCB7D0ADB347}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{B03CC8F6-5D16-4BEB-850B-80E850F1960C}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{C3893CAD-2FC1-4566-84DD-50B5058CFD04}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{D242FE06-015B-4F0A-B4EA-02FAFCCE83B6}.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{D88DAE1B-819F-450F-8754-2157EC8BA229}.dll
Spyware:Spyware/Overpro Not disinfected C:\Program Files\MediaPipe\insdl.dll
Spyware:Spyware/Overpro Not disinfected C:\Program Files\MediaPipe\register.dll
Adware:Adware/PurityScan Not disinfected C:\Program Files\scta\ceum.exe
Adware:Adware/PurityScan Not disinfected C:\Program Files\Yazzle Sudoku\uninstaller.exe
Adware:Adware/PurityScan Not disinfected C:\Veracruz.exe
Virus:Trj/SCBop.E Not disinfected C:\WINDOWS\CheckS02.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\IA\KE.vbs
Spyware:Spyware/DCToolbar Not disinfected C:\WINDOWS\keyboard5.exe
Adware:Adware/ConsumerAlertSystem Not disinfected C:\WINDOWS\lvcshmdA.exe
Adware:Adware/DigInk Not disinfected C:\WINDOWS\pf78bb.exe
Virus:Bck/Sanyn.N Not disinfected C:\WINDOWS\sys0396137000-17.exe
Virus:Trj/Downloader.AYV Not disinfected C:\WINDOWS\system32\2.exe
Adware:Adware/Adservice Not disinfected C:\WINDOWS\system32\AdService.dll
Virus:Trj/Haxdoor.HY Not disinfected C:\WINDOWS\system32\directprt.sys
Dialer:Dialer.FKM Not disinfected C:\WINDOWS\system32\dmm.exe
Adware:Adware/AdLogix Not disinfected C:\WINDOWS\system32\hhagyei.sys
Adware:Adware/AdLogix Not disinfected C:\WINDOWS\system32\hoiiyff.vxd
Adware:Adware/AdLogix Not disinfected C:\WINDOWS\system32\kgwwbc.exe
Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\ldD90A.tmp
Virus:Trj/Downloader.CIM Not disinfected C:\WINDOWS\system32\mmxp2passion.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\m?config.exe
Virus:Trj/Downloader.AYV Not disinfected C:\WINDOWS\system32\pre1.exe
Virus:Trj/Downloader.AYV Not disinfected C:\WINDOWS\system32\pre2.exe
Virus:Trj/Agent.BPC Not disinfected C:\WINDOWS\system32\swinosag.exe
Adware:Adware/Zeno Not disinfected C:\WINDOWS\system32\swinosap.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\S?mantec\S?mantec\!update-3655.0000
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\S?mantec\wuaclt.exe
Adware:Adware/AdLogix Not disinfected C:\WINDOWS\system32\unpack.exe
Adware:Adware/AdLogix Not disinfected C:\WINDOWS\system32\wizqec.exe
Adware:Adware/AdLogix Not disinfected C:\WINDOWS\system32\wizqed.exe
Virus:Trj/Haxdoor.HY Not disinfected C:\WINDOWS\system32\__delete_on_reboot__directpt.dll
Adware:Adware/Zenosearch Not disinfected C:\ZICORN001.exe
___________________________________________
again, thanks for all this help!