Below are all the scan reports.
Panda scan
Incident Status Location
Possible Virus. No disinfected C:\WINDOWS\SYSTEM32\SHDOCSVC.EXE
Possible Virus. No disinfected C:\WINDOWS\system32\shdocsvc.exe
Virus:W32/Smitfraud.D Disinfected Operating system
Possible Virus. No disinfected C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OSA.exe
Adware:adware/antivirus-gold No disinfected C:\WINDOWS\desktop.html
Adware:adware/psguard No disinfected C:\WINDOWS\warnhp.html
Possible Virus. No disinfected C:\WINDOWS\system32\shdocsvc.exe
Virus:W32/Smitfraud.D Disinfected C:\WINDOWS\system32\wininet.dll
Adware:Adware/PsGuard No disinfected C:\WINDOWS\system32\FF.tmp
Possible Virus. No disinfected C:\WINDOWS\Downloaded Program Files\html.exe
Possible Virus. No disinfected C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP139\A0013345.com
Possible Virus. No disinfected C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP139\A0013347.com
Possible Virus. No disinfected C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013432.exe
Possible Virus. No disinfected C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013434.exe
Possible Virus. No disinfected C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013440.exe
Possible Virus. No disinfected C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013441.exe
Adware:Adware/SAHAgent No disinfected C:\Recycled\NPROTECT\00001744.inf
Possible Virus. No disinfected C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OSA.exe
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\WHO\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-4c2073ff.zip[a.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\WHO\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-4c2073ff.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\WHO\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-4c2073ff.zip[VerifierBug.class]
Hikack this log
Logfile of HijackThis v1.99.1
Scan saved at 11:27:04 PM, on 11/14/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\shdocsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\WINDOWS\System32\NotifyPhoneBook.exe
C:\WINDOWS\System32\atievxx.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
D:\Programs\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdocsvc.dll/blank.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB001" /M "Stylus C45"
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [FHStart] C:\WINDOWS\system32\shdocsvc.exe home
O4 - HKLM\..\RunOnce: [Panda_cleaner_41898] C:\WINDOWS\System32\ActiveScan\pavdr.exe 41898
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: OSA.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
Smitfiles
smitRem © log file
version 2.7
by noahdfear
Microsoft Windows XP [Version 5.1.2600]
The current date is: Mon 11/14/2005
The current time is: 22:25:58.31
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
warnhp.html
desktop.html
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Remaining Post-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
warnhp.html
desktop.html
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
wininet.dll is missing!!
———————————————————
ewido security suite - Scan report
———————————————————
+ Created on: 10:57:10 PM, 11/14/2005
+ Report-Checksum: 838389E4
+ Scan result:
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013448.exe -> Spyware.Raze : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013449.exe -> TrojanDropper.Agent.ri : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013450.exe -> TrojanDownloader.Small.bho : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013451.exe -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013452.DLL -> TrojanDownloader.IstBar.gu : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013453.DLL -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013454.EXE -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013455.exe -> TrojanDownloader.Small.rr : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013456.exe -> Trojan.LowZones.cu : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013460.dll -> TrojanProxy.Small.ct : Cleaned with backup
C:\System Volume Information\_restore{278F9886-8148-4190-BD76-A203A3173F43}\RP140\A0013461.dll -> Trojan.Small.ev : Cleaned with backup
C:\Documents and Settings\WHO\Cookies\who@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\WHO\Cookies\who@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\WHO\Cookies\who@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\WHO\Cookies\who@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\WHO\Cookies\[removed][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
::Report End
P.S. I used Ad aware Professional ver6 instead of the SE 1.06. Is that a problem?