This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Check my log please...?

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First time HiJackThis user here. I know I have some carp** on my comp, not sure what I should keep and remove, can someone help me out. Cheers.

My Log:

Logfile of HijackThis v1.99.1
Scan saved at 19:18:23, on 24/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BitTornado\btdownloadgui.exe
C:\PROGRA~1\MOZILL~1\firefox.exe
C:\Documents and Settings\Nav\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.btbroadbandstart.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Global Startup: SATARaid.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F49B338B-DF77-4710-AE20-ED29E277DADB}: NameServer = 194.72.0.98 194.72.9.38
O18 - Protocol: msnim - 0 - (no file)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: FireDaemon Service: winsecure (winsecure) - Unknown owner - C:\WINDOWS\security\FireDaemon.exe (file missing)
Please download Mwav.
Doubleclick the file.

This scan takes around 3 hours to finish when set to scan everything.

Put a check next to the items below before scanning:

*Memory
*Startup Folders
*Drive - All Local Drives
*Folder - then click "browse" to change the directory to C: (default is C:\Windows)
*Registry
*System Folders
*Services
*Include Sub-Directory
*Scan All Files

Please make sure ALL of these are checked, then press the scan button. This will take hours to complete.

**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run.

Highlight the portion of the scan that lists infected items and hold CTRL + C to Copy then paste it here. The whole log with be extremely big so there is no way to copy the whole thing. I just need the infected items list.
^Thanks for that mate. this is what I got for the virus log: Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "redv Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "redv Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cydoor.topicks.a Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Ahead\NeroDigital\settings.xml". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero Recode\Recode-Deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\system32\cmmgr32.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\HydraVision" refers to invalid object "C:\Program Files\ATI Technologies\ATI HydraVision\HydraVision". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE" refers to invalid object "C:\Program Files\Messenger\msmsgs.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\setup.exe" refers to invalid object "C:\Program Files\ATI Technologies\ATI Control Panel\setup.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Trend Micro\PC-cillin 2002\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Trend Micro\". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".cue". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".lwtp". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".mdmp". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rjs". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rjt". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object "OpenWithList". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "NVIDIA nForce Drivers". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "RealPlayer 6.0". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{3248F0A8-6813-11D6-A77B-00B0D0150010}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B6F867E8-F092-4C5E-7D72-AC7057DBEF45}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{C90F3E44-3BF6-11D4-A110-00500405613A}". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0A346871-C8AA-4D8D-B665-4906C9BF371C}" refers to invalid object "C:\Program Files\AVSMedia\VideoConverter3\NCTVideoCompress.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{24B53040-3A78-4D52-A6C9-9B84A3D75DF8}" refers to invalid object "C:\Program Files\AVSMedia\VideoConverter3\NCTVideoCompress.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{2B7E6AA9-C4FA-4951-815B-4AFE39D81453}" refers to invalid object "C:\Program Files\Messenger\msgsc.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{A1031BAF-3039-4dd6-BC5E-522F007DAF8B}" refers to invalid object "C:\Program Files\Messenger\msmsgs.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{AB1D8565-40E9-4616-984D-98465687E82C}" refers to invalid object "C:\Program Files\Messenger\msgsc.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B69003B3-C55E-4b48-836C-BC5946FC3B28}" refers to invalid object "C:\Program Files\Messenger\msgsc.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BBBFCB14-3B21-491c-9E2A-B0F3D50F83FD}" refers to invalid object "C:\Program Files\Messenger\msgsc.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BC20CB75-A981-460e-81D4-F06F61B59247}" refers to invalid object "C:\Program Files\Messenger\msmsgs.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{c0164c20-33c8-4f60-bfd1-557e08a93f58}" refers to invalid object "C:\Program Files\MSN\MSNCoreFiles\OOBE\obemetal.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DF66AFC9-C61D-404a-B535-64FBF91D420F}" refers to invalid object "C:\Program Files\Messenger\msgsc.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E0B8F398-BB08-4298-87F0-34502693902E}" refers to invalid object ""C:\Program Files\Messenger\msmsgs.exe"". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E3A3B1D9-5675-43c0-BF04-37BE11939FB7}" refers to invalid object "C:\Program Files\Messenger\msgsc.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{ec48db94-98df-4c2f-932f-bbc28af0a316}" refers to invalid object "C:\Program Files\MSN\MSNCoreFiles\OOBE\obemetal.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F3A614DC-ABE0-11d2-A441-00C04F795683}" refers to invalid object "C:\Program Files\Messenger\msmsgs.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{FB7199AB-79BF-11d2-8D94-0000F875C541}" refers to invalid object "C:\Program Files\Messenger\msgsc.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{00CEDBF1-864D-11D3-908D-00C0F03B3EDC}" refers to invalid object "C:\Program Files\Real\RealPlayer\ierjplug.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{218CB45F-20B6-11d2-8E17-0000F803A446}" refers to invalid object "C:\Program Files\Messenger\msmsgs.exe". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{3201590C-8C63-4558-8142-82C29FC695E9}" refers to invalid object "C:\Program Files\Messenger\msmsgs.exe". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{405DE7B2-E7DD-11D2-92C5-00C0F01F77C1}" refers to invalid object "C:\Program Files\Real\RealPlayer\rpau3260.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{47F59201-8783-11D2-8343-00A0C945A819}" refers to invalid object "C:\Program Files\Internet Explorer\PLUGINS\RichFX\Player\nprfxins.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{53CED51D-432B-45b2-A3E0-0CE2C24235D4}" refers to invalid object "C:\Program Files\Messenger\msmsgs.exe". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{A67004E0-8362-42F9-B186-88706C346DD9}" refers to invalid object "C:\Program Files\Real\RealPlayer\rpplugins\ierpplug.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{ABB1251C-F0AB-4468-AF66-ABC79ABA7BC6}" refers to invalid object "C:\Program Files\AVSMedia\VideoConverter3\NCTVideoCompress.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{E02AD29E-80F5-46c6-B416-9B3EBDDF057E}" refers to invalid object "C:\Program Files\Messenger\msmsgs.exe". Action Taken: No Action Taken. Entry "HKCR\.sll" refers to invalid object "SSLFile". Action Taken: No Action Taken. Entry "HKCR\Connection Manager Profile\shell\open\command" refers to invalid object "C:\WINDOWS\system32\CMMGR32.EXE "%1"". Action Taken: No Action Taken. Entry "HKCR\DBC.MPEG.1\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\LiveUpdate.MIDI.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\RealJukebox.CDA.1\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealJukebox.wma.1\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.3GPP2.10\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.3GPP_AMR.10\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.AAC.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.AIFF.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.AMR.10\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.AMR_WB.10\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.AU.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.AVI.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MP2.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MP3.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MP3PL.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MP4.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MPA.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MPEG.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.qt.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.SDP.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.WAV.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.wax.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.wm.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.wmf.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.wmv.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.wmx.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.wvx.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\4B833905.exe tagged as not-a-virus:RemoteAdmin.Win32.NetClient.a. No Action Taken. File C:\System Volume Information\_restore{28DB04BD-6A44-465C-A124-11EA9D9FA0BF}\RP1\A0000064.exe tagged as not-a-virus:RemoteAdmin.Win32.NetCat.110. No Action Taken. File C:\WINDOWS\security\logs\nc.exe tagged as not-a-virus:RemoteAdmin.Win32.NetCat.110. No Action Taken. File C:\WINDOWS\security\logs\nc.exe tagged as not-a-virus:RemoteAdmin.Win32.NetCat.110. No Action Taken.
Please download Ewido Security Suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    • You will need to step through the process of cleaning files one-by-one.
    • If ewido detects a file you KNOW to be legitimate, select none as the action.
    • DO NOT select "Perform action on all infections"
    • If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")
I'm not sure if you wanted me to post the report or not but here it is anyway: ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 12:49:24, 26/11/2005 + Report-Checksum: A55DD997 + Scan result: HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup :mozilla.13:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.22:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.23:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.26:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.28:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.29:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.52:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.53:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.54:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.55:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.56:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d4qf23g7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup C:\Documents and Settings\Dad\Cookies\dad@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\Dad\Cookies\dad@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup C:\Documents and Settings\Dad\Cookies\[removed][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\Documents and Settings\Dad\Cookies\dad@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.15:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.36:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.37:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.38:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.39:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.40:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.45:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.47:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.48:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.49:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.50:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.55:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.58:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.72:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.73:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.74:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.79:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.80:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.81:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.82:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.83:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.84:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.85:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.88:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup :mozilla.89:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup :mozilla.92:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup :mozilla.93:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup :mozilla.97:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.100:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.104:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.106:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.107:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.108:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.109:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.111:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.115:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.125:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.126:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.127:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.145:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.146:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.147:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.148:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.158:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.159:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.164:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.195:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup :mozilla.215:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.216:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.217:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.218:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.231:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup :mozilla.233:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup :mozilla.234:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup :mozilla.235:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup :mozilla.236:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup :mozilla.237:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.238:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.239:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.249:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.250:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.251:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.252:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.253:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.264:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.265:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.266:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.267:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.268:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.269:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.270:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.271:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.272:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.332:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.333:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.334:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\wfbn4x7z.Nav\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.6:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.7:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.8:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.9:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.14:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup :mozilla.15:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup :mozilla.16:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup :mozilla.23:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.26:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.27:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.28:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.29:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.30:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.31:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.34:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.35:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.37:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.68:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.82:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.83:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.84:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.85:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.86:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.87:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.88:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.89:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.90:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.91:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup :mozilla.95:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup :mozilla.96:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.97:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.103:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.104:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.105:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.106:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.107:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.108:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.109:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.120:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.121:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.131:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.132:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.133:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.134:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.135:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.136:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.137:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.138:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.173:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup :mozilla.174:C:\Documents and Settings\Nav\Application Data\Mozilla\Firefox\Profiles\yu8duf2h.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup C:\Documents and Settings\Nav\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.6:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.7:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.8:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.9:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.10:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.11:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.12:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.19:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.50:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.51:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.52:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.78:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.79:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.80:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.81:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.82:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.83:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.106:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.120:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.121:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.128:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.129:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.130:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.134:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.136:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.151:C:\Documents and Settings\Satinder\Application Data\Mozilla\Firefox\Profiles\ae30bf2o.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup ::Report End
Logfile of HijackThis v1.99.1
Scan saved at 14:48:08, on 26/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BitTornado\btdownloadgui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\K-Lite Codec Pack\bsplayer\bsplayer.exe
C:\Documents and Settings\Nav\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.btbroadbandstart.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Global Startup: SATARaid.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F49B338B-DF77-4710-AE20-ED29E277DADB}: NameServer = 194.72.0.98 194.72.9.38
O18 - Protocol: msnim - 0 - (no file)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: FireDaemon Service: winsecure (winsecure) - Unknown owner - C:\WINDOWS\security\FireDaemon.exe (file missing)


FYI: I uninstalled Norton and installed Kaspersky Anti-Virus
Not bad, mate. Better actually. Just got one question, what programs do you recommend using to get rid of spyware/malware/virus the whole works? Thanks for all the help so far, really appreciate it!
Actually there is one thing that is bugging me, not sure if you can help or not. Whenever I delete something in my 'Shared Documents' it still shows the item I have deleted, I always have to refresh to see if it's gone or not. when I refresh it's usually gone. any ide aof whats going on? :huh:
Make sure you keep your Windows OS current by visiting Windows update
Also download, install and keep updated- Antivirus Software (and use only one):
Free for home users:
AVG free version I like this one.

Many exploits are directed at Internet Explorer, you dont have to use it. Try a different browser:
Like Firefox,
And Thunderbird for controling spam in your e-mail.

Install a firewall.
Zone Alarm
I use both.
Download, install and update before using:
Ad-Aware SE Personal edition
Spybot Search and destroy
Becarful with spyware "removers and scanners"– there are many "rogue/suspect" programs that "claim to remove" spyware.

Other programs to consider:
SpywareBlaster
IE-SPYAD

AntiTrojan software to fill in the gap:
a2 free


Wish there was only one program needed.

Actually there is one thing that is bugging me, not sure if you can help or not.

Whenever I delete something in my 'Shared Documents' it still shows the item I have deleted, I always have to refresh to see if it's gone or not. when I refresh it's usually gone.
any ide aof whats going on? :huh:

Have not got a clue. :blink: Sorry
Running more than one AV will use up all of your memory when one AV finds and quarantines a file the other is trying to get rid. Sorry I didn't see that in your log.

Running more than one of these at a time can cause system crashes, high system usage and/or conflicts with each other.*

So Tony Kline says

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI