OK, done as said. I noticed Ewido found something as soon as I rebooted normally, which it cleaned. I have also received a pop up browser screen.
Here is my Ewido log, followed by the new Hijack This log:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 11:09:38 PM, 12/25/2005
+ Report-Checksum: 3D124F69
+ Scan result:
HKLM\SOFTWARE\Need2Find -> Spyware.Need2Find : Cleaned with backup
HKLM\SOFTWARE\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
HKLM\SOFTWARE\Need2Find\bar\Partner -> Spyware.Need2Find : Cleaned with backup
[656] C:\WINDOWS\system32\assldpc.dll -> Spyware.Look2Me : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Grand Master HooHa\Application Data\Mozilla\Firefox\Profiles\j6sc3o9q.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\Cookies\grand master hooha@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\Cookies\grand master hooha@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\Cookies\grand master hooha@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\Cookies\grand master hooha@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\Cookies\grand master hooha@coxhsi.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\Cookies\grand master hooha@e-2dj6wfkigiczadq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\Cookies\grand master hooha@e-2dj6wjkykkcjcfo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\Cookies\grand master hooha@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\Cookies\grand master hooha@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temp\E9E3CF.tmp/Quicklinks.exe -> Adware.MDH : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\4DUZ0H63\toolbar[1].txt -> Downloader.Adload.j : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\C5QN0LYF\tool1[1].txt -> Trojan.Small : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\GL2Z8HQV\country[1].htm -> Trojan.Small : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\GL2Z8HQV\hosts[1].txt -> Trojan.Qhost.el : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\IJYBC54Z\9400[1].cab/Quicklinks.exe -> Adware.MDH : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\K16V492N\ltndload[1].dll -> Adware.Sud : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\K16V492N\tool4[1].txt -> Trojan.Small : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\KNS9ERMT\drsmartload[1].exe -> Downloader.Adload.l : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\Q5NW5G3Q\installerus[1].exe -> Downloader.Qoologic.at : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\Q9TY3E5O\mm[2].js -> Spyware.Chitika : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\RQ43BT4P\ltndmain[1].dll -> Adware.Sud : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\RQ43BT4P\tool5[1].txt -> Trojan.Small : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\T4KVL5GL\inst_0004[1].exe -> Downloader.Small.cam : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\WDULKH6F\mir[1].exe -> Proxy.Wopla.n : Cleaned with backup
C:\Documents and Settings\Grand Master HooHa\Local Settings\Temporary Internet Files\Content.IE5\XBJ7TXO2\tool2[1].txt -> Hijacker.Spywad.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\146FCFE3-4119-455F-97FB-1885B3\08C3403D-9286-4944-976A-AA91F4 -> Downloader.Qoologic.az : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\146FCFE3-4119-455F-97FB-1885B3\240C7529-B1E6-446E-B596-6E71A1 -> Downloader.Qoologic.at : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\9073CE2B-5A1E-4D35-A1E8-EB19EC\05C6F247-C3DF-419A-856A-024D4F -> Downloader.Qoologic.at : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\9073CE2B-5A1E-4D35-A1E8-EB19EC\B7A79035-16C1-434E-8A37-2B6F8E -> Downloader.Qoologic.at : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\9073CE2B-5A1E-4D35-A1E8-EB19EC\CF02721C-15E0-4F25-B6C1-38333F -> Downloader.Qoologic.at : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\AA9F9FA0-AFF9-42CC-8387-9BF814\C5ED9549-CAA4-4E8E-9DF3-1BC7C6 -> Adware.Sud : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/Program Files/spysheriff/heur002.dll -> Adware.SpySheriff : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/Program Files/spysheriff/IESecurity.dll -> Spyware.SpywareNo : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/Program Files/spysheriff/ProcMon.dll -> Adware.SpySheriff : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/Program Files/spysheriff/Uninstall.exe -> Adware.SpySheriff : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/WINDOWS/system32/child.dll -> Downloader.Small.bug : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/WINDOWS/VGltIENvcm5lbGl1cw/command.exe -> Adware.CommAd : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/WINDOWS/VGltIENvcm5lbGl1cw/asappsrv.dll -> Spyware.CommAd : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/Documents and Settings/Grand Master HooHa/Application Data/Sun/Java/Deployment/cache/javapi/v1.0/file/Dummy.class-451cae74-7ffe8ca6.class -> Trojan.ClassLoader.Dummy.d : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/WINDOWS/desktop.html -> Hijacker.Generic : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051218133630.zip/WINDOWS/inet20002/alg.exe -> Worm.Delf.i : Cleaned with backup
C:\RECYCLER\NPROTECT\00000000.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00000019.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\S-1-5-21-861567501-1383384898-725345543-500\Dc1.exe -> Logger.Small.dg : Cleaned with backup
C:\RECYCLER\S-1-5-21-861567501-1383384898-725345543-500\Dc2.exe -> Downloader.PassAlert.e : Cleaned with backup
C:\WINDOWS\system32\0wsogti2.dll -> Adware.Sud : Cleaned with backup
C:\WINDOWS\system32\assldpc.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\casetacl.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\chmdlg32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cRtsrv.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\en64l1jq1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\enn6l15s1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\g6402ghmg64a2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\gp00l3dm1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\gp0ql3d51.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\GSFSPidGen.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\h60q0gd5e60.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\hagbccla.exe -> Proxy.Wopla.n : Cleaned with backup
C:\WINDOWS\system32\hr8m05l1e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\i4jqle151h.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\irakeng.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\jt0207doe.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\jt6207joe.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\l00ulad91d0.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\l6n40g5qe6.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\maieftp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mericons.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mkencode.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\msc71.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\msrddm.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mvnql9551.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\o2ro0c93ef.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\o4840elqehqe0.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\r26ulcj91fo.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\r46ulej91ho.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\sbripto.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\smellstyle.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\sxeio.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\vgactl.cpl -> Downloader.Qoologic.at : Cleaned with backup
C:\WINDOWS\system32\wdaservc.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wuauclt.dll -> Downloader.Qoologic.at : Cleaned with backup
C:\WINDOWS\tool2.exe -> Hijacker.Spywad.n : Cleaned with backup
C:\winstall.exe -> Hijacker.Spywad.n : Cleaned with backup
G:\Documents and Settings\fff\Local Settings\Temp\asmfiles.cab/asm.exe -> Spyware.Altnet : Cleaned with backup
G:\Documents and Settings\fff\Local Settings\Temp\__unin__.exe -> Spyware.Altnet : Cleaned with backup
G:\WINNT\Temp\Altnet\adm25.dll -> Spyware.Altnet : Cleaned with backup
G:\WINNT\Temp\Altnet\admdloader.dll -> Spyware.Altnet : Cleaned with backup
G:\WINNT\Temp\Altnet\admfdi.dll -> Spyware.Altnet : Cleaned with backup
G:\WINNT\Temp\Altnet\admprog.dll -> Adware.Altnet : Cleaned with backup
::Report End
Hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 11:14:28 PM, on 12/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MAILFR~1\mantispm.exe
C:\Program Files\ATI Multimedia\main\ATISched.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Grand Master HooHa\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.fredoneverything.net/
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Matador] "C:\PROGRA~1\MAILFR~1\mantispm.exe" -quiet
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) -
https://support.micr...ActiveX/odc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1124561307953
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1....loadManager.ocx
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} -
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) -
http://apps.corel.co...NetOpPlugin.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.h.../qdiagh.cab?326
O20 - Winlogon Notify: MCD - C:\WINDOWS\system32\dnr2019oe.dll
O21 - SSODL: SysTray.Exmr - {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Thanks for your help.