Hello,
Thanks for correcting me on that here are the two log saves performed correctly:
#1. Ewido scan run in "save mode" and Log saved:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 7:09:45 AM, 1/25/2006
+ Report-Checksum: C467D2AC
+ Scan result:
C:\WINDOWS\system32\csmmu.exe -> Downloader.Agent.uj : Cleaned with backup
C:\WINDOWS\system32\favset.exe -> Trojan.Favadd.an : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\f0xadt2v.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@server.iad.liveperson[1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP136\A0075104.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP136\A0076104.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP136\A0077104.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP137\A0077171.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP137\A0078165.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP137\A0078195.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP137\A0079195.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP137\A0080195.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP137\A0081195.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP137\A0081205.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP138\A0081369.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP138\A0082370.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP138\A0082397.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP140\A0083397.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP142\A0083512.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP142\A0083553.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP142\A0084550.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP143\A0084587.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP143\A0085587.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP145\A0085746.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP145\A0086746.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP146\A0086811.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP146\A0086850.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP147\A0086913.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP147\A0086945.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP148\A0087942.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP148\A0088942.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP148\A0088976.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP149\A0089000.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP149\A0089043.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP149\A0089059.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP149\A0089085.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP150\A0089134.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP150\A0089158.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP151\A0089199.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP151\A0089200.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP153\A0089536.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP153\A0089576.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP153\A0090576.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP154\A0091577.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP154\A0092576.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP154\A0093577.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP154\A0094301.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP154\A0094321.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP154\A0095321.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP154\A0096320.exe -> Downloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109481.exe -> Trojan.Qhost.df : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109482.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109483.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109484.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109485.exe -> Spyware.Trymedia : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109486.exe/cd_clint.dll -> Spyware.Cydoor : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109487.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109488.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109489.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109490.dll -> Adware.Gator : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109491.dll -> Adware.Gator : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109492.dll -> Adware.Gator : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109493.exe -> Spyware.DownloadWare : Cleaned with backup
C:\System Volume Information\_restore{DF52645B-C4D5-486F-A095-CCFB58F5505E}\RP160\A0109537.exe -> Not-A-Virus.Downloader.Win32.DigStream.a : Cleaned with backup
C:\My old Disk Structure -- 04-02-16 0623PM\WINDOWS\NDNuninstall5_48.exe -> Adware.NewDotNet : Cleaned with backup
::Report End
#2. Hijack this log here:
Logfile of HijackThis v1.99.1
Scan saved at 7:20:06 AM, on 1/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Video Enhanced\MSNVE.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.747\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://g.msn.com/0SE...S01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.msn.com/0SE...S01?FORM=TOOLBR
F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh309190.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [AtiPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MSN Video Enhanced] "C:\Program Files\MSN Video Enhanced\MSNVE.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\\Steam.exe -silent
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh309190.dll/201
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?4f4e4a5a8cb8454081dfa1c7979fad22
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?4f4e4a5a8cb8454081dfa1c7979fad22
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1136903579716
O17 - HKLM\System\CCS\Services\Tcpip\..\{283DADEF-454E-400A-B787-E00B5BD19670}: NameServer = 85.255.114.51,85.255.112.86
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C8BE458-F77F-4033-B76F-C0AD5D952916}: NameServer = 85.255.114.51 85.255.112.86
O20 - AppInit_DLLs: C:\WINDOWS\system32\sqlnkfh.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
Thanks again for your proffesional help and I look forward to moving forward in helping my PC.
Cheers,
Sean