Ewido Log
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:25:05 PM, 2/14/2006
+ Report-Checksum: 960BEBB
+ Scan result:
C:\Documents and Settings\Asratu C\Cookies\asratu c@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned without backup
C:\Documents and Settings\Asratu C\Cookies\asratu c@e-2dj6wjnycncjocp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned without backup
C:\Documents and Settings\Asratu C\Cookies\asratu c@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\01_04_200618_47_01.zip/0.scl -> TrackingCookie.2o7 : Error during cleaning
C:\Program Files\Spy Cleaner\Backup\01_07_200604_43_02.zip/0.scl -> TrackingCookie.2o7 : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/0.scl -> TrackingCookie.Advertising : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/1.scl -> TrackingCookie.Atdmt : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/10.scl -> TrackingCookie.Hitbox : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/11.scl -> TrackingCookie.Hitbox : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/12.scl -> TrackingCookie.Mediaplex : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/13.scl -> TrackingCookie.Ru4 : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/14.scl -> TrackingCookie.Revenue : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/15.scl -> TrackingCookie.Bluestreak : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/16.scl -> TrackingCookie.Zedo : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/17.scl -> TrackingCookie.Questionmarket : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/18.scl -> TrackingCookie.Specificclick : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/19.scl -> TrackingCookie.Overture : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/2.scl -> TrackingCookie.Centrport : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/20.scl -> TrackingCookie.Trafficmp : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/21.scl -> TrackingCookie.Adtech : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/22.scl -> TrackingCookie.Statcounter : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/23.scl -> TrackingCookie.2o7 : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/25.scl -> TrackingCookie.Tribalfusion : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/26.scl -> TrackingCookie.Liveperson : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/27.scl -> TrackingCookie.2o7 : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/28.scl -> TrackingCookie.Pointroll : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/29.scl -> TrackingCookie.Overture : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/30.scl -> TrackingCookie.2o7 : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/31.scl -> TrackingCookie.Aavalue : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/32.scl -> TrackingCookie.Bridgetrack : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/34.scl -> TrackingCookie.Adserver : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/37.scl -> TrackingCookie.Webtrendslive : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/4.scl -> TrackingCookie.Coremetrics : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/5.scl -> TrackingCookie.Doubleclick : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/6.scl -> TrackingCookie.Fastclick : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/7.scl -> TrackingCookie.Fastclick : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/8.scl -> TrackingCookie.Hitbox : Cleaned without backup
C:\Program Files\Spy Cleaner\Backup\12_30_200519_17_20.zip/9.scl -> TrackingCookie.Hitbox : Cleaned without backup
C:\Program Files\Spy Cleaner\Temp\01_07_200604_43_02\0.scl -> TrackingCookie.2o7 : Cleaned without backup
::Report End
HJT log
Logfile of HijackThis v1.99.1
Scan saved at 10:34:28 PM, on 2/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\1XConfig.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\BHODemon 2\BHODemon.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Documents and Settings\Asratu C\Desktop\HijackThis.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\alg.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.n....1&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.n...=6.1&bm=ho_home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\system32\ZCfgSvc.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2\BHODemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg...t/c381/chat.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell....iler/SysPro.CAB
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg...v45/yacscom.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1127706426837
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.del...ll/gtdownde.cab
O20 - Winlogon Notify: Sebring - C:\WINDOWS\system32\LgNotify.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
Thank you