I followed your instructions. Here's the output from the ewido scan
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 7:49:25 PM, 2/22/2006
+ Report-Checksum: 7B422500
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{39C78B50-7E98-4aa0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj -> Adware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj\CLSID -> Adware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj\CurVer -> Adware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj.1 -> Adware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{39C78B50-7E98-4AA0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\IObjSafety.DemoCtl -> Adware.MediaMotor : Cleaned with backup
HKLM\SOFTWARE\Classes\IObjSafety.DemoCtl\Clsid -> Adware.MediaMotor : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39C78B50-7E98-4aa0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\media-motor -> Adware.MediaMotor : Cleaned with backup
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\.DEFAULT\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{39C78B50-7E98-4AA0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKU\.DEFAULT\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-484763869-839522115-1343024091-1004\Software\IST -> Adware.ISTBar : Cleaned with backup
HKU\S-1-5-21-484763869-839522115-1343024091-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -> Downloader.ConHook.l : Cleaned with backup
HKU\S-1-5-21-484763869-839522115-1343024091-1004\Software\TimeSink, Inc. -> Adware.TimeSink : Cleaned with backup
HKU\S-1-5-21-484763869-839522115-1343024091-1004\Software\TimeSink, Inc.\TsAdBot -> Adware.TimeSink : Cleaned with backup
HKU\S-1-5-21-484763869-839522115-1343024091-1004\Software\TimeSink, Inc.\TsAdBot\Clients -> Adware.TimeSink : Cleaned with backup
HKU\S-1-5-21-484763869-839522115-1343024091-1004\Software\TimeSink, Inc.\TsAdBot\Clients\ba016002 -> Adware.TimeSink : Cleaned with backup
HKU\S-1-5-18\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{39C78B50-7E98-4AA0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-18\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup
C:\kc.exe -> Trojan.LowZones.dk : Cleaned with backup
C:\mmx888.exe -> Downloader.VB.sh : Cleaned with backup
C:\elt888.exe -> Logger.Agent.hi : Cleaned with backup
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\qxxj.exe -> Downloader.Qoologic.ax : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@media.fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned with backup
D:\Documents and Settings\LocalService\Cookies\system@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0GC964Y8\eeedo[1].exe/eee2.exe -> Adware.MediaMotor : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0GC964Y8\mm83[1].ocx -> Downloader.VB.ov : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0GC964Y8\mmx888[1].exe -> Downloader.VB.sh : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0GC964Y8\optimize[1].exe -> Downloader.Dyfuca.ei : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8L2WLFP4\elitemediapop[1].exe -> Trojan.LowZones.am : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8L2WLFP4\elt888[1].exe -> Logger.Agent.hi : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8L2WLFP4\titdric[1].cab/drwst.exe -> Adware.MDH : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8L2WLFP4\ZIFI002[1].exe -> Adware.ZenoSearch : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\9BVTGDSE\876057[1].exe -> Adware.Mirar : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\9BVTGDSE\nem220[1].dll -> Downloader.Dyfuca : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\9BVTGDSE\optimize[1].exe -> Downloader.Dyfuca.ei : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\9BVTGDSE\surv3[1].exe -> Downloader.VB.vv : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\9BVTGDSE\whCC-GIANT[1].exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SRXCQETK\876029[1].exe -> Adware.SaveNow : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SRXCQETK\htwfdr[1].exe -> Downloader.Small.bmx : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SRXCQETK\installer_251[1].exe -> Downloader.Qoologic.al : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SRXCQETK\kcash[1].exe -> Trojan.LowZones.dk : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SRXCQETK\ltndload[1].dll -> Adware.Sud : Cleaned with backup
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SRXCQETK\mm63[1].ocx -> Adware.MediaMotor : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@ads.realcastmedia[2].txt -> TrackingCookie.Realcastmedia : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@as1.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@c.goclick[2].txt -> TrackingCookie.Goclick : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@c5.zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@com[2].txt -> TrackingCookie.Com : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@data2.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@data3.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@data4.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@e-2dj6wfmywjczokq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@eztracks.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@h.starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@hypertracker[2].txt -> TrackingCookie.Hypertracker : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@media.fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@paypopup[2].txt -> TrackingCookie.Paypopup : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@realcastmedia[2].txt -> TrackingCookie.Realcastmedia : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@reduxads.valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@salesforce.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@sel.as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@stat.onestat[2].txt -> TrackingCookie.Onestat : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@stats.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@www.starware[1].txt -> TrackingCookie.Starware : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Cookies\rick beckham@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Local Settings\Temp\cln4.tmp -> Downloader.Dyfuca.dp : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Local Settings\Temp\tm31202.exe -> Downloader.Qoologic.ax : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Local Settings\Temporary Internet Files\Content.IE5\S54FSDYZ\3[1].bin -> Dropper.Agent.abb : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Local Settings\Temporary Internet Files\Content.IE5\S54FSDYZ\rcverlib[1].exe -> Downloader.Qoologic.ax : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Local Settings\Temporary Internet Files\Content.IE5\S54FSDYZ\rcverlib[2].exe -> Downloader.Qoologic.ax : Cleaned with backup
D:\Documents and Settings\Rick Beckham\Local Settings\Temporary Internet Files\Content.IE5\SHE7MVWL\Microsoft_Windows_Advanced_Upgrade_Wizard_Logo______________________________________________________________________[1].emf -> Exploit.MS05-053-WMF : Cleaned with backup
D:\Program Files\Jalmp\jalmp.dll -> Adware.Suggestor : Cleaned with backup
D:\Program Files\whInstall -> Adware.Webhancer : Cleaned with backup
D:\Program Files\whInstall\whAgent.inf -> Adware.Webhancer : Cleaned with backup
D:\Program Files\whInstall\whInstaller.ini -> Adware.Webhancer : Cleaned with backup
D:\WINDOWS\876029.exe -> Adware.SaveNow : Cleaned with backup
D:\WINDOWS\876057.exe -> Adware.Mirar : Cleaned with backup
D:\WINDOWS\eciv.exe/eee2.exe -> Adware.MediaMotor : Cleaned with backup
D:\WINDOWS\htwfdr.exe -> Downloader.Small.bmx : Cleaned with backup
D:\WINDOWS\mm63.ocx -> Adware.MediaMotor : Cleaned with backup
D:\WINDOWS\mm83.ocx -> Downloader.VB.ov : Cleaned with backup
D:\WINDOWS\nem220.dll -> Downloader.Dyfuca : Cleaned with backup
D:\WINDOWS\surv3.exe -> Downloader.VB.vv : Cleaned with backup
D:\WINDOWS\system32\0cw80lwc.dll -> Adware.Sud : Cleaned with backup
D:\WINDOWS\system32\adsetup.exe -> Dropper.Agent.abb : Cleaned with backup
D:\WINDOWS\system32\bffdkvf.exe -> Downloader.Qoologic.ax : Cleaned with backup
D:\WINDOWS\system32\dwdsregt.exe -> Adware.ZenoSearch : Cleaned with backup
D:\WINDOWS\system32\hpsw.exe -> Adware.Suggestor : Cleaned with backup
D:\WINDOWS\system32\kffwg.dll -> Downloader.Qoologic.ax : Cleaned with backup
D:\WINDOWS\system32\owwcyq.exe -> Downloader.Qoologic.ax : Cleaned with backup
D:\WINDOWS\system32\rqdsregp.exe -> Adware.ZenoSearch : Cleaned with backup
D:\WINDOWS\system32\swinrsap.exe -> Adware.ZenoSearch : Cleaned with backup
D:\WINDOWS\system32\vgactl.cpl -> Downloader.Qoologic.ad : Cleaned with backup
D:\WINDOWS\system32\wgse.exe -> Trojan.Runner.h : Cleaned with backup
D:\WINDOWS\system32\WinATS.dll -> Adware.Mirar : Cleaned with backup
D:\WINDOWS\system32\WinDmy.dll -> Adware.Mirar : Cleaned with backup
D:\WINDOWS\system32\WinNB57.dll -> Adware.Mirar : Cleaned with backup
D:\WINDOWS\system32\wuauclt.dll -> Downloader.Qoologic.ae : Cleaned with backup
D:\WINDOWS\system32\yppkq.dat -> Downloader.Qoologic.ax : Cleaned with backup
D:\WINDOWS\Temp\F3C1.tmp/drwst.exe -> Adware.MDH : Cleaned with backup
D:\WINDOWS\Temp\mit7A5.tmp/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup
D:\WINDOWS\Temp\mit7A5.tmp.cab/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup
D:\WINDOWS\Temp\NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup
D:\WINDOWS\whCC-GIANT.exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup
D:\WINDOWS\wsem303.dll -> Downloader.Dyfuca.dt : Cleaned with backup
D:\WINDOWS\ZIFI002.exe -> Adware.ZenoSearch : Cleaned with backup
::Report End
And here's the hijackthis report
Logfile of HijackThis v1.99.1
Scan saved at 7:50:43 PM, on 2/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
C:\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - D:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - D:\WINDOWS\nem220.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\YES\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - D:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - D:\WINDOWS\system32\WinNB57.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Glitch - {C3F699FD-5F86-451B-8150-81979857047E} - D:\WINDOWS\system32\nsv4.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - D:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - D:\WINDOWS\system32\WinNB57.dll (file missing)
O4 - HKLM\..\Run: [Iomega Automatic Backup 1.0.1] D:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CyberArmorLoader] pcsldr.exe
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TIAP] c:\windows\eee2.exe
O4 - HKLM\..\Run: [5464] C:\windows\eee2.exe
O4 - HKLM\..\Run: [wahm] C:\windows\eee2.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] D:\WINDOWS\system32\swinrsai.exe FI002
O4 - HKLM\..\Run: [0cw80lwc.dll] RUNDLL32.EXE 0cw80lwc.dll,b 135344
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [areslite] "D:\Program Files\Ares Lite Edition\AresLite.exe" -h
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: &AOL Toolbar Search - d:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Viewpoint Search - res://D:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - D:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - D:\WINDOWS\system32\wuauclt.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - D:\WINDOWS\system32\wuauclt.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mpg: D:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .wav: D:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O15 - Trusted Zone:
http://click.getmirar.com (HKLM)
O15 - Trusted Zone:
http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone:
http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone:
http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcaf...96/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1121039407869
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) -
http://awbeta.net-nu.../FIX/WinATS.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcaf...,26/mcgdmgr.cab
O18 - Filter: text/html - {2F6E85DC-8D2D-4896-8A4F-7DF8A7B1749D} - D:\PROGRA~1\Jalmp\jalmp.dll
O20 - AppInit_DLLs: cahooknt.dll
O23 - Service: CyberArmor Run Service (CyberArmorRunService) - Unknown owner - D:\PROGRA~1\CYBERA~1\casvc.exe
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - D:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - D:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Iomega App Services - Iomega Corporation - D:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - D:\WINDOWS\scvhost.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe