Below is my new hijack log followed by the wido log.
Windows pop-up with various sites.
Tim (Lcm300)
Logfile of HijackThis v1.99.1
Scan saved at 10:08:14 AM, on 3/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
F:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\geeksquad\HijackThis.exe
O3 - Toolbar: Yahoo! Companion -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [eTrustPPAP] "F:\Program Files\CA\eTrust
PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy
Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
/background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
- C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}
- C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet
Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} -
http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://cdn2.zone.msn...ro.cab34246.cab
O18 - Filter: text/html - {BA576CDE-9949-4473-A8F7-6C17C2A7E600} -
C:\WINDOWS\system32\wdc1n.dll
O20 - Winlogon Notify: ShellServiceObjectDelayLoad -
C:\WINDOWS\system32\en4sl1h71.dll (file missing)
O23 - Service: ewido security suite control - ewido networks -
C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks -
C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program
Files\Ahead\InCD\InCDsrv.exe
________________________
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:02:00 AM, 3/4/2006
+ Report-Checksum: BBF25781
+ Scan result:
HKU\S-1-5-21-1614895754-854245398-1202660629-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6001CDF7-6F45-471B-A203-0225615E35A7} -> Adware.Generic : Cleaned with backup
[676] C:\WINDOWS\system32\kzdkyr.dll -> Adware.Look2Me : Cleaned with backup
C:\aebcq9z5w.exe -> Downloader.Agent.afi : Cleaned with backup
C:\Documents and Settings\tim.TIM-HQWWOP0G5QX\Desktop\WINDOWS.000\Downloaded Program Files\gsda.dll -> Not-A-Virus.Downloader.Win32.SpyGame : Cleaned with backup
C:\Documents and Settings\tim.TIM-HQWWOP0G5QX\Desktop\WINDOWS.000\TEMP\Brilliant\bdeinsta2.dll -> Adware.Altnet : Cleaned with backup
C:\Documents and Settings\tim.TIM-HQWWOP0G5QX\Desktop\WINDOWS.000\TEMP\Brilliant\bdeplayer\BDEPlayer2.cab/bdeplayer2.dll -> Adware.BrilliantDigital : Cleaned with backup
C:\NNSCAA638.EXE -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\Gnucleus\Downloads\CloneDVD v2 8 8 2 + Universal Patch zip.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Program Files\Gnucleus\Downloads\CloneDVD v2.8.8.2 and Patch 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Program Files\outlook\p.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Program Files\RealOne Player 6.0.10.446\Realone Player\setup.exe -> Dropper.Pakes : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0116652.exe -> Downloader.VB.xr : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0116655.exe -> Downloader.VB.vv : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0116665.dll -> Adware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0116685.exe/eee2.exe -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0116694.exe -> Adware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0116699.exe -> Adware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0116704.dll -> Adware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0117690.exe -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0117691.exe -> Adware.ZenoSearch : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0117694.dll -> Hijacker.Small.jf : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP204\A0117733.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0117752.exe -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0117753.dll -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0117779.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0117783.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0117789.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0117793.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0117798.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0117802.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118004.exe -> Adware.DealHelper : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118008.exe -> Adware.DealHelper : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118135.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118143.exe -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118144.exe -> Downloader.VB.uc : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118146.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118151.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118180.exe -> Downloader.VB.xu : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118181.exe -> Downloader.Adload.v : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118182.exe -> Downloader.VB.xv : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118183.exe -> Hijacker.VB.li : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118184.exe -> Hijacker.VB.li : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118185.exe -> Hijacker.StartPage.aib : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118187.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118198.exe -> Downloader.VB.nw : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118199.exe -> Hijacker.VB.ij : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118200.exe -> Hijacker.VB.ij : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP205\A0118213.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP206\A0118518.dll -> Adware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP206\A0118632.exe -> Heuristic.Win32.AVKiller : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP206\A0118957.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP206\A0118963.exe -> Adware.Suggestor : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP206\A0118964.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP206\A0118969.exe -> Adware.ZenoSearch : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP206\A0118979.dll -> Adware.Suggestor : Cleaned with backup
C:\System Volume Information\_restore{0344325D-BEE3-4738-8A1F-68E96A5C7022}\RP206\A0118980.dll -> Adware.Look2Me : Cleaned with backup
C:\visfx500.exe -> Dropper.Agent.aie : Cleaned with backup
C:\WINDOWS\6=LE.exe/eee2.exe -> Adware.MediaMotor : Cleaned with backup
C:\WINDOWS\seli.exe/eee2.exe -> Adware.MediaMotor : Cleaned with backup
C:\WINDOWS\surv3.exe -> Downloader.VB.vv : Cleaned with backup
C:\WINDOWS\system32\kzdkyr.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\lv8609lse.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mcspy.exe -> Downloader.Small.ckq : Cleaned with backup
C:\WINDOWS\system32\pre2.exe -> Dropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\qldsregn.exe -> Adware.ZenoSearch : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@as-eu.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@data2.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\WINDOWS\Temp\Cookies\tim@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
::Report End
Thank you.