---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 9:17:54 PM, 4/15/2006
+ Report-Checksum: 743DFAEC
+ Scan result:
HKU\S-1-5-21-299502267-1547161642-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{279A1B41-6CAC-4ABF-B39C-72C8E489F685} -> Adware.AdBlaster : Cleaned with backup
HKU\S-1-5-21-299502267-1547161642-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{55BE9F0D-6CAF-4C3E-B125-5A13A8C9D0EC} -> Adware.Generic : Cleaned with backup
[948] C:\WINMC\system32\cslvcqd.dll -> Downloader.Qoologic.bj : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@ad.adition[2].txt -> TrackingCookie.Adition : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@amazonbebe.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@data2.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@data3.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@e-2dj6wfkogidjmfo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@e-2dj6wfliehcjidq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@e-2dj6wjl4amczgeo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@e-2dj6wjlycod5ggo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@e-2dj6wjnyaiazmbp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@e-2dj6wjnyelc5kgo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@e-2dj6wjnyqmcjwfp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@maxim.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Dina Turchek\Cookies\dina turchek@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Tim Lastoria\Cookies\tim lastoria@com[2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Cookies\tim lastoria@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Cookies\tim lastoria@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Cookies\tim lastoria@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Cookies\tim lastoria@com[1].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Cookies\tim lastoria@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Cookies\tim lastoria@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Cookies\tim lastoria@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Cookies\tim lastoria@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Cookies\tim lastoria@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Desktop\hijackthis\backups\backup-20060415-172426-257.dll -> Adware.AdBlaster : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Desktop\hijackthis\backups\backup-20060415-172426-458.dll -> Adware.SafeSurfing : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Local Settings\Temp\tp7543.exe -> Downloader.Qoologic.ax : Cleaned with backup
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Local Settings\Temporary Internet Files\Content.IE5\8H23GPEN\rcverlib[1].exe -> Downloader.Qoologic.ax : Cleaned with backup
C:\Program Files\Radmin\raddrv.dll -> Not-A-Virus.RemoteAdmin.Win32.RAdmin.22 : Cleaned with backup
C:\RECYCLER\S-1-5-21-1085031214-1123561945-725345543-1003\Dc10.dll -> Adware.Look2Me : Cleaned with backup
C:\RECYCLER\S-1-5-21-1085031214-1123561945-725345543-1003\Dc9.dll -> Adware.Look2Me : Cleaned with backup
C:\WINMC\876057.exe -> Adware.Mirar : Cleaned with backup
C:\WINMC\pss\osxwr.exeCommon Startup -> Downloader.Qoologic.bj : Cleaned with backup
C:\WINMC\Sngsh40.dll -> Adware.AdBlaster : Cleaned with backup
C:\WINMC\system\sngsh35.dll -> Adware.AdBlaster : Cleaned with backup
C:\WINMC\system32\cjbyw.dat -> Downloader.Qoologic.bj : Cleaned with backup
C:\WINMC\system32\dmonwv.dll -> Downloader.Agent.agw : Cleaned with backup
C:\WINMC\system32\irismon.dll -> Adware.SafeSurfing : Cleaned with backup
C:\WINMC\system32\irssyncd.exe -> Adware.SafeSurfing : Cleaned with backup
C:\WINMC\system32\ngsh35.dll -> Adware.AdBlaster : Cleaned with backup
C:\WINMC\system32\ngsh40.dll -> Adware.AdBlaster : Cleaned with backup
C:\WINMC\system32\qkdsregp.exe -> Adware.ZenoSearch : Cleaned with backup
C:\WINMC\system32\raddrv.dll -> Not-A-Virus.RemoteAdmin.Win32.RAdmin.22 : Cleaned with backup
C:\WINMC\system32\sms_msn.exe -> Adware.AdBlaster : Cleaned with backup
C:\WINMC\system32\sms_msn40.exe -> Adware.AdBlaster : Cleaned with backup
C:\WINMC\system32\w5332cb3.dll -> Downloader.Agent.ahv : Cleaned with backup
C:\WINMC\unwn.exe -> Trojan.Qoologic : Cleaned with backup
D:\My Documents\My Utilities\Newsbin Pro v5.0.1.5807\Patch.exe -> Downloader.VB.ts : Cleaned with backup
D:\My Documents\PPC-6700\Current Software\Resco Audio Recorder v3.21\keygen.exe -> Logger.ProAgent.t : Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 9:35:37 PM, on 4/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINMC\System32\smss.exe
C:\WINMC\system32\winlogon.exe
C:\WINMC\system32\services.exe
C:\WINMC\system32\lsass.exe
C:\WINMC\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINMC\System32\svchost.exe
C:\WINMC\system32\spoolsv.exe
C:\WINMC\Explorer.EXE
C:\WINMC\system32\hphmon04.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINMC\system32\netdde.exe
C:\WINMC\ehome\RMSysTry.exe
C:\Program Files\Nimblesoft\360 Friends\XboxFriendsList.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\MCE\MCEVideoEncoder\MCEVideoEncoder.exe
C:\WINMC\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINMC\eHome\ehRecvr.exe
C:\WINMC\eHome\ehSched.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINMC\System32\svchost.exe
C:\WINMC\system32\msiexec.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINMC\ehome\RMSvc.exe
C:\WINMC\system32\r_server.exe
C:\WINMC\system32\svchost.exe
C:\WINMC\system32\wbem\wmiapsrv.exe
C:\WINMC\System32\dmadmin.exe
C:\WINMC\system32\svchost.exe
C:\WINMC\system32\dllhost.exe
C:\WINMC\system32\wscntfy.exe
C:\WINMC\system32\wuauclt.exe
C:\Documents and Settings\Tim Lastoria.OFFICEPC\Desktop\hijackthis\HijackThis.exe
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINMC\system32\mudak.exe
F2 - REG:system.ini: UserInit=C:\WINMC\SYSTEM32\Userinit.exe,xqkdvnr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINMC\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINMC\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPHmon04] C:\WINMC\system32\hphmon04.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Orb] C:\Program Files\ORB Networks\ORB\bin\OrbTray.exe
O4 - Startup: 360 Friends.lnk = ?
O4 - Startup: MCEVideoEncoder.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINMC\ehome\RMSysTry.exe
O8 - Extra context menu item: &Download by NetAnts - C:\PROGRA~1\NetAnts\NAGet.htm
O8 - Extra context menu item: Download &All by NetAnts - C:\PROGRA~1\NetAnts\NAGetAll.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Subscribe in default RSS reader - C:\Documents and Settings\Tim Lastoria.OFFICEPC\Application Data\RssBandit\iecontext_subscribefeed.htm
O8 - Extra context menu item: Transfer with Image Converter 2 - C:\Program Files\Sony\Image Converter 2\menu.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\PROGRA~1\NetAnts\NetAnts.exe
O9 - Extra 'Tools' menuitem: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\PROGRA~1\NetAnts\NetAnts.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINMC\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINMC\system32\shdocvw.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\WINMC\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://files.member....s/sbc/yinst.cab
O16 - DPF: {656FAD09-4DE3-4C34-9600-0928C855FD7A} (AxTaskList Class) -
http://moneycentral....bs/pmupd806.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1142219215765
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.7) -
http://advisor.futur...lobal/msc37.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) -
http://messenger.zon...ss.cab31267.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://driveragent.c...driveragent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINMC\system32\BTXPPanel.dll
O20 - Winlogon Notify: MacDrive-iTunes compatibility - C:\Program Files\Common Files\Mediafour\MacDriveiTunesPatch.dll
O20 - Winlogon Notify: NavLogon - C:\WINMC\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINMC\SYSTEM32\WRLogonNTF.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINMC\system32\r_server.exe" /service (file missing)