ok when ran About Buster it automatically cleaned w/o any option? still have log and will post it.
Also The Ewido Log is too big for a post (even by itself) will split it up and post next.
AboutBuster 6.05
Scan started on [8/5/2006] at [8:25:41 PM]
————————————————————-
Internet Explorer Instances Terminated!
HomeSearch Service stopped if present
————————————————————-
Streams(ADS) not scanned: System not NTFS
————————————————————-
Removed File! : C:\WINDOWS\hupsuw.dat
Removed File! : C:\WINDOWS\pyxkmd.txt
Removed File! : C:\WINDOWS\ynjyvr.txt
Removed File! : C:\WINDOWS\cgvjzx.dat
Removed File! : C:\WINDOWS\sdtyar.log
Removed File! : C:\WINDOWS\bbeyp.txt
Removed File! : C:\WINDOWS\koujdj.txt
Removed File! : C:\WINDOWS\hrmqdf.txt
Removed File! : C:\WINDOWS\eszdza.dat
Removed File! : C:\WINDOWS\oduia.log
Removed File! : C:\WINDOWS\iddgu.log
Removed File! : C:\WINDOWS\crelxx.log
Removed File! : C:\WINDOWS\ysavmj.txt
Removed File! : C:\WINDOWS\fstgok.log
Removed File! : C:\WINDOWS\bmeznu.log
Removed File! : C:\WINDOWS\ojokph.log
Removed File! : C:\WINDOWS\joeoo.log
Removed File! : C:\WINDOWS\ehddgi.txt
Removed File! : C:\WINDOWS\ektgke.log
Removed File! : C:\WINDOWS\hzhkpy.log
Removed File! : C:\WINDOWS\fmjgzq.log
Removed File! : C:\WINDOWS\tlxcj.txt
Removed File! : C:\WINDOWS\hbrweq.log
Removed File! : C:\WINDOWS\qwcmxp.txt
Removed File! : C:\WINDOWS\vdakas.txt
Removed File! : C:\WINDOWS\fledc.log
Removed File! : C:\WINDOWS\mnzgiy.txt
Removed File! : C:\WINDOWS\pbweu.log
Removed File! : C:\WINDOWS\ubbgit.txt
Removed File! : C:\WINDOWS\ypqas.txt
Removed File! : C:\WINDOWS\ikshin.txt
Removed File! : C:\WINDOWS\vofrvp.log
Removed File! : C:\WINDOWS\krbpj.log
Removed File! : C:\WINDOWS\lyqch.txt
Removed File! : C:\WINDOWS\lyqzx.log
Removed File! : C:\WINDOWS\hjwrv.log
Removed File! : C:\WINDOWS\xipsn.log
Removed File! : C:\WINDOWS\wdhjhp.log
Removed File! : C:\WINDOWS\melsex.txt
Removed File! : C:\WINDOWS\kzocr.log
Removed File! : C:\WINDOWS\pvsfks.txt
Removed File! : C:\WINDOWS\crvrxc.log
Removed File! : C:\WINDOWS\qtwzkt.log
Removed File! : C:\WINDOWS\mleso.txt
Removed File! : C:\WINDOWS\dgxycd.log
Removed File! : C:\WINDOWS\kcvpop.txt
Removed File! : C:\WINDOWS\pkadr.dat
Removed File! : C:\WINDOWS\edqpsm.dat
Removed File! : C:\WINDOWS\humhvb.dat
Removed File! : C:\WINDOWS\kkadoo.dat
Removed File! : C:\WINDOWS\oogfft.log
Removed File! : C:\WINDOWS\cprpat.log
Removed File! : C:\WINDOWS\xllyc.dat
Removed File! : C:\WINDOWS\omohon.txt
Removed File! : C:\WINDOWS\czmpua.txt
Removed File! : C:\WINDOWS\xiury.log
Removed File! : C:\WINDOWS\ydzzlv.log
Removed File! : C:\WINDOWS\eokuv.log
Removed File! : C:\WINDOWS\ilztir.log
Removed File! : C:\WINDOWS\xwrvuo.log
Removed File! : C:\WINDOWS\ohcrmy.log
Removed File! : C:\WINDOWS\uxvtp.txt
Removed File! : C:\WINDOWS\bzjpbh.dat
Removed File! : C:\WINDOWS\sewia.dat
Removed File! : C:\WINDOWS\wysibo.txt
Removed File! : C:\WINDOWS\bkuec.txt
Removed File! : C:\WINDOWS\txzvid.dat
Removed File! : C:\WINDOWS\xldijj.dat
Removed File! : C:\WINDOWS\fjgzpn.txt
Removed File! : C:\WINDOWS\dtnlv.log
Removed File! : C:\WINDOWS\ynpsfj.log
Removed File! : C:\WINDOWS\nxxlm.dat
Removed File! : C:\WINDOWS\qdnnwa.dat
Removed File! : C:\WINDOWS\qgnwh.txt
Removed File! : C:\WINDOWS\uhupvh.dat
Removed File! : C:\WINDOWS\wtsrq.txt
Removed File! : C:\WINDOWS\trhsw.dat
Removed File! : C:\WINDOWS\uwdtcv.txt
Removed File! : C:\WINDOWS\yforew.log
Removed File! : C:\WINDOWS\hhkho.log
Removed File! : C:\WINDOWS\cdyzje.log
Removed File! : C:\WINDOWS\fxwvl.txt
Removed File! : C:\WINDOWS\zpfebo.dat
Removed File! : C:\WINDOWS\ddnply.dat
Removed File! : C:\WINDOWS\dnlgv.dat
Removed File! : C:\WINDOWS\bgmvtn.txt
Removed File! : C:\WINDOWS\poxhr.txt
Removed File! : C:\WINDOWS\znssxp.log
Removed File! : C:\WINDOWS\ftjcvy.dat
Removed File! : C:\WINDOWS\exbykt.log
Removed File! : C:\WINDOWS\huagup.log
Removed File! : C:\WINDOWS\jgdol.txt
Removed File! : C:\WINDOWS\wnvhr.log
Removed File! : C:\WINDOWS\bfxvaq.txt
Removed File! : C:\WINDOWS\qkmxvw.txt
Removed File! : C:\WINDOWS\szkob.dat
Removed File! : C:\WINDOWS\cjgtd.txt
Removed File! : C:\WINDOWS\pxyfju.dat
Removed File! : C:\WINDOWS\oktlh.dat
Removed File! : C:\WINDOWS\kkmmwi.log
Removed File! : C:\WINDOWS\zlnwev.log
Removed File! : C:\WINDOWS\dtbad.txt
Removed File! : C:\WINDOWS\system32\gcphv.log
Removed File! : C:\WINDOWS\system32\vupfj.log
Removed File! : C:\WINDOWS\system32\hwckj.dat
Removed File! : C:\WINDOWS\system32\bbwrw.txt
Removed File! : C:\WINDOWS\system32\ojcos.txt
Removed File! : C:\WINDOWS\system32\ehcvi.dat
Removed File! : C:\WINDOWS\system32\yavrf.dat
Removed File! : C:\WINDOWS\system32\auocm.log
Removed File! : C:\WINDOWS\system32\lvjsv.dat
Removed File! : C:\WINDOWS\system32\asnon.dat
Removed File! : C:\WINDOWS\system32\kslak.txt
Removed File! : C:\WINDOWS\system32\tvwjn.dat
Removed File! : C:\WINDOWS\system32\skjxw.log
Removed File! : C:\WINDOWS\system32\aueqh.dat
Removed File! : C:\WINDOWS\system32\gfaig.txt
Removed File! : C:\WINDOWS\system32\lsstk.txt
Removed File! : C:\WINDOWS\system32\axopk.dat
Removed File! : C:\WINDOWS\system32\dsstc.log
Removed File! : C:\WINDOWS\system32\jzemj.log
Removed File! : C:\WINDOWS\system32\tsyqe.txt
Removed File! : C:\WINDOWS\system32\aohnl.txt
Removed File! : C:\WINDOWS\system32\yvjak.txt
Removed File! : C:\WINDOWS\system32\munqm.log
Removed File! : C:\WINDOWS\system32\mpvda.txt
Removed File! : C:\WINDOWS\system32\idpbr.txt
Removed File! : C:\WINDOWS\system32\stidb.log
Removed File! : C:\WINDOWS\system32\kjzqg.log
Removed File! : C:\WINDOWS\system32\bdtru.log
Removed File! : C:\WINDOWS\system32\bmger.txt
Removed File! : C:\WINDOWS\system32\vlmbw.log
Removed File! : C:\WINDOWS\system32\ndstr.log
Removed File! : C:\WINDOWS\system32\hirgt.txt
Removed File! : C:\WINDOWS\system32\bzfcg.txt
Removed File! : C:\WINDOWS\system32\qhycz.log
Removed File! : C:\WINDOWS\system32\ppxpm.txt
Removed File! : C:\WINDOWS\system32\lokau.log
Removed File! : C:\WINDOWS\system32\meoab.txt
————————————————————-
Removed Temp Files
Internet Explorer Settings Reset!
————————————————————-
Scan was COMPLETED SUCCESSFULLY at 8:29:52 PM
Logfile of HijackThis v1.99.1
Scan saved at 9:55:05 PM, on 8/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\S3hotkey.exe
C:\WINDOWS\system32\S3tray2.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SPPDPSRV.EXE
C:\WINDOWS\System32\SPDTMONX.EXE
C:\WINDOWS\twain_32\SiPix\SCBLINK2\BLINK2CC.exe
C:\WINDOWS\twain_32\SiPix\SCBLINK2\USBPNP.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\SPDEVMONSRV.exe
C:\WINDOWS\system32\SPdevmonx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Starfish Internet Service
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [S3hotkey] S3hotkey.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [SPPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SPPDPSRV.EXE
O4 - HKLM\..\Run: [SHARP SetupPrinter] RunDLL32 INST32.DLL,RunDll_SetDefaultPrinter AJ5030 PDP
O4 - HKLM\..\Run: [SHARP Email Assistant] C:\PROGRA~1\SHARP\AJ5030\SPEMAI~1.EXE
O4 - HKLM\..\Run: [AJ5030 Print to Desktop] C:\WINDOWS\System32\SPDTMONX.EXE
O4 - HKLM\..\Run: [BLINK2CC] C:\WINDOWS\twain_32\SiPix\SCBLINK2\BLINK2CC.exe
O4 - HKLM\..\Run: [USBPNP] C:\WINDOWS\twain_32\SiPix\SCBLINK2\USBPNP.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co…b?1096144231750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1136558995991
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: FireDaemon Service: msagent (msagent) - Unknown owner - C:\WINDOWS\security\FireDaemon.exe (file missing)
O23 - Service: FireDaemon Service: netclient (netclient) - Unknown owner - C:\WINDOWS\security\FireDaemon.exe (file missing)
O23 - Service: AJ5030 Device Monitor (SPDevmonSrv) - Unknown owner - C:\WINDOWS\system32\SPDEVMONSRV.exe
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: FireDaemon Service: winsecure (winsecure) - Unknown owner - C:\WINDOWS\security\FireDaemon.exe (file missing)
Thanks again guys/gals
-Rewdi