Turbs
Topic Starter
Hey guys, alot of helpful stuff here thanks alot.
I have gone thru all the pre-posting scans suggested but don't know if the problem is fixed as i don't understand the hijackthis logfile.
If someone can please let me know if i've fixed the problem or if it can be fixed, it would be greatly appreciated as my computer is only 6months old.
HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 9:43:16 PM, on 7/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ABIT\ABIT uGuru\GuruClock.exe
C:\Program Files\ABIT\ABIT uGuru\uGuru_Event_Receiver.exe
C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
F:\My Documents\My Documents\utorrent.exe
C:\WINDOWS\F?nts\r?ndll32.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\AVerTV 6.0\AVerQT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
F:\My Documents\My Downloads\HijackThis.exe
R3 - URLSearchHook: (no name) - {CA13EFAE-7039-79CD-4A53-5510E1567FC9} - C:\WINDOWS\system32\jqwa.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GuruClock] C:\Program Files\ABIT\ABIT uGuru\GuruClock.exe
O4 - HKLM\..\Run: [ABIT uGuru] C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [µTorrent] "F:\My Documents\My Documents\utorrent.exe"
O4 - HKCU\..\Run: [Xhiykhgs] C:\WINDOWS\F?nts\r?ndll32.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV 6.0\AVerQT.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1145706821046
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145712165953
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{49C99B41-4745-45BF-85C8-CFFC0EF020E3}: NameServer = 203.0.178.191,192.168.100.200
O17 - HKLM\System\CS1\Services\Tcpip\..\{49C99B41-4745-45BF-85C8-CFFC0EF020E3}: NameServer = 203.0.178.191,192.168.100.200
O17 - HKLM\System\CS2\Services\Tcpip\..\{49C99B41-4745-45BF-85C8-CFFC0EF020E3}: NameServer = 203.0.178.191,192.168.100.200
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
Ewido report:
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 8:46:41 PM 7/08/2006
+ Scan result:
HKU\S-1-5-21-1390067357-725345543-2621077-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{052B12F7-86FA-4921-8482-26C42316B522} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1390067357-725345543-2621077-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{873EB32D-AE1A-4183-89BD-45A77F761BE4} -> Adware.Generic : Cleaned with backup (quarantined).
C:\WINDOWS\system32\jqwa.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
F:\My Documents\My Documents\TheGameOfLife-dm.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Local Settings\Temporary Internet Files\Content.IE5\8ZIRYDAT\SysProtectScannerInstall[1].exe -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Local Settings\Temporary Internet Files\Content.IE5\2ROJI1OF\!update-4095[1].0000 -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\!update.exe -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Local Settings\Temporary Internet Files\Content.IE5\8ZIRYDAT\!update-4120[1].0000 -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ѕуmbols\iexplore.exe -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
F:\My Documents\My Downloads\Diablo_2_Lord_of_Destruction_Keygen.rar/install.exe -> Downloader.Small.bwy : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Local Settings\Temporary Internet Files\Content.IE5\2ROJI1OF\L2[1].exe -> Downloader.Small.cvw : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win2073.tmp.exe -> Downloader.Small.cvw : Cleaned with backup (quarantined).
F:\My Documents\My Downloads\Diablo_2_Lord_of_Destruction_Keygen.rar/crack.exe -> Downloader.VB.afo : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ixt0.dll -> Downloader.Zlob.adb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\khlrnfrs.dll -> Logger.VBStat.d : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\VerifierBug.class-43404e4a-651e7c7b.class -> Not-A-Virus.Exploit.Java.Bytverify : Ignored.
C:\WINDOWS\system32\components\flx6.dll -> Not-A-Virus.Hoax.Win32.Renos.ds : Ignored.
:mozilla.13:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.12:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.379:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.397:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.414:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.482:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Turban\Cookies\turban@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.30:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.31:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.32:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.33:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.526:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.38:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.39:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.72:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.540:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.75:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.34:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.50:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.51:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.52:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.53:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.148:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.610:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Turban\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.624:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.625:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.419:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.418:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.426:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.427:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.428:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.429:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.630:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.631:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.632:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.633:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.634:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.635:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.636:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.637:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Turban\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.433:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.95:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.445:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.446:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.447:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.448:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.71:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.78:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.79:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.463:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.466:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.467:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.468:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.469:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.470:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.471:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.472:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.480:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.481:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.499:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.502:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.521:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.534:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.535:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.536:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.537:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.538:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Turban\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.527:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.528:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\Turban\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-7e4442f4-4ea50650.class -> Trojan.ClassLoader.Dummy.d : Cleaned with backup (quarantined).
::Report end
THanks in advance for any help, sorry if I have broken the rules by failing to name the infection.
I have gone thru all the pre-posting scans suggested but don't know if the problem is fixed as i don't understand the hijackthis logfile.
If someone can please let me know if i've fixed the problem or if it can be fixed, it would be greatly appreciated as my computer is only 6months old.
HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 9:43:16 PM, on 7/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ABIT\ABIT uGuru\GuruClock.exe
C:\Program Files\ABIT\ABIT uGuru\uGuru_Event_Receiver.exe
C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
F:\My Documents\My Documents\utorrent.exe
C:\WINDOWS\F?nts\r?ndll32.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\AVerTV 6.0\AVerQT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
F:\My Documents\My Downloads\HijackThis.exe
R3 - URLSearchHook: (no name) - {CA13EFAE-7039-79CD-4A53-5510E1567FC9} - C:\WINDOWS\system32\jqwa.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GuruClock] C:\Program Files\ABIT\ABIT uGuru\GuruClock.exe
O4 - HKLM\..\Run: [ABIT uGuru] C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [µTorrent] "F:\My Documents\My Documents\utorrent.exe"
O4 - HKCU\..\Run: [Xhiykhgs] C:\WINDOWS\F?nts\r?ndll32.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV 6.0\AVerQT.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1145706821046
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145712165953
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{49C99B41-4745-45BF-85C8-CFFC0EF020E3}: NameServer = 203.0.178.191,192.168.100.200
O17 - HKLM\System\CS1\Services\Tcpip\..\{49C99B41-4745-45BF-85C8-CFFC0EF020E3}: NameServer = 203.0.178.191,192.168.100.200
O17 - HKLM\System\CS2\Services\Tcpip\..\{49C99B41-4745-45BF-85C8-CFFC0EF020E3}: NameServer = 203.0.178.191,192.168.100.200
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
Ewido report:
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 8:46:41 PM 7/08/2006
+ Scan result:
HKU\S-1-5-21-1390067357-725345543-2621077-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{052B12F7-86FA-4921-8482-26C42316B522} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1390067357-725345543-2621077-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{873EB32D-AE1A-4183-89BD-45A77F761BE4} -> Adware.Generic : Cleaned with backup (quarantined).
C:\WINDOWS\system32\jqwa.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
F:\My Documents\My Documents\TheGameOfLife-dm.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Local Settings\Temporary Internet Files\Content.IE5\8ZIRYDAT\SysProtectScannerInstall[1].exe -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Local Settings\Temporary Internet Files\Content.IE5\2ROJI1OF\!update-4095[1].0000 -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\!update.exe -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Local Settings\Temporary Internet Files\Content.IE5\8ZIRYDAT\!update-4120[1].0000 -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ѕуmbols\iexplore.exe -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
F:\My Documents\My Downloads\Diablo_2_Lord_of_Destruction_Keygen.rar/install.exe -> Downloader.Small.bwy : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Local Settings\Temporary Internet Files\Content.IE5\2ROJI1OF\L2[1].exe -> Downloader.Small.cvw : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win2073.tmp.exe -> Downloader.Small.cvw : Cleaned with backup (quarantined).
F:\My Documents\My Downloads\Diablo_2_Lord_of_Destruction_Keygen.rar/crack.exe -> Downloader.VB.afo : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ixt0.dll -> Downloader.Zlob.adb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\khlrnfrs.dll -> Logger.VBStat.d : Cleaned with backup (quarantined).
C:\Documents and Settings\Turban\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\VerifierBug.class-43404e4a-651e7c7b.class -> Not-A-Virus.Exploit.Java.Bytverify : Ignored.
C:\WINDOWS\system32\components\flx6.dll -> Not-A-Virus.Hoax.Win32.Renos.ds : Ignored.
:mozilla.13:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.12:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.379:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.397:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.414:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.482:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Turban\Cookies\turban@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.30:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.31:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.32:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.33:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.526:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.38:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.39:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.72:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.540:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.75:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.34:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.50:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.51:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.52:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.53:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.148:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.610:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Turban\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.624:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.625:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.419:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.418:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.426:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.427:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.428:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.429:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.630:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.631:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.632:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.633:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.634:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.635:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.636:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.637:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Turban\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.433:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.95:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.445:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.446:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.447:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.448:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.71:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.78:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.79:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.463:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.466:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.467:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.468:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.469:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.470:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.471:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.472:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.480:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.481:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.499:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.502:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.521:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.534:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.535:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.536:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.537:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.538:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Turban\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.527:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.528:C:\Documents and Settings\Turban\Application Data\Mozilla\Firefox\Profiles\bewvawz3.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\Turban\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-7e4442f4-4ea50650.class -> Trojan.ClassLoader.Dummy.d : Cleaned with backup (quarantined).
::Report end
THanks in advance for any help, sorry if I have broken the rules by failing to name the infection.