ok, i'm stupid and figured out the fixwareout thing, i just looked for the win2k2 file and then hit execute, and then followed your other instructions. my computer seems better now, but there is still slow-down and my desktop background is now blinking between grey and white. first, here is what i get when i right click on my desktop and hit source:
***** This file is automatically generated by Microsoft Windows *****
——–>
style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none"
bottomMargin=0 bgColor=#3a6ea5 leftMargin=0 background="" topMargin=0
rightMargin=0>
style="LEFT: 0px; WIDTH: 1024px; POSITION: absolute; TOP: 0px; HEIGHT: 768px">[image unavailable: image]
style="LEFT: 0px; WIDTH: 100%; POSITION: absolute; TOP: 0px; HEIGHT: 100%" cache
src="file:///C:/WINDOWS/Firefox%20Wallpaper.bmp">
its properties also say it is an http file, non-encrypted, and is located at
file://C:\WINDOWS\desktop.html
also, here is the log from ewido and an updated hijackthis
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 5:05:49 PM 9/2/2006
+ Scan result:
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\e9e0c67a4854855d514f79c8670ce366 -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\WINDOWS\system32\FLEOK\msbb.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msbb.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\180solutions -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\180solutions\msbb -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan\catsrv51.exe.q_8047002_q -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\Overpro-347.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\acledit4.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\camocx03.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\iehost34.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\terabyte.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\unwise56.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\35569fe9c3ec913aa556b9f4541fe3c1 -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\d75ac80aa00f31286174cb9ab9122d84 -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\BullsEye Network -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\BullsEye Network\bin -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\BullsEye Network\bin\bargains.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\BO2802040113.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\MoreResultsSetup.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msbb321.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\eXactUtil -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\09a4b1807ce9cbd972dda1ee484c83ef -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\6c1b8ef6e3ca2f2aa8d663295f6433bf -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\6f3d872e841a1e4b557e91d32a1d54a9 -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\89015e0ad3bb8187347e383786c6524e -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\9b9bdb9a1e5f77a33f390d75f887bcd7 -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\WINDOWS\preInsMt.exe -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\WINDOWS\preInsTT.exe -> Adware.BiSpy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Jao.jao -> Adware.BlazeFind : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Jao.jao.1 -> Adware.BlazeFind : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Jao.jao\CLSID -> Adware.BlazeFind : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Jao.jao\CurVer -> Adware.BlazeFind : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{49F365E8-0D7B-4236-85E0-CBD6E2696F11}.exe -> Adware.Casino : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan\CSIE.DLL.q_FFC8401_q -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\ff42e1ba6190a2ebcf3123dd869c772d -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Program Files\Lycos\IEagent\CSBIINST.DLL -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Program Files\Lycos\IEagent\CSSSINST.DLL -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Program Files\Lycos\Sidesearch\ClrSchUninstall_78_86.exe -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch\Loader -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch\SideBars -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch\SideSearch -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch\resolvers -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ToolBand.ToolBandObj -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ToolBand.ToolBandObj.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ToolBand.ToolBandObj\CLSID -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ToolBand.ToolBandObj\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\0f12c6b15f848517c04793a55a6fb5d3 -> Adware.EZula : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\24fa7d5443c3f99b0772c569420402a5 -> Adware.EZula : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\5ad00ef2bf2b15f86aa5d8b2d132a111 -> Adware.EZula : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\684a2a4cda9d45a1f64fd535b0c654cc -> Adware.EZula : Cleaned with backup (quarantined).
C:\Program Files\Web Offer -> Adware.eZula : Cleaned with backup (quarantined).
C:\Program Files\Web Offer\CHPON.dll -> Adware.eZula : Cleaned with backup (quarantined).
C:\Program Files\Web Offer\wo.exe -> Adware.eZula : Cleaned with backup (quarantined).
C:\WINDOWS\woinstall.exe -> Adware.EZula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe.1 -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CLSID -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CurVer -> Adware.Ezula : Cleaned with backup (quarantined).
HKU\S-1-5-21-515967899-1532298954-839522115-1003\Software\Web Offer -> Adware.Ezula : Cleaned with backup (quarantined).
HKU\S-1-5-21-515967899-1532298954-839522115-1003\Software\Web Offer\Setup -> Adware.Ezula : Cleaned with backup (quarantined).
HKU\S-1-5-21-515967899-1532298954-839522115-1003\Software\Web Offer\Setup\ID -> Adware.Ezula : Cleaned with backup (quarantined).
C:\WINDOWS\system32\GrlNt0i.dll -> Adware.F1Organizer : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{0865BE98-4E6A-45FE-BAA2-D91EBEB21A2E}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{0E310E29-5AC3-4BCD-BC8F-A9D1931DBE21}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{121787DC-BF4C-405A-8BCC-06168B887D37}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{1AAE6EFA-3277-4F8F-AF0C-4979CF8833EF}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{29353D1E-1E8B-4FA7-BB26-F5A336AD2ABF}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2B9DF4CE-1863-4BB3-B7D8-B41E50B3DB6B}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{68A54CE1-4A90-40F1-B142-204428E8EEEE}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{6E3C1B44-7519-4551-91AE-5A38DE10DC16}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{98464BFC-E5CC-472A-A616-D506DB707F67}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{A5163EE6-6B60-4E35-AEC8-FDE8241DF678}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{AC18ECBC-F384-4404-95A3-9CCBCDD41FC0}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{AE3E6357-DA83-4120-B392-FED7213FEC7A}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B3A74C2C-DDA1-488F-BFB5-9336F2EFF5FD}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B3BAB8E4-E2F0-437D-867C-989D72133A2B}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B5E13677-A0E8-4CBA-A1E1-9E7507D78115}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B91E5A77-F487-4371-A24A-2D3FFBB68D01}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{BEFEA71B-BC62-472E-BC89-E7DB0208FB58}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C50061AC-2CF5-4E1B-ADC9-D4A125773E2D}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C59339E6-C790-4BE2-BA69-52BB717346B3}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C8C13E1E-BB07-4A97-B160-6D05DBB5B486}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{CD6E6D3D-1E36-482A-AECA-D2F371D7EDC0}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E793F7C1-1F84-4C2D-B220-BA85E879F8A8}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{EDC9AB10-FF90-4492-AD79-56B4A066BD94}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{FBAF4904-FB6B-4CCB-B5C2-DD3868C426EA}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Media-Codec.Chl -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Media-Codec.Chl\CLSID -> Adware.Generic : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\b66fb5c26f91a2dbd4a3ad17dcccdb8d/systb.dll -> Adware.ImiBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-515967899-1532298954-839522115-1003\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\updater -> Adware.KeenValue : Cleaned with backup (quarantined).
HKLM\SOFTWARE\updater\{8D15A72D-62E0-4733-B057-0A81B4FFEB3D} -> Adware.KeenValue : Cleaned with backup (quarantined).
HKLM\SOFTWARE\MaxSpeed -> Adware.Maxspeed : Cleaned with backup (quarantined).
C:\Program Files\MemoryWatcher -> Adware.MemoryWatcher : Cleaned with backup (quarantined).
C:\Program Files\MemoryWatcher\EULA.URL -> Adware.MemoryWatcher : Cleaned with backup (quarantined).
C:\Program Files\MemoryWatcher\MemoryWatcher.exe -> Adware.MemoryWatcher : Cleaned with backup (quarantined).
C:\Program Files\MemoryWatcher\TrayIcon.ocx -> Adware.MemoryWatcher : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\midADdle -> Adware.MidAddle : Cleaned with backup (quarantined).
HKLM\SOFTWARE\WildMedia -> Adware.MidAddle : Cleaned with backup (quarantined).
HKLM\SOFTWARE\WildMedia\LicenseStores -> Adware.MidAddle : Cleaned with backup (quarantined).
HKLM\SOFTWARE\midADdle -> Adware.MidAddle : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj.1 -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj\CLSID -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj\CurVer -> Adware.MoneyTree : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{76F6B2F3-2B46-4F52-9BF0-23BC630D3B78}.exe -> Adware.Msnagent : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan\rvqhr.dll.q_8048002_q -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\urpo.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rυndll.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClickSpring -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{398B84A7-D2E7-4760-85A4-EC3F120E8FBA}.exe -> Adware.Raze : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA Software Installer -> Adware.SafeSurfing : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer Software Installer -> Adware.SafeSurfing : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\8c18963519f11c3036a5401b81b44287 -> Adware.Sahat : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\SAHAgent_.exe -> Adware.Sahat : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\SahHtml_.exe -> Adware.Sahat : Cleaned with backup (quarantined).
C:\WINDOWS\system32\SahHtml.exe -> Adware.Sahat : Cleaned with backup (quarantined).
C:\WINDOWS\system32\sahagent1019.exe -> Adware.Sahat : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SEP -> Adware.SEP : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed\Privacy Info.url -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed\Terms and Conditions.url -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed\Uninstall Instructions.url -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\SEP -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\SEP\sep.dll -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\b05d7c2eb5067ccbf631742e510fb8f4 -> Adware.Sidesearch : Cleaned with backup (quarantined).
C:\Program Files\Alcohol Soft\Alcohol 120% Toolbar\a120_tb.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan\ceutil58.exe.q_8041001_q -> Adware.UrlSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\clbcatex.exe -> Adware.UrlSpy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DMO -> Adware.VX2 : Cleaned with backup (quarantined).
C:\Program Files\Common Files\midaddle\WildWinTracker.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
C:\WINDOWS\system32\silent.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer -> Adware.YourSiteBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer.1 -> Adware.YourSiteBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer\CLSID -> Adware.YourSiteBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer\CurVer -> Adware.YourSiteBar : Cleaned with backup (quarantined).
C:\WINDOWS\system32\csero.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\setup_incred_8.exe -> Downloader.Keenval : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2A22AD41-B07E-4A5D-ADB2-F6F3B075F6B6}.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{4BE76ACB-8C56-4448-9436-5B30858B822B}.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\0021-bdl94126.EXE -> Downloader.VB.ca : Cleaned with backup (quarantined).
C:\WINDOWS\desktop.html -> Not-A-Virus.Hoax.Win32.Aflac.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{0D61E880-95AE-4DA7-8FC6-506214682135}.exe -> Trojan.Hoster : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{12FCD71D-951A-4602-B930-E426494F1DF0}.exe -> Trojan.Hoster : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\28df04be958b091cd20727d43b04b445 -> Trojan.MemwatchAd : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{0A58A3FA-CB40-4898-96E5-D1798781A352}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{14EB22AD-772D-4613-B57A-FD9E68DB27A6}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{293FB7E7-028C-4AE5-A976-388C643A6248}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2D171C5A-A472-4527-A46E-5F527420B2D4}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{3980395F-2F6E-4EF5-9D10-FF84C9951391}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{61AAE436-77E6-48B5-B799-763E9CFB1D7B}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{67778CCF-08DD-4DDA-86AF-310B1EE7BBC7}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{8DBAE51C-4459-493E-846F-449E04D0D5A1}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{9079F124-FBB0-43E6-AF0A-2E613717BB43}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{994848BD-04C6-4D18-9374-623F8DCB4F6A}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{9D1EF86C-5CFC-4B0F-B0AE-1DA650E51679}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B096A208-4C4B-4322-85BD-95134831368A}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{BBF11D71-7228-43B2-BB3C-BE6903D2D9DF}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C16928FB-948F-4987-8A24-B26504FF399A}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C9773CDE-5334-4ACA-BCC4-A9DE2184F358}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{CD08F5A8-0918-4677-ACB8-61DA88A76ACD}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{D5DE4E05-75DB-4C42-8E7E-F44553E945FE}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{DC51C070-123F-4881-B2EB-988E86BA95DA}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E0B9D55D-BA29-4A5A-8AF9-565867BB3BA6}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E23837B2-51BC-43FF-92A4-D5C44681F19C}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E8E73C4A-87D7-427B-9AA1-99AF61D34915}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{ED14F2A3-075C-43D7-A18B-4BBC7F9040B8}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{F4D19EB8-7ECD-47FA-81A9-E89E83BEE606}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{FCDC95E7-C462-49B5-8E1E-E8B52CDBEACD}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\0e5c4ef61a2b9aca928117ec6c55f33f -> Trojan.Septic.a : Cleaned with backup (quarantined).
C:\SEPinst.exe -> Trojan.Septic.a : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dmawg.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{14474303-759F-4799-8AA6-FD26D12069DA}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2A0C71B9-1C12-4E0B-B46B-C6CE020E4248}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2DB8D9E7-B6F5-4CB2-858F-998C8291BF3E}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2EB39867-B32D-4B3B-999A-26D92D336FEA}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{3348AF28-46A0-41B3-AB1A-531D6C4B92C5}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{3C066E59-41F8-48A1-8AEB-35B849E91003}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{43E285EF-6E5D-4EEC-850D-0A02B095A000}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{51D978CF-476E-4A29-9749-4437F8718509}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{6E9B416A-C5EF-46F9-B487-030A5CDFD43F}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{73A98F53-171A-42ED-8418-A25F0AA90628}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{7476B804-C7B6-4466-B81C-D6B9BBACF18C}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{7F069BF6-B387-4EC5-8F49-221DAAD904A5}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{9259A184-6783-4EB6-8F51-4F91D6F5CF75}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{A1B8DD77-C91E-4750-A984-2B507CF3CBD1}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{A99C0143-B559-4F7F-92BD-6BC1092622F6}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{AB5D8654-249E-480C-BC10-13096FB574B6}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B13895B7-3B14-4432-BF08-71CF9A02A11B}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B24BC282-1798-4BFB-A012-B1274248B2F9}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{BE147E5C-AE30-4060-8D0D-50F1CE93FDF1}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{EF50BE81-BBFB-4DAC-BD62-F9B2B8301B0E}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{F08DE81C-F62D-4299-8CB5-98F8A6C3885F}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{F80A01D1-EF7C-42C9-871E-6B4A7B16F247}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{FD3350B3-AE33-4E45-8833-B5D4EB11C85B}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{FF5DF0CC-85EB-4F15-9085-EA0064FDFB68}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\8240a5782c881b8508f89fcb144b9143 -> Trojan.VB.od : Cleaned with backup (quarantined).
::Report end
Logfile of HijackThis v1.99.1
Scan saved at 5:19:08 PM, on 9/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\SYMANT~1\Rtvscan.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Russell\Desktop\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\{51D33DF5-4CAF-4857-AFE9-AD83A889F459}.dll (file missing)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\{51D33DF5-4CAF-4857-AFE9-AD83A889F459}.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [hovcy.exe] C:\WINDOWS\system32\hovcy.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} -
http://www.netpaloffers.net/NetpalOffers/DMO1/GrlNt0i.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/048868ac7c072b…ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1156535059545
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
any help in tying up any loose viruses/malware etc…would be greatly appreciated (especially making sure those three trojans are gone, because i don't remember seeing those particular trojans on the ewido list)
also, this ewido program rocks, i'm going to buy a copy of it after i get my computer cleaned up (and possibley reformatted). peace.