Alright, i did all of this, except i coudln't get the on-line virus scans to work properly, i'm currently using Mozilla while IE is down, so i kept getting errors whenever i tried to scan. I completed the rest however.
Here is my Ewido log:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 12:47:59 PM, 07/06/2005
+ Report-Checksum: 85119A7B
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2FB10B1F-E342-08A1-CBAA-D4A2CD2ABAC6} -> Spyware.CoolWebSearch
HKLM\SOFTWARE\Classes\CLSID\{43F226F3-3EDD-1F6E-B1F9-426F80DAB07E} -> Spyware.CoolWebSearch
HKLM\SOFTWARE\Classes\CLSID\{447160CD-ECF5-4EA2-8A8A-1F70CA363F85} -> Spyware.ClientMan
HKLM\SOFTWARE\Classes\CLSID\{5AF0B5AF-80E5-5F00-7457-4FF9847707D9} -> Spyware.CoolWebSearch
HKLM\SOFTWARE\Classes\CLSID\{6257B617-2809-056A-FCEC-83AB849FBF72} -> Spyware.CoolWebSearch
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE -> Spyware.CoolWebSearch
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW -> Spyware.CoolWebSearch
HKLM\SOFTWARE\SearchRelevancy -> Spyware.SearchRelevancy
HKLM\SOFTWARE\SearchRelevancy\Update -> Spyware.SearchRelevancy
[428] C:\WINDOWS\System32\winlspak.dll -> TrojanDownloader.Agent.br
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Altnet1.zip -> Heuristic.Suspicious-Zip
:mozilla.11:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\klsklhoy.default\cookies.txt -> Spyware.Cookie.Atdmt
:mozilla.8:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Myaffiliateprogram
:mozilla.11:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Atdmt
:mozilla.15:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Netshelter
:mozilla.18:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Netshelter
:mozilla.19:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Adtech
:mozilla.20:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Adtech
:mozilla.21:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Smarttargetting
:mozilla.22:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Tribalfusion
:mozilla.24:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Trendmicro
:mozilla.29:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Webtrendslive
:mozilla.32:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Doubleclick
:mozilla.35:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Addynamix
:mozilla.38:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Realmedia
:mozilla.39:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Realmedia
:mozilla.40:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Targetnet
:mozilla.45:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Falkag
:mozilla.60:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\default.hrc\cookies.txt -> Spyware.Cookie.Mediaplex
:mozilla.6:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Atdmt
:mozilla.15:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Advertising
:mozilla.16:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Advertising
:mozilla.23:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Mediaplex
:mozilla.24:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Questionmarket
:mozilla.25:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Doubleclick
:mozilla.27:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Hitbox
:mozilla.30:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Hitbox
:mozilla.31:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Hitbox
:mozilla.36:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Boldchat
:mozilla.38:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Ticketmaster
:mozilla.39:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\217vd1lz.default\cookies.txt -> Spyware.Cookie.Ticketmaster
:mozilla.18:C:\Documents and Settings\Nat\Application Data\Mozilla\Firefox\Profiles\ghzd2ebk.default\cookies.txt -> Spyware.Cookie.Atdmt
:mozilla.19:C:\Documents and Settings\Nat\Application Data\Mozilla\Firefox\Profiles\ghzd2ebk.default\cookies.txt -> Spyware.Cookie.Mediaplex
:mozilla.23:C:\Documents and Settings\Nat\Application Data\Mozilla\Firefox\Profiles\ghzd2ebk.default\cookies.txt -> Spyware.Cookie.Doubleclick
:mozilla.27:C:\Documents and Settings\Nat\Application Data\Mozilla\Firefox\Profiles\ghzd2ebk.default\cookies.txt -> Spyware.Cookie.Casalemedia
:mozilla.28:C:\Documents and Settings\Nat\Application Data\Mozilla\Firefox\Profiles\ghzd2ebk.default\cookies.txt -> Spyware.Cookie.Fastclick
:mozilla.29:C:\Documents and Settings\Nat\Application Data\Mozilla\Firefox\Profiles\ghzd2ebk.default\cookies.txt -> Spyware.Cookie.Webmd
:mozilla.32:C:\Documents and Settings\Nat\Application Data\Mozilla\Firefox\Profiles\ghzd2ebk.default\cookies.txt -> Spyware.Cookie.Tribalfusion
C:\Program Files\Logitech\Desktop Messenger\8876480\6.1.4.36-8876480L\Program\runner.exe -> Spyware.BackWeb
C:\Program Files\Microsoft Office\Office\MSOHTMED.EXE -> Heuristic.Win32.Downloader
C:\RECYCLER\NPROTECT\00001004.exe -> TrojanDownloader.Agent.bq
C:\RECYCLER\NPROTECT\00001005.exe -> Trojan.Agent.bi
C:\RECYCLER\NPROTECT\00001006.dll -> Spyware.SearchPage
C:\RECYCLER\NPROTECT\00001007.dll -> Spyware.SearchPage
C:\RECYCLER\NPROTECT\00001008.dll -> Spyware.SearchPage
C:\RECYCLER\NPROTECT\00001009.dll -> Spyware.SearchPage
C:\RECYCLER\NPROTECT\00001010.dll -> Spyware.SearchPage
C:\RECYCLER\NPROTECT\00001056.dll -> Spyware.SearchPage
C:\RECYCLER\NPROTECT\00001079.exe -> TrojanDownloader.Agent.oq
C:\RECYCLER\NPROTECT\00001087.exe -> TrojanDownloader.Agent.oq
C:\RECYCLER\NPROTECT\00001089.exe -> TrojanDownloader.Agent.oq
C:\RECYCLER\NPROTECT\00001090.exe -> TrojanDownloader.Agent.oq
C:\RECYCLER\NPROTECT\00001095.dll -> Spyware.SearchPage
C:\RECYCLER\NPROTECT\00001098.exe -> TrojanDownloader.Agent.oq
C:\RECYCLER\NPROTECT\00001099.exe -> TrojanDownloader.Agent.oq
C:\RECYCLER\NPROTECT\00001100.exe -> TrojanDownloader.Agent.oq
C:\RECYCLER\NPROTECT\00001103.exe -> TrojanDownloader.Agent.oq
C:\WINDOWS\addcr.exe -> TrojanDownloader.Agent.ap
C:\WINDOWS\apind.dll -> TrojanDownloader.Agent.bc
C:\WINDOWS\apphn.exe -> TrojanDownloader.Agent.bq
C:\WINDOWS\applp.exe -> Trojan.Agent.bi
C:\WINDOWS\apprh32.exe -> TrojanDownloader.Agent.ap
C:\WINDOWS\cdplayer.ini:jphzzi -> Trojan.Agent.bi
C:\WINDOWS\cdplayer.ini:uqzir -> TrojanDownloader.Agent.bq
C:\WINDOWS\cryp32.exe -> TrojanDownloader.Agent.ap
C:\WINDOWS\desktop.ini:tlkzmt -> Trojan.Agent.bi
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\WinCtlAdX.dll -> Spyware.WinAD
C:\WINDOWS\Downloaded Program Files\YSBactivex.dll -> TrojanDownloader.IstBar.gp
C:\WINDOWS\EDow_AS2.exe -> TrojanDownloader.QDown.m
C:\WINDOWS\eqlsUIConfig.ini:wjupl -> TrojanDownloader.Agent.bc
C:\WINDOWS\eula.htm:mldegw -> Trojan.Agent.bi
C:\WINDOWS\gds.dll -> Heuristic.Win32.Downloader
C:\WINDOWS\gpl.dll -> Spyware.Gpl
C:\WINDOWS\ipix32.exe -> Trojan.Agent.bi
C:\WINDOWS\mfchd32.exe -> Trojan.Agent.bi
C:\WINDOWS\mfcyy32.dll -> TrojanDownloader.Agent.bc
C:\WINDOWS\mxtarget.ini:sopykm -> Trojan.Agent.bi
C:\WINDOWS\netac32.exe -> TrojanDownloader.Agent.ap
C:\WINDOWS\NTIWVEDT.INI:kpilew -> Trojan.Agent.bi
C:\WINDOWS\NTIWVEDT.INI:kscsuc -> Trojan.Agent.bi
C:\WINDOWS\n_gkburp.txt -> TrojanDownloader.Agent.ap
C:\WINDOWS\n_jpmtdg.txt:vpbrgy -> TrojanDownloader.Agent.bq
C:\WINDOWS\n_jpmtdg.txt -> TrojanDownloader.Agent.ap
C:\WINDOWS\n_pflczd.txt -> TrojanDownloader.Agent.oq
C:\WINDOWS\n_vafkcj.txt -> TrojanDownloader.Agent.ap
C:\WINDOWS\ODBC.INI:xvmnh -> TrojanDropper.Small.tn
C:\WINDOWS\SchedLgU.Txt:fiipwp -> Trojan.Agent.bi
C:\WINDOWS\SchedLgU.Txt:mlhmnw -> Trojan.Agent.bi
C:\WINDOWS\sdkll32.exe -> TrojanDownloader.Agent.ap
C:\WINDOWS\setdebug.exe:kuqse -> TrojanDownloader.Agent.bq
C:\WINDOWS\SIGVERIF.TXT:kjbpnt -> Trojan.Agent.bi
C:\WINDOWS\smscfg.ini:yllguf -> Trojan.Agent.bi
C:\WINDOWS\sysms32.exe -> Trojan.Agent.bi
C:\WINDOWS\system32:pjaa.dll -> Heuristic.Win32.Downloader
C:\WINDOWS\system32\addbd.exe -> TrojanDownloader.Agent.ap
C:\WINDOWS\system32\atldz.exe -> TrojanDownloader.Agent.oq
C:\WINDOWS\system32\calsp.dll -> TrojanDownloader.Agent.br
C:\WINDOWS\system32\carules.dll -> Spyware.Coupon
C:\WINDOWS\system32\cryp.exe -> Trojan.Agent.bi
C:\WINDOWS\system32\cydja.dll -> Spyware.SearchPage
C:\WINDOWS\system32\ielx32.exe -> Trojan.Agent.bi
C:\WINDOWS\system32\iesj32.exe -> Trojan.Agent.bi
C:\WINDOWS\system32\mfcqp32.exe -> Trojan.Agent.bi
C:\WINDOWS\system32\mscjjn.dll -> Spyware.180Solutions
C:\WINDOWS\system32\mshw32.exe -> TrojanDownloader.Agent.ap
C:\WINDOWS\system32\netdc.dll -> TrojanDownloader.Agent.bc
C:\WINDOWS\system32\netes.exe -> Trojan.Agent.bi
C:\WINDOWS\system32\netip.exe -> Trojan.Agent.bi
C:\WINDOWS\system32\netun32.exe -> Trojan.Agent.bi
C:\WINDOWS\system32\ntfe.dll -> TrojanDownloader.Agent.bc
C:\WINDOWS\system32\sdkok32.exe -> Trojan.Agent.bi
C:\WINDOWS\system32\sysiq32.dll -> TrojanDownloader.Agent.bc
C:\WINDOWS\system32\__delete_on_reboot__calsp.dll -> TrojanDownloader.Agent.br
C:\WINDOWS\system32\__delete_on_reboot__winlspak.dll -> TrojanDownloader.Agent.br
C:\WINDOWS\sysux.exe -> Trojan.Agent.bi
C:\WINDOWS\trace.txt:mxxiqy -> Trojan.Agent.bi
C:\WINDOWS\twain.dll:qqpar -> TrojanDownloader.Agent.ap
C:\WINDOWS\vb.ini:pkmadp -> Trojan.Agent.bi
C:\WINDOWS\vbaddin.ini:hcjhpn -> Trojan.Agent.bi
C:\WINDOWS\VSWizard.ini:fpmkow -> Trojan.Agent.bi
C:\WINDOWS\VSWizard.ini:njknoz -> Trojan.Agent.bi
C:\WINDOWS\WAR2R.INI:ljgqru -> Trojan.Agent.bi
C:\WINDOWS\wininit.ini:hvnzxn -> Trojan.Agent.bi
C:\WINDOWS\_delis32.ini:ucwqp -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:atcwql -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:bixkpd -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:bjelmt -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:bwuwjd -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:bymjmh -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:crmdqs -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:crvtyk -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:cvvyy -> TrojanDropper.Small.tn
C:\WINDOWS\_MSRSTRT.EXE:dlwdn -> TrojanDownloader.Agent.bc
C:\WINDOWS\_MSRSTRT.EXE:eckeru -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:fhomwd -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:fxyju -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:idbjpb -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:ieoltk -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:ijugki -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:jchnpt -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:jfaiqv -> TrojanDownloader.Agent.bc
C:\WINDOWS\_MSRSTRT.EXE:jjiaa -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:jxcerw -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:jxwlyu -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:kirrzf -> Spyware.SearchPage
C:\WINDOWS\_MSRSTRT.EXE:kqtjgc -> TrojanDownloader.Agent.ap
C:\WINDOWS\_MSRSTRT.EXE:ljdsju -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:lufhmg -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:mhuofe -> Spyware.SearchPage
C:\WINDOWS\_MSRSTRT.EXE:ngehct -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:nhbaxe -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:onzoj -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:qnesb -> TrojanDropper.Small.tn
C:\WINDOWS\_MSRSTRT.EXE:rbxynb -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:rddlfm -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:rpsbcx -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:sfxmgo -> Spyware.SearchPage
C:\WINDOWS\_MSRSTRT.EXE:titepk -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:tuvbkw -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:tzfpor -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:ureqtc -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:vgiuvb -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:vvgpqj -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:xfdgat -> Spyware.SearchPage
C:\WINDOWS\_MSRSTRT.EXE:xobfe -> TrojanDownloader.Agent.bc
C:\WINDOWS\_MSRSTRT.EXE:ybmkly -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:yclflc -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:ydienr -> Trojan.Agent.bi
C:\WINDOWS\_MSRSTRT.EXE:ypfhd -> TrojanDropper.Small.tn
C:\WINDOWS\_MSRSTRT.EXE:yxrimv -> TrojanDownloader.Agent.bq
C:\WINDOWS\_MSRSTRT.EXE:zwmgek -> Trojan.Agent.bi
::Report End
And here is my Hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 12:50:38 PM, on 07/06/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\winln.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\d3vv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\LVComS.exe
C:\Program Files\Logitech\Video\LowLight.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\Matt\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\cydja.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\cydja.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about
:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\cydja.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\cydja.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\cydja.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\cydja.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\cydja.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: GDS module - {A084A565-B09B-4e4c-A497-7CC50AEAB2A7} - C:\WINDOWS\gds.dll (file missing)
O2 - BHO: Class - {F4625626-5DCB-AEB7-598A-486B27B92A72} - C:\WINDOWS\system32\systn32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [cryp32.exe] C:\WINDOWS\cryp32.exe
O4 - HKLM\..\Run: [d3vv.exe] C:\WINDOWS\d3vv.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: FriendFinder Messenger.lnk = C:\Program Files\FriendFinder Messenger\FriendFinder Messenger.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: ConferenceRoom Java Client -
http://irc.theamateurchat.com/java/cr.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) -
http://www.phgenit.com/plugin/awarew...ab/awswaxf.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_42.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/06f89839...p/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.co...?1099631719984
O16 - DPF: {861FDA2A-2B57-4BDA-8B8B-305C9D5D8604} (_Multimedia Player) -
http://www.pussyharem.com/stream/mmp.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) -
http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
https://www.stopzilla.com/_download/...ler/dwnldr.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cab
O20 - Winlogon Notify: OemStartMenuData - C:\WINDOWS\
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\winln.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Thanks :)