Sorry it took me a while to reply. I have the ewido and HijackThis logs here. I forgot to delete the O9 entry on HJT, but I will do that soon.
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 1:54:39 PM, 7/6/2005
+ Report-Checksum: C22D007D
+ Scan result:
:mozilla.8:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Fastclick : Ignored
:mozilla.9:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Fastclick : Ignored
:mozilla.10:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Fastclick : Ignored
:mozilla.12:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Fastclick : Ignored
:mozilla.13:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Fastclick : Ignored
:mozilla.14:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Fastclick : Ignored
:mozilla.15:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Mediaplex : Ignored
:mozilla.21:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Adserver : Ignored
:mozilla.22:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Adserver : Ignored
:mozilla.23:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Adserver : Ignored
:mozilla.24:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Adserver : Ignored
:mozilla.25:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Adserver : Ignored
:mozilla.33:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
:mozilla.38:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Atdmt : Ignored
:mozilla.42:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
:mozilla.43:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
:mozilla.44:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
:mozilla.45:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
:mozilla.46:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
:mozilla.47:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
:mozilla.49:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
:mozilla.50:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
:mozilla.51:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Ignored
C:\Program Files\hijackthis\backups\backup-20050628-104005-386.dll -> Not-A-Virus.RiskWare.Downloader.PopCap.a : Ignored
C:\WINDOWS\_MSRSTRT.EXE -> Not-A-Virus.Tool.Reboot : Ignored
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{38EA95B6-06DF-844E-6763-813A152D6F74} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{4BB35A55-A91A-11CF-BA7C-00A0D1001A5A} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{86E5D74F-02EB-11D3-A464-0080C858F182} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{86E5D751-02EB-11D3-A464-0080C858F182} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{6B1BE80A-567F-11D1-B652-0060976C699F} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{AAB7FAED-91F8-4591-8E4C-9291D2B7F381} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CCAR -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1270689400-4103935507-3403473811-1006\Software\Support Software -> Spyware.NetworkEssentials : Cleaned with backup
C:\Documents and Settings\Bong\Cookies\bong@ehg-nestleusainc.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Bong\Cookies\bong@hotbabes.com.19522.fb.dbbsrv[2].txt -> Spyware.Cookie.Dbbsrv : Cleaned with backup
C:\Documents and Settings\Bong\Cookies\bong@programs.wegcash[2].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\Hahnbi\.jpi_cache\file\1.0\BlackBox.class-6b226ce5-2de5a93b.class -> Trojan.ClassLoader.c : Cleaned with backup
C:\Documents and Settings\Hahnbi\.jpi_cache\file\1.0\Dummy.class-7bd741bf-358478cc.class -> Trojan.ClassLoader.Dummy.d : Cleaned with backup
C:\Documents and Settings\Hahnbi\.jpi_cache\file\1.0\VerifierBug.class-4115fd15-2f137b82.class -> Trojan.Byteverify : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.282:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.285:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.295:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.307:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.308:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.309:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.322:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.331:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.332:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.335:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup
:mozilla.336:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup
:mozilla.368:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.369:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.370:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.371:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.372:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.404:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.406:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.419:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.426:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.427:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.428:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.429:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.465:C:\Documents and Settings\Hahnbi\Application Data\Mozilla\Firefox\Profiles\5kwqk77q.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Hahnbi\Cookies\hahnbi@ysbweb[1].txt -> Spyware.Cookie.Ysbweb : Cleaned with backup
C:\WINDOWS\AolCInUn.exe:wanjxn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\MPTBox.INI:yqihlf -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\MSVCP60.DLL:vebaeh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\opuc.dll:xmzdsz -> Spyware.OneMoreSearch : Cleaned with backup
C:\WINDOWS\tmpcpyis.bat -> Backdoor.AcidShiver : Cleaned with backup
C:\WINDOWS\twain.dll:tcmnim -> Spyware.OneMoreSearch : Cleaned with backup
C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwthost.dll -> Spyware.WildTangent : Cleaned with backup
C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\WINDOWS\wt\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 1:56:39 PM, on 7/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.xanga.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe