here is the ewido thing.....
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 1:25:19 PM, 2/14/2006
+ Report-Checksum: BA3F2781
+ Scan result:
HKLM\SOFTWARE\VGroup -> Adware.SAHA : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKU\.DEFAULT\Software\salm -> Adware.180Solutions : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-18\Software\salm -> Adware.180Solutions : Cleaned with backup
C:\clogs.exe -> Adware.WinAD : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\
[email protected][1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Gan Ning\Application Data\Mozilla\Firefox\Profiles\1vomw1jd.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Gan Ning\Application Data\Mozilla\Firefox\Profiles\1vomw1jd.default\cookies-1.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Gan Ning\Application Data\Mozilla\Firefox\Profiles\1vomw1jd.default\cookies-1.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Gan Ning\Application Data\Mozilla\Firefox\Profiles\1vomw1jd.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Gan Ning\Application Data\Mozilla\Firefox\Profiles\1vomw1jd.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Gan Ning\Application Data\Mozilla\Firefox\Profiles\1vomw1jd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Gan Ning\Application Data\Mozilla\Firefox\Profiles\1vomw1jd.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Gan Ning\Application Data\Mozilla\Firefox\Profiles\1vomw1jd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Gan Ning\Application Data\Mozilla\Firefox\Profiles\1vomw1jd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gan Ning\Cookies\gan
[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gan Ning\Cookies\gan ning@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gan Ning\Cookies\gan ning@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Gan Ning\Cookies\gan ning@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Gan Ning\Cookies\gan ning@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Gan Ning\Desktop\New Folder\backups\backup-20060202-212056-250.dll -> Trojan.Crypt.o : Cleaned with backup
C:\Documents and Settings\Gan Ning\Desktop\New Folder\backups\backup-20060202-213054-926.dll -> Adware.Virtumonde : Cleaned with backup
C:\Documents and Settings\Gan Ning\Desktop\New Folder\backups\backup-20060202-213144-804.dll -> Adware.Virtumonde : Cleaned with backup
C:\Documents and Settings\Gan Ning\Desktop\New Folder\backups\backup-20060202-213249-314.dll -> Adware.Virtumonde : Cleaned with backup
C:\Documents and Settings\Gan Ning\Desktop\New Folder\backups\backup-20060209-202712-235.dll -> Adware.Virtumonde : Cleaned with backup
C:\Documents and Settings\Gan Ning\Desktop\New Folder\backups\backup-20060212-180209-260.dll -> Adware.Virtumonde : Cleaned with backup
C:\Documents and Settings\Gan Ning\Desktop\New Folder\backups\backup-20060213-221428-848.dll -> Adware.Virtumonde : Cleaned with backup
C:\Documents and Settings\Gan Ning\Desktop\New Folder\backups\backup-20060213-221442-814.dll -> Adware.Virtumonde : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temp\jfgudk.exe -> Downloader.IstBar.or : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temp\nein.exe -> Downloader.Small.bgl : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temp\resD.tmp -> Adware.180Solutions : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temp\setup4030.cab/liqp7c25q_.dll -> Adware.Sahat : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temporary Internet Files\Content.IE5\MR29K5Y5\1[1].bin -> Downloader.Small.bue : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temporary Internet Files\Content.IE5\MR29K5Y5\inst_0004[1].exe -> Downloader.Small.cam : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temporary Internet Files\Content.IE5\MR29K5Y5\nein[1].exe -> Downloader.Small.bgl : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temporary Internet Files\Content.IE5\MR29K5Y5\newfrn[1].exe -> Hijacker.VB.is : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temporary Internet Files\Content.IE5\UPUWB19C\installerus[1].exe -> Downloader.Qoologic.at : Cleaned with backup
C:\Documents and Settings\Gan Ning\Local Settings\Temporary Internet Files\Content.IE5\UXTKFVZA\ltndload[1].dll -> Adware.Sud : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\
[email protected][2].txt -> TrackingCookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6IWP119O\876029[1].exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6IWP119O\toolbar3[1].cab/IExploreSkins.exe -> Adware.WebSearch : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6IWP119O\toolbar3[1].cab/TBPS.exe -> Adware.WebSearch : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\PWJFSGKU\clogs[1].rar -> Adware.WinAD : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\PWJFSGKU\stubinstaller6282[1].exe -> Downloader.Small.asf : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\installerus.exe -> Downloader.Qoologic.at : Cleaned with backup
C:\inst_0004.exe -> Downloader.Small.cam : Cleaned with backup
C:\SystemGuard.exe/1.html -> Hijacker.Linker.j : Cleaned with backup
C:\SystemGuard.exe/ss.exe -> Trojan.LowZones.d : Cleaned with backup
C:\WINDOWS\1.html -> Hijacker.Linker.j : Cleaned with backup
C:\WINDOWS\876029.exe -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\aim.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\MsLS32.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\mspath.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\newfrn.exe -> Hijacker.VB.is : Cleaned with backup
C:\WINDOWS\ss.exe -> Trojan.LowZones.d : Cleaned with backup
C:\WINDOWS\system32\0ky00ol4.dll -> Adware.Sud : Cleaned with backup
C:\WINDOWS\system32\attyfjgl.dll -> Trojan.Crypt.o : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\
[email protected][1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\WINDOWS\system32\pi1_58.exe -> Downloader.Small.bue : Cleaned with backup
C:\WINDOWS\system32\rpcdlt.exe -> Logger.VB.eh : Cleaned with backup
C:\WINDOWS\Temp\Del1.tmp -> Downloader.Small.asf : Cleaned with backup
C:\WINDOWS\Temp\mit2.tmp/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup
C:\WINDOWS\Temp\mit2.tmp.cab/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup
C:\WINDOWS\Temp\NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup
C:\WINDOWS\Temp\setup4030.cab/liqp7c25q_.dll -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\tsecure.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\winfixer\WinFixer2006FreeInstall.exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
::Report End
and here is the hjt...
Logfile of HijackThis v1.99.1
Scan saved at 1:33:48 PM, on 2/14/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Gan Ning\Desktop\New Folder\HijackThis.exe
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{6055DDC0-97C3-44C6-8BDB-CDCDA3571EDC}: NameServer = 208.27.113.151 208.25.241.60
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe