Thanks so much. Here are my reports: (Note: I had the AutoUpdate file)
Logfile of HijackThis v1.99.1
Scan saved at 4:02:38 PM, on 5/23/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\soundman.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\a2\a2guard.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\DOCUME~1\closch\LOCALS~1\Temp\HijackThis.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 3:49:46 PM, 5/23/2005
+ Report-Checksum: C407DC2C
+ Date of database: 5/23/2005
+ Version of scan engine: v3.0
+ Duration: 11 min
+ Scanned Files: 52708
+ Speed: 75.56 Files/Second
+ Infected files: 76
+ Removed files: 76
+ Files put in quarantine: 76
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\WINDOWS\system32\HookPopup.dll -> Spyware.DealHelper.ab -> Cleaned with backup
C:\WINDOWS\system\lalak.exe -> TrojanDownloader.Small.aly -> Cleaned with backup
C:\WINDOWS\Nail.exe -> Trojan.Nail -> Cleaned with backup
C:\WINDOWS\bsx32\EECH1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\SPZ3.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\cfgmgr52.dll -> Spyware.BookedSpace.e -> Cleaned with backup
C:\WINDOWS\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\My404.exe -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\WINDOWS\lqkozepc.exe -> Spyware.BookedSpace.e -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Local Settings\Temp\Cookies\closch@specificpop[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Local Settings\Temp\Cookies\closch@dcsi8dupuerp17vzhd59b2lwc_8u5u[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Local Settings\Temp\Cookies\closch@S0014-01-2-16-217494-54117[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Local Settings\Temp\Cookies\closch@S005-01-6-28-254547-85570[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Local Settings\Temp\Cookies\closch@S005-01-6-28-254547-85610[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Local Settings\Temp\Cookies\closch@S0014-01-2-16-217494-54117[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Local Settings\Temp\djebmm350.exe -> Spyware.Broadcap.a -> Cleaned with backup
C:\Documents and Settings\closch\Local Settings\Temp\pcs_0006.exe -> Spyware.Pacer.b -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@bannerads[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@bannerads[4].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@dcsi8dupuerp17vzhd59b2lwc_8u5u[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@S005-01-6-28-254547-85570[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@S0014-01-2-16-217494-54117[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@dcszqjbnh21e5hmqkbwitxmhi_8f9v[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@geocities[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@S0012-01-1-7-217494-47679[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@S0014-01-2-16-217494-54117[4].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@15876760[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@S005-01-6-28-254547-85570[3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@S0014-01-2-16-217494-54117[3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@10620967[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@bannerads[5].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@bannerads[3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@72067136[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@exitexchange[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@dcs9vjhcvoifwzvpkr3ppi958_9w3d[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@shopnav[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@S109821[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@dcsw8cxeoau4fifujx3tdt6ky_7s8w[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\closch\Cookies\closch@exitexchange[3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020344.exe -> TrojanDownloader.Wintool.e -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020349.exe -> Spyware.BargainBuddy -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020352.exe -> Spyware.WebSearch.aj -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020368.dll -> Spyware.CoolBar.a -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020370.exe -> Spyware.DealHelper.x -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020373.exe -> Spyware.Apropos -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020383.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020384.dll -> Spyware.VirtualBouncer.g -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020385.dll -> Spyware.VirtualBouncer.g -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020386.dll -> Spyware.VirtualBouncer.g -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020387.dll -> Spyware.VirtualBouncer.g -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020389.exe -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020414.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020466.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020520.EXE -> Trojan.AproposAd -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020521.EXE -> Trojan.AproposAd -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020529.exe -> Trojan.AproposAd -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP474\A0020530.exe -> Trojan.AproposAd -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP475\A0020574.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP475\A0020575.exe -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP475\A0020576.exe -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP475\A0020577.dll -> Spyware.EliteBar.af -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP475\A0020578.exe -> TrojanDownloader.Apropo.g -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP475\A0020581.exe -> Spyware.Apropos -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP475\A0020584.dll -> Spyware.Wintol.y -> Cleaned with backup
C:\System Volume Information\_restore{38A44F46-57B2-4F3E-96A3-F4596F62DCF3}\RP475\A0020585.exe -> TrojanDownloader.Wintool.f -> Cleaned with backup
::Report End