View Single Post
Old 10-21-2006, 01:47 PM   #7 (permalink)
orage
Registered User
 
Join Date: May 2005
Posts: 110
OS: XP


Thank you very much for your help!!! I was able to install bitdefender antivirus, did a full virus scan, and nothing was found. This is my new HJT results and and Ewido report:

----------------------------
Logfile of HijackThis v1.99.1
Scan saved at 12:44:27 p.m., on 21/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Wiliman Duran\Desktop\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

--------------------------



Ewido

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 12:40:06 p.m. 21/10/2006

+ Scan result:



:mozilla.6:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.7:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.8:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.20:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.14:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{2F64F4B3-96AA-42F7-A356-AEF02858B426}\{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt/{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt -> TrackingCookie.Adjuggler : Error during cleaning.
:mozilla.15:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{2F64F4B3-96AA-42F7-A356-AEF02858B426}\{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt/{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt -> TrackingCookie.Adjuggler : Error during cleaning.
:mozilla.16:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{2F64F4B3-96AA-42F7-A356-AEF02858B426}\{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt/{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt -> TrackingCookie.Adjuggler : Error during cleaning.
:mozilla.55:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.56:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.58:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.18:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{2F64F4B3-96AA-42F7-A356-AEF02858B426}\{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt/{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt -> TrackingCookie.Burstbeacon : Error during cleaning.
:mozilla.53:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.17:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{2F64F4B3-96AA-42F7-A356-AEF02858B426}\{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt/{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt -> TrackingCookie.Burstnet : Error during cleaning.
:mozilla.57:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.77:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.78:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.79:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.80:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.82:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup (quarantined).
:mozilla.13:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{2F64F4B3-96AA-42F7-A356-AEF02858B426}\{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt/{5FED9B24-AC51-483A-9ADB-EDF2121B5491}.txt -> TrackingCookie.Trafic : Error during cleaning.
:mozilla.52:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Wiliman Duran\Application Data\Mozilla\Firefox\Profiles\yq21w9y0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).


::Report end
orage is offline