Hi Alba
OK, no luck again with deleting the NT service but everything else seemed to go fine and (touch wood) there's no sign of Spy Sherrif.
Below are all logs requested.
Thanks again
===========
Hijack This
===========
Scan saved at 18:36:56, on 19/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\hjt\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\chwcl.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\chwcl.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\chwcl.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\chwcl.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\chwcl.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\chwcl.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\chwcl.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.blueyonder.co.uk/
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {0FA38F98-1D55-4DB3-50F0-DD4C594E086C} - C:\WINDOWS\system32\mfcxd32.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [apppz.exe] C:\WINDOWS\apppz.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [SNInstall] C:\DOCUME~1\Barry\LOCALS~1\Temp\32.tmp
O4 - Startup: Free WebSite Tools.lnk = ?
O4 - Global Startup: Motorola Desktop Suite.lnk = C:\Program Files\Motorola\Motorola Desktop Suite\DesktopSuite.exe
O4 - Global Startup: Motorola Desktop Suite mRouter Config.lnk = C:\Program Files\Intuwave Ltd\Shared\mRouterRunTime\mRouterConfig.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\Msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\Msjava.dll
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} (Eyeball Video Session Control) -
http://imlive.com/ChatSource/gVideoContol.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) -
http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} -
https://register3.valueactive.com/236/webolr/OCX/FlashAX.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\d3wc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
==============
About Buster log
==============
AboutBuster 5.0 reference file 30
Scan started on [19/09/2005] at [18:43:32]
------------------------------------------------
Streams(ADS) not scanned: System not NTFS
------------------------------------------------
Removed File! : C:\Windows\chwcl.dll
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 18:43:59
==============
hslog.txt,
==============
Horseserver Removal Tool v1.05
by Atri
-
-
1. Registry Fix Started
-
Registry fix complete
-
2. Deleted Services
-
-
3. Finding files Located on system
-
p2.ini
ps.a3d
-
4. Deleting files that were found.
-
-
5. Checking for and Removing Winupdate
-
-
-
=============
smitfiles.txt
=============
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Post-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Wininet.dll ~~~
CLEAN!
==============
Panda scan
==============
Incident Status Location
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3bb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mssi.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkuk.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mstx32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apihu.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\winup32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apiia32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkbx.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mfcgz32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\addyx.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apijw.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkij32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ntgk.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3ko.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysvh32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\appxe.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apprv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mswa32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ienu.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msdp.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysfm32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\appkq.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\iexy32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysla.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ipgk32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\javatm.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ntrp.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkxd32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\wingk.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\addoy.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\javajp32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\javalg.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ipbv.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3aj32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\atlya32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\javaeb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\iedw.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\wingt.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mszg32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\addyb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\crxj32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\netkj.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ipoy32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\atlpt32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3xj.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\netoj32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\javaoc32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msqz32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ipux32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\addlf.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\netxh.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ntha32.exe
Adware:adware/cws.searchmeup No disinfected C:\WINDOWS\mstasks1.exe
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINDOWS\chwcli.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINDOWS\dtpzyo.dat
Adware:adware program No disinfected C:\WINDOWS\System32mscore.bin
Adware:Adware/SearchAid No disinfected C:\WINDOWS\edubis.dat
Adware:Adware/SearchAid No disinfected C:\WINDOWS\lcqgha.dat
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addwh32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntmw.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlry32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\appnf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfcze32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atldu32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winnc.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ipon32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crhj.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlci.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crog32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apizp32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3oe.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntwf.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\appmh32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msmv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winbb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apizw32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msri.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atljp.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atldg.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfcjd32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntiq.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\netfl.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ipli32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ieuo.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sysxf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkcb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\javacp.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlhy.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ipdc32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfcnd.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ippz32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\javaue32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3rs32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkkx32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3ae.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\javasf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\netdl.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\javajz32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3st32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\netmp32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntgb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apimu32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msrf.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ipwh32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addza32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crzz32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apiqh.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\windb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winco32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addep.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlsd32.exe
Dialer

ialer.BEW No disinfected C:\Documents and Settings\Tammy\Local Settings\Temporary Internet Files\Content.IE5\STU7W9MZ\access[1].cgi
Possible Virus. No disinfected C:\Program Files\HTML Guardian\htmlg.exe
Adware:Adware/Twain-Tech No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP417\A0290609.inf
Adware:Adware/IPInsight No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP417\A0290614.inf
Adware:Adware/IPInsight No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP417\A0290615.ini
Virus:Trj/Downloader.ECQ Disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP417\A0292950.exe
Virus:Trj/Downloader.ECQ Disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP417\A0292951.exe
Adware:Adware/IPInsight No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP417\A0292954.inf
Adware:Adware/Popuper No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300048.dll
Adware:Adware/SpySheriff No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300049.dll
Adware:Adware/SpySheriff No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300050.dll
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300057.dll
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300181.dll
Virus:Trj/Microjoin.S Disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300182.exe
Adware:Adware/SpySheriff No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300186.exe
Virus:Trj/Downloader.EFA Disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300187.dll
Adware:Adware/Spywad No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300188.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{EE4D7178-3E4B-44D3-9019-DAD8E28A3D08}\RP454\A0300190.exe
Adware:Adware/SearchAid No disinfected C:\FOUND.052\FILE0000.CHK
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\hjt\backups\backup-20050919-184014-684.dll
Possible Virus. No disinfected C:\installation_files\html_guardian\HTMLGuardian.exe[htmlg.CAB][htmlg.exe]
Possible Virus. No disinfected C:\installation_files\htmlg_pro.zip[pro.exe][htmlg.exe]