Thanks NonSuch--
I could not believe the number of infections found by ewido. As requested, log posted below along with the latest HJT. But when I tried to run ActiveScan, IE produced the same error message as what prompted my original post: "Internet Explorer has encountered a problem and needs to close. We are sorry for the inconvenience."
***********************************************************
ewido:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:56:56 PM, 9/28/2005
+ Report-Checksum: ABF70493
+ Scan result:
HKLM\SOFTWARE\Classes\AdultBar.AdultBar -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultBar.AdultBar\CLSID -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultBar.AdultBar\CLSID\\ -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultBar.AdultBar\CurVer -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultBar.AdultBar.1 -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultBar.AdultBar.1\CLSID\\ -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultSearch.AdultSearch -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultSearch.AdultSearch\CLSID -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultSearch.AdultSearch\CLSID\\ -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultSearch.AdultSearch\CurVer -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultSearch.AdultSearch.1 -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultSearch.AdultSearch.1\CLSID\\ -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\bundle.BundleObj\CLSID\\ -> Spyware.ClientMan : Cleaned with backup
HKLM\SOFTWARE\Classes\bundle.BundleObj.1\CLSID\\ -> Spyware.ClientMan : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{11A4CA8C-A8B9-49c2-A6D3-3F64C9EEBAE6}\TypeLib\\ -> Spyware.TX4 : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1E432263-6841-4653-8F02-366A2F77E339} -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{447160CD-ECF5-4EA2-8A8A-1F70CA363F85} -> Spyware.ClientMan : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF}\TypeLib\\ -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} -> Spyware.NetNucleus : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9FB534E3-67CB-4307-AE0A-9E8B5581BE2C} -> Spyware.WindowsSearchBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A1DD937D-71E1-4BB5-BD5D-1B01B9CB1C2F} -> Spyware.WindowsSearchBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{AF8B3C81-CD19-45FB-B6BE-160D27711DE8}\TypeLib\\ -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C91E8926-D4BE-4685-99F4-0D996B96BAC0} -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A}\TypeLib\\ -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FFFFDA2C-A0D5-4D60-8EE1-1B7F8929E24D} -> Spyware.SideSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\HTMLEdit.IETracker\CLSID\\ -> Spyware.CommonName : Cleaned with backup
HKLM\SOFTWARE\Classes\HTMLEdit.IETracker.1\CLSID\\ -> Spyware.CommonName : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{16097036-894C-4C00-A61F-93CA0D49A70E} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{16097036-894C-4C00-A61F-93CA0D49A70E}\ProxyStubClsid32\\ -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{1B540D44-3F61-4394-AE30-25FDC3649405}\ProxyStubClsid32\\ -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2ED5AF98-9258-45BA-B79B-06625C92F662} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2ED5AF98-9258-45BA-B79B-06625C92F662}\ProxyStubClsid32\\ -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6D7D135E-F7C2-4A27-A87C-C0DFEB3A628F}\TypeLib\\ -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6F59D850-A155-4930-98AE-689A2BC7B8E8}\TypeLib\\ -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{700DC0DD-F409-42E0-9DE5-21EE1A2BA9FD} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{700DC0DD-F409-42E0-9DE5-21EE1A2BA9FD}\ProxyStubClsid32\\ -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273}\TypeLib\\ -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\ProxyStubClsid32\\ -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C91E8926-D4BE-4685-99F4-0D996B96BAC0} -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C91E8926-D4BE-4685-99F4-0D996B96BAC0}\ProxyStubClsid32\\ -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{CE9B37EC-D243-47A2-83DB-3A8350175193}\ProxyStubClsid32\\ -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D1320CBB-403D-483D-AE9A-688960A96977} -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D1320CBB-403D-483D-AE9A-688960A96977}\TypeLib\\ -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{F8D96098-E9F7-42E1-88F3-A3719D70EA8D}\TypeLib\\ -> Spyware.BrowserAid : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{FD42F6D3-7AB1-470C-979B-7996EDC99099} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{FD42F6D3-7AB1-470C-979B-7996EDC99099}\ProxyStubClsid32\\ -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\POP.Loader\CLSID\\ -> Spyware.PeopleOnPage : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\QaBar -> Spyware.Adultlinks : Cleaned with backup
HKLM\SOFTWARE\Classes\QaBar\CLSID -> Spyware.Adultlinks : Cleaned with backup
HKLM\SOFTWARE\Classes\QaBar\CLSID\\ -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\QaBar\CurVer -> Spyware.Adultlinks : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5E594162-60A9-487D-84B8-DBDD716CB862} -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.AutoSearch\CLSID\\ -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.AutoSearch.1\CLSID\\ -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.Band -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.Band\CLSID -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.Band\CLSID\\ -> Spyware.WindowsSearchBar : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.Band\CurVer -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.Band.1 -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.Band.1\CLSID\\ -> Spyware.WindowsSearchBar : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.EventHandler -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.EventHandler\CLSID -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.EventHandler\CLSID\\ -> Spyware.WindowsSearchBar : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.EventHandler\CurVer -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.EventHandler.1 -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WindowsSB.EventHandler.1\CLSID\\ -> Spyware.WindowsSearchBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{850CD0B8-DA33-4558-A8C8-95D7908E37A7} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\{2CF0B992-5EEB-4143-99C2-5297EF71F44B} -> Spyware.BrowserAid : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bargain Buddy -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ISTbarISTbar -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{8A0DCBDA-6E20-489C-9041-C1E8A0352E75} -> Spyware.NetNucleus : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/anmqsrho.dll\\.Owner -> Spyware.SearchBarCash : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/anmqsrho.dll\\{52DCAD2D-D5DD-8EA5-315A-B4FE032A28F9} -> Spyware.SearchBarCash : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/btiein.dll\\.Owner -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/btiein.dll\\{26E8361F-BCE7-4F75-A347-98C88B418322} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/PdpPlugin.dll\\.Owner -> Spyware.Gator : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/PdpPlugin.dll\\{731918D2-517A-47E2-886A-3BC1380C591D} -> Spyware.Gator : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/rnmrnkoe.dll\\.Owner -> Spyware.SearchBarCash : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/rnmrnkoe.dll\\{912EE662-9BDF-DBCA-9FEC-CC133D477FFF} -> Spyware.SearchBarCash : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{FFFFDA2C-A0D5-4D60-8EE1-1B7F8929E24D} -> Spyware.SideSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinDH -> Spyware.DealHelper : Cleaned with backup
HKLM\SOFTWARE\SecureWin -> Spyware.Adlogix : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinIK -> Spyware.CommonName : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinIK\Security -> Spyware.CommonName : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinIK\Enum -> Spyware.CommonName : Cleaned with backup
HKU\.DEFAULT\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\toolbar\UrlSearchHooks -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\toolbar\UrlSearchHooks -> Spyware.WebSearch : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\mynoe76m.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\mynoe76m.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Mark Leonardis\Application Data\Mozilla\Firefox\Profiles\e3j4cgcb.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\Common Files\services.exe -> Spyware.Maxifiles : Cleaned with backup
C:\WINNT\bsx32 -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASI2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASI50.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASICLRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASICLV.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASIEPRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASIEZ.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASIKAB2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASIMBC.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASIRCPRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASISS2RE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ASISSRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPC.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPD.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPF.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPFAM.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPFI.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPFIN.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPG.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPH.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPHL.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPJ.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPM.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPMTV.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPN.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPR.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPS.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPSHOP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPSP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\TMPW.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\WEBS1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\WEBS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\bsx32\ZNETGP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINNT\gogotools.exe/SilentInstallW32.exe -> Spyware.GogoTools : Cleaned with backup
C:\WINNT\NDNuninstall4_50.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINNT\NDNuninstall4_80.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINNT\NDNuninstall6_38.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINNT\svcproc.exe -> Trojan.Stervis.i : Cleaned with backup
C:\WINNT\system32\aomparse.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\BO2202031216.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINNT\system32\BO2802040113.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINNT\system32\bS_L.dll/bi.dll -> Trojan.Bispy.A : Cleaned with backup
C:\WINNT\system32\bS_L.dll/preInsBI.exe -> Spyware.BiSpy : Cleaned with backup
C:\WINNT\system32\bS_L.dll/bi.dll -> Trojan.Bispy.A : Cleaned with backup
C:\WINNT\system32\bS_L.dll/preInsBI.exe -> Spyware.BiSpy : Cleaned with backup
C:\WINNT\system32\ca.dll -> Spyware.SearchIt : Cleaned with backup
C:\WINNT\system32\ca2.dll -> Spyware.SearchIt : Cleaned with backup
C:\WINNT\system32\cdgbkend.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\chktrust.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINNT\system32\coqujf.exe -> Spyware.Adstart : Cleaned with backup
C:\WINNT\system32\ctbv2.dll -> Adware.SAHA : Cleaned with backup
C:\WINNT\system32\cwgmgr32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\daquery.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\hwetwiz.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\iezset.exe -> Adware.eZula : Cleaned with backup
C:\WINNT\system32\ignet.dll -> TrojanDropper.Mudrop.w : Cleaned with backup
C:\WINNT\system32\ignet2.dll -> TrojanDropper.Mudrop.w : Cleaned with backup
C:\WINNT\system32\ihv6mon.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\in5bCs.dll/bi.dll -> Spyware.BiSpy : Cleaned with backup
C:\WINNT\system32\in5bCs.dll/biprep.exe -> Trojan.Bispy.B : Cleaned with backup
C:\WINNT\system32\in5bCs.dll/bi.dll -> Spyware.BiSpy : Cleaned with backup
C:\WINNT\system32\in5bCs.dll/biprep.exe -> Trojan.Bispy.B : Cleaned with backup
C:\WINNT\system32\kddne.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\kvdsf.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\mbbi8016.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINNT\system32\mcjter40.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\mer2cenu.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\mpftedit.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\mvvideo.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\naf2A.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\nostalgia.dll/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\WINNT\system32\nostalgia.dll/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\WINNT\system32\nostalgia.dll/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\WINNT\system32\nostalgia.dll/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\WINNT\system32\nostalgia1.dll/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\WINNT\system32\nostalgia1.dll/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\WINNT\system32\nostalgia1.dll/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\WINNT\system32\nostalgia1.dll/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\WINNT\system32\nstui2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\nvtigf.exe -> Spyware.Adstart : Cleaned with backup
C:\WINNT\system32\otethk32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\pelmon.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\pglstore.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\pLqsp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\QTBar.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\SHAgent.dll -> Adware.SAHA : Cleaned with backup
C:\WINNT\system32\SHAgentNew.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINNT\system32\solgntfy.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\SWRT01.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINNT\system32\virsion.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\weatherb.dll -> TrojanDropper.Small.so : Cleaned with backup
C:\WINNT\system32\WinStat12.dll -> Spyware.Winsta : Cleaned with backup
C:\WINNT\system32\wjtdecod.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\wunsta.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\wzhtcpip.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\zergkmk.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINNT\ttil_sbc.exe -> Adware.eZula : Cleaned with backup
C:\WINNT\whxowgms.exe -> Spyware.BookedSpace : Cleaned with backup
::Report End
*************************************************************
HJT:
Logfile of HijackThis v1.99.1
Scan saved at 11:08:00 PM, on 9/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\devldr32.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\System32\DRIVERS\dcfssvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\RealVNC\VNC4\winvnc4.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\EdB\Desktop\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://support.microsoft.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 7335159073
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftup ... 7501289458
O16 - DPF: {F554B9AB-E6C9-4FA6-BFE7-B3CB24AD5027} (MSN Money Charting) -
http://fdl.msn.com/public/investor/v11/investor.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: dcfssvc (Dcfssvc) - Eastman Kodak Company - C:\WINNT\System32\DRIVERS\dcfssvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINNT\System32\ImapiRox.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\winvnc4.exe" -service (file missing)