thanks for the quick response
Logfile of HijackThis v1.99.1
Scan saved at 22:43:57, on 06/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\apps\ActivSurf\4448364\Program\backweb-4448364.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Koescp\Wzbs.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\Apps\ActivBoard\OSD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\sally isfree\My Documents\adware spyware etc\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.tesco.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SU B_PVER}&ar=home
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tesco internet access
R3 - Default URLSearchHook is missing
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ActivSurf] C:\apps\ActivSurf\4448364\Program\backweb-4448364.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ICcontrol] C:\WINDOWS\iccontrol.exe
O4 - HKLM\..\Run: [Odbcbho] C:\Program Files\Koescp\Wzbs.exe
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [pbmini] C:\Program Files\PCAST\PodcastbarMini\PodcastBarMiniStater.ex e
O4 - HKCU\..\Run: [Update Service] C:\Program Files\Common Files\Teknum Systems\update.exe /startup
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Packard Bell - {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - C:\Apps\IECustom\script.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net
O16 - DPF: Yahoo! Blackjack -
http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) -
http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {0AE0F5F9-8233-49A4-A3C8-004CE190787B} (BMSpeedCheck Control) -
http://www.pdbox.co.kr/boxmedia/ctrl...SpeedCheck.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) -
http://www.tvkoo.com/update/KooPlayer.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
http://software-dl.real.com/05622f27...p/RdxIE601.cab
O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} (PowerPlayer Control) -
http://www.ppstream.com/bin/powerplayer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsof...?1125956114018
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1125956095002
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
O16 - DPF: {D8600320-952A-46B4-86C8-793EC9F2B2DC} (ADispX Control) -
http://www.uusee.com/uusee/psp.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.hp.com/sj/en/check/qdiagh.cab?326
O16 - DPF: {FAFF0003-0A01-121A-A1C9-08032B23E0CC} -
http://uk.global-acces.com/7adpower/nat2.exe
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} -
http://ps.itv.mop.com/dn/files/pCast...0_20060123.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1ECC8B83-A114-4430-9CB6-E453AFA10625}: NameServer = 80.225.252.58 80.225.252.50
O17 - HKLM\System\CS1\Services\Tcpip\..\{1ECC8B83-A114-4430-9CB6-E453AFA10625}: NameServer = 80.225.252.58 80.225.252.50
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 22:37:54, 06/03/2006
+ Report-Checksum: 1648FA6C
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\Rotue -> Adware.InternetOptimizer : Ignored
[2228] C:\Program Files\Koescp\Wzbs.exe -> Trojan.Small.cy : Ignored
C:\Documents and Settings\LocalService\Cookies\system@cl.enhance[1].txt -> TrackingCookie.Enhance : Ignored
C:\Documents and Settings\sally isfree\Cookies\sally isfree@112.2o7[2].txt -> TrackingCookie.2o7 : Ignored
C:\Documents and Settings\sally isfree\Cookies\sally isfree@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignored
C:\Documents and Settings\sally isfree\Cookies\sally isfree@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Ignored
C:\Documents and Settings\sally isfree\Cookies\sally isfree@adtech[2].txt -> TrackingCookie.Adtech : Ignored
C:\Documents and Settings\sally isfree\Cookies\sally isfree@kmpads[2].txt -> TrackingCookie.Kmpads : Ignored
C:\Documents and Settings\sally isfree\Cookies\sally isfree@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Ignored
C:\Documents and Settings\sally isfree\dr.exe -> Downloader.Adload.t : Ignored
C:\Documents and Settings\sally isfree\Local Settings\Temp\Cookies\sally isfree@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignored
C:\Documents and Settings\sally isfree\Local Settings\Temp\Cookies\sally isfree@com[2].txt -> TrackingCookie.Com : Ignored
C:\Documents and Settings\sally isfree\Local Settings\Temp\Cookies\sally isfree@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Ignored
C:\Documents and Settings\sally isfree\Local Settings\Temp\Cookies\sally isfree@data2.perf.overture[1].txt -> TrackingCookie.Overture : Ignored
C:\Documents and Settings\sally isfree\Local Settings\Temp\Cookies\sally isfree@e-2dj6wflokoajekq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored
C:\Documents and Settings\sally isfree\Local Settings\Temp\Cookies\sally isfree@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Ignored
C:\Documents and Settings\sally isfree\Local Settings\Temp\nssB.tmp -> Downloader.IstBar : Ignored
C:\Documents and Settings\sally isfree\Local Settings\Temporary Internet Files\Content.IE5\QH7GTWZ6\install[1].exe -> Downloader.
VB.xr : Ignored
C:\Documents and Settings\sally isfree\xxx.exe -> Dropper.Agent.mf : Ignored
C:\Program Files\Koescp\Wzbs.exe -> Trojan.Small.cy : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq376.tmp -> TrackingCookie.2o7 : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq377.tmp -> TrackingCookie.Adtech : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq378.tmp -> TrackingCookie.Falkag : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq379.tmp -> TrackingCookie.Bluestreak : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq37A.tmp -> TrackingCookie.Casalemedia : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq37C.tmp -> TrackingCookie.Com : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq37F.tmp -> TrackingCookie.Questionmarket : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq38A.tmp -> TrackingCookie.Tradedoubler : Ignored
C:\WINDOWS\lbbho.dll -> Adware.Neon : Ignored
C:\WINDOWS\Temp\Cookies\sally isfree@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignored
C:\WINDOWS\Temp\Cookies\sally isfree@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Ignored
C:\WINDOWS\Temp\Cookies\sally isfree@h.starware[1].txt -> TrackingCookie.Starware : Ignored
C:\WINDOWS\Temp\Cookies\sally isfree@paypopup[2].txt -> TrackingCookie.Paypopup : Ignored
C:\WINDOWS\Temp\Cookies\sally isfree@starware[2].txt -> TrackingCookie.Starware : Ignored
C:\WINDOWS\Temp\Cookies\sally isfree@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Ignored
C:\WINDOWS\Temp\Cookies\sally isfree@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Ignored
::Report End