ok ewido scan completed and new hijack this log, unable to update ewido and spy sweeper still will not run application:
Logfile of HijackThis v1.99.1
Scan saved at 5:59:58 AM, on 6/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\Program Files\ewido anti-malware\ewidoctrl.exe
E:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
E:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
E:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
E:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
E:\WINDOWS\system32\wscntfy.exe
E:\WINDOWS\DvzCommon\DvzMsgr.exe
E:\Program Files\Palm\HOTSYNC.EXE
E:\Documents and Settings\Owner\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.fluidgroove.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://rl.webtracer.cc/-/?bayzm (obfuscated)
O1 - Hosts: 3510794929 auto.search.msn.com
O4 - Startup: HotSync Manager.lnk = E:\Program Files\Palm\HOTSYNC.EXE
O8 - Extra context menu item: &AIM Search - res://E:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Viewpoint Search - res://E:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - E:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by23fd.bay23.hotmail.msn.com/...s/MsnPUpld.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) -
http://www.kodakgallery.com/download...1/axofupld.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} -
http://pictures04.aim.com/ygp/aol/pl...IM.9.5.1.8.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) -
http://us.dl1.yimg.com/download.yaho...opper1_4us.cab
O19 - User stylesheet: E:\WINDOWS\stsheets.dat
O20 - Winlogon Notify: igfxcui - E:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - E:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - E:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - E:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - E:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - E:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
ewido:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 5:43:03 AM, 6/10/2006
+ Report-Checksum: 609B993B
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{00000001-C003-4A2F-9142-7CB1D78DE6C1} -> Adware.InternetOptimizer : Ignored
HKLM\SOFTWARE\Classes\CLSID\{7FD44536-9DF0-4034-939F-5BD4D98E3187} -> Adware.Generic : Ignored
HKLM\SOFTWARE\Classes\CLSID\{F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} -> Adware.Generic : Ignored
C:\Documents and Settings\Eupie Namocatcat\Cookies\eupie namocatcat@2o7[1].txt -> TrackingCookie.2o7 : Ignored
HKLM\SOFTWARE\Classes\CLSID\{0DD6DF67-E153-DF83-F668-96227EBA767C} -> Adware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3D782BB3-F2A5-11D3-BF4C-000000000000} -> Adware.ActivShopper : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7B30E423-F515-4FA4-3E7D-E7674D2337E3} -> Adware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C3D1ED9E-9B11-B261-24E2-872B4D9DCD06} -> Adware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1993962763-73586283-839522115-1003\Software\_siq -> Adware.Begin2Search : Cleaned with backup
C:\Documents and Settings\Eupie Namocatcat\Cookies\eupie namocatcat@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Eupie Namocatcat\Cookies\eupie namocatcat@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Eupie Namocatcat\Cookies\eupie namocatcat@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Eupie Namocatcat\Cookies\eupie namocatcat@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Eupie Namocatcat\Cookies\eupie namocatcat@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\Eupie Namocatcat\Cookies\eupie namocatcat@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Eupie Namocatcat\Cookies\eupie namocatcat@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Eupie Namocatcat\Cookies\eupie namocatcat@www.web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\ed.exe -> Dropper.Agent.mm : Cleaned with backup
C:\Program Files\Cxtpls\Cxtpls.dll -> Adware.Apropos : Cleaned with backup
C:\Program Files\Cxtpls\uninstaller.exe -> Adware.Apropos : Cleaned with backup
C:\Program Files\Cxtpls\WinGenerics.dll -> Adware.Apropos : Cleaned with backup
C:\q.exe -> Downloader.Apher : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\mp3.ocx -> Downloader.Agent.ex : Cleaned with backup
C:\WINDOWS\SSK_B5.EXE -> Dropper.SurfSide.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\akcore.dll -> Adware.Coreak : Cleaned with backup
C:\WINDOWS\SYSTEM32\aklsp.dll -> Downloader.Agent.br : Cleaned with backup
C:\WINDOWS\SYSTEM32\akrules.dll -> Downloader.Agent.bt : Cleaned with backup
C:\WINDOWS\SYSTEM32\akupd.dll -> Downloader.Agent.br : Cleaned with backup
C:\WINDOWS\SYSTEM32\BO2801040128.dll -> Adware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\BO2809040510.exe -> Adware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\SYSTEM32\calsp.dll -> Downloader.Agent.br : Cleaned with backup
C:\WINDOWS\SYSTEM32\casync.dll -> Adware.Couponage : Cleaned with backup
C:\WINDOWS\SYSTEM32\Msbb321.dll -> Adware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\siae3123.exe -> Dropper.Small.sc : Cleaned with backup
C:\WINDOWS\SYSTEM32\SWRT01.dll -> Adware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\Temp\auf0.exe -> Downloader.Apropo.al : Cleaned with backup
E:\Documents and Settings\E-Venus\Cookies\e-venus@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned with backup
E:\Documents and Settings\E-Venus\Cookies\e-venus@cliks[1].txt -> TrackingCookie.Cliks : Cleaned with backup
E:\Documents and Settings\Eupie\Cookies\eupie@abetterinternet[2].txt -> TrackingCookie.Abetterinternet : Cleaned with backup
E:\Documents and Settings\Eupie\Cookies\eupie@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup
E:\Documents and Settings\Eupie\Cookies\eupie@bestoffersnetworks[2].txt -> TrackingCookie.Bestoffersnetworks : Cleaned with backup
E:\Documents and Settings\Eupie\Cookies\eupie@cliks[2].txt -> TrackingCookie.Cliks : Cleaned with backup
E:\Documents and Settings\Eupie\Cookies\eupie@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
E:\Documents and Settings\Eupie\Local Settings\Temp\4.tmp -> Adware.WinShow : Cleaned with backup
E:\Documents and Settings\Eupie\Local Settings\Temp\4.tmp.exe -> Adware.WinShow : Cleaned with backup
E:\Documents and Settings\Owner\Cookies\owner@com[1].txt -> TrackingCookie.Com : Cleaned with backup
E:\Documents and Settings\Owner\Local Settings\Temp\582.tmp\thnall1z.exe -> Adware.BetterInternet : Cleaned with backup
E:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
E:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@marthastewart.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
E:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned with backup
E:\Documents and Settings\Owner\Local Settings\Temp\pmt.exe -> Downloader.Small.bke : Cleaned with backup
E:\Program Files\TBONAS\TBONcomp.dll -> Adware.ActivShopper : Cleaned with backup
E:\Program Files\TBONAS\TBONlchr.dll -> Adware.ActivShopper : Cleaned with backup
E:\System Volume Information\_restore{44CBE810-B63E-4057-8931-E31E6CD4E890}\RP485\A0170108.EXE -> Adware.Bestofer : Cleaned with backup
E:\System Volume Information\_restore{44CBE810-B63E-4057-8931-E31E6CD4E890}\RP573\A0174918.dll -> Downloader.Agent.jb : Cleaned with backup
E:\System Volume Information\_restore{44CBE810-B63E-4057-8931-E31E6CD4E890}\RP573\A0174919.dll -> Downloader.Agent.jb : Cleaned with backup
E:\System Volume Information\_restore{44CBE810-B63E-4057-8931-E31E6CD4E890}\RP573\A0174920.exe:gmfvc -> Downloader.Agent.bq : Cleaned with backup
E:\System Volume Information\_restore{44CBE810-B63E-4057-8931-E31E6CD4E890}\RP573\A0174921.exe -> Downloader.Agent.bq : Cleaned with backup
E:\WINDOWS\dinst.exe -> Adware.BetterInternet : Cleaned with backup
E:\WINDOWS\Downloaded Program Files\mp3.ocx -> Downloader.Agent.ex : Cleaned with backup
E:\WINDOWS\svcproc.exe -> Adware.BetterInternet : Cleaned with backup
E:\WINDOWS\system32\siq.dll -> Adware.HotSearchBar : Cleaned with backup
E:\WINDOWS\tct101.dll -> Downloader.Dyfuca.eg : Cleaned with backup
E:\WINDOWS\thin-114-1-x-x.exe -> Adware.BetterInternet : Cleaned with backup
::Report End