okay, here is the ewido log:
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 14

21 31.07.2006
+ Scan result:
:mozilla.103:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.541:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.118:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.119:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.120:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.121:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.83:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.84:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.85:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.86:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.33:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.34:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.35:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.94:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.139:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.140:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.23:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.24:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.447:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.16:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.17:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.18:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.19:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.20:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.21:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.409:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.92:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.95:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.14:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.25:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.152:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.153:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.155:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.51:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.73:C:\Documents and Settings\Monty\Application Data\Mozilla\Firefox\Profiles\7ardbqy4.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
::Report end
and the smitfraudfix log:
SmitFraudFix v2.76
Scan done at 13:26:40,81, 31.07.2006
Run from C:\Documents and Settings\Monty\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler]
"cholecyst"="{ee2975b6-e8d5-405e-8448-8fe9590f6cfb}"
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\1024\ Deleted
C:\Program Files\IntCodec\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
and the latest hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 14:30:59, on 31.07.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\hijackthis.exe
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: BulletProof FTP Server.lnk = C:\Program Files\BPFTP Server\bpftpserver.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1125439877140
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe