---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 21:38:31, 09-06-2005
+ Report-Checksum: 29F0C1F5
+ Date of database: 09-06-2005
+ Version of scan engine: v3.0
+ Duration: 10 min
+ Scanned Files: 81309
+ Speed: 124.43 Files/Second
+ Infected files: 68
+ Removed files: 68
+ Files put in quarantine: 68
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
D:\
+ Scan result:
C:\Documents and Settings\Thelen\Cookies\thelen@247realmedia[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@51889961[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@89138634[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@ad12.bannerbank[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@ad9.bannerbank[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@ads.addynamix[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@artemis.porntrack[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@as1.falkag[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@atdmt[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@a[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@bluestreak[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@bravenet[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@burstnet[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@cgi-bin[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@cgi-bin[4].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@cgi-bin[5].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@cgi-bin[7].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@cgi-bin[8].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@counter12.sextracker[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@counter15.sextracker[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@counter2.sextracker[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@counter5.sextracker[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@counter6.sextracker[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@data.coremetrics[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@ehg-bskyb.hitbox[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@ehg-cafepress.hitbox[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@ehg-lowermybills.hitbox[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@fastclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@geocities[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@hitbox[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@internetfuel[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@interracialschoolgirls[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@landing.domainsponsor[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@linksynergy[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@list[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@magpie.sitetracker[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@mediamgr.ugo[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@mediaplex[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@perf.overture[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@phg.hitbox[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@realguide.real[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@realmedia[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@real[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@search.msn[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@servedby.advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@servedby.netshelter[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@server.iad.liveperson[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@sexlist[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@sextracker[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@spylog[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@stat.onestat[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@statse.webtrendslive[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@tradedoubler[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@tribalfusion[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@valueclick[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@vip.clickzs[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@wowvault.ign[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@www.armaniexchange[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@xiti[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@z1.adserver[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Cookies\thelen@zedo[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Thelen\Local Settings\Temp\Cookies\thelen@as1.falkag[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\WINDOWS\autoload.exe -> Not-A-Virus.Tool.Autoloader -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\videox.dll -> Spyware.Redhotnetworks -> Cleaned with backup
::Report End
Logfile of HijackThis v1.99.0
Scan saved at 21:41:19, on 09-06-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Pulsar Software\GammaLaunch\gamma.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Thelen\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NvMixerTray] C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [GammaLaunch] C:\Program Files\Pulsar Software\GammaLaunch\gamma.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {B38FF5B6-85AA-4A36-85FF-3D71F2E0A01F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {B38FF5B6-85AA-4A36-85FF-3D71F2E0A01F} - (no file) (HKCU)
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cabO16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} (Video Class) -
http://spystream.babenet.com/cabs/videox.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/055f4f517f48b4062317/netzip/RdxIE601.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnmessengersetupdownloader.cabO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: RadClock - Unknown - C:\WINDOWS\system32\RadClock.exe