i have done the following that you have said to do here are my reports thanks for your time
hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 16:49:49, on 23/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\SecuritySuite.exe
C:\Documents and Settings\leon\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.co.uk/
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [SlowDownCPU] C:\WINDOWS\INF\MSI\SlowDownCPU\SlowDownCPU.exe
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKLM\..\Run: [FvXdb] C:\WINDOWS\jiuexuy.exe
O4 - HKLM\..\Run: [3QPYA5] "C:\DOCUME~1\leon\LOCALS~1\Temp\cxtpls_loader. exe" /PC=CP.IST2 /SHUN /UNAR="/CTUN"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) -
http://gamingzone.ubisoft.com/dev/pa.../GSManager.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} -
http://www.tbcode.com/ist/softwares/...06_regular.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/Ms...Downloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
ewido log:
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 17:29:27, 23/10/2005
+ Report-Checksum: 4B6110F5
+ Scan result:
HKLM\SOFTWARE\Classes\YSBactivex.Installer -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\YSBactivex.Installer\CLSID -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Mod uleUsage\C:/WINDOWS/Downloaded Program Files/istactivex.dll -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Mod uleUsage\C:/WINDOWS/Downloaded Program Files/istactivex.dll\\.Owner -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Mod uleUsage\C:/WINDOWS/Downloaded Program Files/istactivex.dll\\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\YourSiteBar -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\YourSiteBar\Historyfiles -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\YourSiteBar\Historygoogle -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\YourSiteBar\Historysearch -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-682003330-152049171-2146912999-1008\Software\Avenue Media -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-682003330-152049171-2146912999-1008\Software\IST -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-682003330-152049171-2146912999-1008\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{86227D9C-0EFE-4F8A-AA55-30386A3F5686} -> Spyware.YourSiteBar : Cleaned with backup
HKU\S-1-5-21-682003330-152049171-2146912999-1008\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
HKU\S-1-5-21-682003330-152049171-2146912999-1008\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-682003330-152049171-2146912999-1008\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686} -> Spyware.YourSiteBar : Cleaned with backup
HKU\S-1-5-21-682003330-152049171-2146912999-1008\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{C900B400-CDFE-11D3-976A-00E02913A9E0} -> Spyware.Webhancer : Cleaned with backup
HKU\S-1-5-21-682003330-152049171-2146912999-1008\Software\Microsoft\Windows\CurrentVersion\Pol icies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-682003330-152049171-2146912999-1008\Software\Policies\Avenue Media -> Spyware.InternetOptimizer : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqC.tmp -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD.tmp -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq10.tmp -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq11.tmp -> Spyware.Cookie.Adviva : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq12.tmp -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq13.tmp -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq15.tmp -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq16.tmp -> Spyware.Cookie.Com : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq17.tmp -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq18.tmp -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq19.tmp -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1A.tmp -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B.tmp -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1C.tmp -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1D.tmp -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1F.tmp -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq20.tmp -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq21.tmp -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq23.tmp -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq24.tmp -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25.tmp -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq26.tmp -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq27.tmp -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28.tmp -> Spyware.Cookie.Onestat : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq29.tmp -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A.tmp -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2B.tmp -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2C.tmp -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2D.tmp -> Spyware.Cookie.Xxxcounter : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2E.tmp -> Spyware.Cookie.Adserver : Cleaned with backup
C:\FOUND.004\FILE0639.CHK -> Spyware.NewDotNet : Cleaned with backup
C:\FOUND.004\FILE0642.CHK/whAgent.exe -> Spyware.WebHancer : Cleaned with backup
C:\FOUND.004\FILE0650.CHK -> Spyware.WebHancer : Cleaned with backup
C:\FOUND.004\FILE0651.CHK -> Spyware.WebHancer : Cleaned with backup
C:\FOUND.004\FILE0665.CHK -> Spyware.WebHancer : Cleaned with backup
C:\Documents and Settings\julie\Cookies\julie@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\julie\Cookies\julie@ehg-littlewoods.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\julie\Cookies\julie@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\leon\Local Settings\Temp\SHNT288.exe -> Spyware.NewDotNet : Cleaned with backup
C:\Documents and Settings\leon\Local Settings\Temp\wh.exe/whAgent.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP8\A0001458.dll -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP8\A0001459.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP8\A0001460.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP8\A0001461.dll -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP8\A0001521.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP8\A0001527.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP8\A0001532.dll -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP22\A0014133.dll -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP22\A0014134.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP22\A0014135.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP22\A0014136.dll -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP23\A0014289.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP23\A0014302.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP23\A0014303.dll -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP23\A0014314.exe/whAgent.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP23\A0014315.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP27\A0015938.dll -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP27\A0015939.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP27\A0015940.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP27\A0015941.dll -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{1AEDB6B4-5C4B-48A7-A57C-E7FB87350BAD}\RP27\A0015944.dll -> Spyware.WebHancer : Cleaned with backup
::Report End