Here's the logs sorry it took so long.
Panda ScanIncident Status Location
Adware:adware/adsmart No disinfected C:\WINDOWS\SYSTEM32\vxgame6.exe
Adware:adware/azesearch No disinfected C:\WINDOWS\SYSTEM32\ztoolbar.xml
Spyware:spyware/searchcentrix No disinfected Windows Registry
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\City Mp3 Trust Error\Wipe safe.exe
Virus:Bck/SmallHTTP.C Disinfected C:\Program Files\internet explorer\shttps\http.exe
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MediaTicketsInstaller.INF
Virus:Trj/Shellbot.B Disinfected C:\WINDOWS\system\svchost.exe
Adware:Adware/Tubby No disinfected C:\WINDOWS\system32\10735486.exe
Adware:Adware/Tubby No disinfected C:\WINDOWS\system32\25264017.exe
Adware:Adware/Tubby No disinfected C:\WINDOWS\system32\2895763.exe
Adware:Adware/Tubby No disinfected C:\WINDOWS\system32\436858.exe
Adware:Adware/Tubby No disinfected C:\WINDOWS\system32\67029893.exe
Adware:Adware/Tubby No disinfected C:\WINDOWS\system32\70342907.exe
Virus:Trj/Downloader.EQS Disinfected C:\WINDOWS\system32\cszdl.exe
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20050913-200325.backup
Possible Virus. No disinfected C:\WINDOWS\system32\svcdl32.exe
Security Risk:Application/RestartNo disinfected C:\WINDOWS\system32\Tools\Restart.exe
Virus:Trj/Sapilayr.B Disinfected C:\WINDOWS\system32\vxgame6.exe
Virus:Trj/Multidropper.AVO Disinfected C:\WINDOWS\wmplayer.exe
I couldn't find the MediaTicketsInstaller folder on my computer, and I also couldn't find the one located in Windows Registry.
Ewido---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 12:43:30 PM, 9/24/2005
+ Report-Checksum: B951C786
+ Scan result:
:mozilla.13:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\srxej62z.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\srxej62z.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Tina\Application Data\Mozilla\Firefox\Profiles\m7e6t3ed.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
::Report End
HiJackThisLogfile of HijackThis v1.99.1
Scan saved at 11:30:42 AM, on 9/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Wacom\TabUserW.exe
C:\Program Files\HiJackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\Net2Phone\Net2fone.exe
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\Net2Phone\Net2fone.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cabO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cabO16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/15009/CTSUEng.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefender.com/scan8/oscan8.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} -
http://www.bitdefender.com/scan/Msie/bitdefender.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...StatsClient.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMesse...pDownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZIntro.cab32846.cabO16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?315O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/15009/CTPID.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{33C425F1-69E5-4F22-BB60-CDCA667F820A}: NameServer = 69.50.177.204,85.255.112.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{396BA175-4D10-4AF1-91CA-D7ADAFB7D742}: NameServer = 69.50.177.204,85.255.112.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{3FEE8B23-46DE-46EE-8B93-CDD2479EC428}: NameServer = 69.50.177.204,85.255.112.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{53A6D3E7-5DBB-49E8-B52A-955B682DF5CB}: NameServer = 69.50.177.204,85.255.112.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{9AF24F60-778A-4814-B33B-6CED8D67EEFE}: NameServer = 69.50.177.204,85.255.112.25
O17 - HKLM\System\CS1\Services\Tcpip\..\{33C425F1-69E5-4F22-BB60-CDCA667F820A}: NameServer = 69.50.177.204,85.255.112.25
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe
SmitFile smitRem log file
version 2.5
by noahdfear
The current date is: Sat 09/24/2005
The current time is: 10:05:49.04
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Pre-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Post-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN! :)
One concern of mine.
There is a peculiar looking file called svchost.exe under my system32 folder. I realise that svchost is a useful thing running in task manager ... but I thought it wasn't supposed to have .exe on the end of it. Also, this file has NO PICTURE when you view as tiles.