Hey once again....i did everything you told me...updated to sp1....scanned basically everything !!! However, i ran into a little problem when i was trying to run combofix...it runs i followed the instructions but then suddenly after few seconds the window disappears..i didn't click on the window either....so i do not have the log file for that !!! here is the log file for the other two you requested.
Logfile of HijackThis v1.99.1
Scan saved at 5:50:29 PM, on 25/07/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Everstrike Software\Universal Shield 3.1\US30Service.exe
C:\Program Files\ZyDAS\ZD1211 802.11g Utility\ZDWlan.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\sahish\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.ca/R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: ZDWlan.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: US30Service - Unknown owner - C:\Program Files\Everstrike Software\Universal Shield 3.1\US30Service.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\gbcjola.exe (file missing)
************
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:10:37 PM 25/07/2006
+ Scan result:
C:\WINDOWS\thiselt.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004276.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\nsn56B.dll -> Adware.Ezula : Cleaned with backup (quarantined).
C:\Program Files\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Browser Helper -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Browser Helper\cf1 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-1606980848-1078145449-854245398-1003\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-1606980848-1078145449-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-1606980848-1078145449-854245398-1003\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ftuninst.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\WINDOWS\System32ftuninst.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\lvnm0951e.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004326.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\amm06.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004340.exe -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\WinNB58.dll -> Adware.Mirar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Adware.MoneyTree : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\SHNT288.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004282.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004341.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004279.DLL -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004280.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004281.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP16\A0001721.exe -> Adware.Relevant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004288.dll -> Adware.RK : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004332.exe -> Adware.RK : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\C3B5D7.tmp/mptft.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\D0F5D3.tmp/mptft.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\E6C5D5.tmp/mptft.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\E7C5D4.tmp/mptft.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\F5E5D6.tmp/mptft.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004272.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\WINDOWS\System32tfthot.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\C0F560.tmp/bdpn.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\C3B5D7.tmp/ahnciup.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\D0F5D3.tmp/ahnciup.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\E6C5D5.tmp/ahnciup.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\E7C5D4.tmp/ahnciup.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\F5E5D6.tmp/ahnciup.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004284.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004285.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ahnciup.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\hvzead7v.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\i577.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\i57F.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004343.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004246.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004263.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004301.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004320.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004321.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004349.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP38\A0013774.DLL -> Backdoor.Agent.adr : Cleaned with backup (quarantined).
F:\System Volume Information\_restore{0F1C0490-20F6-4CA9-A9FC-5265CC79FC7C}\RP79\A0028908.exe -> Backdoor.Iroffer.1228 : Cleaned with backup (quarantined).
F:\System Volume Information\_restore{78E1496F-8143-4A95-B669-4D1DFFA27345}\RP8\A0000288.exe -> Backdoor.Iroffer.1228 : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dlh9jkdq7.exe -> Downloader.Small.dht : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP24\A0010857.exe -> Downloader.Tibs.gc : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MediaTicketsInstaller.ocx -> Dropper.PurityScan.ae : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP20\A0004257.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP24\A0013086.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\C0F560.tmp/mptft.exe -> Hijacker.StartPage.ajj : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\ICD1.tmp\USDR6_0001_D08M0404NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\USDR6_0001_D08M0404NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
F:\System Volume Information\_restore{5A552F0B-C1DE-4F6F-A34D-DB1C4DD11042}\RP18\A0002878.exe -> Not-A-Virus.HackTool.Win32.Xray.a : Cleaned with backup (quarantined).
F:\System Volume Information\_restore{0F1C0490-20F6-4CA9-A9FC-5265CC79FC7C}\RP79\A0028900.exe -> Not-A-Virus.RemoteAdmin.Win32.RA.3826 : Cleaned with backup (quarantined).
F:\System Volume Information\_restore{78E1496F-8143-4A95-B669-4D1DFFA27345}\RP8\A0000293.exe -> Not-A-Virus.RemoteAdmin.Win32.RA.3826 : Cleaned with backup (quarantined).
F:\System Volume Information\_restore{0F1C0490-20F6-4CA9-A9FC-5265CC79FC7C}\RP79\A0028904.bat -> Trojan.NoShare.q : Cleaned with backup (quarantined).
C:\Documents and Settings\sahish\Local Settings\Temp\C0F560.tmp/xd7ehbkw.exe -> Trojan.Runner.j : Cleaned with backup (quarantined).
::Report end