Followed the instructions posted and the results are as follows. Thanks again for all the help, really appreciate it. I apologize for any inconviniences.
Logfile of HijackThis v1.99.1
Scan saved at 9:20:26 AM, on 5/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
c:\windows\system32\iirudu.exe
C:\Jeremy\HiJack\HijackThis.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RavTimeXP] C:\WINDOWS\WEB\KI.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [mvykoe] c:\windows\system32\iirudu.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted IP range: 67.19.185.246
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.../kavwebscan.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1116148618357O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) -
http://gwacee.multip...os/uploader.cabO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 8:54:32 AM, 5/24/2005
+ Report-Checksum: 1506DB95
+ Date of database: 5/24/2005
+ Version of scan engine: v3.0
+ Duration: 29 min
+ Scanned Files: 35854
+ Speed: 20.46 Files/Second
+ Infected files: 60
+ Removed files: 60
+ Files put in quarantine: 60
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
D:\
+ Scan result:
C:\WINDOWS\system32\drivers\delprot.sys -> Trojan.Delprot.a -> Cleaned with backup
C:\WINDOWS\system32\kpdsxr.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\WINDOWS\system32\intfsdffdsronsad.exe -> Spyware.ISearch.d -> Cleaned with backup
C:\WINDOWS\isrvs\desktop.exe -> Spyware.ISearch.d -> Cleaned with backup
C:\WINDOWS\isrvs\isearch.xpi/chrome/isearch.jar/content/isearch/isearch.js -> Spyware.ISearch.e -> Cleaned with backup
C:\WINDOWS\isrvs\ffisearch.exe -> Spyware.Isearch -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaAccX.dll_tobedeleted -> Spyware.WinAD -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaAccX.dll -> Spyware.WinAD -> Cleaned with backup
C:\Documents and Settings\gwacee\Cookies\gwacee@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\gwacee\Cookies\gwacee@fastclick[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\gwacee\7.dat -> Spyware.ISearch.d -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\EYF\aurareco.exe -> Spyware.BetterInternet.f -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0015409.exe -> Spyware.ISearch.d -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0015419.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016407.exe -> Spyware.ISearch.d -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016412.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016432.dll -> Spyware.WinAD.ag -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0017600.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0017609.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016449.exe -> Spyware.Bargainbuddy -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016450.exe -> Spyware.BargainBuddy -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016451.exe -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016452.exe -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016453.exe -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016454.srg -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016455.dll -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016459.exe -> Spyware.Apropos -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016481.exe -> Spyware.ISearch.d -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016486.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016489.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016491.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016497.exe -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016519.exe -> Spyware.ISearch.d -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0016528.exe -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0017512.exe -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0017514.exe -> Trojan.AproposAd -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0017515.exe -> Trojan.AproposAd -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0017534.dll -> Spyware.WinAD.ag -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0017562.exe -> Spyware.ISearch.d -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0017566.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP110\A0017572.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP111\A0018636.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP111\A0018637.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP111\A0019721.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP112\A0021870.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP113\A0021910.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP113\A0021925.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022097.exe -> TrojanDownloader.Delf.lf -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022098.dll -> TrojanProxy.Small.bo -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022099.exe -> TrojanProxy.Lager.g -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022100.exe -> TrojanProxy.Lager.g -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022101.exe -> Trojan.LowZones.y -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022102.exe -> TrojanDownloader.Apropo.ab -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022103.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022104.dll -> TrojanProxy.Small.bo -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022106.EXE -> TrojanProxy.Small.bo -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP118\A0022107.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP119\A0022122.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP119\A0022128.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{C5CC459E-B165-42BE-AECA-0CA0A547517B}\RP119\A0022129.exe -> Trojan.Nail -> Cleaned with backup
::Report End