ok.. i completed your instructions and so far i havent had any aurora pop ups.. here are the 3 logs you requested.
--------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 1:01:28 PM, 5/29/2005
+ Report-Checksum: 701F5EC4
+ Date of database: 5/28/2005
+ Version of scan engine: v3.0
+ Duration: 742 min
+ Scanned Files: 129002
+ Speed: 2.90 Files/Second
+ Infected files: 46
+ Removed files: 46
+ Files put in quarantine: 46
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\WINDOWS\SYSTEM32\__delete_on_reboot____delete_on_reboot__skqtlzi.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@63516465[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@shopnav[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@bluestreak[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@78631544[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@geocities[4].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@adknowledge[3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@bannerspace[3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@63516465[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@gostats[3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[3].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP98\A0015769.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP98\A0015950.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP98\A0015913.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP98\A0015926.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP98\A0015941.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP99\A0015951.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP99\A0016026.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP99\A0016032.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP99\A0016036.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP99\A0016045.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP99\A0016046.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP99\A0016047.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP99\A0016052.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016060.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016061.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016062.dll -> Spyware.180solutions -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016063.dll -> Spyware.VirtualBouncer.d -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016064.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016065.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016066.dll -> Spyware.ImiBar.d -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016067.exe -> Spyware.Ebates.a -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016068.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016069.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016070.exe -> Spyware.BiSpy.q -> Cleaned with backup
C:\System Volume Information\_restore{386009F4-EDC0-4013-923D-A1C0DE62F1EA}\RP100\A0016071.dll -> Spyware.Wheaterbug.a -> Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 2:40:04 PM, on 5/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\calcheck.exe
C:\Program Files\NovaStor\NovaBackup\NbkCtrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\NovaStor\NOVABA~1\NSENGINE.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.nfl.com/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [Ulead Photo Express Calendar Checker] C:\Program Files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\calcheck.exe
O4 - HKLM\..\Run: [NovaBackup 7 Tray Control] "C:\Program Files\NovaStor\NovaBackup\NbkCtrl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by102fd.bay10...es/MsnPUpld.cabO23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Ad-aware 6 Personal
Adobe Download Manager 1.2 (Remove Only)
Adobe Reader 6.0
AIM "You've Got Pictures" Picture Finder Plugin v9.5.1.6
America Online (Choose which version to remove)
AOL Connectivity Services
AOL Instant Messenger
AOL Spyware Protection
Ares 1.8.1
BellSouth FastAccess DSL Help Center
BJ Printer Driver
BroadJump Client Foundation
CCleaner (remove only)
Cool Edit Pro 2.0
DeadAIM
DivX Player
D-Link AirPlus G Wireless LAN Adapter
ewido security suite
Hijackthis 1.99.1
HijackThis 1.99.1
iDEN GPS Upgrade Utility
InterVideo WinDVD
iPod for Windows 2005-02-07
iPod Update 2004-04-28
iTunes
Java 2 Runtime Environment Standard Edition v1.3.1_02
Macromedia Shockwave Player
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Data Access Components KB870669
Microsoft Office 2000 Premium
Mozilla Firefox (1.0.3)
MSN Messenger 6.2
MSN Music Assistant
NEXTPIMP Media Center BETA RC2.1
NovaBACKUP 7.1
NTI CD-Maker 2000 Plus
Outlook Express Q823353
P2P Networking
Photo Manager
Pop-Up Stopper Free Edition
QuickTime
Remove DivX Codec
Sonique
Spybot - Search & Destroy 1.3
The ABI Network- A Division of Direct Revenue
Ulead DVD MovieFactory 3 Suite
Ulead Photo Explorer 8.0 SE
Ulead Photo Express My Scrapbook 2.0
Ulead VideoStudio 7 SE DVD
WeatherBug
Windows Blaster Worm Removal Tool (KB833330)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB821557
Windows XP Hotfix - KB823182
Windows XP Hotfix - KB823559
Windows XP Hotfix - KB823980
Windows XP Hotfix - KB824105
Windows XP Hotfix - KB824141
Windows XP Hotfix - KB824146
Windows XP Hotfix - KB828028
Windows XP Hotfix - KB828035
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB833987
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB837001
Windows XP Hotfix - KB839645
Windows XP Hotfix - KB840315
Windows XP Hotfix - KB840374
Windows XP Hotfix - KB840987
Windows XP Hotfix - KB841356
Windows XP Hotfix - KB841533
Windows XP Hotfix - KB841873
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB873376
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887822
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Hotfix (SP2) [See Q329048 for more information]
Windows XP Hotfix (SP2) [See Q329115 for more information]
Windows XP Hotfix (SP2) [See Q329390 for more information]
Windows XP Hotfix (SP2) [See Q329834 for more information]
Windows XP Hotfix (SP2) Q328310
Windows XP Hotfix (SP2) Q329170
Windows XP Hotfix (SP2) Q329441
Windows XP Hotfix (SP2) Q810577
Windows XP Hotfix (SP2) Q810833
Windows XP Hotfix (SP2) Q811493
Windows XP Hotfix (SP2) Q815021
Windows XP Hotfix (SP2) Q817606
Windows XP Hotfix (SP2) Q819696
Windows XP Service Pack 1a
Windows XP Uninstall
Yahoo! Messenger
Thank you again for your help.. I did not notice any programs that I did not recognize.