Okay - I downloaded Ewido and Nailfix and here's the results:
I ran Ewido and here's the scan log:
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:39:28 PM, 6/8/2005
+ Report-Checksum: 61BCCD49
+ Date of database: 6/8/2005
+ Version of scan engine: v3.0
+ Duration: 84 min
+ Scanned Files: 89238
+ Speed: 17.55 Files/Second
+ Infected files: 73
+ Removed files: 73
+ Files put in quarantine: 73
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\Documents and Settings\Georgia\Cookies\georgia@46672343[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Cookies\georgia@adknowledge[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Cookies\georgia@burstnet[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Cookies\georgia@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Cookies\georgia@geocities[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Cookies\georgia@xiti[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia\Desktop\OregonTrail-dm.exe -> Spyware.Trymedia.a -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@atdmt[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@bannerspace[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@Bazooka-Adware-and-Spyware-Scanner[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@burstnet[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@fastclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@geocities[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@mediaplex[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@targetnet[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@tradedoubler[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@tribalfusion[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Cookies\georgia@zedo[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\installer_MARKETING35.exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\Documents and Settings\Georgia.HOME-44BVAB40ED\Local Settings\Temporary Internet Files\Content.IE5\OAA5QBT0\Setup[1].exe -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\Documents and Settings\Owner.HOME-D2NXQ7ZRIT\Local Settings\Temp\2.qtdfmp -> Not-A-Virus.Hoax.Renos.a -> Cleaned with backup
C:\Documents and Settings\Owner.HOME-D2NXQ7ZRIT\Local Settings\Temp\5.qtdfmp -> TrojanDownloader.Small.ayc -> Cleaned with backup
C:\Documents and Settings\Owner.HOME-D2NXQ7ZRIT\Local Settings\Temp\6.qtdfmp -> TrojanDownloader.Small.aux -> Cleaned with backup
C:\Documents and Settings\Owner.HOME-D2NXQ7ZRIT\Local Settings\Temp\FRV\aurareco.exe -> Spyware.BetterInternet.f -> Cleaned with backup
C:\Documents and Settings\Owner.HOME-D2NXQ7ZRIT\Local Settings\Temp\maxdd.game -> Dialer.Generic -> Cleaned with backup
C:\Documents and Settings\Owner.HOME-D2NXQ7ZRIT\Local Settings\Temp\vx2.game -> Backdoor.Agent.iw -> Cleaned with backup
C:\Program Files\Internet Explorer\sgjnnieg.exe -> TrojanDownloader.Small.vn -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\03D56AEB-BAB7-408D-8589-280C2F\813497D1-5551-4C9C-9C7B-E9B3C1 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\03D56AEB-BAB7-408D-8589-280C2F\9861334E-D38C-439B-910C-429EEB -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\3003CB57-3CA0-4034-B638-8B4D97\AB69292D-9629-4CF5-8482-A98FF8 -> Spyware.Azesearch -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\3003CB57-3CA0-4034-B638-8B4D97\DE01089C-9228-4EDF-B03C-88FA33 -> Spyware.Azesearch.b -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\65A7F329-D892-4CE1-9BDD-EDD0EC\4F2E0BC0-BBC0-457A-921E-2EF0DD -> TrojanDownloader.Agent.jq -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\694810B5-D29D-4A92-AE33-5C5307\77BFB99B-614A-48DF-9D7C-138D52 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\694810B5-D29D-4A92-AE33-5C5307\7D6A8F9D-EDF0-4E1E-85F1-A4B806 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\81948EFC-974D-43CF-A735-579EFE\0554B06E-CD0E-44AF-9907-9064DE -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\81948EFC-974D-43CF-A735-579EFE\995F8D03-DEF7-4AC4-BB94-DF26E9 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\829ADB8B-7FC8-4CF5-A759-4E002C\D844714C-53BD-40B9-9B48-C5C12F -> Spyware.BargainBuddy -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\829ADB8B-7FC8-4CF5-A759-4E002C\EE2100D4-70E4-4E5B-B6E4-DA696E -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\93235C5E-3C05-4B6C-8438-5618C0\986A7523-E677-45EB-B787-733868 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\93235C5E-3C05-4B6C-8438-5618C0\BACCBF08-B986-4DE8-9B4C-AE9479 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\9ECF7B5C-626D-49CD-B547-C05CA4\00F0D7F9-90D3-438A-996C-657006 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\9ECF7B5C-626D-49CD-B547-C05CA4\DD9D91F2-26FA-4080-BFF5-38BBCB -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B5FF8198-34FB-47DF-BF1A-7DFF17\9305CB84-F05B-405F-9DA3-9E9915 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B5FF8198-34FB-47DF-BF1A-7DFF17\EC670ADE-5A13-4009-A56D-AEC567 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\BC434FB4-39EC-4C46-9DFA-0DFF44\19ADFBD4-4117-4E9A-ACCE-B3AA20 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\BC434FB4-39EC-4C46-9DFA-0DFF44\9BBA9EC6-1CE9-4731-B818-172880 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\DC76FD55-45D7-49F3-A847-B8F378\7ABEED61-D884-4BC6-8381-DC583D -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\DC76FD55-45D7-49F3-A847-B8F378\A2DB503F-2BED-4254-86D8-E5B14F -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\ED582C43-E92B-4C62-A269-8AF5AA\7930B291-4EBC-450B-AB45-E935D1 -> Trojan.Pakes -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\ED582C43-E92B-4C62-A269-8AF5AA\AAE64327-4026-4ED7-B802-DA2B9E -> Trojan.Pakes -> Cleaned with backup
C:\System Volume Information\_restore{14DDB7A4-A174-40C2-BAE4-B0368E6258B6}\RP10\A0000490.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{14DDB7A4-A174-40C2-BAE4-B0368E6258B6}\RP12\A0000494.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{14DDB7A4-A174-40C2-BAE4-B0368E6258B6}\RP20\A0000550.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{14DDB7A4-A174-40C2-BAE4-B0368E6258B6}\RP21\A0000598.dll -> Spyware.Winsta -> Cleaned with backup
C:\System Volume Information\_restore{14DDB7A4-A174-40C2-BAE4-B0368E6258B6}\RP21\A0000606.exe -> Trojan.Nail -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\EPXActiveX.ocx -> Spyware.Winsta -> Cleaned with backup
C:\WINDOWS\SYSTEM32\bbchk.exe -> Spyware.Bargainbuddy -> Cleaned with backup
C:\WINDOWS\SYSTEM32\exclean.exe -> Spyware.BargainBuddy -> Cleaned with backup
C:\WINDOWS\SYSTEM32\wifvwpt.exe -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\WINDOWS\SYSTEM32\wifvwptndw30104lib.dll -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\WINDOWS\SYSTEM32\WinStat11.dll -> Spyware.Winsta -> Cleaned with backup
::Report End
and here's the new Hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 4:40:07 PM, on 6/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\HJT\HijackThis.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O15 - Trusted Zone:
http://www.neededware.comO16 - DPF: Yahoo! Gin -
http://download.game...nts/y/nt1_x.cabO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
How does it look? Also, any recommendations on what I should have on my system to keep it clean? Thank you.