I loved the Cleanup prgram, it got rid almost 900 MB!
The Kaspersky logs were as followed.
Critical Areas scan....
-------------------------------------------------------------------------------
KASPERSKY ANTI-VIRUS WEB SCANNER REPORT
Thursday, July 14, 2005 14:52:52
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Anti-Virus Web Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 14/07/2005
Kaspersky Anti-Virus database records: 138348
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - Critical Areas:
C:\WINDOWS
C:\DOCUME~1\NATHAN~1\LOCALS~1\Temp\
Scan Statistics:
Total number of scanned objects: 15195
Number of viruses found: 1
Number of infected objects: 3
Number of suspicious objects: 0
Duration of the scan process: 1294 sec
Infected Object Name - Virus Name
C:\WINDOWS\Downloaded Installations\{448A5AAF-26A0-4574-B76E-6C4166145AB1}\Recruit.msi/Data1.cab/mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.14
C:\WINDOWS\Downloaded Installations\{448A5AAF-26A0-4574-B76E-6C4166145AB1}\Recruit.msi/Data1.cab Infected: not-a-virus:Client-IRC.Win32.mIRC.14
C:\WINDOWS\Downloaded Installations\{448A5AAF-26A0-4574-B76E-6C4166145AB1}\Recruit.msi Infected: not-a-virus:Client-IRC.Win32.mIRC.14
Scan process completed.
My Computer scan...
-------------------------------------------------------------------------------
KASPERSKY ANTI-VIRUS WEB SCANNER REPORT
Thursday, July 14, 2005 18:20:47
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Anti-Virus Web Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 14/07/2005
Kaspersky Anti-Virus database records: 138348
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 86127
Number of viruses found: 22
Number of infected objects: 83
Number of suspicious objects: 2
Duration of the scan process: 6096 sec
Infected Object Name - Virus Name
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer2.zip/install.exe Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer2.zip Suspicious: Password-protected-EXE
C:\Documents and Settings\Default User\My Documents\Nathaniel\Anonymous\snowfall\pumpkin_hss2.exe/WISE0014.BIN Infected: not-a-virus:AdWare.EZula.a
C:\Documents and Settings\Default User\My Documents\Nathaniel\Anonymous\snowfall\pumpkin_hss2.exe/WISE0015.BIN/data0002 Infected: not-a-virus:AdWare.Sidesearch.d
C:\Documents and Settings\Default User\My Documents\Nathaniel\Anonymous\snowfall\pumpkin_hss2.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Sidesearch.d
C:\Documents and Settings\Default User\My Documents\Nathaniel\Anonymous\snowfall\pumpkin_hss2.exe/WISE0016.BIN Infected: not-a-virus:AdWare.IGetNet
C:\Documents and Settings\Default User\My Documents\Nathaniel\Anonymous\snowfall\pumpkin_hss2.exe Infected: not-a-virus:AdWare.IGetNet
C:\Documents and Settings\Nathaniel\My Documents\Games\Sierra\Half-Life\hltv.exe Infected: not-a-virus:Server-Proxy.Win32.Hltv
C:\Documents and Settings\Nathaniel\My Documents\Games\Sierra\HL\Half-Life 2\hl1110_full_update.exe/WISE0025.BIN Infected: not-a-virus:Server-Proxy.Win32.Hltv
C:\Documents and Settings\Nathaniel\My Documents\Games\Sierra\HL\Half-Life 2\hl1110_full_update.exe Infected: not-a-virus:Server-Proxy.Win32.Hltv
C:\Documents and Settings\Nathaniel\My Documents\Games\Sierra\HL\hl1110_full_update.exe/WISE0025.BIN Infected: not-a-virus:Server-Proxy.Win32.Hltv
C:\Documents and Settings\Nathaniel\My Documents\Games\Sierra\HL\hl1110_full_update.exe Infected: not-a-virus:Server-Proxy.Win32.Hltv
C:\Documents and Settings\Nathaniel\rebates.exe/WEBREB~1.EXE Infected: not-a-virus:AdWare.WinAD.ao
C:\Documents and Settings\Nathaniel\rebates.exe Infected: not-a-virus:AdWare.WinAD.ao
C:\Program Files\bearshare\Installer\BSINSTALL.exe/WISE0023.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\Program Files\bearshare\Installer\BSINSTALL.exe/WISE0023.BIN/data0001.cab Infected: not-a-virus:AdWare.SaveNow.z
C:\Program Files\bearshare\Installer\BSINSTALL.exe/WISE0023.BIN Infected: not-a-virus:AdWare.SaveNow.z
C:\Program Files\bearshare\Installer\BSINSTALL.exe/WISE0027.BIN Infected: not-a-virus:AdWare.SaveNow.bo
C:\Program Files\bearshare\Installer\BSINSTALL.exe Infected: not-a-virus:AdWare.SaveNow.bo
C:\Program Files\bearshare\Installer\saveinstwm.exe/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\Program Files\bearshare\Installer\saveinstwm.exe/data0001.cab Infected: not-a-virus:AdWare.SaveNow.z
C:\Program Files\bearshare\Installer\saveinstwm.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP118\A0051002.exe/data0002 Infected: not-a-virus:AdWare.Broadcap.c
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP118\A0051002.exe Infected: not-a-virus:AdWare.Broadcap.c
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP119\A0051411.exe Infected: not-a-virus:AdWare.Sahat.m
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057623.exe Infected: not-virus:Hoax.Win32.Renos.d
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057638.exe Infected: Trojan-Proxy.Win32.Lager.t
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057651.exe Infected: Trojan.Win32.LowZones.y
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057652.exe Infected: not-virus:Hoax.Win32.Renos.d
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057661.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057662.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057663.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057664.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057666.exe/data0003 Infected: not-a-virus:AdWare.ToolBar.HotSearchBar.i
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057666.exe Infected: not-a-virus:AdWare.ToolBar.HotSearchBar.i
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057667.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057668.exe Infected: not-virus:Hoax.Win32.Renos.d
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057671.dll Infected: Trojan.Win32.Agent.co
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP121\A0057675.exe Infected: Trojan-Downloader.Win32.Small.bct
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP122\A0058636.exe Infected: Trojan-Proxy.Win32.Lager.t
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP123\A0059639.exe Infected: Trojan-Proxy.Win32.Lager.t
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP123\A0060632.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP123\A0060633.dll Infected: Trojan.Win32.Agent.co
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP123\A0060635.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060660.exe Infected: Trojan-Proxy.Win32.Lager.t
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060661.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060662.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060664.dll Infected: Trojan.Win32.Agent.co
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060715.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060723.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060724.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060725.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060726.dll Infected: Trojan.Win32.Agent.co
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060729.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060740.exe Infected: not-virus:Hoax.Win32.Renos.d
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060744.dll Infected: not-a-virus:AdWare.ToolBar.HotSearchBar.i
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060745.exe/data0003 Infected: not-a-virus:AdWare.ToolBar.HotSearchBar.i
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060745.exe Infected: not-a-virus:AdWare.ToolBar.HotSearchBar.i
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060749.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060750.exe Infected: Trojan-Proxy.Win32.Lager.s
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060752.exe Infected: Trojan-Proxy.Win32.Lager.s
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060756.exe Infected: Trojan-Downloader.Win32.Small.avt
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060778.exe Infected: not-virus:Hoax.Win32.Renos.d
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060779.dll Infected: Backdoor.Win32.Padodor.az
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060780.exe Infected: Backdoor.Win32.Padodor.az
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060781.exe Infected: Trojan.Win32.LowZones.y
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060782.exe Infected: Trojan-Downloader.Win32.Small.bct
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060924.sys Infected: Backdoor.Win32.Haxdoor.gen
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060925.sys Infected: Backdoor.Win32.Haxdoor.gen
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060943.msi/Data1.cab/mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.14
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060943.msi/Data1.cab Infected: not-a-virus:Client-IRC.Win32.mIRC.14
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP124\A0060943.msi Infected: not-a-virus:Client-IRC.Win32.mIRC.14
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP135\A0063530.dll Infected: not-a-virus:AdWare.NavExcel.i
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP89\A0045200.rbf Infected: not-a-virus:Client-IRC.Win32.mIRC.14
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP95\A0046563.exe/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP95\A0046563.exe/data0001.cab Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP95\A0046563.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP95\A0046564.exe/WISE0023.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP95\A0046564.exe/WISE0023.BIN/data0001.cab Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP95\A0046564.exe/WISE0023.BIN Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP95\A0046564.exe/WISE0027.BIN Infected: not-a-virus:AdWare.SaveNow.bo
C:\System Volume Information\_restore{E8D80984-BC7C-495C-BFA0-118E9A5282DE}\RP95\A0046564.exe Infected: not-a-virus:AdWare.SaveNow.bo
C:\WINDOWS\Downloaded Installations\{448A5AAF-26A0-4574-B76E-6C4166145AB1}\Recruit.msi/Data1.cab/mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.14
C:\WINDOWS\Downloaded Installations\{448A5AAF-26A0-4574-B76E-6C4166145AB1}\Recruit.msi/Data1.cab Infected: not-a-virus:Client-IRC.Win32.mIRC.14
C:\WINDOWS\Downloaded Installations\{448A5AAF-26A0-4574-B76E-6C4166145AB1}\Recruit.msi Infected: not-a-virus:Client-IRC.Win32.mIRC.14
Scan process completed.
And the Hijackthis log is...
Logfile of HijackThis v1.99.1
Scan saved at 6:28:12 PM, on 7/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\LTMSG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Documents and Settings\Nathaniel\My Documents\Downloads\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://comcast.net/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O12 - Plugin for .pdf: c:\program files\adobe\acrobat 7.0\reader\browser\nppdf32.dll
O16 - DPF: RaptisoftGameLoader -
http://www.miniclip....tgameloader.cabO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....467&clcid=0x409O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) -
http://esupport.aol....oach_core_1.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aol.com...kup/qdiagcc.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1113790688109O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/.../GrooveAX27.cabO16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) -
http://secure2.comne...login-devel.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabThat's everything.