You guys seriously rule! My computer is a lot better, however here are the logs you asked for.
FIND IT LOG
------------------------------
Microsoft Windows XP [Version 5.1.2600]
The current date is: Mon 08/08/2005
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
»»»»»»»»»»»»»»»»»»»»»»»» Todo Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» aurora Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» Suspect's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Dont delete file's in the section without guidance
If any doubt back them up first
* UPX! C:\WINDOWS\System32\NPKCSVC.EXE
* UPX! C:\WINDOWS\IFINST27.EXE
»»»»» lagitamate file's can/will show in this section.
»»»»»»»»»»»»»»»»»»»»»»»» Buddy file's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» SAHAgent Files found »»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» Misc checks »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»» Check for Windows\SYSTEM32\cache32_rtneg* folder.
Volume in drive C has no label.
Volume Serial Number is 58D4-0625
Directory of C:\WINDOWS\SYSTEM32
»»»»» Checking for SAHAgent ico files.
Volume in drive C has no label.
Volume Serial Number is 58D4-0625
Directory of C:\WINDOWS\system32
08/08/2005 05:30 PM 1,406 AddQuit.ico
08/08/2005 05:30 PM 9,470 Desktop.ico
08/08/2005 05:30 PM 1,406 Help.ico
08/08/2005 05:30 PM 5,350 IE.ico
08/08/2005 05:30 PM 1,718 Open.ico
08/08/2005 05:30 PM 1,718 Quick.ico
08/08/2005 05:30 PM 2,550 Uninstall.ico
7 File(s) 23,618 bytes
0 Dir(s) 2,408,194,048 bytes free
»»»»»»»»»»»»»»»»»»»»»»»».
END OF FIND IT LOG
------------------------------------------
Panda Activescan LOG
Incident Status Location
Spyware:spyware/cydoor No disinfected C:\WINDOWS\cache277
Adware:adware/savenow No disinfected Windows Registry
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-50c9a229-78b4719e.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-50c9a229-78b4719e.zip[Beyond.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5be9df7-61c2ec35.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nocheat.jar-11f63847-313eaf19.zip[Dummy.class]
Virus:W32/Magistr.B Disinfected Archive Folders\Deleted Items\Highsmith: It is a great.\letter.bat
Virus:W32/Zafi.B.worm Disinfected Personal Folders\Deleted Items\Don`t worry, be happy!\www.ecard.com.funny.picture.index.nude.php356.pif
Virus:W32/Magistr.B Disinfected Personal Folders\Deleted Items\Highsmith: It is a great.\letter.bat
Virus:W32/Zafi.B.worm Disinfected Personal Folders\Deleted Items\Don`t worry, be happy!\www.ecard.com.funny.picture.index.nude.php356.pif
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-2d1d9b17-570b83d6.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-50c9a229-18b29f85.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5aa61af4-73f59a11.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv102.jar-7fb6d57-7cdaaef5.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv233.jar-6327cb56-1a254892.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv233.jar-6327cb56-1a254892.zip[Matrix.class]
Virus:Exploit/iFrame Disinfected Archive Folders\Deleted Items\Deleted Items\Re: Let's be friends\reply.htm
Virus:W32/Bugbear.B Disinfected Archive Folders\Deleted Items\Deleted Items\RE: TFT Meeting\United Defense Presentation.ppt.pif
Virus:W32/Magistr.B Disinfected Archive Folders\Deleted Items\Deleted Items\Net
[email protected] 2 August.\Instrument.bat
Virus:W32/Zafi.B.worm Disinfected Archive Folders\Deleted Items\Don`t worry, be happy!\www.ecard.com.funny.picture.index.nude.php356.pif
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Erica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-6d181bc9-1365b77d.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Erica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nocheat.jar-11f63847-5a8f3e58.zip[Dummy.class]
Possible Virus. No disinfected C:\Downloads\Mir3Full.exe
Possible Virus. No disinfected C:\Downloads\skyblade\SkyBlade_Client\Patch.psh
Possible Virus. No disinfected C:\Downloads\skyblade.zip[Patch.psh]
END PANDA
---------------------------------
SMITFILES
smitRem log file
version 2.3
by noahdfear
The current date is: Mon 08/08/2005
The current time is: 15:12:41.21
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Pre-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
intell32.exe
oleext.dll
wppp.html
intmonp.exe
msmsgs.exe
ole32vbs.exe
msole32.exe
shnlog.exe
intmon.exe
hhk.dll
logfiles
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
uninstIU.exe
sites.ini
popuper.exe
~~~ Drive root ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Post-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Wininet.dll ~~~
CLEAN!
END SMITFILES
--------------------------------
EWIDO
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 5:23:15 PM, 8/8/2005
+ Report-Checksum: BBF997E5
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{3CE36D52-D914-5BA5-C0E2-3F53AE992ABB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8138EE4F-2AC5-6CBF-E88D-A0A94EE71F0C} -> Spyware.CoolWebSearch : Cleaned with backup
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-50c9a229-78b4719e.zip/Gummy.class -> Trojan.Java.Femad : Error during cleaning
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5be9df7-61c2ec35.zip/Gummy.class -> Trojan.Java.Femad : Error during cleaning
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nocheat.jar-11f63847-313eaf19.zip/Matrix.class -> TrojanDownloader.OpenConnection.s : Error during cleaning
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-2d1d9b17-570b83d6.zip/Gummy.class -> Trojan.Java.Femad : Error during cleaning
C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-2d1d9b17-570b83d6.zip/Beyond.class -> Trojan.Java.ClassLoader.k : Error during cleaning
C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-50c9a229-18b29f85.zip/Gummy.class -> Trojan.Java.Femad : Error during cleaning
C:\Documents and Settings\Brian\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5aa61af4-73f59a11.zip/Gummy.class -> Trojan.Java.Femad : Error during cleaning
C:\Documents and Settings\Debra\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Debra\Cookies\
[email protected][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Erica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-6d181bc9-1365b77d.zip/Gummy.class -> Trojan.Java.Femad : Error during cleaning
C:\Documents and Settings\Erica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nocheat.jar-11f63847-5a8f3e58.zip/Matrix.class -> TrojanDownloader.OpenConnection.s : Error during cleaning
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\erica@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\erica@adorigin[2].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\erica@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\erica@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][2].txt -> Spyware.Cookie.Adbutler : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][1].txt -> Spyware.Cookie.I12 : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\erica@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\erica@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Erica.HP29447202212\Cookies\
[email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\ms32.tmp -> TrojanDownloader.Small.azk : Cleaned with backup
C:\RECYCLER\NPROTECT\00174439.TXT -> Spyware.Cookie.Onestat : Cleaned with backup
C:\RECYCLER\NPROTECT\00174441.TXT -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\RECYCLER\NPROTECT\00174445.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00174455.TXT -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\RECYCLER\NPROTECT\00174463.TXT -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\RECYCLER\NPROTECT\00175961.TXT -> Spyware.Cookie.Adocean : Cleaned with backup
C:\RECYCLER\NPROTECT\00175967.TXT -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\RECYCLER\NPROTECT\00175968.TXT -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\RECYCLER\NPROTECT\00175969.TXT -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\RECYCLER\NPROTECT\00176014.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00176015.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00180073.TXT -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\RECYCLER\NPROTECT\00180074.TXT -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\RECYCLER\NPROTECT\00180402.TXT -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\RECYCLER\NPROTECT\00180532.TXT -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\RECYCLER\NPROTECT\00180783.EXE -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\RECYCLER\NPROTECT\00180788.EXE -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\RECYCLER\NPROTECT\00180796.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\RECYCLER\NPROTECT\00180798.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00180811.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00180820.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181413.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181427.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181635.exe -> Dialer.Generic : Cleaned with backup
C:\RECYCLER\NPROTECT\00181708.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181725.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181728.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181737.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181740.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181741.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181744.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181753.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181756.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181762.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181767.TXT -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\RECYCLER\NPROTECT\00181778.TXT -> Spyware.Cookie.Spylog : Cleaned with backup
C:\RECYCLER\NPROTECT\00181786.TXT -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\RECYCLER\NPROTECT\00181800.TXT -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\RECYCLER\NPROTECT\00181807.TXT -> Spyware.Cookie.Xxxcounter : Cleaned with backup
C:\RECYCLER\NPROTECT\00181809.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00181819.TXT -> Spyware.Cookie.Adocean : Cleaned with backup
C:\RECYCLER\NPROTECT\00181820.TXT -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\RECYCLER\NPROTECT\00181856.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181898.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181900.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00181976.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182040.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182048.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182061.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182096.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182148.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182167.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182208.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182224.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182226.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182230.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182241.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182245.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182251.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182252.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\NPROTECT\00182253.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\S-1-5-21-4152783838-1037494192-3789139140-1009\Dc1.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlww32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3au.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\explorer.scf:edqgah -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\ieby.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipsz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msdfmap.ini:idtwe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32:mmaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\system32\addtr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\appzl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3yn.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfcwg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netpv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ghyktn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:mjuux -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:nwoefm -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:vvvzlj -> TrojanDownloader.Agent.bc : Cleaned with backup
::Report End
END EWIDO
----------------
Whats the final verdict?