I Have dun all the tests and deleted the infected files but here are the lists you asked for
Hijack This Log
Logfile of HijackThis v1.99.1
Scan saved at 12:09:18 AM, on 1/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
D:\System Restore\Vir and Spy Ware Tools\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.roseonlinegame.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/downloads/kws/ ... nicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 8458219834
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) -
http://nprotect.roseonlinegame.com/nPro ... en/npx.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} -
http://nprotect.roseonlinegame.com/nPro ... /npkcx.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
Hijack This Uninstall List
ATI - Software Uninstall Utility
ATI Display Driver
ewido anti-malware
HijackThis 1.99.1
Hotfix for Windows XP (KB896344)
Kaspersky On-line Scanner
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB912919)
Spybot - Search & Destroy 1.4
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900930)
Update for Windows XP (KB910437)
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
EWidow Scan Report
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:53:33 PM, 1/29/2006
+ Report-Checksum: B0C339AD
+ Scan result:
C:\Documents and Settings\Baowolfe\Cookies\baowolfe@adopt.euroclick[1].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Baowolfe\Cookies\baowolfe@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Documents and Settings\Baowolfe\Cookies\baowolfe@stat.onestat[2].txt -> Spyware.Cookie.Onestat : Cleaned with backup
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018622.dll -> Spyware.NewDotNet : Cleaned with backup
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018623.dll -> Spyware.Quick : Cleaned with backup
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018624.exe -> Spyware.MyWebSearch : Cleaned with backup
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018627.exe/2 -> Spyware.Chiem : Cleaned with backup
D:\From Lynders Comp\Stuffses\Lynder Games\Tumblebugs\BeetleBompSetup-dm.exe -> Adware.Trymedia : Cleaned with backup
::Report End
Kaspersky Scan Results
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Sunday, January 29, 2006 23:56:49
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 30/01/2006
Kaspersky Anti-Virus database records: 163250
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 50364
Number of viruses found: 3
Number of infected objects: 22
Number of suspicious objects: 0
Duration of the scan process: 3146 sec
Infected Object Name - Virus Name
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018651.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018651.exe Infected: Trojan-Downloader.Win32.Agent.er
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018652.exe/WISE0019.BIN Infected: Trojan-Downloader.Win32.Agent.er
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018652.exe/WISE0021.BIN/EXE-file/data0001/EXE-file Infected: Trojan-Downloader.Win32.Agent.ic
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018652.exe/WISE0021.BIN/EXE-file/data0001/EXE-file Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018652.exe/WISE0021.BIN/EXE-file/data0001 Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018652.exe/WISE0021.BIN/EXE-file Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018652.exe/WISE0021.BIN Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018652.exe Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018653.exe/WISE0019.BIN Infected: Trojan-Downloader.Win32.Agent.er
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018653.exe/WISE0021.BIN/EXE-file/data0001/EXE-file Infected: Trojan-Downloader.Win32.Agent.ic
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018653.exe/WISE0021.BIN/EXE-file/data0001/EXE-file Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018653.exe/WISE0021.BIN/EXE-file/data0001 Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018653.exe/WISE0021.BIN/EXE-file Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018653.exe/WISE0021.BIN Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018653.exe Infected: Trojan-Downloader.Win32.Agent.gn
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018654.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018654.exe Infected: Trojan-Downloader.Win32.Agent.er
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018656.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018656.exe Infected: Trojan-Downloader.Win32.Agent.er
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018657.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er
D:\System Volume Information\_restore{3B987EF0-7D11-47C2-A3C0-58486DA3A553}\RP157\A0018657.exe Infected: Trojan-Downloader.Win32.Agent.er
Scan process completed.
I have restarted my PC in Safe Mode and Opened D:\System Volume Information and deleted al the folders in this folder as they were all infected as you can see then rebooted the PC in normal mode after emptying the Trash Bin
Here ya go if there is anything else you need you know where to find me