Well, I ran both, but we still have all the same problems. ewido went ape****, and I had to shut it down, because it kept trying to clean multiple files after the scan. Whatever this thing is, it's propagating like mad. AVG also picked up YET ANOTHER TROJAN. Make that four. This is after being physically disconnected to the internet for an hour, during all scans.
Here's my report from ewido:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:01:44 PM, 7/4/2005
+ Report-Checksum: 90F1F40B
+ Scan result:
HKLM\SOFTWARE\Dsi -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{8F9FBEB8-D216-4d6c-8D21-513157E09C0D} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\{8F9FBEB8-D216-4d6c-8D21-513157E09C0D} -> Spyware.Maxspeed : Cleaned with backup
HKU\S-1-5-21-1715567821-1383384898-682003330-1003\Software\WareOut -> TrojanDownloader.Wareout : Cleaned with backup
HKU\S-1-5-21-1715567821-1383384898-682003330-1003\Software\WareOut\Options -> TrojanDownloader.Wareout : Cleaned with backup
[1960] VM_013F0000 -> Adware.BetterInternet : Error during cleaning
C:\eied_s7.cab/eied_s7_c_7.exe -> TrojanDownloader.Mediket.ae : Cleaned with backup
C:\ntdetect.hta -> TrojanDropper.Inor.cj : Cleaned with backup
C:\Program Files\hijackthis\backups\backup-20050529-163834-600.dll -> Spyware.SBSoft : Cleaned with backup
C:\Program Files\Netscape\Netscape\Plugins\npwthost.dll -> Spyware.WildTangent : Cleaned with backup
C:\WINDOWS\mooxsfhixt.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xrjpdx.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\veqngdb.exe -> Adware.BetterInternet : Cleaned with backup
::Report End
And from Find it (whoever wrote that should be spanked.

apostrophes don't denote plurals.

Sorry. nitpicker in me coming out.):
Microsoft Windows XP [Version 5.1.2600]
The current date is: Mon 07/04/2005
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
»»»»»»»»»»»»»»»»»»»»»»»» Todo Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» aurora Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» Suspect's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Dont delete file's in the section without guidance
If any doubt back them up first
* UPX! C:\WINDOWS\System32\AIZAKAA.EXE
* UPX! C:\WINDOWS\System32\AQNBVAC.EXE
* UPX! C:\WINDOWS\System32\CUOKTHF.EXE
* UPX! C:\WINDOWS\System32\DQJNWV.EXE
* UPX! C:\WINDOWS\System32\GFZLDPY.EXE
* UPX! C:\WINDOWS\System32\KPWCUDV.EXE
* UPX! C:\WINDOWS\System32\MACMKYI.EXE
* UPX! C:\WINDOWS\System32\NKVEWP.EXE
* UPX! C:\WINDOWS\System32\OTJSAGJ.EXE
* UPX! C:\WINDOWS\System32\OVDVTVF.EXE
* UPX! C:\WINDOWS\System32\PYPDOR.EXE
* UPX! C:\WINDOWS\System32\QHJKJDI.EXE
* UPX! C:\WINDOWS\System32\QJTVXQJ.EXE
* UPX! C:\WINDOWS\System32\QLWPCJR.EXE
* UPX! C:\WINDOWS\System32\QRZQYD.EXE
* UPX! C:\WINDOWS\System32\TIQNKJB.EXE
* UPX! C:\WINDOWS\System32\TTGVXB.EXE
* UPX! C:\WINDOWS\System32\UVZNYZ.EXE
* UPX! C:\WINDOWS\System32\VAQWMBC.EXE
* UPX! C:\WINDOWS\System32\VPRSUR.EXE
* UPX! C:\WINDOWS\System32\ZEOUBN.EXE
* UPX! C:\WINDOWS\System32\ZRRKHNJ.EXE
»»»»» lagitamate file's can/will show in this section.
»»»»»»»»»»»»»»»»»»»»»»»» Buddy file's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» SAHAgent Files found »»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» Misc checks »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»» Check for Windows\SYSTEM32\cache32_rtneg* folder.
Volume in drive C has no label.
Volume Serial Number is 009C-548B
Directory of C:\WINDOWS\SYSTEM32
»»»»» Checking for SAHAgent ico files.
Volume in drive C has no label.
Volume Serial Number is 009C-548B
Directory of C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»».
HKEY_CURRENT_USER\Software\aurora\AUP3D5om
HKEY_CURRENT_USER\Software\aurora\AUB3D5om
HKEY_CURRENT_USER\Software\aurora\AUs3t5icky1S
HKEY_CURRENT_USER\Software\aurora\AUs3t5icky3S
HKEY_CURRENT_USER\Software\aurora\AUs3t5icky4S
HKEY_CURRENT_USER\Software\aurora\AUE3v5nt
HKEY_CURRENT_USER\Software\aurora\AUT3h5rshSBath
HKEY_CURRENT_USER\Software\aurora\AUT3h5rshSysSInf
HKEY_CURRENT_USER\Software\aurora\AUT3h5rshSCheckS In
HKEY_CURRENT_USER\Software\aurora\AUT3h5rshSMots
HKEY_CURRENT_USER\Software\aurora\AUL3n5Title
HKEY_CURRENT_USER\Software\aurora\AU3N5a7tionSCode
HKEY_CURRENT_USER\Software\aurora\AUD3s5tSSEnd
HKEY_CURRENT_USER\Software\aurora\AUC3u5rrentSMode
HKEY_CURRENT_USER\Software\aurora\AUC3n5tFyl
HKEY_CURRENT_USER\Software\aurora\AUM3o5deSSync
HKEY_CURRENT_USER\Software\aurora\AUC3n5trMsgSDisp
HKEY_CURRENT_USER\Software\aurora\AUI3g5noreS
HKEY_CURRENT_USER\Software\aurora\AUs3t5icky2S
HKEY_CURRENT_USER\Software\aurora\AUL3a5stSSChckin
HKEY_CURRENT_USER\Software\aurora\AUC1o3d5eOfSFina lAd
HKEY_CURRENT_USER\Software\aurora\AUT3i5m7eOfSFina lAd
HKEY_CURRENT_USER\Software\aurora\AUI3d5OfSInst
HKEY_CURRENT_USER\Software\aurora\AUI3n5ProgSCab
HKEY_CURRENT_USER\Software\aurora\AUI3n5ProgSEx
HKEY_CURRENT_USER\Software\aurora\AUI3n5ProgSLstes t