I saw some sweet Vundo action. Hopefully that did the trick:
***********Hijack this log (fresh with another rename):
Logfile of HijackThis v1.99.1
Scan saved at 9:27:22 PM, on 11/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\WINDOWS\system32\basfipm.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\WINDOWS\system32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.00\Jconfig\hjavaw.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe
C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Software AG\Extended Transport Service\xtsdssvc.exe
c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\Program Files\Software AG\Universal Transaction Platform\bin\utxel.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Software AG\Universal Transaction Platform\bin\utxdaem.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\Hijack_this.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://Email Removed.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.comR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.dell.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.241.32.12:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,pmxuman.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {992C3C1A-D273-4CEA-8E79-9C14A04F1449} - C:\WINDOWS\system32\awtqn.dll (file missing)
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - C:\WINDOWS\system32\kwbeqqgg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Tair] "C:\PROGRA~1\COMMON~1\CROSOF~1\mmc.exe" -vt ndrv
O4 - Startup: Microsoft Office Outlook 2003.lnk = ?
O4 - Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) -
http://www.linkedin.com/cab/LinkedInContactFinderControl.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://inquira.webex.com/client/T22L/webex/ieatgpc.cabO23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Software AG EventLayer Service (argevtsrv) - Software AG - C:\Program Files\Software AG\System Management Hub\bin\argevsrv.exe
O23 - Service: Software AG MILayer Service (argmlsrv) - Software AG - C:\Program Files\Software AG\System Management Hub\bin\argmlsrv.exe
O23 - Service: Software AG CSLayer Service (argsrv) - Software AG - C:\Program Files\Software AG\System Management Hub\bin\argsrv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: ConverterService - Unknown owner - C:\InQuira_7.2_staging\inquira\src\prep\ext\msofficeprep\.\converterservice.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
O23 - Service: Inquira-IM-JMS (IM_OpenJMS) - Unknown owner - C:\InQuira_7.2\InfoManager\servicewrapper\bin\wrapper.exe
O23 - Service: Inquira-bayer - Unknown owner - C:\InQuira_7.2\bin\win32\inquira.exe
O23 - Service: Inquira-bayer-infomanager - Unknown owner - C:\InQuira_7.2\bin\win32\inquira.exe
O23 - Service: Inquira-bayerrt1 - Unknown owner - C:\InQuira_7.2\bin\win32\inquira.exe
O23 - Service: Inquira-sprint - Unknown owner - C:\InQuira_7.2\bin\win32\inquira.exe
O23 - Service: Inquira-SprintDev - Unknown owner - C:\InQuira_7.2\bin\win32\inquira.exe
O23 - Service: Inquira-SprintDev-workbench - Unknown owner - C:\InQuira_7.2\bin\win32\inquira.exe
O23 - Service: Inquira-SprintDevrt1 - Unknown owner - C:\InQuira_7.2\bin\win32\inquira.exe
O23 - Service: Inquira-sprintrt1 - Unknown owner - C:\InQuira_7.2\bin\win32\inquira.exe
O23 - Service: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Software AG UTX Daemon (ServiceUTXDAEM) - Software AG - C:\Program Files\Software AG\Universal Transaction Platform\bin\utxdaem.exe
O23 - Service: Software AG UTX Event Logger (ServiceUTXEL) - Software AG - C:\Program Files\Software AG\Universal Transaction Platform\bin\utxel.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Software AG XTS Directory Server (XTSDirSrv) - Software AG - C:\Program Files\Software AG\Extended Transport Service\xtsdssvc.exe
**********Combo fix log
Grant Liu - 06-11-09 21:20:46.98 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Grant Liu\Desktop\Destroy Spyware"
((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\Grant Liu\Application Data\Dxcuknwrd.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\wtssvcc.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Program Files\Common Files\CROSOF~1
C:\QooBox\Purity\Program Files\Common Files\CROSOF~1\??crosoft
((((((((((((((((((((((((((((((( Files Created from 2006-10-09 to 2006-11-09 ))))))))))))))))))))))))))))))))))
2006-11-09 11:40 60,436 --a------ C:\WINDOWS\system32\kwbeqqgg.dll
2006-11-08 23:09 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2006-11-08 10:36 60,436 --a------ C:\WINDOWS\system32\irtpncxy.dll
2006-11-08 10:36 110,612 --a------ C:\WINDOWS\system32\warrrojv.exe
2006-11-08 10:16 131,072 --a------ C:\WINDOWS\system32\vqvpd.dll
2006-11-08 10:15 45,056 --a------ C:\mpnaaq7.exe
2006-11-08 10:15 323,072 --a------ C:\165.exe
2006-11-08 10:15 28,672 --a------ C:\WINDOWS\system32hlvi6wkjc.exe
2006-11-08 10:15 28,672 --a------ C:\WINDOWS\system32\pfbo0yj.exe
2006-11-08 10:15 28,672 --a------ C:\WINDOWS\system32\hlvi6wkjc.exe
2006-11-08 10:15 24,576 --a------ C:\WINDOWS\system32ysjaevwx.exe
2006-11-08 10:15 24,576 --a------ C:\WINDOWS\system32\ysjaevwx.exe
2006-11-08 10:15 217,276 --a------ C:\WINDOWS\srviityu.exe
2006-11-08 10:15 20,480 --a------ C:\WINDOWS\stub_mm3.exe
2006-11-08 10:15 0 --a------ C:\WINDOWS\system32nrnqetwbz.exe
2006-11-08 10:14 40,973 ---hs---- C:\WINDOWS\system32\qomklkh.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-09 21:22 -------- d-------- C:\Program Files\Common Files
2006-11-09 21:19 -------- d-------- C:\Program Files\Java
2006-11-09 21:18 -------- d-------- C:\Program Files\Common Files\Java
2006-11-09 21:14 -------- d-------- C:\Program Files\Trillian
2006-11-09 18:45 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-09 16:47 -------- d-------- C:\Program Files\SpywareBlaster
2006-11-09 14:08 -------- d-------- C:\Program Files\CentraOne
2006-11-08 23:26 -------- d-------- C:\Documents and Settings\Grant Liu\Application Data\çasks
2006-11-08 23:10 -------- d-------- C:\Program Files\Internet Explorer
2006-11-08 23:04 -------- d-------- C:\Program Files\Outlook Express
2006-11-08 23:04 -------- d-------- C:\Program Files\Common Files\System
2006-11-08 22:32 -------- d-------- C:\Program Files\Windows Defender
2006-11-08 22:14 -------- d-------- C:\Program Files\CCleaner
2006-11-08 16:11 -------- d-------- C:\Program Files\Windows NT
2006-11-08 16:04 -------- d-------- C:\Program Files\Messenger
2006-11-08 12:45 -------- d-------- C:\Program Files\Lavasoft
2006-11-08 12:45 -------- d-------- C:\Documents and Settings\Grant Liu\Application Data\Lavasoft
2006-11-08 11:50 -------- d-------- C:\Program Files\Advanced Batch Converter
2006-11-08 10:36 -------- d-------- C:\Program Files\VSAdd-in
2006-11-08 10:27 -------- d-------- C:\Documents and Settings\Grant Liu\Application Data\Skype
2006-11-06 15:27 -------- d-------- C:\Documents and Settings\Grant Liu\Application Data\LinkedIn
2006-10-17 17:03 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-17 17:03 -------- d-------- C:\Program Files\ATI Technologies
2006-10-17 13:23 -------- d-------- C:\Program Files\Google
2006-10-04 10:44 -------- d-------- C:\Program Files\ReaSoft
2006-09-30 11:11 -------- d-------- C:\Program Files\QuickTime
2006-09-30 11:11 -------- d-------- C:\Program Files\Apoint
2006-09-28 07:58 186954 --a------ C:\WINDOWS\system32\atasnt40.dll
2006-09-25 12:44 -------- d-------- C:\Program Files\EditPlus 2
2006-09-22 16:03 -------- d-------- C:\Program Files\Sprint eRAS
2006-09-21 08:25 -------- d-------- C:\Program Files\eRAS
2006-09-20 10:19 50688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2006-09-18 15:21 -------- d-------- C:\Documents and Settings\Grant Liu\Application Data\Google
2006-09-15 13:16 53248 --a------ C:\WINDOWS\uni_e6h.exe
2006-09-15 09:21 -------- d-------- C:\Program Files\Mozilla Thunderbird
2006-09-12 21:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-08-25 07:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 04:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 01:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 03:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_7 -reboot 1"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"Tair"="\"C:\\PROGRA~1\\COMMON~1\\CROSOF~1\\mmc.exe\" -vt ndrv"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000000
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"Source"="C:\\Program Files\\Windows NT\\meceweqyq.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,b4,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\Program Files\\Messenger\\pofozos.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,b4,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: 06-11-09 21:24:50.54
C:\ComboFix.txt ... 06-11-09 21:24
*********Vundo log
VundoFix V6.2.8
Checking Java version...
Scan started at 9:00:04 PM 11/9/2006
Listing files found while scanning....
C:\WINDOWS\system32\awtqn.dll
C:\WINDOWS\system32\nqtwa.ini
C:\WINDOWS\system32\nqtwa.bak1
C:\WINDOWS\system32\nqtwa.bak2
C:\WINDOWS\system32\nqtwa.ini2
C:\WINDOWS\system32\nqtwa.tmp
Beginning removal...
Attempting to delete C:\WINDOWS\system32\awtqn.dll
C:\WINDOWS\system32\awtqn.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\nqtwa.ini
C:\WINDOWS\system32\nqtwa.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\nqtwa.bak1
C:\WINDOWS\system32\nqtwa.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\nqtwa.bak2
C:\WINDOWS\system32\nqtwa.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\nqtwa.ini2
C:\WINDOWS\system32\nqtwa.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\nqtwa.tmp
C:\WINDOWS\system32\nqtwa.tmp Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.2.8
Checking Java version...
Scan started at 9:15:24 PM 11/9/2006
Listing files found while scanning....
No infected files were found.