I apolagize for the bump this morning... I guess I didn't see that when I read the stickies... I'm just trying to get this figured out. Also about it being a work computer... this is a branch store from our main one, and only one computer and one employee (myself) using this computer, making me the IT person lol.
And here is the fresh HJT and Pandascan.
Logfile of HijackThis v1.99.1
Scan saved at 11:34:00 AM, on 3/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Intuit\Entitlement Client v2\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://parts.tecumsehpower.com/
O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\cscentfy.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {388315d1-92bc-4108-aa98-53aefd73e6a4} - C:\WINDOWS\system32\appind.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\tmp26.tmp.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\xxxvwu.dll",setvm
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {13D448F2-4D80-40BD-B1D7-25A9B7CB1474} (PMSImage Control) -
http://parts.tecumsehpower.com/install/PMSImage.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {3B3CC57A-6F3D-4596-A8D6-19E4A216AD0C} (pcval Control) -
https://dsi2.datascape2.com:8443/AgentProfile/dspcval.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1166560941910
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172092756046
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} -
http://cdn.downloadcontrol.com/files/installers/cab/Install-Errorprotector-Free.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - C:\WINDOWS\system32\QBPOSProtocol.dll
O20 - AppInit_DLLs:
O20 - Winlogon Notify: appind - C:\WINDOWS\SYSTEM32\appind.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Entitlement Service v2 - Intuit, Inc. - C:\Program Files\Common Files\Intuit\Entitlement Client v2\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: QBPOS Database Extended Manager (QBPOSDBExtServices) - Intuit Inc. - C:\Program Files\Intuit\QuickBooks Point of Sale 5.0\DatabaseServer\QBPOSDBServiceEx.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
PANDASCAN===============================================
Incident Status Location
Virus:Trj/KillAV.FG Disinfected Operating system
Virus:trj/abwiz.a Disinfected Operating system
Potentially unwanted tool:application/winfixer2005 Not disinfected c:\windows\downloaded program files\UERT_0001_D19M2109NetInstaller.exe
Virus:trj/briz.f Disinfected Operating system
Virus:W32/NuWar.AL.worm Disinfected C:\Documents and Settings\QBPOSDBSrvUser\Local Settings\Temporary Internet Files\Content.IE5\4HE7GDMN\sc[1].exe
Virus:Trj/Alanchum.TW Disinfected C:\Documents and Settings\QBPOSDBSrvUser\Local Settings\Temporary Internet Files\Content.IE5\812VSLEZ\via[1].exe
Virus:Trj/Alanchum.TW Disinfected C:\Documents and Settings\QBPOSDBSrvUser\Local Settings\Temporary Internet Files\Content.IE5\812VSLEZ\via[2].exe
Virus:W32/NuWar.AL.worm Disinfected C:\Documents and Settings\QBPOSDBSrvUser\Local Settings\Temporary Internet Files\Content.IE5\8XENKHIB\sm[1].exe
Virus:W32/NuWar.AL.worm Disinfected C:\Documents and Settings\QBPOSDBSrvUser\Local Settings\Temporary Internet Files\Content.IE5\WDYF01MV\dd[1].exe
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\savoyshop\Application Data\Mozilla\Firefox\Profiles\dbcssqdv.default\cookies.txt[.com.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\savoyshop\Cookies\savoyshop@atdmt[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\savoyshop\Cookies\savoyshop@doubleclick[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\savoyshop\Cookies\savoyshop@hitbox[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\savoyshop\Cookies\savoyshop@mediaplex[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\savoyshop\Cookies\savoyshop@questionmarket[2].txt
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\savoyshop\Local Settings\Temp\Temporary Internet Files\Content.IE5\WLN3Q5KR\ffa_dn_20070322[1]
Virus:Trj/KillAV.FG Disinfected C:\Program Files\Common Files\Symantec Shared\ccApp.exe1174934001
Virus:Trj/KillAV.FG Disinfected C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
Virus:Trj/KillAV.FG Disinfected C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\adirss.exe
Virus:W32/NuWar.AL.worm Disinfected C:\WINDOWS\system32\bak\adirss.exe
Virus:W32/NuWar.AL.worm Disinfected C:\WINDOWS\system32\bak\lnwin.exe
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\bak\lsasss.exe
Virus:Trj/Conhook.BH Disinfected C:\WINDOWS\system32\ddayvvv.dll
Virus:Trj/Qhost.EV Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20070226-125618.backup
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\system32\lnwin.exe
Virus:Trj/Alanchum.TW Disinfected C:\WINDOWS\system32\ma.exe.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe