Yep, I was not fully clean. Went camping for the weekend and there were a bunch of windows open and download prompts when I came back.
Don't worry about the delay getting back to me, I'd been away. I also work 12-hour shifts 4 days per week so I'm only dealing with this on weekends.
My system was not so cripled this time that I was able to do things exactly as you requested.
Here is my MAlwarebytes log:
Malwarebytes' Anti-Malware 1.23
Database version: 993
Windows 5.1.2600 Service Pack 1
19:59:33 2008-07-25
mbam-log-7-25-2008 (19-59-33).txt
Scan type: Full Scan (A:\|C:\|E:\|)
Objects scanned: 66102
Time elapsed: 10 minute(s), 56 second(s)
Memory Processes Infected: 3
Memory Modules Infected: 3
Registry Keys Infected: 39
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 5
Files Infected: 97
Memory Processes Infected:
C:\WINDOWS\TnVueWEgQnVzaW5lc3M\command.exe (Adware.CommAd) -> Failed to unload process.
C:\Documents and Settings\Mike\Local Settings\Temp\!update.exe (Adware.PurityScan) -> Unloaded process successfully.
C:\Documents and Settings\Mike\Application Data\?ppPatch\rundll.exe (Adware.PurityScan) -> Unloaded process successfully.
Memory Modules Infected:
C:\WINDOWS\system32\awtqrqoN.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\TnVueWEgQnVzaW5lc3M\asappsrv.dll (Adware.CommAd) -> Delete on reboot.
C:\WINDOWS\system32\xwbdhfuh.dll (Adware.ClickSpring) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1b65714b-beca-4302-a250-f07e7b768a3e} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{1b65714b-beca-4302-a250-f07e7b768a3e} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdservice (Adware.CommAd) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdservice (Adware.CommAd) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{df669e1b-56af-782f-aa34-7fa291ee1acf} (Adware.ClickSpring) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{df669e1b-56af-782f-aa34-7fa291ee1acf} (Adware.ClickSpring) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1e404d48-670a-4085-a6a0-d195793ddd33} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9f593aac-ca4c-4a41-a7ff-a00812192d61} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{749ec66f-a838-4b38-b8e5-e65d905fff74} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1e404d48-670a-4085-a6a0-d195793ddd33} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{ff46f4ab-a85f-487e-b399-3f191ac0fe23} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{82336a8d-6cd0-4647-b791-75fca8cf2b39} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{82336a8d-6cd0-4647-b791-75fca8cf2b39} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98dbbf16-ca43-4c33-be80-99e6694468a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bc97b254-b2b9-4d40-971d-78e0978f5f26} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000162-9980-0010-8000-00aa00389b71} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\speedrunner (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gooochi (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\Sidebar.DLL (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MySidesearch (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\SpeedRunner (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\testCPV6.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Deewoo Network Manager (Adware.Radio) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/xpreload.ocx (Heuristics.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06492663-42ce-2b57-dea7-bfe7f4ed0eb4} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{06492663-42ce-2b57-dea7-bfe7f4ed0eb4} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5e363ce5-c72e-c561-8aa9-1041fca9940b} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5e363ce5-c72e-c561-8aa9-1041fca9940b} (Adware.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{82336a8d-6cd0-4647-b791-75fca8cf2b39} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\xpreload.ocx (Heuristics.Malware) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\awtqrqon -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\awtqrqon -> Quarantined and deleted successfully.
Folders Infected:
C:\Program Files\Temporary (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Webtools (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Sakora (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\mjc (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Application Data\speedrunner (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\awtqrqoN.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\Noqrqtwa.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Noqrqtwa.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cmvvdopp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ppodvvmc.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nlibyrqc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cqrybiln.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tcwwcqni.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\inqcwwct.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\TnVueWEgQnVzaW5lc3M\asappsrv.dll (Adware.CommAd) -> Delete on reboot.
C:\WINDOWS\TnVueWEgQnVzaW5lc3M\command.exe (Adware.CommAd) -> Delete on reboot.
C:\WINDOWS\system32\xwbdhfuh.dll (Adware.ClickSpring) -> Delete on reboot.
C:\Documents and Settings\Mike\Local Settings\Temp\!update.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Application Data\?ppPatch\rundll.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files\Webtools\webtools.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Application Data\Microsoft\Windows\gqqft.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Application Data\SpeedRunner\SpeedRunner.exe (Adware.SpeedRunner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Application Data\SpeedRunner\SRUninstall.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Local Settings\Temp\NDR11.tmp (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\4PEROXI3\!update-4495[1].0000 (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\mfru\mfrua.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\mfru\mfrul.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\mfru\mfrum.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\mfru\mfrup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\mfru\mfrud\mfruc.dll (Adware.TargetServer) -> Quarantined and deleted successfully.
C:\Program Files\mjc\mjc.exe (Adware.MJC) -> Quarantined and deleted successfully.
C:\Program Files\Sakora\Sakora.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\Outerinfo\FF\components\FF.dll.vir (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\444.470.vir (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\ICROSO~1\svchost.exe.vir (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe.vir (Adware.BHO) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\sjtque.dll.vir (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\ati2mtaaa.sys.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\SDFix\backups_old\mrofinu1000106.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\SDFix\backups_old\mrofinu572.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\SDFix\backups_old\mrofinu572.exe.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\SDFix\backups_old\rwwnw64d.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP109\A0097454.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0097465.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0098480.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0098512.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0105568.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0105569.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0106692.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0106698.exe (Trojan.Proxy) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0106759.exe (Trojan.Proxy) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0106779.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0108877.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0108878.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0108920.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0109977.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0109978.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0109979.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0109981.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0110025.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP110\A0110024.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP111\A0110178.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP112\A0110183.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP113\A0110193.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP113\A0110197.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP113\A0110198.exe (Spyware.TargetSaver) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP113\A0110208.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP113\A0110209.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP113\A0110222.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP113\A0110223.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP113\A0110224.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP114\A0110259.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FB5BD683-819D-47F8-B55F-E7C131C638D7}\RP115\A0110305.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\17PHolmes572.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b104.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b152.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b155.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\b156.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu572.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu572.exe.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cklemxbmnvqnq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rrwnw64p.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\olixds01\olixds011065.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\imp32\keysrve.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\provdll\globsetup.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\OBDE\idexpnd.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sfig\mcirev2.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Application Data\speedrunner\config.cfg (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gside.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winpfz33.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zxdnt3d.cfg. (Adware.ZenoSearch) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zxdnt3d.cfg (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\BM2f49c9b1.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM2f49c9b1.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\default.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\xpreload.ocx (Heuristics.Malware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Start Menu\Programs\Startup\DW_Start.lnk (Malware.Links) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mike\Start Menu\Programs\Startup\Deewoo.lnk (Malware.Links) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\oibshohfaev.dll (Adware.BHO) -> Delete on reboot.
C:\WINDOWS\system32\qnfiieqswhhcn.dll (Adware.BHO) -> Delete on reboot.
Here is my most recent HIT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:07, on 2008-07-25
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Gigabyte\ET5\GUI.exe
C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\DOCUME~1\Mike\APPLIC~1\PPPATC~1\rundll.exe
C:\Program Files\WinTV\Ir.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {092836FC-C426-4532-8931-7FDAC143E393} - (no file)
O2 - BHO: (no name) - {1B65714B-BECA-4302-A250-F07E7B768A3E} - (no file)
O2 - BHO: (no name) - {247C5C8D-CCFC-4C55-8ACE-59D4EAD21B13} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6DBA5A11-DA13-4E08-9B6D-E2FDE408CF8C} - (no file)
O2 - BHO: (no name) - {DD679F4F-5FFA-2928-AC34-7FA291EE4FC8} - (no file)
O2 - BHO: (no name) - {EFF70636-DB72-418E-A823-1E5F54D0759B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe
O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Oraa] "C:\DOCUME~1\Mike\APPLIC~1\PPPATC~1\rundll.exe" -vt yazb
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O15 - Trusted Zone: *.sxload.net (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: xxyaxXPF - C:\WINDOWS\
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
--
End of file - 4126 bytes
Mike