Help - Search - Members - Calendar
Full Version: Now time for my wifes computer
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
dieseltkd
Here is her Highjack This file:

Logfile of HijackThis v1.99.1
Scan saved at 3:29:04 PM, on 9/16/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\OpenAFS\Client\Program\afsd_service.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\program files\support.com\client\bin\tgcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Symantec\SAV8\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\Audio3D0.exe
C:\Program Files\Tmnxsaa\Uwwwse.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\iissrv.exe
C:\WINDOWS\System32\vidmon\vidmon.exe
C:\WINDOWS\System32\nfomon\nfomon.exe
C:\Program Files\TopSearch\TopSearch.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\WNLOGO~1.EXE
C:\PROGRA~1\COMMON~1\TSKS~1\dexplore.exe
C:\Program Files\Common Files\AOL\1137104828\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1137104828\ee\AOLServiceHost.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cleanmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Rachel\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {F5C3F060-3AD4-3474-A2D8-6C1336AD30E1} - C:\WINDOWS\System32\uojm.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: TChkBHO Class - {5F2B369D-7486-47C7-A0FA-7D0943A2D8C0} - C:\WINDOWS\system32\odykm.dll (file missing)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll
O2 - BHO: (no name) - {F5C3F060-3AD4-3474-A2D8-6C1336AD30E1} - C:\WINDOWS\System32\uojm.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\bin\tgcmd.exe /server
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\Symantec\SAV8\vptray.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [qWqo2q] C:\documents and settings\rachel\local settings\temp\qWqo2q.exe
O4 - HKLM\..\Run: [jIo6SC9Ui] C:\documents and settings\rachel\local settings\temp\jIo6SC9Ui.exe
O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\System32\IEHost.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [04c911032b26] C:\WINDOWS\System32\ccfgnt98.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [fafd1233f03c] C:\WINDOWS\System32\Audio3D0.exe
O4 - HKLM\..\Run: [Jpswy] C:\Program Files\Tmnxsaa\Uwwwse.exe
O4 - HKLM\..\Run: [wnddrv] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [iissrv] C:\WINDOWS\iissrv.exe
O4 - HKLM\..\Run: [vidmon] C:\WINDOWS\System32\vidmon\vidmon.exe
O4 - HKLM\..\Run: [kcxin] C:\DOCUME~1\Rachel\LOCALS~1\Temp\app7B.tmp
O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\System32\nfomon\nfomon.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137104828\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [TopSearch] C:\Program Files\TopSearch\TopSearch.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [779T35O] cmuhits.exe
O4 - HKCU\..\Run: [Brhgdgek] C:\WINDOWS\System32\WNLOGO~1.EXE
O4 - HKCU\..\Run: [Iinl] "C:\PROGRA~1\COMMON~1\TSKS~1\dexplore.exe" -vt rbnd
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab
O16 - DPF: {9184D21C-9835-42C5-A883-EA8BE7FC048D} (Downloader Class) - https://www.shop.intuit.com/commerce/accoun...bles/ie/IDA.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj...ploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg...,15/mcgdmgr.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\Symantec\SAV8\Rtvscan.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: IBM AFS Client (TransarcAFSDaemon) - Unknown owner - C:\Program Files\OpenAFS\Client\Program\afsd_service.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
LoPhatPhuud
Your wife's computer is a mess! The only protection I see is Symantec Corporate AV. We'll address decent protection later. First is to get it clean. I want Ewido first, then HiJackTHis to clean the items showing in her log. Ewido may remove items I list in HJT, but at least we'll know they are gone. THen I'll check the HJT log and I may want run a special fix, just to be safe. CLeaning her computer is going to take some time, and if at all possible, keep it off line until we are done (apart from what is needed to clean it)


First:
Download the latest version of Ewido.

http://www.ewido.net/en/download/

Install it and reboot your computer.

Open Ewido.

1. Click the Update Now line.
2. After the update is completed click the "Scanner" button on the top line.
3. Click the "Complete System Scan" line to begin the scan.
4. When the scan is complete, click the "Save Report" button to save the report.
5. Click the "Scanner" button on the top to return to the results.
6. Click the "Set All Elements to" Recommended Action.
7. Click the "Apply all actions" button.
8. Click on the "Reports" Icon at the top.
9. Click on the report that was generated today to see the results on the right side.
10. Highlight the results on the right side and copy and paste them into your reply.


Second:
Reboot in Safe Mode* and run HiJackThis. <-- IMPORTANT

Check the following items in HijackThis.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {F5C3F060-3AD4-3474-A2D8-6C1336AD30E1} - C:\WINDOWS\System32\uojm.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: TChkBHO Class - {5F2B369D-7486-47C7-A0FA-7D0943A2D8C0} - C:\WINDOWS\system32\odykm.dll (file missing)
O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll
O2 - BHO: (no name) - {F5C3F060-3AD4-3474-A2D8-6C1336AD30E1} - C:\WINDOWS\System32\uojm.dll

O4 - HKLM\..\Run: [qWqo2q] C:\documents and settings\rachel\local settings\temp\qWqo2q.exe
O4 - HKLM\..\Run: [jIo6SC9Ui] C:\documents and settings\rachel\local settings\temp\jIo6SC9Ui.exe
O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\System32\IEHost.exe
O4 - HKLM\..\Run: [04c911032b26] C:\WINDOWS\System32\ccfgnt98.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [fafd1233f03c] C:\WINDOWS\System32\Audio3D0.exe
O4 - HKLM\..\Run: [Jpswy] C:\Program Files\Tmnxsaa\Uwwwse.exe
O4 - HKLM\..\Run: [wnddrv] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [iissrv] C:\WINDOWS\iissrv.exe
O4 - HKLM\..\Run: [vidmon] C:\WINDOWS\System32\vidmon\vidmon.exe
O4 - HKLM\..\Run: [kcxin] C:\DOCUME~1\Rachel\LOCALS~1\Temp\app7B.tmp
O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\System32\nfomon\nfomon.exe
O4 - HKLM\..\Run: [TopSearch] C:\Program Files\TopSearch\TopSearch.exe
O4 - HKLM\..\Run: [779T35O] cmuhits.exe
O4 - HKCU\..\Run: [Brhgdgek] C:\WINDOWS\System32\WNLOGO~1.EXE
O4 - HKCU\..\Run: [Iinl] "C:\PROGRA~1\COMMON~1\TSKS~1\dexplore.exe" -vt rbnd

O20 - AppInit_DLLs:


Close all windows except HijackThis and click Fix checked.


While still in Safe Mode*, delete the following: (you may need to show hidden files**)
(Files specified without a full path will be located in C:\Windows\ or C:\Windows\System32\)
C:\Program Files\PeDevice\ <--delete entire folder,
C:\documents and settings\rachel\local settings\temp\qWqo2q.exe
C:\documents and settings\rachel\local settings\temp\jIo6SC9Ui.exe
C:\WINDOWS\System32\IEHost.exe
C:\WINDOWS\System32\ccfgnt98.exe
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
C:\WINDOWS\System32\Audio3D0.exe
C:\Program Files\Tmnxsaa\ <--delete entire folder,
C:\WINDOWS\svchost.exe
C:\WINDOWS\iissrv.exe
C:\WINDOWS\System32\vidmon\ <--delete entire folder,
C:\DOCUME~1\Rachel\Local Settings\Temp\app7B.tmp
C:\WINDOWS\System32\nfomon\ <--delete entire folder,
C:\Program Files\TopSearch\ <--delete entire folder,
C:\WINDOWS\System32\cmuhits.exe
C:\WINDOWS\System32\WNLOGO~1.EXE
C:\Program Files\Common Files\TSKS~1\dexplore.exe


*How to Boot into Safe mode: http://service1.symantec.com/SUPPORT/tsgen...001052409420406
**Show Hidden and System files and folders: http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Also, uncheck the boxes for hiding known file extensions and hiding protected operating system files. We want to see it all. When we finish here, it would be a good idea to rehide the protected operating system files but leave the rest to be shown.

Reboot in normal mode

Run HiJackThis again and post a new log in this thread.
dieseltkd
Here are the new reports:

Here is the Ewido report:
C:\Temp\180SAInstaller.exe/clientax.dll -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\WINDOWS\system32\asycfilt.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\browser9.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\terabyte.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\unwise56.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\Program Files\Aprps -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\AI_07-09-2006.log -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\AI_08-09-2006.log -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\AI_12-09-2006.log -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\CxtPls.dll -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\CxtPls.exe -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\ProxyStub.dll -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\WinGenerics.dll -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\ace.dll -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\atl.dll -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\libexpat.dll -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\plg0 -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\plg0\cxtpls.dll -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\pstub0 -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\pstub0\proxystub.dll -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\uninstaller.exe -> Adware.Apropos : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msfaol.dll -> Adware.ClientMan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Dsi -> Adware.Delfin : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users\Application Data\pcsvc\patchme.exe -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users\Application Data\wsxs\patchme.exe -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Uninstall Information\RemoveWebDP.exe -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nfomon\nfo.ocx -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nfomon\nfom.dll -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ezPopStub.exe -> Adware.EZula : Cleaned with backup (quarantined).
C:\WINDOWS\woinstall.exe -> Adware.EZula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{E1412445-4FF8-410e-8D24-F2CF86B171A4} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E1412445-4FF8-410e-8D24-F2CF86B171A4} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rotue -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msiaih.dll -> Adware.Ipend : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msnimk.gif -> Adware.Ipend : Cleaned with backup (quarantined).
HKLM\SOFTWARE\MaxSpeed -> Adware.Maxspeed : Cleaned with backup (quarantined).
C:\WINDOWS\system32\HyperLinker2.exe -> Adware.MDH : Cleaned with backup (quarantined).
C:\WINDOWS\system32\HyperLinker3.exe -> Adware.MDH : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ilmdat.exe -> Adware.MDH : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__W_N_L_O_G_O_~_1_._E_X_E_ -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ati2evxx.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\uojm.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed\Privacy Info.url -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed\Terms and Conditions.url -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed\Uninstall Instructions.url -> Adware.SideFind : Cleaned with backup (quarantined).
C:\WINDOWS\system32\audiosrv.exe -> Adware.UrlSpy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Common.Buttons -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\Temp\Remover.exe -> Adware.Winad : Cleaned with backup (quarantined).
C:\WINDOWS\system32\lcinstaller.exe -> Adware.WinAD : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{00000000-15D9-4736-AB29-131578A45F2B} -> Adware.Wordsonweb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ms.exe -> Downloader.VB.cw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Aau4zZ.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Biz1J.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Biz1K.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\BmsZu0w1.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Bmyf.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\BuqQXbj.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Bzw65.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Cij14Y6.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Cljy.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Cnma.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Cxe0n.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\CzidS.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\DiiCd.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Ditm4YYT.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Dxv0WMP.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Dzg1p5.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\EgtIq.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Ekm2OAS.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\EmoY0lW.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\EpaNv5.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Fah1q5.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\FepP.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\FmrC.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Gga6fez.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\GnsDj.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Grxe.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Hcj2s6.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Hdk276.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\HieuD52.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\HjwMu62.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\HqjsNv.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\HrfU4.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Hyza4.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Idk277f.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Idk277g.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Ihjc.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Ikd7y3Fz.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Iqa4.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Irktpx.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Ixfi0U.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\KnlaMVh.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\KnuQDC55.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\KopJ3f.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\KrwH5f.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\KueFa9.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\LtctEJ.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\MpncNxj.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Mszsh9f.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Mts1.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Npcs9W4P.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\NtvO.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\NwgIc08.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\OkqN0Y44.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\OvgQC.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Ozf42o.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Ozkx1Xc1.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\PvxQ.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Qep78k13.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\QhqYq.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\QvvpP4T.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\QyjTF.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Rakm220.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Rky8W.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Rnfhy4bo.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\RntQDB55.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Rtgw.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\RuaXK.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Sfm6d.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\SjsAtZ.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Szqu0w1A.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Txma1lp.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Ubsw.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\UzwcWo.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\UzxdWo.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Vcw5Bb.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Vgr1.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Vhp7fw.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Vins58.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Vju9053.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\VscW.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\VvxQ4Tw.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Wfpr4KF2.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\WmdD.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Xex6Dcx.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Xiub3v26.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Xowexd5.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\YxaS5Vz.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Zcrg36vE.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Zfl8.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Zitu.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ZjgV.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Zmt93a5.exe -> Downloader.VB.em : Cleaned with backup (quarantined).
C:\WINDOWS\iisvers.exe -> Hijacker.Agent.ep : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wsrchc3.dll -> Hijacker.Agent.ep : Cleaned with backup (quarantined).
C:\WINDOWS\wsrv32.exe -> Hijacker.Agent.ep : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mseggo.gif -> Logger.Delf.dx : Cleaned with backup (quarantined).
C:\Program Files\Gobjpyd\Ojcf.exe -> Trojan.Small.cy : Cleaned with backup (quarantined).

Here is her new Highjack This log:

Logfile of HijackThis v1.99.1
Scan saved at 11:19:19 PM, on 9/16/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\program files\support.com\client\bin\tgcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Symantec\SAV8\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\Program Files\Common Files\AOL\1137104828\ee\AOLHostManager.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\AOL\1137104828\ee\AOLServiceHost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Rachel\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\bin\tgcmd.exe /server
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\Symantec\SAV8\vptray.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137104828\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab
O16 - DPF: {9184D21C-9835-42C5-A883-EA8BE7FC048D} (Downloader Class) - https://www.shop.intuit.com/commerce/accoun...bles/ie/IDA.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj...ploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg...,15/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\Symantec\SAV8\Rtvscan.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: IBM AFS Client (TransarcAFSDaemon) - Unknown owner - C:\Program Files\OpenAFS\Client\Program\afsd_service.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
LoPhatPhuud
Much cleaner. Now lets followup and then do some checking. Note that Vundo may prove negative, I just want to be sure since some indicators were there.

First:
Please download
VundoFix.exe
to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button."
when VundoFix appears at reboot.


Second:
Run HiJackThis and press the Scan' button

When the scan is finished:
Check the following items in HijackThis.
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load

O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)

Close all windows except HijackThis and click Fix checked.

Reboot in normal mode

Delete the following file:
C:\WINDOWS\System32\bridge.dll

Run HiJackThis again and post a new log in this thread.


Last:
Please download SilentRunners from here:
http://www.silentrunners.org/Silent%20Runners.zip

Unzip it to the desktop and double-click on it.
Silent Runners will ask if you want to skip the supplementary search.
Please select 'No' to include them.

The program will take longer to run, but will give us more information.

If you get any kind of warning message about scripts, please choose to allow the script to run.

When the scan is finished, a message will pop up and a logfile will have been created on the desktop.
The logfile is named 'Startup Programs' by default and will be located where the program is.

Please post the entire contents of this logfile for me to see.
Second:
dieseltkd
Here is her VundoFix file:


VundoFix V6.1.5

Checking Java version...

Scan started at 10:03:31 AM 9/17/2006

Listing files found while scanning....

No infected files were found.


Beginning removal...

Here is her HiJackThis file:

Logfile of HijackThis v1.99.1
Scan saved at 11:12:52 AM, on 9/17/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\program files\support.com\client\bin\tgcmd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Symantec\SAV8\vptray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Common Files\AOL\1137104828\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1137104828\ee\AOLServiceHost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Rachel\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\bin\tgcmd.exe /server
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\Symantec\SAV8\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137104828\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab
O16 - DPF: {9184D21C-9835-42C5-A883-EA8BE7FC048D} (Downloader Class) - https://www.shop.intuit.com/commerce/accoun...bles/ie/IDA.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj...ploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg...,15/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\Symantec\SAV8\Rtvscan.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: IBM AFS Client (TransarcAFSDaemon) - Unknown owner - C:\Program Files\OpenAFS\Client\Program\afsd_service.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe


Here is SilentRunners file:

"Silent Runners.vbs", revision 48, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup" [MS]
"nwiz" = "nwiz.exe /installquiet" ["NVIDIA Corporation"]
"ATIModeChange" = "Ati2mdxx.exe" ["ATI Technologies, Inc."]
"ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
"IgfxTray" = "C:\WINDOWS\System32\igfxtray.exe" ["Intel Corporation"]
"HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
"ezShieldProtector for Px" = "C:\WINDOWS\System32\ezSP_Px.exe" ["Easy Systems Japan Ltd."]
"ZTgServerSwitch" = "c:\program files\support.com\client\bin\tgcmd.exe /server" ["Support.com, Inc."]
"AGRSMMSG" = "AGRSMMSG.exe" ["Agere Systems"]
"VAIO Recovery" = "C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" ["Sony Electronics Inc"]
"HPDJ Taskbar Utility" = "C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" ["HP"]
"HP Software Update" = ""C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"" ["Hewlett-Packard Company"]
"vptray" = "C:\PROGRA~1\Symantec\SAV8\vptray.exe" ["Symantec Corporation"]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"HostManager" = "C:\Program Files\Common Files\AOL\1137104828\ee\AOLHostManager.exe" ["America Online, Inc."]
"ViewMgr" = "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" ["Viewpoint Corporation"]
"!ewido" = ""C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized" ["Anti-Malware Development a.s."]

HKLM\Software\Microsoft\Active Setup\Installed Components\
{306D6C21-C1B6-4629-986C-E59E1875B8AF}\(Default) = (no title provided)
\StubPath = ""C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}\(Default) = "AOL Toolbar Launcher"
-> {HKLM...CLSID} = "AOL Toolbar Launcher"
\InProcServer32\(Default) = "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll" ["America Online, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {HKLM...CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> {HKLM...CLSID} = "Desktop Explorer"
\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM...CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\Program Files\Real\RealOne Player\rpshellext.dll" [file not found]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
"{BDA77241-42F6-11d0-85E2-00AA001FE28C}" = "LDVP Shell Extensions"
-> {HKLM...CLSID} = "VpshellEx Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
"{DC515C27-6CAC-11D1-BAE7-00C04FD140D2}" = "AFS Client Shell Extension"
-> {HKLM...CLSID} = "AFS Client Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\OpenAFS\Client\Program\afs_shl_ext.dll" ["OpenAFS Project"]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {HKLM...CLSID} = "Portable Media Devices"
\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {HKLM...CLSID} = "Portable Media Devices Menu"
\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "ewido anti-spyware 4.0"
-> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
\InProcServer32\(Default) = "C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll" ["Anti-Malware Development a.s."]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]
INFECTION WARNING! NavLogon\DLLName = "C:\WINDOWS\System32\NavLogon.dll" [null data]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AFS Client Shell Extension\(Default) = "{DC515C27-6CAC-11D1-BAE7-00C04FD140D2}"
-> {HKLM...CLSID} = "AFS Client Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\OpenAFS\Client\Program\afs_shl_ext.dll" ["OpenAFS Project"]
ewido anti-spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM...CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Program Files\ewido anti-spyware 4.0\context.dll" ["Anti-Malware Development a.s."]
LDVPMenu\(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}"
-> {HKLM...CLSID} = "VpshellEx Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
ewido anti-spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM...CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Program Files\ewido anti-spyware 4.0\context.dll" ["Anti-Malware Development a.s."]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
AFS Client Shell Extension\(Default) = "{DC515C27-6CAC-11D1-BAE7-00C04FD140D2}"
-> {HKLM...CLSID} = "AFS Client Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\OpenAFS\Client\Program\afs_shl_ext.dll" ["OpenAFS Project"]
LDVPMenu\(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}"
-> {HKLM...CLSID} = "VpshellEx Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]


Active Desktop and Wallpaper:
-----------------------------

Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Rachel\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


Startup items in "Rachel" & "All Users" startup folders:
--------------------------------------------------------

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{DE9C389F-3316-41A7-809B-AA305ED9D922}"
-> {HKLM...CLSID} = "AOL Toolbar"
\InProcServer32\(Default) = "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll" ["America Online, Inc."]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{DE9C389F-3316-41A7-809B-AA305ED9D922}" = "AOL Toolbar"
-> {HKLM...CLSID} = "AOL Toolbar"
\InProcServer32\(Default) = "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll" ["America Online, Inc."]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{3369AF0D-62E9-4BDA-8103-B4C75499B578}\
"ButtonText" = "AOL Toolbar"
"CLSIDExtension" = "{DE9C389F-3316-41A7-809B-AA305ED9D922}"
-> {HKLM...CLSID} = "AOL Toolbar"
\InProcServer32\(Default) = "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll" ["America Online, Inc."]

{AC9E2541-2814-11D5-BC6D-00B0D0A1DE45}\
"ButtonText" = "AIM"
"Exec" = "C:\Program Files\AIM\aim.exe" ["America Online, Inc."]


Miscellaneous IE Hijack Points
------------------------------

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://www.sony.com/vaiopeople

Missing lines (compared with English-language version):
[Strings]: 1 line


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

ewido anti-spyware 4.0 guard, ewido anti-spyware 4.0 guard, "C:\Program Files\ewido anti-spyware 4.0\guard.exe" ["Anti-Malware Development a.s."]
VAIO Media Music Server, VAIOMediaPlatform-MusicServer-AppServer, ""C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server"" ["Sony Corporation"]
VAIO Media Music Server (HTTP), VAIOMediaPlatform-MusicServer-HTTP, ""C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP"" ["Sony Corporation"]
VAIO Media Music Server (UPnP), VAIOMediaPlatform-MusicServer-UPnP, "C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe" ["Sony Corporation"]
VAIO Media Photo Server, VAIOMediaPlatform-PhotoServer-AppServer, "C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe" ["Sony Corporation"]
VAIO Media Photo Server (HTTP), VAIOMediaPlatform-PhotoServer-HTTP, ""C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP"" ["Sony Corporation"]
VAIO Media Photo Server (UPnP), VAIOMediaPlatform-PhotoServer-UPnP, "C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe" ["Sony Corporation"]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
hpzsnt08\Driver = "hpzsnt08.dll" ["HP"]


----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 10 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 18 seconds.
---------- (total run time: 81 seconds)
LoPhatPhuud
Great! The Vundo log was negative (good) and the Silent Runners log was clean. Keep Ewido installed. After the trial period the real time protection will stop but it is an excellent on demand scanner that should be run weekly along with your AntiVirus. Make sure the definitions are kept updated.

Here is some more info on steps you can take..

Now, unless there are still issues not reflected in your log(s), your system is clean and we are finished. Here are some simple steps you can take to reduce the chance of infection in the future.

1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system and Internet Explorer. This includes SP1 and SP2 if you use Windows XP. The first defense against infection is a properly patched Operating System.
a. Windows Update: http://windowsupdate.microsoft.com/

If you have Word, Excel, Outlook or other Office programs installed. Consider using Microsoft Update instead of Windows Update. See the FAQ page here for more information: http://update.microsoft.com/microsoftupdat...t.aspx?ln=en-us

Also, download and install Microsoft Baseline Analyzer.(Note that MBSA is only for Win 2000 SP3 or later and Office XP or later) When run, it will check system for security exposures, including missing updates. I suggest running it weekly. You can obtain more information here: http://www.microsoft.com/technet/security/...s/mbsahome.mspx


2. Check your Java Runtime version. (Current=1.5.0_08, aka Version 5.0, Update 8)
You can check the current version of the Java Runtime Modules installed by opening the Java Control Panel and selecting 'About' from the 'General' tab.
The current version can be downloaded from Sun here: http://java.sun.com/javase/downloads/index.jsp Scroll down the page to 'Java Runtime Environment (JRE) 5.0 Update 8' and press the 'Download' button. On the new web page, click the 'Accept License Agreement' button. Then select 'Windows Offline Installation, Multi-language' in the Windows Platform area just below the Accept button.

Note: Be sure to remove all prior versions using Add/Remove Programs before you install the new one. Remember to reboot after removal.

3. Adjust your security settings for ActiveX:
Select Internet Options from the Control Panels, or from Internet Explorer (Tools -> Internet Options)
Press 'default level', then OK
Now press "Custom Level."

In the ActiveX controls and plug-ins section set these options:
'Download signed ActiveX controls' - Prompt
'Download unsigned ActiveX controls' - Disable
'Initialize and script ActiveX controls not maked as safe'- Disable
All other options accept the default

For Windows XP2 SP2 users, check this link for additional steps you can take to secure Internet Explorer: http://www.microsoft.com/technet/security/...xp/iesecxp.mspx
Also,for Sp2 SP2 and IE users, in IE, Tools -> Manage Add-ons will give you a list of all BHO's, Extensions, and ActiveX modules installed on your computer. You can update, enable or disable them.

4. Download and install the following free programs
a. SpywareBlaster (ActiveX protection): http://www.javacoolsoftware.com/spywareblaster.html
b. IE/Spyad (Malicious Site protection): http://www.spywarewarrior.com/uiuc/resource.htm#IESPYAD
You may want to consider also installing ZonedOut (http://www.funkytoad.com/zonedout.htm) to handle the Restricted Site List.
c. Hoster (HOSTS file manager): http://www.funkytoad.com/hoster.htm

5. Install Spyware Detection and Removal Programs:
You may also want to consider installing one (or more) of the following:
a. Windows Defender: http://www.microsoft.com/athome/security/s...re/default.mspx
NOTE: Windows Defender only runs on Windows 2000, XP, Vista, and 2003.
b. Spybot S&D: http://security.kolla.de/index.php?lang=en&page=download
c. AdAware Personal: http://www.lavasoft.de/

Use these programs to regularly scan your system for and remove many forms of spyware/malware. I recommend a combination of Microsoft Spyware and TeaTimer from Spybot S&D.

If you use, or plan on using, additional spyware/malware detection and/or removal programs, please check Items 8 and 9.

6. Install A Toolbar to Detect Phishes
Phishing is prevalent and on the rise. Make sure the site you go to is real. Your ISP may offer a toolbar to warn you of fake sites or you can choose one of the following
a. Spoofstick Toolbar
b. Netcraft Toolbar
c. PhishGuard

7. Reset System Restore
If you are using Windows ME or Windows XP, please reset your System Restore. See Windows help for information.

8. Clean Temporary Files and Folders
Download and install the disk cleanup utility called Cleanup! from here:
http://cleanup.stevengould.org/

Cleanup! will get rid of any malware which may be hiding in your temp folders (a common hiding place). You may also regain a massive amount of disk space.
Here is a tutorial which describes its usage:
http://www.bleepingcomputer.com/forums/tutorial93.html

Run the disk cleanup utility called Cleanup! that you have already downloaded and installed
Check the custom settings to your liking under options, but be sure to delete temporary files and temporary internet files for all user profiles. Also, cleanout the prefetch folder and the recycle bin.
Then reboot into normal mode to let it clean out the remaining files.

9. Rogue/Suspect Anti-Spyware
Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List. It will save you a lot of grief, as well as money if you are thinking of purchasing. Here is the link: http://www.spywarewarrior.com/rogue_anti-spyware.htm

10. Anti-Spyware Programs Compared
Want to know just how effective your anti-spyware program is? Wonder how well any of the "rogue" programs listed above work? Check this link for an independent comparison of several anti-spyware programs: http://www.spywarewarrior.com/asw-test-guide.htm

11. Alternate Browser
Consider using an alternate browser as your default. I recommend and use Firefox as my primary browser. It is still necessary to keep Internet Explorer current and protected in order to use Windows Update.


For more information about Spyware, the tools available, and other informative material, including information on how you may have been infected in the first place, please check out this link: http://forum.gladiator-antivirus.com/index...?showtopic=9857

"It is your responsibility to read and adhere to the End User Licensing Agreement (EULA) of all software and services mentioned."

Good luck, and thanks for coming to our forums for help with your security and malware issues.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.